Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 14.10.2014, 10:11   #16
schrauber
/// the machine
/// TB-Ausbilder
 

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



ok, dann bleiben noch 200

ESET meckert immer viel an, aber da ist schon einiges dabei was runter muss
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 16.10.2014, 13:43   #17
sugus666
 
Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Status / next step?



hallo Schrauber
.... ich biin etwas verunsichert. Seit dem Poste # 9 hänge ich etwas in der Luft, der damalige Status war ja, dass ich das Tool ESET deinstallierenund gelöschen musste, die 250 (noch nicht bewerteten) Befunde aber sind m.E. noch unbearbeitet auf dem System -was soll/muss für die abschliessende Bereinigung noch machen?

Gruss & Dank für deine Bemühungen
sugus666
__________________


Alt 16.10.2014, 18:56   #18
schrauber
/// the machine
/// TB-Ausbilder
 

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



Was meinst Du mit in der Luft hängen? Ich hab gesagt Du sollst alles löschen was ESET gefunden hat. Die Sachen die Du sicher kennst kannste natürlich behalten.

Poste bitte mal ein frisches FRST Log, sollten aber durch sein.
__________________
__________________

Alt 17.10.2014, 07:17   #19
sugus666
 
Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



hi Schrauber
das muss ein Missverständnis sein... bei welchem Post hast du mir geschrieben wegen der Löschung (in # 9 war die Rde von ESET Programm / Daten / Papierkorb). Sind die Befunde irgendwo in Quarathäne? Mit welchem Tool soll gelöscht werden?
Gruss
sugus666


Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-10-2014
Ran by Marcel at 2014-10-17 08:12:37
Running from F:\90 Daten Systemordner\Downloads_sys
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 15 Plugin (HKLM-x32\...\{AF82C1A9-56DC-4CCD-A36C-CAE56D541DFA}) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Photoshop Album 2.0 Starter Edition (HKLM-x32\...\{11B569C2-4BF6-4ED0-9D17-A4273943CB24}) (Version: 2.00.100 - Adobe Systems, Inc.)
Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
AllShare Framework DMS (HKLM\...\{83232C27-8C3F-44A5-9EB2-BB7161228ADD}) (Version: 1.3.23 - Samsung)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS Wireless Router Device Discovery Utility (HKLM-x32\...\{09CDCA35-23FF-4ED6-AFDA-BBD55235CE4B}) (Version: 1.4.6.5 - ASUS)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Brother MFL-Pro Suite MFC-9440CN (HKLM-x32\...\{C83FB11D-9EC6-49D7-99A7-DDDB2264883C}) (Version: 1.0.1.0 - Brother Industries, Ltd.)
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.22 - Cliqz.com)
Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CPUID CPU-Z 1.69.2 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.30.00 - Lenovo Group Limited) Hidden
DisplayLink Core Software (HKLM\...\{BB07E020-7224-4EC3-864E-2AA0BF42A7DD}) (Version: 7.4.51572.0 - DisplayLink Corp.)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.1.51 - Lenovo)
Energy Manager (x32 Version: 1.0.1.51 - Lenovo) Hidden
eTax.zug 2013 jP 1.0.0 (HKLM-x32\...\9994-2633-2807-7220) (Version: 1.0.0 - Information Factory AG)
Evernote v. 5.5.3 (HKLM-x32\...\{B1A0F908-1448-11E4-8684-00163E98E7D0}) (Version: 5.5.3.4236 - Evernote Corp.)
FileZilla Client 3.9.0.5 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.5 - Tim Kosse)
FileZilla Server (HKLM-x32\...\FileZilla Server) (Version: beta 0.9.44 - FileZilla Project)
FreeFileSync 6.9 (HKLM-x32\...\FreeFileSync) (Version: 6.9 - Zenju)
Freemake Video Converter Version 4.1.4 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.4 - Ellora Assets Corporation)
Freemake Video Downloader (HKLM-x32\...\Freemake Video Downloader_is1) (Version: 3.7.0 - Ellora Assets Corporation)
FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 1.0.1 - )
ICP Basis 7.00 (HKLM-x32\...\ICP Basis 7.00) (Version:  - )
inSSIDer Home (HKLM-x32\...\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
Intel Experience Center - Configuration (x32 Version: 1.9.0.8 - Intel) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 7.1.0.2103 - Intel Corporation)
Intel(R) Experience Center Desktop Software (HKLM-x32\...\{85de612b-ee05-476a-87cc-52e5740de420}) (Version: 1.9.0.8 - Intel)
Intel(R) Experience Center Driver (Version: 1.9.0.8 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel(R) PRO/Wireless Driver (Version: 16.05.3000.0599 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3304 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden
Intel(R) Smart Connect Technology (HKLM\...\{D6FBF816-ACB8-46CC-ACC6-C8BBA85F497D}) (Version: 4.2.40.2418 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{1c7272f2-45cf-469f-b7e9-17c6b212549c}) (Version: 16.5.3 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 7 Update 67 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417067FF}) (Version: 7.0.670 - Oracle)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
join.me (HKCU\...\JoinMe) (Version: 1.17.0.153 - LogMeIn, Inc.)
K-Lite Codec Pack 9.3.0 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.3.0 - )
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.29.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.4.5.35 - SunplusIT)
Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab)
Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.0 - Lenovo)
Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.0.13.12271 - Lenovo)
Lenovo USB Graphics (HKLM\...\{7257526E-B74A-488E-BA2E-56327482B06B}) (Version: 7.4.51587.0 - Lenovo)
Lenovo VeriFace (HKLM\...\Lenovo VeriFace) (Version: 5.0.13.5261 - Lenovo)
Lenovo Yoga PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.1.9.3 - Lenovo)
Lenovo Yoga PhoneCompanion (x32 Version: 1.1.9.3 - Lenovo) Hidden
MailStore Home 8.2.0.9316 (HKLM-x32\...\MailStore Home_universal1) (Version: 8.2.0.9316 - MailStore Software GmbH)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Visio Professional 2003 (HKLM-x32\...\{90510407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Project Standard 2002 (HKLM-x32\...\{903A0407-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2915.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM-x32\...\{95140000-0137-0407-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation)
Mozilla Firefox 32.0.3 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0.3 (x86 de)) (Version: 32.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
My Swisscom Assistant (HKLM-x32\...\My Swisscom Assistant) (Version: 1.1.0.71 - Swisscom (Schweiz) AG)
NirSoft ShellExView (HKLM-x32\...\NirSoft ShellExView) (Version:  - )
Nitro Reader 3 (HKLM\...\{4756C731-B54E-451A-9AF1-86E8AB1BEBBB}) (Version: 3.5.6.5 - Nitro)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.1 - Notepad++ Team)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Private Tax 2013 1.4.0 (HKLM-x32\...\0579-4231-5684-8562) (Version: 1.4.0 - Information Factory AG)
Q-Dir (HKLM\...\Q-Dir) (Version:  - )
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7058 - Realtek Semiconductor Corp.)
ReminderInstaller (HKLM-x32\...\InstallShield_{48B99BC9-CEB0-485E-96B1-4609BC86D2DE}) (Version: 1.00.0000 - Absolute Software.)
ReminderInstaller (x32 Version: 1.00.0000 - Absolute Software.) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Samsung Link 2.0.0.1409291832 (HKLM\...\8474-7877-9059-0204) (Version: 2.0.0.1409291832 - Copyright 2013 SAMSUNG)
Sandboxie 4.12 (64-bit) (HKLM\...\Sandboxie) (Version: 4.12 - Sandboxie Holdings, LLC)
Screenpresso (HKCU\...\Screenpresso) (Version: 1.5.2.0 - Learnpulse)
Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Snapform Viewer 1.7.36 (HKLM\...\2841-5017-1617-4151) (Version: 1.7.36 - Ringler Informatik AG)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.8.7 - Synaptics Incorporated)
ThinkPad USB 3.0 Dock (HKLM-x32\...\{69109A9C-1D00-4A84-9ABF-AAE9CADD20DD}) (Version: 1.07.15 - Lenovo)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft en-us Dictionary (Version: 16.1.924.1 - Microsoft Corporation) Hidden
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2899475) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{23AE87D8-AB2F-4539-935C-442BC976F469}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.15 - Lenovo)
UserGuide (x32 Version: 1.0.0.15 - Lenovo) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WHS ProStation (HKCU\...\InstallShield_{E56B8E1D-8E90-46DC-AE55-EBA87ED69A5F}) (Version: 2.38.56.10.2 - WH SELFINVEST)
WHS ProStation (x32 Version: 2.38.56.10.2 - WH SELFINVEST) Hidden
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Driver Package - Lenovo (ACPIVPC) System  (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
XAMPP (HKLM-x32\...\xampp) (Version: 1.8.3-4 - Bitnami)
Yoga Picks (HKLM-x32\...\{267C8BA0-876B-4589-9F14-EFB84ABCEA7F}) (Version: 1.5.014.0106 - Lenovo)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1FA5F244-9468-D082-1262-D4EE85889A47} No File
CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Marcel\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Marcel\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5FB02946-9468-D082-10B9-C1AE85889A47} No File
CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Marcel\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Marcel\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

09-10-2014 21:21:58 Revo Uninstaller's restore point - Avira Savings Advisor
13-10-2014 06:41:12 Installed Java 7 Update 67
15-10-2014 09:21:46 Installed Oracle VM VirtualBox 4.3.18

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {04232B5E-E0AC-4061-BED7-2DB835B4BAE2} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {114B555B-6E44-421B-90EC-509925C4578F} - System32\Tasks\4Team updater => C:\Program Files (x86)\4Team Corporation\4Team-Updater\4Team-Updater.exe
Task: {11CF1733-D8D7-4871-9BB3-A8BBE91DE674} - System32\Tasks\MsgUpdateCheck (ed5bac9b-5ca0-4f99-aa46-a881a08ff6f3) => C:\SmartDraw CI\MarkedUp\tray\TrayNotifierNET35.exe [2014-04-30] (MarkedUp Inc)
Task: {19676596-235C-492C-9BBD-B736CE6B4742} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {47DAC2D1-53B1-4FA7-BBF0-C85625213A6A} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-16] (Adobe Systems Incorporated)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4A43190F-D283-4BB8-BEF5-86B2DB9FC4F4} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
Task: {5177C064-CC6E-4D71-BE7A-B42FA270C361} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {52F8F128-3155-435F-B4DD-99F8EC651CC8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-09-10] (Microsoft Corporation)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6AB1569F-4369-4546-88C8-735FD098A9AD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {74EAEBD2-C829-4716-8089-1355EFA5D9EB} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {79A937C3-5C94-4168-8180-CE1A5CFF2A6F} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2014-08-18] ()
Task: {7BA762F4-A324-42D5-8657-FF70FD0439B1} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {945A01A3-31C7-48BE-ADA2-064B92034779} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {AB1B2D4F-AD1B-4388-807F-BA561CDE4FD9} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-03-28] (Lenovo)
Task: {C71A6436-7370-460F-864E-09FE1370A395} - System32\Tasks\SDMsgUpdate (TE) => C:\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: {CD89B46E-816E-4B02-A703-1EF419CC48DE} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DDA1C19D-4569-46B7-A2D6-43AA1E21C36B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-10-10] (AVAST Software)
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {F97DB1F3-B11D-48E1-B038-8906E0AA1B7E} - System32\Tasks\SDMsgUpdate (Local) => C:\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: {FFA9A996-FEC2-420E-8B15-7FB5F295BCF6} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-29] (Synaptics Incorporated)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2013-08-02 02:31 - 2013-08-02 02:31 - 00198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2013-08-02 02:31 - 2013-08-02 02:31 - 00054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2013-08-02 02:31 - 2013-08-02 02:31 - 00034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll
2014-03-28 08:55 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-08-30 09:15 - 2014-09-29 18:32 - 00025088 _____ () C:\Program Files\Samsung\Samsung Link\JniSys.dll
2014-08-30 09:15 - 2014-09-29 18:32 - 02633728 _____ () C:\Program Files\Samsung\Samsung Link\scone_proxy.dll
2014-08-30 09:15 - 2014-09-29 18:32 - 02540544 _____ () C:\Program Files\Samsung\Samsung Link\scone_stub.dll
2013-12-21 11:25 - 2013-12-21 11:25 - 00036864 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\JNIInterface.dll
2013-12-21 11:26 - 2013-12-21 11:26 - 00144384 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\ASFAPI.dll
2013-12-21 11:27 - 2013-12-21 11:27 - 00018944 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\MediaDB_Manager.dll
2013-10-22 09:52 - 2013-10-22 09:52 - 00030720 _____ () C:\windows\SYSTEM32\MediaDB64.dll
2013-10-22 09:52 - 2013-10-22 09:52 - 00908800 _____ () C:\windows\SYSTEM32\ContentDirectoryPresenter64.dll
2013-12-21 11:27 - 2013-12-21 11:27 - 00521728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\DMS_Manager.dll
2013-07-23 19:19 - 2013-07-23 19:19 - 00049152 _____ () C:\windows\SYSTEM32\boost_date_time-vc90-mt-1_47.dll
2013-07-23 19:19 - 2013-07-23 19:19 - 00016896 _____ () C:\windows\SYSTEM32\boost_system-vc90-mt-1_47.dll
2013-07-23 19:19 - 2013-07-23 19:19 - 00058880 _____ () C:\windows\SYSTEM32\boost_thread-vc90-mt-1_47.dll
2013-07-23 19:19 - 2013-07-23 19:19 - 00299520 _____ () C:\windows\SYSTEM32\boost_serialization-vc90-mt-1_47.dll
2014-08-30 09:16 - 2014-08-30 09:16 - 00669696 _____ () C:\Windows\Temp\sqlite-3.7.151-amd64-sqlitejdbc.dll
2014-08-30 09:15 - 2014-09-29 18:32 - 00049664 _____ () C:\Program Files\Samsung\Samsung Link\JniIO.dll
2014-08-30 09:15 - 2014-09-29 18:32 - 00500224 _____ () C:\Program Files\Samsung\Samsung Link\utils\MetaExtractorDLL.dll
2014-04-22 20:23 - 2005-04-22 13:36 - 00143360 ____N () C:\windows\system32\BrSNMP64.dll
2014-03-28 08:55 - 2014-03-28 08:55 - 00068368 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
2014-03-28 08:55 - 2014-03-28 08:55 - 00669288 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfDataStorageInterface.dll
2014-03-28 08:55 - 2014-03-28 08:55 - 00062224 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
2014-03-28 08:53 - 2014-01-07 00:14 - 00019440 _____ () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
2014-10-10 07:33 - 2014-10-10 07:33 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-10-15 11:46 - 2014-10-15 11:46 - 02874368 _____ () C:\Program Files\AVAST Software\Avast\defs\14101500\algo.dll
2014-10-16 08:18 - 2014-10-16 08:18 - 02874368 _____ () C:\Program Files\AVAST Software\Avast\defs\14101506\algo.dll
2013-12-11 16:46 - 2013-12-11 16:46 - 01114624 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DMSManager.dll
2013-07-23 19:18 - 2013-07-23 19:18 - 00227840 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_serialization-vc90-mt-1_47.dll
2013-07-23 19:18 - 2013-07-23 19:18 - 00038912 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_date_time-vc90-mt-1_47.dll
2013-07-23 19:18 - 2013-07-23 19:18 - 00012800 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_system-vc90-mt-1_47.dll
2013-07-23 19:18 - 2013-07-23 19:18 - 00046592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_thread-vc90-mt-1_47.dll
2013-10-22 09:48 - 2013-10-22 09:48 - 00707072 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ContentDirectoryPresenter.dll
2013-10-24 16:53 - 2013-10-24 16:53 - 00107008 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMCDP.dll
2013-12-11 16:46 - 2013-12-11 16:46 - 00102400 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\FolderCDP.dll
2013-10-24 16:53 - 2013-10-24 16:53 - 00032768 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\Autobackup.dll
2013-04-19 16:38 - 2013-04-19 16:38 - 00055808 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RosettaAllShare.dll
2013-12-11 16:46 - 2013-12-11 16:46 - 00077312 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MetadataFramework.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00520234 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\sqlite3.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00450560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MoodExtractor.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 05717504 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMImgExtractor.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00028672 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AutoChaptering.dll
2013-10-25 19:49 - 2013-10-25 19:49 - 00028160 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AudioExtractor.dll
2013-12-11 16:45 - 2013-12-11 16:45 - 00017920 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoExtractor.dll
2013-10-25 19:53 - 2013-10-25 19:53 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageExtractor.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00013824 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\TextExtractor.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00147456 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexpat.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoThumb.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00064000 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ID3Driver.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00023040 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RichInfoDriver.dll
2013-10-25 19:53 - 2013-10-25 19:53 - 00117248 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ThumbnailMaker.dll
2013-12-11 16:45 - 2013-12-11 16:45 - 00134144 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoMetadataDriver.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\SECMetaDriver.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\photoDriver.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 04671488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avcodec-52.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00686080 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avformat-52.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00070656 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avutil-50.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00152064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\swscale-0.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00366592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\tag.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00289792 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libThumbnail.dll
2013-10-25 19:53 - 2013-10-25 19:53 - 01033728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageMagickWrapper.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 00290816 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libKeyFrame.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00399826 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexif-12.dll.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 00044032 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\us.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-03-28 08:39 - 2013-08-08 22:25 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2009-02-26 13:46 - 2009-02-26 13:46 - 00064344 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll
2011-06-22 11:46 - 2011-06-22 11:46 - 00434016 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll
2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
2014-10-10 07:33 - 2014-10-10 07:33 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-07-25 16:22 - 2014-07-25 16:22 - 00436576 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
2014-07-25 16:22 - 2014-07-25 16:22 - 00318304 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
2014-03-28 08:55 - 2014-03-28 08:55 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
2014-09-25 09:57 - 2014-09-25 09:57 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Marcel\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\StartupFolder: => "Secunia PSI Tray.lnk"
HKLM\...\StartupApproved\Run: => "BTMTrayAgent"
HKLM\...\StartupApproved\Run: => "Yoga PhoneCompanion"
HKLM\...\StartupApproved\Run: => "AutoStartTransition"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "Yoga Picks"
HKLM\...\StartupApproved\Run32: => "BrMfcWnd"
HKLM\...\StartupApproved\Run32: => "ControlCenter3"
HKLM\...\StartupApproved\Run32: => "FileZilla Server Interface"
HKLM\...\StartupApproved\Run32: => "My Swisscom Assistant"
HKCU\...\StartupApproved\Run: => "AshSnap"

========================= Accounts: ==========================

Administrator (S-1-5-21-3121602427-3534730855-1075997385-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-3121602427-3534730855-1075997385-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3121602427-3534730855-1075997385-1003 - Limited - Enabled)
Marcel (S-1-5-21-3121602427-3534730855-1075997385-1001 - Administrator - Enabled) => C:\Users\Marcel

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/17/2014 08:11:19 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (10/16/2014 06:20:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WHS ProStation.exe, Version: 2.38.56.10, Zeitstempel: 0x2a425e19
Name des fehlerhaften Moduls: log4cxx.dll, Version: 0.0.0.0, Zeitstempel: 0x48f48443
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000061b2
ID des fehlerhaften Prozesses: 0x17d4
Startzeit der fehlerhaften Anwendung: 0xWHS ProStation.exe0
Pfad der fehlerhaften Anwendung: WHS ProStation.exe1
Pfad des fehlerhaften Moduls: WHS ProStation.exe2
Berichtskennung: WHS ProStation.exe3
Vollständiger Name des fehlerhaften Pakets: WHS ProStation.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WHS ProStation.exe5

Error: (10/16/2014 04:49:55 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (10/16/2014 03:54:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WHS ProStation.exe, Version: 2.38.56.10, Zeitstempel: 0x2a425e19
Name des fehlerhaften Moduls: log4cxx.dll, Version: 0.0.0.0, Zeitstempel: 0x48f48443
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000061b2
ID des fehlerhaften Prozesses: 0x2004
Startzeit der fehlerhaften Anwendung: 0xWHS ProStation.exe0
Pfad der fehlerhaften Anwendung: WHS ProStation.exe1
Pfad des fehlerhaften Moduls: WHS ProStation.exe2
Berichtskennung: WHS ProStation.exe3
Vollständiger Name des fehlerhaften Pakets: WHS ProStation.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WHS ProStation.exe5

Error: (10/16/2014 11:43:12 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (10/16/2014 10:40:00 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (10/16/2014 08:26:26 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (10/15/2014 11:46:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: FreemakeUtilsService.exe, Version: 1.0.0.0, Zeitstempel: 0x5407f460
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.17278, Zeitstempel: 0x53eeb460
Ausnahmecode: 0xe0434352
Fehleroffset: 0x00012f71
ID des fehlerhaften Prozesses: 0x9a8
Startzeit der fehlerhaften Anwendung: 0xFreemakeUtilsService.exe0
Pfad der fehlerhaften Anwendung: FreemakeUtilsService.exe1
Pfad des fehlerhaften Moduls: FreemakeUtilsService.exe2
Berichtskennung: FreemakeUtilsService.exe3
Vollständiger Name des fehlerhaften Pakets: FreemakeUtilsService.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: FreemakeUtilsService.exe5

Error: (10/15/2014 11:46:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: FreemakeUtilsService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ArgumentException
Stack:
   at System.Security.Principal.SecurityIdentifier..ctor(System.String)
   at FreemakeUtilsService.Common.ToolbarInstallationChecker.GetSidToUsernameDictionary()
   at FreemakeUtilsService.Common.ToolbarInstallationChecker.CheckInfo(FreemakeUtilsService.Common.FreemakeToolbarsInfo)
   at FreemakeUtilsService.Statistics.Manager.StartToolbarInfoCheck()
   at FreemakeUtilsService.Statistics.Manager.SettingsSyncFailed(System.Object, System.EventArgs)
   at FreemakeUtilsService.Common.Synchronizer.OnWorkerCompleted(System.Object, System.ComponentModel.RunWorkerCompletedEventArgs)
   at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(System.ComponentModel.RunWorkerCompletedEventArgs)
   at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(System.Object)
   at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   at System.Threading.ThreadPoolWorkQueue.Dispatch()
   at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (10/15/2014 02:09:53 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005


System errors:
=============
Error: (10/17/2014 08:12:20 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 

Error: (10/17/2014 08:06:04 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 

Error: (10/17/2014 08:03:51 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 

Error: (10/17/2014 08:01:12 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 

Error: (10/17/2014 08:01:09 AM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (10/16/2014 07:49:43 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (10/16/2014 07:49:43 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (10/16/2014 07:49:43 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (10/16/2014 07:49:42 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (10/16/2014 07:49:42 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.


Microsoft Office Sessions:
=========================
Error: (09/12/2014 11:09:25 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6700.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3782 seconds with 480 seconds of active time.  This session ended with a crash.

Error: (06/27/2014 11:30:39 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1123 seconds with 360 seconds of active time.  This session ended with a crash.

Error: (05/21/2014 10:22:13 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6691.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2014-05-07 11:05:12.534
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-07 11:05:12.425
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-07 10:48:58.512
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-07 10:48:58.387
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 14:05:56.982
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-06 14:05:56.857
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-05 14:52:47.959
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-05 14:52:47.834
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements.

  Date: 2014-05-04 18:15:35.488
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-05-04 18:15:35.363
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7-4500U CPU @ 1.80GHz
Percentage of memory in use: 32%
Total physical RAM: 8104.27 MB
Available physical RAM: 5486.56 MB
Total Pagefile: 9384.27 MB
Available Pagefile: 6112.27 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:217.68 GB) (Free:148.41 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.89 GB) NTFS
Drive e: (MAESE_SAFE) (Fixed) (Total:465.75 GB) (Free:20.49 GB) NTFS
Drive f: (Daten) (Fixed) (Total:216.58 GB) (Free:185.33 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: D9341526)

Partition: GPT Partition Type.

========================================================
Disk: 1 (Size: 465.8 GB) (Disk ID: 8D399BC0)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

Alt 17.10.2014, 20:29   #20
schrauber
/// the machine
/// TB-Ausbilder
 

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



Vergiss es, ich hab grad gesehen dass die Formulierung nit zielführend war von meiner einer

Also bitte die Funde von ESET auf den externen Medien von Hand löschen, ausser du kennst die und weißt sie sind sauber.

FRST log bitte, keine Addition.txt

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 17.10.2014, 22:16   #21
sugus666
 
Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

FRST log




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014
Ran by Marcel (administrator) on SUGUS on 17-10-2014 23:11:18
Running from F:\90 Daten Systemordner\Downloads_sys
Loaded Profile: Marcel (Available profiles: Marcel & Administrator)
Platform: Windows 8.1 (X64) OS Language: Englisch (Vereinigte Staaten)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CrypKey (Canada) Ltd.) C:\Windows\System32\Crypserv.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
(FileZilla Project) C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
() C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(Learnpulse) C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Docking Station) C:\Program Files (x86)\Lenovo\USB3.0 Dock\igpxtskmgn64win8.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\ielowutil.exe
(Nenad Hrg (SoftwareOK.com)) C:\Program Files\Q-Dir\Q-Dir.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13656792 2013-10-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432 2013-09-26] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\windows\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-08-02] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-03-28] (Lenovo)
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-03-28] ()
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [59923440 2014-03-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-03-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2014-09-29] (Copyright 2013 SAMSUNG)
HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-06] (Lenovo)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [My Swisscom Assistant] => C:\Program Files (x86)\Swisscom\My Swisscom Assistant\MySwisscomAssistant_Launcher.exe [7503792 2014-02-27] (Swisscom (Schweiz) AG)
HKLM-x32\...\Run: [FileZilla Server Interface] => C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe [2322944 2014-04-08] (FileZilla Project)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-10] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [Screenpresso] => C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10983952 2014-09-22] (Learnpulse)
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [AshSnap] => C:\Program Files (x86)\Ashampoo\Ashampoo Snap 6\ashsnap.exe
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [msnmsgr] => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784392 2014-05-29] (Sandboxie Holdings, LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\igpxtskmgn.lnk
ShortcutTarget: igpxtskmgn.lnk -> C:\Program Files (x86)\Lenovo\USB3.0 Dock\igpxtskmgn64win8.exe (Docking Station)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\start.bat ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
SearchScopes: HKLM-x32 - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
SearchScopes: HKCU - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {A6616B31-4860-41E2-98E3-CA7649AF172F} file:///E:/00%20A%20Temp/001%20USB%20DOking/launch.ocx
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} -  No File
Handler-x32: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default
FF SelectedSearchEngine: Google
FF Homepage: https://www.google.ch/?gfe_rd=cr&ei=ochAVKyvLYuH8Qe04oCYBQ&gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\searchplugins\google-maps.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\abs@avira.com [2014-09-30]
FF Extension: Xmarks - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\foxmarks@kei.com [2014-09-17]
FF Extension: My Swisscom Assistant - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\{6A6114A5-EEF5-45F4-BCD1-B00A7B33E04B} [2014-05-15]
FF Extension: Cliqz Beta - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\cliqz@cliqz.com.xpi [2014-10-15]
FF Extension: Tab Mix Plus - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-09-30]
FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2014-04-29]
FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2014-04-29]
FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox [2014-09-06]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-10]
FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\extensions\cliqz@cliqz.com

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-10]
CHR Extension: (Google Docs) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-10]
CHR Extension: (Google Drive) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-10]
CHR Extension: (YouTube) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-10]
CHR Extension: (Google-Suche) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-10]
CHR Extension: (Google Tabellen) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-10]
CHR Extension: (Avira Browser Safety) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-10]
CHR Extension: (avast! Online Security) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-10]
CHR Extension: (Google Wallet) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-10]
CHR Extension: (Google Mail) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-10]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-10]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-10] (AVAST Software)
R2 Crypkey License; C:\windows\system32\crypserv.exe [122880 2008-05-08] (CrypKey (Canada) Ltd.) [File not signed]
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [9281840 2013-10-11] (DisplayLink Corp.)
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [115632 2013-08-02] (Intel Corporation)
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116656 2013-08-02] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148688 2013-08-02] (Intel Corporation)
R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [124880 2013-08-02] (Intel Corporation)
R2 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [627712 2014-04-08] (FileZilla Project) [File not signed]
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-09-04] (Freemake) [File not signed]
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-05-22] (Ellora Assets Corp.) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-19] (Intel Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-02] ()
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-08-18] (LENOVO INCORPORATED.)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-03-28] (Lenovo)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
R2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-08] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [249872 2014-03-28] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [328720 2014-03-28] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [288472 2013-09-13] (Realtek Semiconductor)
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2014-09-29] (Copyright 2013 SAMSUNG)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [174088 2014-05-29] (Sandboxie Holdings, LLC)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2014-03-28] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [34576 2014-03-28] (Lenovo)
R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2014-01-07] ()
S3 McAWFwk; c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe [X]
S4 McOobeSv2; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-10] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-10-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-10] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-10] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-10-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-10-10] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-10-10] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-10-10] ()
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-23] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-06] (Motorola Solutions, Inc.)
R3 DisplayLinkUsbIo_x64; C:\Windows\System32\drivers\DisplayLinkUsbIo_x64_7.4.48800.0.sys [44944 2013-10-07] ()
R3 dlcdcncm6_x64; C:\Windows\system32\DRIVERS\dlcdcncm6_x64.sys [80688 2013-10-11] (DisplayLink Corp.)
R3 dlusbaudio; C:\Windows\system32\DRIVERS\dlusbaudio_x64.sys [203152 2013-10-11] (DisplayLink Corp.)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [114680 2013-08-02] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [287160 2013-08-02] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494272 2013-08-02] (Intel Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [118728 2013-09-19] (Intel Corporation)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-02] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-02] ()
R3 INETMON; C:\windows\System32\Drivers\INETMON.sys [29088 2013-08-02] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-02] ()
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-17] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3589600 2013-09-19] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] ()
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
S3 qzozigbn; C:\Windows\System32\Drivers\qzozigbn.sys [423240 2014-05-07] (AVAST Software)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [185352 2014-05-29] (Sandboxie Holdings, LLC)
R3 SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 sidtohjv; C:\Windows\System32\Drivers\sidtohjv.sys [423240 2014-05-04] (AVAST Software)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-29] (Synaptics Incorporated)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1527928 2013-08-23] (Sunplus)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2014-05-07] ()
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 PCASp60; System32\Drivers\PCASp60.sys [X]
S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X]
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-15 14:43 - 2014-10-15 14:43 - 00000000 ___RD () C:\Sandbox
2014-10-15 14:40 - 2014-10-16 15:57 - 00001672 _____ () C:\windows\Sandboxie.ini
2014-10-15 14:40 - 2014-10-15 14:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2014-10-15 14:39 - 2014-10-15 14:39 - 00000000 ____D () C:\Program Files\Sandboxie
2014-10-15 11:32 - 2014-10-17 23:08 - 00000435 _____ () C:\windows\system32\Drivers\etc\hosts.ics
2014-10-15 11:23 - 2014-10-15 11:23 - 00000000 ____D () C:\Users\Marcel\VirtualBox VMs
2014-10-15 11:22 - 2014-10-15 12:25 - 00000000 ____D () C:\Users\Marcel\.VirtualBox
2014-10-15 11:22 - 2014-10-11 13:29 - 00917112 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxDrv.sys
2014-10-15 11:22 - 2014-10-11 13:27 - 00129168 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxUSBMon.sys
2014-10-15 11:21 - 2014-10-15 11:21 - 00000000 ____D () C:\Program Files\Oracle
2014-10-15 09:51 - 2014-10-10 00:16 - 00678400 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-10-15 09:51 - 2014-10-09 00:09 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-10-15 09:51 - 2014-09-19 03:24 - 00527360 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-10-15 09:51 - 2014-09-13 08:02 - 02779648 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2014-10-15 09:51 - 2014-09-13 07:30 - 03117568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2014-10-15 09:51 - 2014-09-04 02:10 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll
2014-10-15 09:51 - 2014-09-04 01:57 - 00921600 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll
2014-10-15 09:51 - 2014-09-04 01:49 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmCoreR.dll
2014-10-15 09:51 - 2014-08-29 03:58 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2014-10-15 09:51 - 2014-08-29 01:56 - 02646016 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2014-10-15 09:51 - 2014-08-29 01:47 - 02321920 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2014-10-15 08:38 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\windows\SysWOW64\dhRichClient3.dll
2014-10-15 08:38 - 2011-03-25 20:42 - 00338432 _____ () C:\windows\SysWOW64\sqlite36_engine.dll
2014-10-15 08:06 - 2014-09-28 00:25 - 04183040 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-15 08:06 - 2014-09-26 00:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-15 08:06 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-15 08:06 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-15 08:06 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-15 08:06 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-15 08:06 - 2014-09-26 00:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-15 08:06 - 2014-09-19 04:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-15 08:06 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-15 08:06 - 2014-09-19 03:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-15 08:06 - 2014-09-19 03:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-15 08:06 - 2014-09-19 03:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-15 08:06 - 2014-09-19 03:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-15 08:06 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-15 08:06 - 2014-09-19 03:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-15 08:06 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-15 08:06 - 2014-09-19 03:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-15 08:06 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-15 08:06 - 2014-09-19 02:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-15 08:06 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-15 08:06 - 2014-09-19 02:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-15 08:06 - 2014-09-19 02:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-15 08:06 - 2014-09-19 02:42 - 00363008 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-15 08:06 - 2014-09-19 02:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-15 08:06 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-15 08:06 - 2014-09-19 02:20 - 00315904 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-15 08:06 - 2014-09-19 02:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-15 08:06 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-15 08:06 - 2014-09-19 01:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-15 08:06 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-15 08:06 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-15 08:05 - 2014-09-08 05:15 - 00054752 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2014-10-15 08:05 - 2014-09-08 03:46 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2014-10-15 08:05 - 2014-09-08 03:46 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2014-10-15 08:05 - 2014-09-08 02:08 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2014-10-15 08:05 - 2014-09-08 02:07 - 00137728 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2014-10-15 08:05 - 2014-09-08 02:05 - 03448320 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2014-10-15 08:05 - 2014-09-08 02:04 - 00388608 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2014-10-15 08:05 - 2014-09-08 02:04 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2014-10-15 08:05 - 2014-09-08 02:03 - 01702400 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2014-10-15 08:05 - 2014-09-08 02:03 - 00839680 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2014-10-15 08:05 - 2014-09-08 01:59 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2014-10-15 08:05 - 2014-09-08 01:59 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2014-10-15 08:05 - 2014-09-08 01:56 - 00672256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2014-10-15 08:05 - 2014-09-08 01:56 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2014-10-15 08:04 - 2014-09-13 08:29 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-15 08:04 - 2014-09-13 07:49 - 00068608 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2014-10-15 08:04 - 2014-09-04 02:12 - 00590336 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-15 08:04 - 2014-09-04 02:01 - 00514048 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-15 08:04 - 2014-08-16 06:08 - 21195616 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-10-15 08:04 - 2014-08-16 06:08 - 01507648 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll
2014-10-15 08:04 - 2014-08-16 06:01 - 01710184 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2014-10-15 08:04 - 2014-08-16 05:58 - 01112512 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2014-10-15 08:04 - 2014-08-16 05:57 - 02498880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-10-15 08:04 - 2014-08-16 05:57 - 00428864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-10-15 08:04 - 2014-08-16 05:16 - 18722600 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-10-15 08:04 - 2014-08-16 05:16 - 01205976 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll
2014-10-15 08:04 - 2014-08-16 05:03 - 01467384 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2014-10-15 08:04 - 2014-08-16 03:31 - 00838144 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2014-10-15 08:04 - 2014-08-16 03:04 - 00359424 _____ (Microsoft Corporation) C:\windows\system32\Wldap32.dll
2014-10-15 08:04 - 2014-08-16 02:58 - 00287744 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll
2014-10-15 08:04 - 2014-08-16 02:53 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\httpprxm.dll
2014-10-15 08:04 - 2014-08-16 02:46 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\ProximityService.dll
2014-10-15 08:04 - 2014-08-16 02:45 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll
2014-10-15 08:04 - 2014-08-16 02:43 - 00321024 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wldap32.dll
2014-10-15 08:04 - 2014-08-16 02:43 - 00075776 _____ (Microsoft Corporation) C:\windows\system32\adhsvc.dll
2014-10-15 08:04 - 2014-08-16 02:31 - 00914432 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2014-10-15 08:04 - 2014-08-16 02:31 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\pcsvDevice.dll
2014-10-15 08:04 - 2014-08-16 02:29 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 08:04 - 2014-08-16 02:23 - 01106432 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll
2014-10-15 08:04 - 2014-08-16 02:22 - 00717824 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll
2014-10-15 08:04 - 2014-08-16 02:22 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll
2014-10-15 08:04 - 2014-08-16 02:19 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 08:04 - 2014-08-16 02:18 - 04758528 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll
2014-10-15 08:04 - 2014-08-16 02:17 - 08757760 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll
2014-10-15 08:04 - 2014-08-16 02:14 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll
2014-10-15 08:04 - 2014-08-16 02:13 - 06649344 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-10-15 08:04 - 2014-08-16 02:13 - 05902848 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll
2014-10-15 08:04 - 2014-08-16 02:13 - 00840192 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll
2014-10-15 08:04 - 2014-08-16 02:11 - 00920064 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2014-10-15 08:04 - 2014-08-16 02:10 - 01120768 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe
2014-10-15 08:04 - 2014-08-16 02:08 - 05777408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-10-15 08:04 - 2014-08-16 02:07 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2014-10-15 08:04 - 2014-08-01 01:22 - 00388729 _____ () C:\windows\system32\ApnDatabase.xml
2014-10-14 18:55 - 2014-10-15 10:02 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\VMware
2014-10-14 18:55 - 2014-10-14 19:51 - 00000000 ____D () C:\Users\Marcel\AppData\Local\VMware
2014-10-14 18:53 - 2014-10-15 10:02 - 00000000 ____D () C:\ProgramData\VMware
2014-10-14 11:31 - 2014-10-14 11:31 - 00001126 _____ () C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\join.me.lnk
2014-10-14 11:31 - 2014-10-14 11:31 - 00000000 ____D () C:\Users\Marcel\AppData\Local\LogMeIn
2014-10-14 11:31 - 2014-10-14 11:31 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-10-14 11:26 - 2014-10-14 11:31 - 00000000 ____D () C:\Users\Marcel\AppData\Local\join.me
2014-10-13 10:07 - 2014-10-13 10:07 - 00319912 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2014-10-13 10:07 - 2014-10-13 10:07 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2014-10-13 10:07 - 2014-10-13 10:07 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe
2014-10-13 10:07 - 2014-10-13 10:07 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2014-10-13 08:41 - 2014-10-17 13:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-13 08:41 - 2014-10-17 13:46 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-10-13 08:41 - 2014-10-17 13:46 - 00000000 ____D () C:\Program Files (x86)\Java
2014-10-13 08:41 - 2014-10-13 08:41 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-10-13 08:41 - 2014-10-13 08:41 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-10-13 08:41 - 2014-10-13 08:41 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-10-13 08:33 - 2014-10-13 08:33 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Oracle
2014-10-11 13:27 - 2014-10-11 13:27 - 00142528 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxNetAdp.sys
2014-10-10 07:34 - 2014-10-10 07:34 - 00001993 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-10-10 07:34 - 2014-10-10 07:34 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\AVAST Software
2014-10-10 07:34 - 2014-10-10 07:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-10-10 07:33 - 2014-10-10 07:34 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-10-10 07:33 - 2014-10-10 07:33 - 01041168 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00427360 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00307344 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-10-10 07:33 - 2014-10-10 07:33 - 00224896 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00092008 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00079184 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-10-10 07:33 - 2014-10-10 07:33 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
2014-10-10 07:32 - 2014-10-10 07:32 - 00000000 ____D () C:\Program Files\AVAST Software
2014-10-10 00:16 - 2014-10-10 00:16 - 00001716 _____ () C:\Users\Marcel\Desktop\JRT.txt
2014-10-10 00:14 - 2014-10-10 00:14 - 00000000 ____D () C:\windows\ERUNT
2014-10-09 23:27 - 2014-10-17 23:07 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-09 23:26 - 2014-10-09 23:26 - 00001129 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-10-09 23:26 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-10-09 23:26 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-10-09 23:26 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-10-09 23:20 - 2014-10-09 23:20 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-10-08 17:30 - 2014-10-17 23:11 - 00000000 ____D () C:\FRST
2014-10-03 11:30 - 2014-10-03 17:10 - 00000000 ____D () C:\Program Files\Q-Dir
2014-10-03 11:19 - 2014-10-03 11:19 - 00000000 ____D () C:\Users\Marcel\AppData\Local\GHISLER
2014-10-03 11:17 - 2014-10-03 11:17 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\GHISLER
2014-10-03 09:03 - 2014-10-03 09:18 - 00000004 _____ () C:\windows\vx86036.dat
2014-10-03 09:03 - 2014-10-03 09:13 - 00000260 _____ () C:\CKINFO.TXT
2014-10-03 09:03 - 2014-10-03 09:03 - 00000000 ____D () C:\ProgramData\CrypKey
2014-10-03 09:02 - 2014-10-15 13:44 - 00036047 _____ () C:\windows\errord.log
2014-10-03 09:02 - 2014-10-15 13:44 - 00000868 _____ () C:\windows\error.log
2014-10-03 09:02 - 2014-10-03 09:18 - 00003360 _____ () C:\windows\system32\esnecil.ind
2014-10-03 09:02 - 2014-10-03 09:18 - 00000127 _____ () C:\windows\Crypkey.ini
2014-10-03 09:02 - 2014-10-03 09:18 - 00000000 ____D () C:\Program Files\Stellar Phoenix Outlook PST Repair
2014-10-03 09:02 - 2008-05-08 01:29 - 00122880 _____ (CrypKey (Canada) Ltd.) C:\windows\system32\Crypserv.exe
2014-10-03 09:02 - 2008-03-17 19:12 - 00028664 _____ () C:\windows\system32\Ckldrv.sys
2014-10-03 09:02 - 1999-06-18 22:49 - 00165888 _____ (Kenonic Controls) C:\windows\Ckconfig.exe
2014-10-03 09:02 - 1996-05-03 18:21 - 00027648 ____R () C:\windows\Setup_ck.exe
2014-10-03 09:02 - 1996-05-03 16:36 - 00018432 _____ () C:\windows\Setup_ck.dll
2014-10-03 09:02 - 1995-07-04 19:33 - 00011776 _____ () C:\windows\Ckrfresh.exe
2014-10-02 18:42 - 2014-10-02 18:42 - 00003974 _____ () C:\windows\System32\Tasks\4Team updater
2014-10-02 18:41 - 2014-10-03 16:56 - 00000000 ____D () C:\Program Files (x86)\4Team Corporation
2014-10-02 18:41 - 2014-10-02 18:41 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\4Team
2014-10-02 18:41 - 2014-10-02 18:41 - 00000000 ____D () C:\Users\Marcel\AppData\Local\IsolatedStorage
2014-10-02 09:40 - 2014-10-02 09:40 - 00000000 ____D () C:\Neuer Ordner
2014-10-01 09:42 - 2014-10-09 12:03 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\FileZilla
2014-09-26 15:41 - 2014-09-30 08:40 - 00000000 ____D () C:\Users\Marcel\Tracing
2014-09-26 15:40 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_7.dll
2014-09-26 15:40 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_7.dll
2014-09-26 15:40 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_5.dll
2014-09-26 15:40 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_5.dll
2014-09-26 15:40 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_43.dll
2014-09-26 15:40 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_43.dll
2014-09-26 15:40 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_43.dll
2014-09-26 15:40 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_43.dll
2014-09-26 15:39 - 2014-09-26 15:39 - 00002242 _____ () C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2014-09-26 15:39 - 2014-09-26 15:39 - 00002147 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2014-09-26 15:39 - 2014-09-26 15:39 - 00002147 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2014-09-26 15:39 - 2014-09-26 15:39 - 00000196 _____ () C:\windows\DirectX.log
2014-09-26 15:39 - 2014-09-26 15:39 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-09-26 15:39 - 2014-09-26 15:39 - 00000000 ____D () C:\Program Files (x86)\Microsoft SkyDrive
2014-09-26 15:39 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_42.dll
2014-09-26 15:39 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_42.dll
2014-09-26 15:39 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_32.dll
2014-09-26 15:39 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_32.dll
2014-09-26 15:38 - 2014-09-30 08:54 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Windows Live
2014-09-25 13:13 - 2014-10-08 16:50 - 00003718 _____ () C:\windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2014-09-25 13:13 - 2014-09-25 13:13 - 00003476 _____ () C:\windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon
2014-09-25 09:57 - 2014-09-25 09:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-24 17:16 - 2014-09-24 17:16 - 00000000 ____D () C:\Users\Marcel\AppData\Local\FreemakeVideoDownloader

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-17 23:10 - 2014-04-22 15:38 - 00003922 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{F5291F67-CB16-4602-A1AA-B673A0FBD3F7}
2014-10-17 23:08 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\AppReadiness
2014-10-17 23:07 - 2014-04-22 15:14 - 00000000 __RDO () C:\Users\Marcel\SkyDrive
2014-10-17 23:07 - 2014-03-28 08:55 - 00010752 _____ () C:\windows\system32\VfService.trf
2014-10-17 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\sru
2014-10-17 17:50 - 2014-04-30 12:43 - 00000000 ____D () C:\Users\Marcel\AppData\Local\CrashDumps
2014-10-17 16:56 - 2014-04-29 09:31 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-10-17 16:53 - 2014-04-22 19:56 - 00000432 _____ () C:\windows\BRWMARK.INI
2014-10-17 13:53 - 2014-04-22 15:13 - 00003600 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3121602427-3534730855-1075997385-1001
2014-10-17 13:46 - 2014-04-22 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-17 13:39 - 2014-03-28 08:34 - 01963149 _____ () C:\windows\WindowsUpdate.log
2014-10-17 13:19 - 2014-04-28 20:40 - 00000000 ____D () C:\windows\system32\MRT
2014-10-17 13:16 - 2014-04-28 20:40 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-10-17 10:57 - 2014-05-05 11:47 - 00000000 ____D () C:\xampp
2014-10-16 18:24 - 2014-04-22 19:41 - 00000000 ____D () C:\ProgramData\firebird
2014-10-16 13:35 - 2014-06-12 07:50 - 00011082 _____ () C:\windows\SecuniaPackage.log
2014-10-16 13:35 - 2014-04-29 09:31 - 00003718 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-10-16 08:20 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\NDF
2014-10-15 14:42 - 2014-04-20 09:09 - 00000000 ____D () C:\MADProg
2014-10-15 14:42 - 2014-04-20 09:08 - 00000000 ____D () C:\MADDaten
2014-10-15 13:49 - 2014-03-28 09:27 - 00955470 _____ () C:\windows\system32\perfh00C.dat
2014-10-15 13:49 - 2014-03-28 09:27 - 00256758 _____ () C:\windows\system32\perfc00C.dat
2014-10-15 13:49 - 2014-03-28 09:24 - 01046540 _____ () C:\windows\system32\perfh007.dat
2014-10-15 13:49 - 2014-03-28 09:24 - 00258988 _____ () C:\windows\system32\perfc007.dat
2014-10-15 13:49 - 2013-10-07 20:27 - 00005934 _____ () C:\windows\system32\PerfStringBackup.INI
2014-10-15 13:44 - 2013-08-22 16:46 - 00034703 _____ () C:\windows\setupact.log
2014-10-15 13:44 - 2013-08-22 16:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-10-15 13:44 - 2013-08-22 16:44 - 00499656 _____ () C:\windows\system32\FNTCACHE.DAT
2014-10-15 13:34 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ToastData
2014-10-15 13:34 - 2013-08-22 15:25 - 00524288 ___SH () C:\windows\system32\config\BBI
2014-10-15 13:33 - 2014-07-09 18:28 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\WinStore
2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\MediaViewer
2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\FileManager
2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Camera
2014-10-15 12:32 - 2014-04-22 17:16 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 12:32 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-10-15 12:32 - 2013-08-22 17:20 - 00000000 ____D () C:\windows\CbsTemp
2014-10-15 11:23 - 2014-04-22 15:08 - 00000000 ____D () C:\Users\Marcel
2014-10-15 11:10 - 2014-04-29 10:05 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\vlc
2014-10-14 18:54 - 2014-03-28 08:43 - 00006124 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2014-10-13 10:07 - 2013-10-07 20:23 - 00152266 _____ () C:\windows\PFRO.log
2014-10-10 07:37 - 2014-04-22 16:35 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-10 07:34 - 2014-04-22 16:35 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Google
2014-10-10 00:38 - 2014-04-22 16:42 - 00022391 _____ () C:\windows\Q-Dir.ini
2014-10-10 00:31 - 2014-05-04 19:20 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-10-10 00:31 - 2014-03-28 08:43 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-10 00:09 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\ELAM
2014-10-09 23:58 - 2014-05-07 11:16 - 00000000 ____D () C:\AdwCleaner
2014-10-09 23:43 - 2014-05-07 18:53 - 00000000 ____D () C:\Users\Administrator
2014-10-08 16:42 - 2014-04-22 15:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-05 13:23 - 2014-06-19 14:39 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\SmartDraw
2014-10-03 11:32 - 2014-04-22 16:42 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Q-Dir
2014-10-02 18:40 - 2014-03-28 08:55 - 00000000 ____D () C:\ProgramData\Downloaded Installations
2014-10-01 09:43 - 2014-04-22 16:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2014-10-01 09:43 - 2014-04-22 16:35 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client
2014-10-01 07:58 - 2014-08-30 09:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2014-09-30 00:45 - 2013-08-22 17:38 - 00706016 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-09-30 00:45 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-26 13:19 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\rescache
2014-09-25 17:44 - 2014-04-22 17:41 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Nitro PDF
2014-09-25 13:13 - 2014-03-28 08:43 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-09-22 09:07 - 2014-04-22 16:37 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-22 08:42 - 2014-05-04 18:19 - 00278152 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-09-17 19:14 - 2014-09-06 07:48 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\RHEng
2014-09-17 19:14 - 2014-04-29 14:34 - 00000967 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk
2014-09-17 19:14 - 2014-04-29 14:34 - 00000957 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealtimeSync.lnk

Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Marcel\AppData\Local\Temp\avgnt.exe
C:\Users\Marcel\AppData\Local\Temp\FreemakeVideoDownloader_3.6.4.3.exe
C:\Users\Marcel\AppData\Local\Temp\FreemakeVideoDownloader_3.7.0.1.exe
C:\Users\Marcel\AppData\Local\Temp\gkey.exe
C:\Users\Marcel\AppData\Local\Temp\i4jdel0.exe
C:\Users\Marcel\AppData\Local\Temp\ICReinstall_COMPUTER_BILD-Download-Manager_fuer_Screenpresso.exe
C:\Users\Marcel\AppData\Local\Temp\K-Lite_Codec_Pack_Basic.exe
C:\Users\Marcel\AppData\Local\Temp\ms.exe
C:\Users\Marcel\AppData\Local\Temp\msvcr71.dll
C:\Users\Marcel\AppData\Local\Temp\MySwisscomAssistant_Setup.exe
C:\Users\Marcel\AppData\Local\Temp\nitro_reader3_64.exe
C:\Users\Marcel\AppData\Local\Temp\optprosetup.exe
C:\Users\Marcel\AppData\Local\Temp\pkeyui.exe
C:\Users\Marcel\AppData\Local\Temp\Q-Dir_uninstall.exe
C:\Users\Marcel\AppData\Local\Temp\Quarantine.exe
C:\Users\Marcel\AppData\Local\Temp\safepstbackup_1_00.exe
C:\Users\Marcel\AppData\Local\Temp\SamsungAPInstaller_1412143055024.exe
C:\Users\Marcel\AppData\Local\Temp\ScreenpressoUpd.exe
C:\Users\Marcel\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Marcel\AppData\Local\Temp\wabk.exe
C:\Users\Marcel\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-14 12:26

==================== End Of Log ============================
         
--- --- ---

Alt 18.10.2014, 09:54   #22
sugus666
 
Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



hi Schrauber
habe nun alle suspekten files gelöscht, nachfolgend nochmals frst.txt
Gruss
sugus666


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014
Ran by Marcel (administrator) on SUGUS on 18-10-2014 10:51:21
Running from F:\90 Daten Systemordner\Downloads_sys
Loaded Profiles: Marcel &  (Available profiles: Marcel & Administrator)
Platform: Windows 8.1 (X64) OS Language: Englisch (Vereinigte Staaten)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CrypKey (Canada) Ltd.) C:\Windows\System32\Crypserv.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
(FileZilla Project) C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
() C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(Learnpulse) C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(Docking Station) C:\Program Files (x86)\Lenovo\USB3.0 Dock\igpxtskmgn64win8.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Nenad Hrg (SoftwareOK.com)) C:\Program Files\Q-Dir\Q-Dir.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13656792 2013-10-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432 2013-09-26] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\windows\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-08-02] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-03-28] (Lenovo)
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-03-28] ()
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [59923440 2014-03-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-03-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2014-09-29] (Copyright 2013 SAMSUNG)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5595848 2014-09-22] (ESET)
HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-06] (Lenovo)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [My Swisscom Assistant] => C:\Program Files (x86)\Swisscom\My Swisscom Assistant\MySwisscomAssistant_Launcher.exe [7503792 2014-02-27] (Swisscom (Schweiz) AG)
HKLM-x32\...\Run: [FileZilla Server Interface] => C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe [2322944 2014-04-08] (FileZilla Project)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-10] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [Screenpresso] => C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10983952 2014-09-22] (Learnpulse)
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [AshSnap] => C:\Program Files (x86)\Ashampoo\Ashampoo Snap 6\ashsnap.exe
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [msnmsgr] => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784392 2014-05-29] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Screenpresso] => C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10983952 2014-09-22] (Learnpulse)
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AshSnap] => C:\Program Files (x86)\Ashampoo\Ashampoo Snap 6\ashsnap.exe
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [msnmsgr] => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
HKU\S-1-5-21-3121602427-3534730855-1075997385-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784392 2014-05-29] (Sandboxie Holdings, LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\igpxtskmgn.lnk
ShortcutTarget: igpxtskmgn.lnk -> C:\Program Files (x86)\Lenovo\USB3.0 Dock\igpxtskmgn64win8.exe (Docking Station)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\start.bat ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
SearchScopes: HKLM-x32 - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
SearchScopes: HKCU - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {A6616B31-4860-41E2-98E3-CA7649AF172F} file:///E:/00%20A%20Temp/001%20USB%20DOking/launch.ocx
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} -  No File
Handler-x32: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default
FF SelectedSearchEngine: Google
FF Homepage: https://www.google.ch/?gfe_rd=cr&ei=ochAVKyvLYuH8Qe04oCYBQ&gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\searchplugins\google-maps.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\abs@avira.com [2014-09-30]
FF Extension: Xmarks - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\foxmarks@kei.com [2014-09-17]
FF Extension: My Swisscom Assistant - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\{6A6114A5-EEF5-45F4-BCD1-B00A7B33E04B} [2014-05-15]
FF Extension: Cliqz Beta - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\cliqz@cliqz.com.xpi [2014-10-15]
FF Extension: Tab Mix Plus - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-09-30]
FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2014-04-29]
FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2014-04-29]
FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox [2014-09-06]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-10]
FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\extensions\cliqz@cliqz.com

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-10]
CHR Extension: (Google Docs) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-10]
CHR Extension: (Google Drive) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-10]
CHR Extension: (YouTube) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-10]
CHR Extension: (Google-Suche) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-10]
CHR Extension: (Google Tabellen) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-10]
CHR Extension: (Avira Browser Safety) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-10]
CHR Extension: (avast! Online Security) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-10]
CHR Extension: (Google Wallet) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-10]
CHR Extension: (Google Mail) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-10]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-10]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-10] (AVAST Software)
R2 Crypkey License; C:\windows\system32\crypserv.exe [122880 2008-05-08] (CrypKey (Canada) Ltd.) [File not signed]
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [9281840 2013-10-11] (DisplayLink Corp.)
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [115632 2013-08-02] (Intel Corporation)
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116656 2013-08-02] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148688 2013-08-02] (Intel Corporation)
R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [124880 2013-08-02] (Intel Corporation)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1350112 2014-09-16] (ESET)
R2 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [627712 2014-04-08] (FileZilla Project) [File not signed]
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-09-04] (Freemake) [File not signed]
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-05-22] (Ellora Assets Corp.) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-19] (Intel Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-02] ()
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-08-18] (LENOVO INCORPORATED.)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-03-28] (Lenovo)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
R2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-08] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [249872 2014-03-28] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [328720 2014-03-28] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [288472 2013-09-13] (Realtek Semiconductor)
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2014-09-29] (Copyright 2013 SAMSUNG)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [174088 2014-05-29] (Sandboxie Holdings, LLC)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2014-03-28] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [34576 2014-03-28] (Lenovo)
R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2014-01-07] ()
S3 McAWFwk; c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe [X]
S4 McOobeSv2; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-10] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-10-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-10] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-10] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-10-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-10-10] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-10-10] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-10-10] ()
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-23] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-06] (Motorola Solutions, Inc.)
R3 DisplayLinkUsbIo_x64; C:\Windows\System32\drivers\DisplayLinkUsbIo_x64_7.4.48800.0.sys [44944 2013-10-07] ()
R3 dlcdcncm6_x64; C:\Windows\system32\DRIVERS\dlcdcncm6_x64.sys [80688 2013-10-11] (DisplayLink Corp.)
R3 dlusbaudio; C:\Windows\system32\DRIVERS\dlusbaudio_x64.sys [203152 2013-10-11] (DisplayLink Corp.)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [114680 2013-08-02] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [287160 2013-08-02] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494272 2013-08-02] (Intel Corporation)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-08-18] (ESET)
S0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [241368 2014-08-18] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [169280 2014-08-18] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [158968 2014-09-18] (ESET)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [118728 2013-09-19] (Intel Corporation)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-02] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-02] ()
R3 INETMON; C:\windows\System32\Drivers\INETMON.sys [29088 2013-08-02] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-02] ()
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3589600 2013-09-19] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] ()
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
S3 qzozigbn; C:\Windows\System32\Drivers\qzozigbn.sys [423240 2014-05-07] (AVAST Software)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [185352 2014-05-29] (Sandboxie Holdings, LLC)
R3 SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 sidtohjv; C:\Windows\System32\Drivers\sidtohjv.sys [423240 2014-05-04] (AVAST Software)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-29] (Synaptics Incorporated)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1527928 2013-08-23] (Sunplus)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2014-05-07] ()
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 PCASp60; System32\Drivers\PCASp60.sys [X]
S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X]
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-18 10:07 - 2014-10-18 10:07 - 00000000 ____D () C:\Users\Marcel\AppData\Local\ESET
2014-10-18 10:04 - 2014-10-18 10:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2014-10-18 10:04 - 2014-10-18 10:04 - 00000000 ____D () C:\ProgramData\ESET
2014-10-18 10:04 - 2014-10-18 10:04 - 00000000 ____D () C:\Program Files\ESET
2014-10-18 08:06 - 2014-10-18 08:06 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-10-15 14:43 - 2014-10-15 14:43 - 00000000 ___RD () C:\Sandbox
2014-10-15 14:40 - 2014-10-18 10:05 - 00001704 _____ () C:\windows\Sandboxie.ini
2014-10-15 14:40 - 2014-10-15 14:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2014-10-15 14:39 - 2014-10-15 14:39 - 00000000 ____D () C:\Program Files\Sandboxie
2014-10-15 11:32 - 2014-10-18 08:00 - 00000435 _____ () C:\windows\system32\Drivers\etc\hosts.ics
2014-10-15 11:23 - 2014-10-15 11:23 - 00000000 ____D () C:\Users\Marcel\VirtualBox VMs
2014-10-15 11:22 - 2014-10-15 12:25 - 00000000 ____D () C:\Users\Marcel\.VirtualBox
2014-10-15 11:22 - 2014-10-11 13:29 - 00917112 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxDrv.sys
2014-10-15 11:22 - 2014-10-11 13:27 - 00129168 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxUSBMon.sys
2014-10-15 11:21 - 2014-10-15 11:21 - 00000000 ____D () C:\Program Files\Oracle
2014-10-15 09:51 - 2014-10-10 00:16 - 00678400 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-10-15 09:51 - 2014-10-09 00:09 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-10-15 09:51 - 2014-09-19 03:24 - 00527360 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-10-15 09:51 - 2014-09-13 08:02 - 02779648 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2014-10-15 09:51 - 2014-09-13 07:30 - 03117568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2014-10-15 09:51 - 2014-09-04 02:10 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll
2014-10-15 09:51 - 2014-09-04 01:57 - 00921600 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll
2014-10-15 09:51 - 2014-09-04 01:49 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmCoreR.dll
2014-10-15 09:51 - 2014-08-29 03:58 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2014-10-15 09:51 - 2014-08-29 01:56 - 02646016 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2014-10-15 09:51 - 2014-08-29 01:47 - 02321920 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2014-10-15 08:38 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\windows\SysWOW64\dhRichClient3.dll
2014-10-15 08:38 - 2011-03-25 20:42 - 00338432 _____ () C:\windows\SysWOW64\sqlite36_engine.dll
2014-10-15 08:06 - 2014-09-28 00:25 - 04183040 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-15 08:06 - 2014-09-26 00:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-15 08:06 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-15 08:06 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-15 08:06 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-15 08:06 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-15 08:06 - 2014-09-26 00:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-15 08:06 - 2014-09-19 04:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-15 08:06 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-15 08:06 - 2014-09-19 03:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-15 08:06 - 2014-09-19 03:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-15 08:06 - 2014-09-19 03:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-15 08:06 - 2014-09-19 03:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-15 08:06 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-15 08:06 - 2014-09-19 03:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-15 08:06 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-15 08:06 - 2014-09-19 03:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-15 08:06 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-15 08:06 - 2014-09-19 02:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-15 08:06 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-15 08:06 - 2014-09-19 02:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-15 08:06 - 2014-09-19 02:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-15 08:06 - 2014-09-19 02:42 - 00363008 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-15 08:06 - 2014-09-19 02:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-15 08:06 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-15 08:06 - 2014-09-19 02:20 - 00315904 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-15 08:06 - 2014-09-19 02:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-15 08:06 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-15 08:06 - 2014-09-19 01:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-15 08:06 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-15 08:06 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-15 08:05 - 2014-09-08 05:15 - 00054752 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2014-10-15 08:05 - 2014-09-08 03:46 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2014-10-15 08:05 - 2014-09-08 03:46 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2014-10-15 08:05 - 2014-09-08 02:08 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2014-10-15 08:05 - 2014-09-08 02:07 - 00137728 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2014-10-15 08:05 - 2014-09-08 02:05 - 03448320 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2014-10-15 08:05 - 2014-09-08 02:04 - 00388608 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2014-10-15 08:05 - 2014-09-08 02:04 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2014-10-15 08:05 - 2014-09-08 02:03 - 01702400 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2014-10-15 08:05 - 2014-09-08 02:03 - 00839680 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2014-10-15 08:05 - 2014-09-08 01:59 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2014-10-15 08:05 - 2014-09-08 01:59 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2014-10-15 08:05 - 2014-09-08 01:56 - 00672256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2014-10-15 08:05 - 2014-09-08 01:56 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2014-10-15 08:04 - 2014-09-13 08:29 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-15 08:04 - 2014-09-13 07:49 - 00068608 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2014-10-15 08:04 - 2014-09-04 02:12 - 00590336 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-15 08:04 - 2014-09-04 02:01 - 00514048 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-15 08:04 - 2014-08-16 06:08 - 21195616 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-10-15 08:04 - 2014-08-16 06:08 - 01507648 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll
2014-10-15 08:04 - 2014-08-16 06:01 - 01710184 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2014-10-15 08:04 - 2014-08-16 05:58 - 01112512 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2014-10-15 08:04 - 2014-08-16 05:57 - 02498880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-10-15 08:04 - 2014-08-16 05:57 - 00428864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-10-15 08:04 - 2014-08-16 05:16 - 18722600 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-10-15 08:04 - 2014-08-16 05:16 - 01205976 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll
2014-10-15 08:04 - 2014-08-16 05:03 - 01467384 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2014-10-15 08:04 - 2014-08-16 03:31 - 00838144 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2014-10-15 08:04 - 2014-08-16 03:04 - 00359424 _____ (Microsoft Corporation) C:\windows\system32\Wldap32.dll
2014-10-15 08:04 - 2014-08-16 02:58 - 00287744 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll
2014-10-15 08:04 - 2014-08-16 02:53 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\httpprxm.dll
2014-10-15 08:04 - 2014-08-16 02:46 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\ProximityService.dll
2014-10-15 08:04 - 2014-08-16 02:45 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll
2014-10-15 08:04 - 2014-08-16 02:43 - 00321024 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wldap32.dll
2014-10-15 08:04 - 2014-08-16 02:43 - 00075776 _____ (Microsoft Corporation) C:\windows\system32\adhsvc.dll
2014-10-15 08:04 - 2014-08-16 02:31 - 00914432 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2014-10-15 08:04 - 2014-08-16 02:31 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\pcsvDevice.dll
2014-10-15 08:04 - 2014-08-16 02:29 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 08:04 - 2014-08-16 02:23 - 01106432 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll
2014-10-15 08:04 - 2014-08-16 02:22 - 00717824 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll
2014-10-15 08:04 - 2014-08-16 02:22 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll
2014-10-15 08:04 - 2014-08-16 02:19 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 08:04 - 2014-08-16 02:18 - 04758528 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll
2014-10-15 08:04 - 2014-08-16 02:17 - 08757760 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll
2014-10-15 08:04 - 2014-08-16 02:14 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll
2014-10-15 08:04 - 2014-08-16 02:13 - 06649344 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-10-15 08:04 - 2014-08-16 02:13 - 05902848 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll
2014-10-15 08:04 - 2014-08-16 02:13 - 00840192 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll
2014-10-15 08:04 - 2014-08-16 02:11 - 00920064 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2014-10-15 08:04 - 2014-08-16 02:10 - 01120768 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe
2014-10-15 08:04 - 2014-08-16 02:08 - 05777408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-10-15 08:04 - 2014-08-16 02:07 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2014-10-15 08:04 - 2014-08-01 01:22 - 00388729 _____ () C:\windows\system32\ApnDatabase.xml
2014-10-14 18:55 - 2014-10-15 10:02 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\VMware
2014-10-14 18:55 - 2014-10-14 19:51 - 00000000 ____D () C:\Users\Marcel\AppData\Local\VMware
2014-10-14 18:53 - 2014-10-15 10:02 - 00000000 ____D () C:\ProgramData\VMware
2014-10-14 11:31 - 2014-10-14 11:31 - 00001126 _____ () C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\join.me.lnk
2014-10-14 11:31 - 2014-10-14 11:31 - 00000000 ____D () C:\Users\Marcel\AppData\Local\LogMeIn
2014-10-14 11:31 - 2014-10-14 11:31 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-10-14 11:26 - 2014-10-14 11:31 - 00000000 ____D () C:\Users\Marcel\AppData\Local\join.me
2014-10-13 10:07 - 2014-10-13 10:07 - 00319912 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2014-10-13 10:07 - 2014-10-13 10:07 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2014-10-13 10:07 - 2014-10-13 10:07 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe
2014-10-13 10:07 - 2014-10-13 10:07 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2014-10-13 08:41 - 2014-10-17 13:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-13 08:41 - 2014-10-17 13:46 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-10-13 08:41 - 2014-10-17 13:46 - 00000000 ____D () C:\Program Files (x86)\Java
2014-10-13 08:41 - 2014-10-13 08:41 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-10-13 08:41 - 2014-10-13 08:41 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-10-13 08:41 - 2014-10-13 08:41 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-10-13 08:33 - 2014-10-13 08:33 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Oracle
2014-10-11 13:27 - 2014-10-11 13:27 - 00142528 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxNetAdp.sys
2014-10-10 07:34 - 2014-10-10 07:34 - 00001993 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-10-10 07:34 - 2014-10-10 07:34 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\AVAST Software
2014-10-10 07:34 - 2014-10-10 07:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-10-10 07:33 - 2014-10-10 07:34 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-10-10 07:33 - 2014-10-10 07:33 - 01041168 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00427360 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00307344 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-10-10 07:33 - 2014-10-10 07:33 - 00224896 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00092008 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00079184 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-10-10 07:33 - 2014-10-10 07:33 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-10-10 07:33 - 2014-10-10 07:33 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys
2014-10-10 07:32 - 2014-10-10 07:32 - 00000000 ____D () C:\Program Files\AVAST Software
2014-10-10 00:16 - 2014-10-10 00:16 - 00001716 _____ () C:\Users\Marcel\Desktop\JRT.txt
2014-10-10 00:14 - 2014-10-10 00:14 - 00000000 ____D () C:\windows\ERUNT
2014-10-09 23:27 - 2014-10-18 08:57 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-09 23:26 - 2014-10-09 23:26 - 00001129 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-10-09 23:26 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-10-09 23:26 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-10-09 23:26 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-10-09 23:20 - 2014-10-09 23:20 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-10-08 17:30 - 2014-10-18 10:51 - 00000000 ____D () C:\FRST
2014-10-03 11:30 - 2014-10-03 17:10 - 00000000 ____D () C:\Program Files\Q-Dir
2014-10-03 11:19 - 2014-10-03 11:19 - 00000000 ____D () C:\Users\Marcel\AppData\Local\GHISLER
2014-10-03 11:17 - 2014-10-03 11:17 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\GHISLER
2014-10-03 09:03 - 2014-10-03 09:18 - 00000004 _____ () C:\windows\vx86036.dat
2014-10-03 09:03 - 2014-10-03 09:13 - 00000260 _____ () C:\CKINFO.TXT
2014-10-03 09:03 - 2014-10-03 09:03 - 00000000 ____D () C:\ProgramData\CrypKey
2014-10-03 09:02 - 2014-10-15 13:44 - 00036047 _____ () C:\windows\errord.log
2014-10-03 09:02 - 2014-10-15 13:44 - 00000868 _____ () C:\windows\error.log
2014-10-03 09:02 - 2014-10-03 09:18 - 00003360 _____ () C:\windows\system32\esnecil.ind
2014-10-03 09:02 - 2014-10-03 09:18 - 00000127 _____ () C:\windows\Crypkey.ini
2014-10-03 09:02 - 2014-10-03 09:18 - 00000000 ____D () C:\Program Files\Stellar Phoenix Outlook PST Repair
2014-10-03 09:02 - 2008-05-08 01:29 - 00122880 _____ (CrypKey (Canada) Ltd.) C:\windows\system32\Crypserv.exe
2014-10-03 09:02 - 2008-03-17 19:12 - 00028664 _____ () C:\windows\system32\Ckldrv.sys
2014-10-03 09:02 - 1999-06-18 22:49 - 00165888 _____ (Kenonic Controls) C:\windows\Ckconfig.exe
2014-10-03 09:02 - 1996-05-03 18:21 - 00027648 ____R () C:\windows\Setup_ck.exe
2014-10-03 09:02 - 1996-05-03 16:36 - 00018432 _____ () C:\windows\Setup_ck.dll
2014-10-03 09:02 - 1995-07-04 19:33 - 00011776 _____ () C:\windows\Ckrfresh.exe
2014-10-02 18:42 - 2014-10-02 18:42 - 00003974 _____ () C:\windows\System32\Tasks\4Team updater
2014-10-02 18:41 - 2014-10-03 16:56 - 00000000 ____D () C:\Program Files (x86)\4Team Corporation
2014-10-02 18:41 - 2014-10-02 18:41 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\4Team
2014-10-02 18:41 - 2014-10-02 18:41 - 00000000 ____D () C:\Users\Marcel\AppData\Local\IsolatedStorage
2014-10-02 09:40 - 2014-10-02 09:40 - 00000000 ____D () C:\Neuer Ordner
2014-10-01 09:42 - 2014-10-09 12:03 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\FileZilla
2014-09-26 15:41 - 2014-09-30 08:40 - 00000000 ____D () C:\Users\Marcel\Tracing
2014-09-26 15:40 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_7.dll
2014-09-26 15:40 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_7.dll
2014-09-26 15:40 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_5.dll
2014-09-26 15:40 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_5.dll
2014-09-26 15:40 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_43.dll
2014-09-26 15:40 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_43.dll
2014-09-26 15:40 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_43.dll
2014-09-26 15:40 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_43.dll
2014-09-26 15:39 - 2014-09-26 15:39 - 00002242 _____ () C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2014-09-26 15:39 - 2014-09-26 15:39 - 00002147 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2014-09-26 15:39 - 2014-09-26 15:39 - 00002147 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2014-09-26 15:39 - 2014-09-26 15:39 - 00000196 _____ () C:\windows\DirectX.log
2014-09-26 15:39 - 2014-09-26 15:39 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-09-26 15:39 - 2014-09-26 15:39 - 00000000 ____D () C:\Program Files (x86)\Microsoft SkyDrive
2014-09-26 15:39 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_42.dll
2014-09-26 15:39 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_42.dll
2014-09-26 15:39 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_32.dll
2014-09-26 15:39 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_32.dll
2014-09-26 15:38 - 2014-09-30 08:54 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Windows Live
2014-09-25 13:13 - 2014-10-08 16:50 - 00003718 _____ () C:\windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2014-09-25 13:13 - 2014-09-25 13:13 - 00003476 _____ () C:\windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon
2014-09-25 09:57 - 2014-09-25 09:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-24 17:16 - 2014-09-24 17:16 - 00000000 ____D () C:\Users\Marcel\AppData\Local\FreemakeVideoDownloader
2014-09-18 12:38 - 2014-09-18 12:38 - 00158968 _____ (ESET) C:\windows\system32\Drivers\epfwwfpr.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-18 10:36 - 2014-03-28 08:34 - 02052464 _____ () C:\windows\WindowsUpdate.log
2014-10-18 10:02 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\sru
2014-10-18 09:56 - 2014-04-29 09:31 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-10-18 09:39 - 2014-04-22 19:56 - 00000432 _____ () C:\windows\BRWMARK.INI
2014-10-18 09:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\rescache
2014-10-18 08:03 - 2014-04-22 15:38 - 00003922 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{F5291F67-CB16-4602-A1AA-B673A0FBD3F7}
2014-10-18 08:01 - 2014-04-22 15:14 - 00000000 ___DO () C:\Users\Marcel\SkyDrive
2014-10-17 23:08 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\AppReadiness
2014-10-17 23:07 - 2014-03-28 08:55 - 00010752 _____ () C:\windows\system32\VfService.trf
2014-10-17 17:50 - 2014-04-30 12:43 - 00000000 ____D () C:\Users\Marcel\AppData\Local\CrashDumps
2014-10-17 13:53 - 2014-04-22 15:13 - 00003600 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3121602427-3534730855-1075997385-1001
2014-10-17 13:46 - 2014-04-22 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-17 13:19 - 2014-04-28 20:40 - 00000000 ____D () C:\windows\system32\MRT
2014-10-17 13:16 - 2014-04-28 20:40 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-10-17 10:57 - 2014-05-05 11:47 - 00000000 ____D () C:\xampp
2014-10-16 18:24 - 2014-04-22 19:41 - 00000000 ____D () C:\ProgramData\firebird
2014-10-16 13:35 - 2014-06-12 07:50 - 00011082 _____ () C:\windows\SecuniaPackage.log
2014-10-16 13:35 - 2014-04-29 09:31 - 00003718 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-10-16 08:20 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\NDF
2014-10-15 14:42 - 2014-04-20 09:09 - 00000000 ____D () C:\MADProg
2014-10-15 14:42 - 2014-04-20 09:08 - 00000000 ____D () C:\MADDaten
2014-10-15 13:49 - 2014-03-28 09:27 - 00955470 _____ () C:\windows\system32\perfh00C.dat
2014-10-15 13:49 - 2014-03-28 09:27 - 00256758 _____ () C:\windows\system32\perfc00C.dat
2014-10-15 13:49 - 2014-03-28 09:24 - 01046540 _____ () C:\windows\system32\perfh007.dat
2014-10-15 13:49 - 2014-03-28 09:24 - 00258988 _____ () C:\windows\system32\perfc007.dat
2014-10-15 13:49 - 2013-10-07 20:27 - 00005934 _____ () C:\windows\system32\PerfStringBackup.INI
2014-10-15 13:44 - 2013-08-22 16:46 - 00034703 _____ () C:\windows\setupact.log
2014-10-15 13:44 - 2013-08-22 16:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-10-15 13:44 - 2013-08-22 16:44 - 00499656 _____ () C:\windows\system32\FNTCACHE.DAT
2014-10-15 13:34 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ToastData
2014-10-15 13:34 - 2013-08-22 15:25 - 00524288 ___SH () C:\windows\system32\config\BBI
2014-10-15 13:33 - 2014-07-09 18:28 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\WinStore
2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\MediaViewer
2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\FileManager
2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Camera
2014-10-15 12:32 - 2014-04-22 17:16 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 12:32 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-10-15 12:32 - 2013-08-22 17:20 - 00000000 ____D () C:\windows\CbsTemp
2014-10-15 11:23 - 2014-04-22 15:08 - 00000000 ____D () C:\Users\Marcel
2014-10-15 11:10 - 2014-04-29 10:05 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\vlc
2014-10-14 18:54 - 2014-03-28 08:43 - 00006124 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2014-10-13 10:07 - 2013-10-07 20:23 - 00152266 _____ () C:\windows\PFRO.log
2014-10-10 07:37 - 2014-04-22 16:35 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-10 07:34 - 2014-04-22 16:35 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Google
2014-10-10 00:38 - 2014-04-22 16:42 - 00022391 _____ () C:\windows\Q-Dir.ini
2014-10-10 00:31 - 2014-05-04 19:20 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-10-10 00:31 - 2014-03-28 08:43 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-10 00:09 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\ELAM
2014-10-09 23:43 - 2014-05-07 18:53 - 00000000 ____D () C:\Users\Administrator
2014-10-08 16:42 - 2014-04-22 15:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-05 13:23 - 2014-06-19 14:39 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\SmartDraw
2014-10-03 11:32 - 2014-04-22 16:42 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Q-Dir
2014-10-02 18:40 - 2014-03-28 08:55 - 00000000 ____D () C:\ProgramData\Downloaded Installations
2014-10-01 09:43 - 2014-04-22 16:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2014-10-01 09:43 - 2014-04-22 16:35 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client
2014-10-01 07:58 - 2014-08-30 09:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2014-09-30 00:45 - 2013-08-22 17:38 - 00706016 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-09-30 00:45 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-25 17:44 - 2014-04-22 17:41 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Nitro PDF
2014-09-25 13:13 - 2014-03-28 08:43 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-09-22 09:07 - 2014-04-22 16:37 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-22 08:42 - 2014-05-04 18:19 - 00278152 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe

Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Marcel\AppData\Local\Temp\avgnt.exe
C:\Users\Marcel\AppData\Local\Temp\FreemakeVideoDownloader_3.6.4.3.exe
C:\Users\Marcel\AppData\Local\Temp\FreemakeVideoDownloader_3.7.0.1.exe
C:\Users\Marcel\AppData\Local\Temp\gkey.exe
C:\Users\Marcel\AppData\Local\Temp\i4jdel0.exe
C:\Users\Marcel\AppData\Local\Temp\InstHelper.exe
C:\Users\Marcel\AppData\Local\Temp\K-Lite_Codec_Pack_Basic.exe
C:\Users\Marcel\AppData\Local\Temp\ms.exe
C:\Users\Marcel\AppData\Local\Temp\msvcr71.dll
C:\Users\Marcel\AppData\Local\Temp\MySwisscomAssistant_Setup.exe
C:\Users\Marcel\AppData\Local\Temp\nitro_reader3_64.exe
C:\Users\Marcel\AppData\Local\Temp\pkeyui.exe
C:\Users\Marcel\AppData\Local\Temp\Q-Dir_uninstall.exe
C:\Users\Marcel\AppData\Local\Temp\Quarantine.exe
C:\Users\Marcel\AppData\Local\Temp\safepstbackup_1_00.exe
C:\Users\Marcel\AppData\Local\Temp\SamsungAPInstaller_1412143055024.exe
C:\Users\Marcel\AppData\Local\Temp\ScreenpressoUpd.exe
C:\Users\Marcel\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Marcel\AppData\Local\Temp\wabk.exe
C:\Users\Marcel\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-14 12:26

==================== End Of Log ============================
         
--- --- ---

Alt 18.10.2014, 16:20   #23
schrauber
/// the machine
/// TB-Ausbilder
 

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



Schaut gut aus. Bestehen noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 19.10.2014, 16:49   #24
sugus666
 
Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



keine Probleme, nochmals Danke!!!

Alt 20.10.2014, 10:57   #25
schrauber
/// the machine
/// TB-Ausbilder
 

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 20.10.2014, 15:29   #26
sugus666
 
Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Icon17

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



hi Schrauber
ist alles erledigt - muss nur noch Spende auslösen
Sugus666

Alt 21.10.2014, 11:47   #27
schrauber
/// the machine
/// TB-Ausbilder
 

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - Standard

Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol
arbeitsplatz, fehlercode 0x80070057, fehlercode 0xc0000005, fehlercode 0xe0434352, fenster schließen, pup.optional.conduit.a, pup.optional.defaultsearch.a, pup.optional.driverperformer.a, pup.optional.linkey.a, pup.optional.opencandy, pup.optional.searchprotect.a, pup.optional.trovi.a, rogue.multiple, win32/clientconnect.a, win32/conduit.searchprotect.h, win32/conduit.searchprotect.i, win32/downloadsponsor.a, win32/opencandy.a, win32/toolbar.besttoolbars.g, win32/toolbar.besttoolbars.i, win32/toolbar.besttoolbars.j, win32/toolbar.linkury.e, win64/conduit.searchprotect.a, win64/toolbar.besttoolbars.a, win64/toolbar.besttoolbars.b




Ähnliche Themen: Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol


  1. Das Problem der ASUS UX31E Ultrabook
    Mülltonne - 03.07.2015 (3)
  2. polizeiwarnung; wiederherstellung; programme öffnen nicht mehr
    Log-Analyse und Auswertung - 20.05.2015 (9)
  3. Bluescreen - Polizeiwarnung - Lenovo Ultrabook startet nur bis Lenovo-Symbol!
    Mülltonne - 08.10.2014 (1)
  4. Mein privates Ultrabook (Samsung) stürzt sporadisch ab (Windows Blue Screen)
    Log-Analyse und Auswertung - 28.06.2014 (15)
  5. Windows 7 PC startet nur noch sehr langsam
    Log-Analyse und Auswertung - 09.01.2014 (7)
  6. Windows 7 PC startet nur noch sehr langsam
    Alles rund um Windows - 08.01.2014 (7)
  7. Ultrabook einige infizierte Objekte
    Log-Analyse und Auswertung - 26.09.2013 (15)
  8. Suche Notebook / Ultrabook
    Netzwerk und Hardware - 15.09.2013 (10)
  9. Windows startet nur noch im abgesicherten Modus
    Log-Analyse und Auswertung - 09.07.2013 (1)
  10. Ultrabook Systemcheck
    Log-Analyse und Auswertung - 08.07.2013 (3)
  11. Mozilla Firefox startet nur noch als Administrator
    Netzwerk und Hardware - 14.02.2013 (3)
  12. Computer startet nur noch selten und stürtzt ab
    Plagegeister aller Art und deren Bekämpfung - 07.10.2012 (4)
  13. Laptop startet nur noch mit Netzteil
    Netzwerk und Hardware - 28.08.2011 (9)
  14. Win XP startet nur noch das setup?
    Alles rund um Windows - 03.10.2008 (3)
  15. PC startet nur noch BIOS Utility Setup
    Alles rund um Windows - 06.08.2007 (2)
  16. PC startet nur noch über Netzteilschalter
    Netzwerk und Hardware - 05.10.2006 (5)
  17. hilfe!!!!!!!! win xp startet immer noch nicht
    Alles rund um Windows - 14.09.2005 (2)

Zum Thema Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol - ok, dann bleiben noch 200 ESET meckert immer viel an, aber da ist schon einiges dabei was runter muss - Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol...
Archiv
Du betrachtest: Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.