Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: BKA-Trojaner aber keine Sperrungen

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 17.07.2015, 15:20   #1
ihekne95
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Hallo,
Ich kenne mich überhaupt nicht mit Computern aus und hoffe, dass mir jemand weiterhelfen kann.
Zum Thema:
Ich wollte mir gestern einen Film auf eine dieser Streaming-Seiten ansehen, auf denen man bekanntlich weitergeleitet wird, wenn man sich den Film angucken möchte. Als ich auf eine dieser Seiten war, erschien ein kleines, weißes Fenster im oberen mittigen Bereich der Seite und meinte, dass auf meinem PC illegales Material gefunden wurde und er gesperrt werden würde, wenn man keine 100 Euro zahlt. Die Anzeige war ohne großen Schnick Schnack nur das weiße Kästchen mit der in schwarz gedruckten Aufforderung und einer kleinen Leiste am unteren Ende in der man einen Code eingeben soll (vermutlich Kreditkarte? Habe keine) um das Geld zu überweisen/abzuziehen. Mir war natürlich klar, dass das nicht sein konnte und habe versucht es wegzuklicken, doch es kam immer wieder. Die Seite an sich und den Browser konnte ich vorerst auch nicht schließen, habe es dann aber mit Rechtsklick und 'Fenster Schließen' geschafft.

Als ich dann kurz darauf den Fall gegoogled habe, hat sich herausgestellt, dass es sich womöglich um den BKA-Trojaner handeln könnte, der sich bereits beim Betreten der Seite installiert, im Hintergrund herunterlädt und den Pc/Browser lahm legt bzw sperrt.

An meinem Computer kann ich aber bis jetzt immer noch keine Veränderung feststellen. Hatte gestern nach der Meldung auch sofort mein Virenprogramm angeschmissen und es entdeckte auch gleich zwei mittelschwere Bedrohungen die er aber auch gleich entfernt hat. Dennoch denke ich, dass sich ein solcher Trojaner nicht so einfach entdecken und entfenen lässt.

In einem anderen Forum wurde mir geraten Malwarebytes Antimalware herunterzuladen und meinen Laptop scannen zu lassen. Habe ich auch gleich gemacht und es kamen 82 Befunde heraus. Allerdings hatte mir dasProgramm erst nach dem Scan eröffnet, dass ich meine Datenbank aktualisieren sollte. Also schnell aktualisiert und nochmal durchlaufen lassen. Wieder 14 mal fündig geworden. habe sie erst einmal in Virenquarantäne gepackt und mir auf Anraten Malwarebytes Anti-Rootkit heruntergeladen und ebenfalls alles scannen lassen. Das Ergebnis konnte ich jedoch nicht mehr Einsehen, da mein PC sofort einen Neustart gemacht hat und danach noch einen zweiten, weil das Programm es für nötig Befunden hat, wie ich das aus der Englischen Anzeige lesen konnte, sie mir Windows kurz vor dem zweiten Neustart angezeigt hatte. Allerdings hat sich das Programm nach den Neustarts nicht wieder geöffnet oder mir sonst etwas angezeigt.

Jetzt weiß ich nicht mehr weiter
Da ich zum Zeitpunkt, als sich die Anzeige gezeigt hat, mein Adobe Reader und Flash Player nicht auf die neuste Version aktualisiert hatte, ist die Wahrscheinlichkeit doch groß, dass sich der Trojaner auf meinem Laptop befindet, oder? Doch wie und wo erkenne ich ihn und vor allem wie bekomme ich ihn wieder runter?

Falls es hilft: habe einen Windows 8.1 Lenovo Laptop, Adobe Reader und Flash Player sind mittlerweile aktualisiert, Java ist deaktiviert, Google Chrome (Hatte ich zum Zeitpunkt benutzt) befand sich ebenfalls auf dem neusten Stand, als Virenprogramm benutzte ich AVG (free, nicht PRO).

Es wäre wirklich großartig, wenn mir jemand (vielleicht mit viel Geduld ) helfen könnte.
LG!

Alt 17.07.2015, 15:25   #2
M-K-D-B
/// TB-Ausbilder
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen






Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen.


Bitte beachte folgende Hinweise:
  • Falls wir Hinweise auf illegal erworbene Software finden, werden wir den Support unterbrechen bis jegliche Art von illegaler Software vom Rechner entfernt wurde.
  • Lies dir die Anleitungen sorgfältig durch. Solltest du Probleme haben, stoppe mit deiner Bearbeitung und beschreibe mir dein Problem so gut es geht.
  • Solltest du mir nicht innerhalb von 3 Tagen antworten, gehe ich davon aus, dass du keine Hilfe mehr benötigst. Dann lösche ich dein Thema aus meinem Abo. Solltest du einmal länger abwesend sein, so gib mir bitte Bescheid!
  • Während der Bereinigung bitte nichts installieren oder deinstallieren, außer ich bitte dich darum!
  • Bitte beachten: Download bei filepony.de: So ladet Ihr unsere Tools richtig!
  • Alle zu verwendenen Programme sind auf dem Desktop abzuspeichern und von dort zu starten!


Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags:
So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke aauf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.

Danke für deine Mitarbeit!




Alle Logdateien von MBAM mit Funden posten!!!



Zur ersten Analyse bitte FRST und TDSS-Killer ausführen:



Schritt 1
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)






Schritt 2
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.







Bitte poste mit deiner nächsten Antwort
  • alle Logdateien von MBAM mit Funden,
  • die Logdatei von TDSS-Killer,
  • die beiden neuen Logdateien von FRST.
__________________

__________________

Alt 17.07.2015, 16:13   #3
ihekne95
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Hallo und danke für die schnelle Antwort! Leider auch schon das erste Problem: etwas stimmt mit unserer Internetverbindung nicht und wenn ich etwas runterlade dauert das eine Zeit und anscheinend hängt das manchmal auch mit der Seite zusammen. Auf jeden Fall startet der Download zu Farbar's Recovery Scan Tool bei mir einfach nicht. Es wird immer 0 Byte/s - 0 B von 2,0 MB angezeigt und es verändert sich nichts. Gibt es auch noch eine Möglichkeit es von einer anderen Seite zu Downloaden? Das gleiche Problem hatte ich mit dem Malwarebytes Anti-Rootkit. Da konnte ich es auch nicht von FilePony runterladen und musste eine andere Seite suchen.

Okay hat wundersamerweise doch heruntergeladen Entschuldigung

Okay hier ist FRST.txt.

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
Ran by Franziska (administrator) on LENOVO-PC on 17-07-2015 16:52:40
Running from C:\Users\Franziska\Desktop
Loaded Profiles: Franziska (Available Profiles: Franziska)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\loggingserver.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Pokki) C:\Users\Franziska\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIGJE.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Pokki) C:\Users\Franziska\AppData\Local\Pokki\Engine\HostAppService.exe
(Pokki) C:\Users\Franziska\AppData\Local\Pokki\Engine\HostAppService.exe
(AVG Secure Search) C:\Program Files (x86)\AVG Web TuneUp\avgcefrend.exe
() C:\Program Files\Lenovo PhoneCompanion\adb.exe
(Pokki) C:\Users\Franziska\AppData\Local\Pokki\Engine\StartMenuIndexer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2014-02-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-08-15] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-08-15] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-08-15] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [snp2uvc] => C:\WINDOWS\vsnp2uvc.exe
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-06-30] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [3174800 2015-07-12] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Run: [EPSON BX305 Series] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIGJE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com/?cid={AB46C594-7D09-4979-986C-153B9015C85B}&mid=9c81e2d5481d47d2a1e66159075d9129-c40fa69071f88bcc879e1f6686bbed7b8d9f4f45&lang=de&ds=AVG&coid=avgtbavg&cmpid=1214tb&pr=fr&d=2014-11-06 21:27:08&v=4.1.0.411&pid=wtu&sg=&sap=hp
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://lenovo13.msn.com/?pc=LCJB
hxxp://www.lenovo.com
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={AB46C594-7D09-4979-986C-153B9015C85B}&mid=9c81e2d5481d47d2a1e66159075d9129-c40fa69071f88bcc879e1f6686bbed7b8d9f4f45&lang=de&ds=AVG&coid=avgtbavg&cmpid=1214tb&pr=fr&d=2014-11-06 21:27:08&v=4.1.0.411&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={AB46C594-7D09-4979-986C-153B9015C85B}&mid=9c81e2d5481d47d2a1e66159075d9129-c40fa69071f88bcc879e1f6686bbed7b8d9f4f45&lang=de&ds=AVG&coid=avgtbavg&cmpid=1214tb&pr=fr&d=2014-11-06 21:27:08&v=4.1.0.411&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {97CB315F-D830-4B49-92BC-986D9C008592} URL = 
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.1.4.948\AVG Web TuneUp.dll [2015-07-12] (AVG)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-17] (Oracle Corporation)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.1.4.948\AVG Web TuneUp.dll [2015-07-12] (AVG)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-17] (Oracle Corporation)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.2.0\ViProtocol.dll [2014-12-10] (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{126079A8-E17A-4F05-894B-2B5B8A051737}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{E6F50CE2-672B-468B-BF96-C59F56340331}: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285
FF SelectedSearchEngine: AVG Secure Search
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-17] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-17] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.7.0\\npsitesafety.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-17] (Oracle Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\searchplugins\avg-secure-search.xml [2015-05-07]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2015-07-12]
FF Extension: AVG Web TuneUp - C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\avg@toolbar [2015-05-07]
FF Extension: Adblock Plus - C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18]

Chrome: 
=======
CHR Profile: C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-17]
CHR Extension: (Google Docs) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-17]
CHR Extension: (Google Drive) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-17]
CHR Extension: (YouTube) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-17]
CHR Extension: (AVG Secure Search) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2014-11-06]
CHR Extension: (Google Search) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-17]
CHR Extension: (Google Sheets) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-17]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-19]
CHR Extension: (Cath Kidston) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndlpkmaeinmnbiadacenijnhlolneopm [2014-10-19]
CHR Extension: (Google Wallet) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-17]
CHR Extension: (Gmail) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-06-30] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-06-30] (AVG Technologies CZ, s.r.o.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-08-15] (Lenovo(beijing) Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] ()
S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-08-15] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-08-15] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-08-15] ()
R2 vToolbarUpdater18.7.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe [1874320 2015-07-12] (AVG Secure Search)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1195920 2015-07-12] ()

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. )
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [107736 2015-07-17] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-15] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3593432 2014-10-07] (Realtek Semiconductor Corporation                           )
R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [2853400 2014-01-23] (Sonix Co. Ltd.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-17 16:52 - 2015-07-17 16:53 - 00021675 _____ C:\Users\Franziska\Desktop\FRST.txt
2015-07-17 16:52 - 2015-07-17 16:52 - 00000000 ____D C:\FRST
2015-07-17 16:51 - 2015-07-17 16:51 - 01814528 _____ C:\Users\Franziska\Downloads\Nicht bestätigt 599347.crdownload
2015-07-17 16:38 - 2015-07-17 16:43 - 02133504 _____ (Farbar) C:\Users\Franziska\Desktop\FRST64.exe
2015-07-17 14:23 - 2015-07-17 14:43 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-07-17 14:17 - 2015-07-17 14:48 - 00000000 ____D C:\Users\Franziska\Desktop\mbar
2015-07-17 13:54 - 2015-07-17 14:11 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Franziska\Downloads\mbar-1.09.1.1004.exe
2015-07-17 12:46 - 2015-07-17 12:46 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-07-17 12:46 - 2015-07-17 12:46 - 00002078 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-07-17 12:00 - 2015-07-17 12:00 - 00013555 _____ C:\Users\Franziska\Desktop\Malwarebytes antimalware befunde.txt
2015-07-17 11:08 - 2015-07-17 14:50 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-07-17 11:03 - 2015-07-17 14:17 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-07-17 11:03 - 2015-07-17 11:03 - 00001125 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-07-17 11:03 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-07-17 11:03 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-07-17 10:46 - 2015-07-17 10:57 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Franziska\Downloads\mbam-setup-2.1.8.1057.exe
2015-07-17 00:54 - 2015-07-17 00:54 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Sun
2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\ProgramData\Oracle
2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\Program Files (x86)\Java
2015-07-17 00:15 - 2015-07-17 00:15 - 00563296 _____ (Oracle Corporation) C:\Users\Franziska\Downloads\chromeinstall-8u51.exe
2015-07-13 00:30 - 2015-07-13 00:45 - 33832046 _____ C:\Users\Franziska\Downloads\Adel Tawil - Lieder (Parodie)     Luke Mockridge - Pimmelbingo    .mp4
2015-07-11 22:33 - 2015-07-11 22:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-11 21:20 - 2015-07-11 21:20 - 00001957 _____ C:\Users\Public\Desktop\Lenovo Updates.lnk
2015-06-29 14:05 - 2015-06-29 14:05 - 00000000 ____D C:\Users\Franziska\Desktop\pdf
2015-06-27 18:18 - 2015-06-27 18:18 - 00025592 _____ C:\Users\Franziska\Desktop\Kündigung Mama und Oma Wohnung.odt
2015-06-27 15:08 - 2015-06-27 15:08 - 00000000 ____D C:\Users\Franziska\AppData\Local\GWX
2015-06-26 09:49 - 2015-06-26 09:49 - 00293296 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2015-06-22 21:09 - 2015-05-22 15:08 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-06-22 21:09 - 2015-05-21 15:08 - 01119232 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-06-22 21:09 - 2015-05-21 15:08 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-06-22 21:09 - 2015-05-21 15:08 - 00756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-06-22 21:09 - 2015-05-21 15:08 - 00422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-06-22 21:09 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-06-22 21:09 - 2015-05-21 15:08 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-06-22 21:09 - 2015-04-17 00:07 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-06-19 12:50 - 2015-06-19 12:50 - 00000000 ____D C:\Program Files\Common Files\AV
2015-06-19 12:38 - 2015-07-11 21:15 - 00001279 _____ C:\Users\Franziska\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-17 16:53 - 2014-08-15 00:39 - 01622397 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-17 16:40 - 2014-11-18 14:43 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-17 16:31 - 2014-10-17 15:20 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2372557226-1662704196-739550879-1002
2015-07-17 16:08 - 2014-10-17 15:34 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-17 16:03 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-07-17 16:02 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-07-17 14:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-07-17 14:56 - 2013-08-22 16:46 - 00111918 _____ C:\WINDOWS\setupact.log
2015-07-17 14:48 - 2014-10-17 15:22 - 00000000 ___DO C:\Users\Franziska\OneDrive
2015-07-17 14:48 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska\AppData\Local\Pokki
2015-07-17 14:47 - 2014-10-17 15:34 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-17 14:46 - 2014-10-17 15:14 - 00421286 _____ C:\Users\Franziska\AppData\Local\BTServer.log
2015-07-17 14:46 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-17 14:45 - 2014-03-18 11:44 - 00022568 _____ C:\WINDOWS\PFRO.log
2015-07-17 14:44 - 2014-08-15 02:18 - 00008704 _____ C:\WINDOWS\system32\VfService.trf
2015-07-17 14:44 - 2014-08-15 01:22 - 10539970 _____ C:\WINDOWS\SysWOW64\rootpa.e2e
2015-07-17 14:41 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-07-17 14:40 - 2014-08-15 01:35 - 00000000 ____D C:\Program Files (x86)\Lenovo
2015-07-17 14:40 - 2014-08-15 01:25 - 06317768 _____ C:\Users\Public\CAFADEBUG.log
2015-07-17 13:07 - 2014-11-15 14:48 - 00000000 ____D C:\Users\Franziska\AppData\Local\Adobe
2015-07-17 12:47 - 2015-04-10 20:50 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\ProgramData\Adobe
2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-07-17 11:17 - 2014-11-18 14:43 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-07-17 10:46 - 2014-10-17 16:02 - 00000000 ____D C:\ProgramData\MFAData
2015-07-17 10:46 - 2014-10-17 15:25 - 00003950 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{26E0C7CA-7B0C-4D1A-8D47-19EEFF6E6754}
2015-07-17 10:45 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-07-16 21:33 - 2015-01-23 12:49 - 00000000 ____D C:\Users\Franziska\Documents\Dok. Schule
2015-07-16 21:12 - 2014-10-17 15:34 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-16 21:03 - 2014-10-17 15:34 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-16 21:03 - 2014-10-17 15:34 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-13 00:47 - 2014-11-13 22:52 - 00141824 ___SH C:\Users\Franziska\Downloads\Thumbs.db
2015-07-12 23:02 - 2014-11-06 22:27 - 00000000 ____D C:\Users\Franziska\AppData\Local\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2015-07-12 16:53 - 2014-11-08 18:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-11 22:21 - 2014-08-15 02:31 - 00000000 ____D C:\ProgramData\LU
2015-07-11 22:19 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-07-11 22:18 - 2014-08-15 01:22 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-07-10 16:42 - 2014-10-17 16:15 - 00001008 _____ C:\Users\Public\Desktop\AVG 2015.lnk
2015-07-10 16:42 - 2014-10-17 16:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-07-08 14:35 - 2015-03-19 16:13 - 00000000 ____D C:\Users\Franziska\Documents\gescannte Objekte
2015-07-06 23:24 - 2015-05-04 18:53 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-07-06 23:24 - 2015-05-04 18:53 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-30 23:31 - 2014-10-18 19:32 - 00603136 ___SH C:\Users\Franziska\Desktop\Thumbs.db
2015-06-27 18:20 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska
2015-06-27 14:34 - 2014-10-23 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-06-27 14:23 - 2014-10-23 17:55 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-06-23 00:02 - 2014-12-28 20:41 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-06-23 00:02 - 2014-10-23 22:24 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-06-22 20:48 - 2014-08-15 10:23 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat
2015-06-22 20:48 - 2014-08-15 10:23 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat
2015-06-22 20:48 - 2014-03-18 11:53 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-06-21 20:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-06-21 14:09 - 2015-02-04 16:50 - 00000000 ____D C:\Users\Franziska\Desktop\Neuer Ordner

==================== Files in the root of some directories =======

2014-10-17 15:14 - 2015-07-17 14:46 - 0421286 _____ () C:\Users\Franziska\AppData\Local\BTServer.log
2014-10-20 17:20 - 2014-11-01 17:39 - 0007596 _____ () C:\Users\Franziska\AppData\Local\resmon.resmoncfg
2014-08-15 01:24 - 2014-08-15 01:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Franziska\AppData\Local\Temp\1_flashplayer.exe
C:\Users\Franziska\AppData\Local\Temp\2_flashplayer.exe
C:\Users\Franziska\AppData\Local\Temp\AutoRun.exe
C:\Users\Franziska\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Franziska\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Franziska\AppData\Local\Temp\drm_dyndata_7360010.dll
C:\Users\Franziska\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Franziska\AppData\Local\Temp\eauninstall.exe
C:\Users\Franziska\AppData\Local\Temp\oct3EA.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct4F2C.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct51DB.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct53B0.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct549A.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct5B9A.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct641E.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct6475.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct72B1.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct801A.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct948E.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\octE19D.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\The Sims 2 Pets_uninst.exe
C:\Users\Franziska\AppData\Local\Temp\VP6Install.exe
C:\Users\Franziska\AppData\Local\Temp\VP6VFW.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-07-17 12:28

==================== End of log ============================
         
--- --- ---


Auddition.txt.
[CODE]Additional
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
Ran by Franziska at 2015-07-17 16:54:44
Running from C:\Users\Franziska\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2372557226-1662704196-739550879-500 - Administrator - Disabled)
Franziska (S-1-5-21-2372557226-1662704196-739550879-1002 - Administrator - Enabled) => C:\Users\Franziska
Gast (S-1-5-21-2372557226-1662704196-739550879-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2372557226-1662704196-739550879-1004 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3D-Schach 2.0 (HKLM-x32\...\{CE057820-2732-11D4-A8C5-0050DA353A30}) (Version:  - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{665D4B18-EA91-BE16-3212-218C63F5DC4E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.8.0 - AppEx Networks)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6081 - AVG Technologies)
AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.4.948 - AVG Technologies)
Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden
CEP - Color Enable Package (HKLM-x32\...\CEP - Colour Enable Packages_is1) (Version: 6.0b (beta) - Numenor, for ModTheSims2)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.52 - Conexant)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Die Sims 2: Open For Business (HKLM-x32\...\{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}) (Version:  - )
Die Sims 2: Wilde Campus-Jahre (HKLM-x32\...\{01521746-02A6-4A72-00BD-A285DF6B80C6}) (Version:  - )
Die Sims™ 2 Apartment-Leben (HKLM-x32\...\{B6F5B704-06D3-4687-90F3-6195304AD755}) (Version:  - Electronic Arts)
Die Sims™ 2 Gute Reise (HKLM-x32\...\{F248ADFA-64E0-4b03-8A83-059078BED6A0}) (Version:  - Electronic Arts)
Die Sims™ 2 Haustiere (HKLM-x32\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version:  - )
Die Sims™ 2 Super Deluxe (HKLM-x32\...\{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}) (Version:  - Electronic Arts)
Die Sims™ 2 Vier Jahreszeiten (HKLM-x32\...\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) (Version:  - )
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Druckerdeinstallation für EPSON BX305 Series (HKLM\...\EPSON BX305 Series) (Version:  - SEIKO EPSON Corporation)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.17 - Lenovo)
Energy Manager (x32 Version: 1.5.0.17 - Lenovo) Hidden
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
FarmVille 2 (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Pokki_34e8f5c0c9e5744bf2cdb514283762dd0524776b) (Version: 1.0.4.55785 - Pokki)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.)
Host App Service (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Pokki) (Version: 0.269.7.660 - Pokki)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1321.0_WHQL - Sonix)
Lenovo FusionEngine  (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.2 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.2 - Lenovo) Hidden
Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.36.1 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited)
Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo)
Lenovo Web Start (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1) (Version: 1.0.2.53457 - Pokki)
LibreOffice 4.3.4.1 (HKLM-x32\...\{7D983A32-F645-48AB-8E38-4ACD234F40BC}) (Version: 4.3.4.1 - The Document Foundation)
Little Alchemy (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\littlealchemy-c7de5d8adcfd810d98ec68069ab57bd9) (Version: 1.1.1 - Recloak)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.3 - Mozilla)
Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro)
OEM Application Profile (HKLM-x32\...\{8F92E0CF-620B-5C20-F292-59C93567B06D}) (Version: 1.00.0000 - Ihr Firmenname)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.805.806.012214 - REALTEK Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.20.243 - REALTEK Semiconductor Corp.)
Start Menu (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Pokki_Start_Menu) (Version: 0.269.7.660 - Pokki)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)

==================== Restore Points =========================

27-06-2015 14:21:49 Windows Update
10-07-2015 21:32:10 Windows Update
11-07-2015 22:17:33 Installiert REALTEK PCIE Wireless LAN Driver
17-07-2015 12:28:57 Windows Update

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {059FF85A-96A7-4F30-A151-025BF8D10B64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
Task: {0C6938DC-5060-47BB-A244-9A5EB9241201} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo)
Task: {107C5BBF-0D1D-4850-A7CE-80A15540F1AE} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-06-27] (Microsoft Corporation)
Task: {12470315-4A24-4A46-978B-34FE10051EE7} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {13842334-9265-4B05-9B11-BB24C42F8DC4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {2C817108-BF13-4F80-A785-9C358584854F} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {307BD0C3-750A-40EF-A3F9-4288EDF529BD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-17] (Adobe Systems Incorporated)
Task: {35FDB4CA-8E11-4760-899E-1C6B82C96F61} - System32\Tasks\{808CE7D6-F887-46A4-8EAC-78FDCF14B029} => pcalua.exe -a E:\Setup.exe -d E:\
Task: {3F25A2CE-84E0-4B57-8CD6-D67BEBA2A6E4} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {4E3DA8B7-52C1-44FF-8494-9303931DF0B1} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: {9523A3F0-9354-4859-AB26-D73344A8B4FA} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] ()
Task: {AE485BC0-FDB5-4ECA-9875-A86CD8B8DBAE} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo)
Task: {B8114FCD-1409-421C-B736-0F019EE4C980} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] ()
Task: {FA2727FE-C2D9-4520-B56D-97513B9D0DAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-02-25 17:02 - 2015-07-12 23:02 - 01195920 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2014-04-18 22:12 - 2014-04-18 22:12 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2014-08-15 01:27 - 2014-01-22 14:04 - 00084992 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2014-08-15 02:13 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-08-15 02:18 - 2014-08-15 02:18 - 00067856 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
2014-08-15 02:18 - 2014-08-15 02:18 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll
2015-07-12 23:02 - 2015-07-12 23:02 - 00168336 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\loggingserver.exe
2014-08-15 01:24 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2014-03-26 12:50 - 2014-08-15 02:23 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2014-12-10 20:26 - 2015-07-12 23:02 - 03174800 _____ () C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
2014-04-18 22:12 - 2014-04-18 22:12 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-08-15 02:18 - 2014-08-15 02:18 - 00815104 _____ () C:\Program Files\Lenovo PhoneCompanion\adb.exe
2015-07-12 23:02 - 2015-07-12 23:02 - 00528272 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\log4cplusU.dll
2014-11-06 22:26 - 2015-07-12 23:02 - 40638864 _____ () C:\Program Files (x86)\AVG Web TuneUp\libcef.dll
2015-04-28 22:15 - 2015-04-28 22:15 - 00569856 _____ () C:\Users\Franziska\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll
2015-04-28 22:15 - 2015-04-28 22:15 - 01400846 _____ () C:\Users\Franziska\AppData\Local\Pokki\Engine\avcodec-54.dll
2015-04-28 22:15 - 2015-04-28 22:15 - 00151054 _____ () C:\Users\Franziska\AppData\Local\Pokki\Engine\avutil-51.dll
2015-04-28 22:15 - 2015-04-28 22:15 - 00222734 _____ () C:\Users\Franziska\AppData\Local\Pokki\Engine\avformat-54.dll
2015-07-16 21:12 - 2015-07-13 23:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
2015-07-16 21:12 - 2015-07-13 23:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\Users\Franziska\OneDrive:ms-properties

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VisualDiscovery => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run32: => "snp2uvc"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{AFBD7067-D2F6-4D3C-85B3-88A008C18967}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{663A46B4-3414-4F48-A319-A422F7F43977}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{AC2767B5-A536-457E-B67B-50A79A754C46}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{77D8B7D4-27EC-4437-A263-031784DFAC63}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{55376DCC-D006-4A28-AA16-B85FAC106F3E}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{084835F4-19BE-43D6-BEB8-78503B45965C}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
FirewallRules: [{1F9F0BC2-0CF8-4AA0-974C-7BA40E438A95}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{EE98E101-3C74-4620-AE02-3ADF1B6FA0CD}] => (Allow) LPort=55100
FirewallRules: [{0798E54B-7073-4647-8B2A-685DE6EC27D3}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{0A8AAECB-B085-4693-8040-C11384793642}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{AB42E82B-FAD0-4683-B81E-CBA57E9CE423}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{DA68199A-F30C-4B34-B07D-55BC97A1320D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BEE4CC4D-667E-4F8F-A4B9-C3191BCA1FC5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{7FADA343-E843-4133-A0D4-4BC7788FC0A5}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{518A6693-CCCD-4A4B-B9D9-01F793BF96AE}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{1C8585A3-15F7-4FF0-A443-C7D6A06A964A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{D1DD6BFC-A9A7-4E39-BCE5-7A467EDBD48B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{D53DDE3E-9291-4381-BFBE-4405895AD9D4}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{A02C96FC-1AC8-4B35-AB3B-3530569EF51D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{28841159-30B7-405D-9466-DA3C044D5BE5}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{43A83805-ED93-4F21-B195-E5CB8AE4B9DD}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{6929263B-9A5C-42DA-835C-976C8D9937FE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: Dell 3333dn
Description: Dell 3333dn
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Dell
Service: usbscan
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 02:43:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „Microsoft.WindowsAlarms_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 02:41:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 01:00:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: LENOVO-PC)
Description: Produkt: Adobe Reader XI (11.0.11) - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011012}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (07/17/2015 12:12:46 AM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT)
Description: There was an error with the Windows Location Provider database

Error: (07/13/2015 03:54:09 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm LiveComm.exe, Version 17.5.9600.20911 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1160

Startzeit: 01d0bd72a923b637

Endzeit: 4294967295

Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe

Berichts-ID: 9f362b2b-2966-11e5-838a-28d244c25993

Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe

Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1

Error: (07/13/2015 12:18:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WUDFHost.exe, Version: 6.3.9600.17415, Zeitstempel: 0x5450412e
Name des fehlerhaften Moduls: amdocl64.dll, Version: 10.0.1359.5, Zeitstempel: 0x5351e341
Ausnahmecode: 0xc0000409
Fehleroffset: 0x0000000000cddf47
ID des fehlerhaften Prozesses: 0xd58
Startzeit der fehlerhaften Anwendung: 0xWUDFHost.exe0
Pfad der fehlerhaften Anwendung: WUDFHost.exe1
Pfad des fehlerhaften Moduls: WUDFHost.exe2
Berichtskennung: WUDFHost.exe3
Vollständiger Name des fehlerhaften Pakets: WUDFHost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WUDFHost.exe5

Error: (07/11/2015 10:11:14 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005


System errors:
=============
Error: (07/17/2015 02:44:04 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (07/17/2015 02:43:56 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca


Microsoft Office:
=========================
Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

Error: (07/17/2015 02:43:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Microsoft.WindowsAlarms_8wekyb3d8bbwe!App-2144927141

Error: (07/17/2015 02:41:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

Error: (07/17/2015 01:00:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: LENOVO-PC)
Description: Adobe Reader XI (11.0.11) - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011012}1625(NULL)(NULL)(NULL)

Error: (07/17/2015 12:12:46 AM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT)
Description: -2147024883

Error: (07/13/2015 03:54:09 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.20911116001d0bd72a923b6374294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe9f362b2b-2966-11e5-838a-28d244c25993microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (07/13/2015 12:18:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: WUDFHost.exe6.3.9600.174155450412eamdocl64.dll10.0.1359.55351e341c00004090000000000cddf47d5801d0bcef6e576b7fC:\Windows\System32\WUDFHost.exeC:\Windows\System32\amdocl64.dllda91dd9b-28e3-11e5-8389-28d244c25993

Error: (07/11/2015 10:11:14 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005


==================== Memory info =========================== 

Processor: AMD A6-6310 APU with AMD Radeon R4 Graphics 
Percentage of memory in use: 33%
Total physical RAM: 7128.26 MB
Available physical RAM: 4752.48 MB
Total Virtual: 8280.26 MB
Available Virtual: 5363.95 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:890.1 GB) (Free:831.13 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.14 GB) NTFS
Drive f: () (Removable) (Total:3.68 GB) (Free:0.14 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: E07FA830)

Partition: GPT Partition Type.

========================================================
Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End of log ============================
         
--- --- ---


Der TDSSKiller hat jedoch nichts gefunden. Nach dem Scan heißt es 'No threats found' aber ich habe alle Schritte befolgt
__________________

Alt 17.07.2015, 19:44   #4
M-K-D-B
/// TB-Ausbilder
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Servus,


und was ist mit den Logdateien von MBAM?

Ich hatte dich doch gebeten, alle Logdateien mit Funden zu posten...


In welchem Forum hast du denn um Hilfe gebeten? Bitte dazu einen Link posten.

Geändert von M-K-D-B (17.07.2015 um 19:50 Uhr)

Alt 17.07.2015, 20:10   #5
ihekne95
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Achso, stimmt! Ich war kurz verwirrt was mit MBMA gemeint ist.

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org


Error, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Update, Bad md5 or size: akadomains, 11, 
Error, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Update, Bad md5 or size: akaips, 11, 
Update, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Manual, Remediation Database, 2015.5.13.1, 2015.7.15.2, 
Update, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Manual, Domain Database, 0.0.0.0, 2015.6.12.1, 
Update, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Manual, IP Database, 0.0.0.0, 2015.6.12.1, 
Update, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Manual, Rootkit Database, 2015.6.2.1, 2015.7.16.1, 
Error, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, 0, 
Error, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, 0, 
Update, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, AKA IP Database, 0.0.0.0, 2015.7.15.1, 
Update, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, Malware Database, Failed, Unable to access update server, 2015.6.3.3, 2015.7.17.2, 
Update, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, AKA Domain Database, Failed, Unable to access update server, 0.0.0.0, 2015.7.16.1, 
Error, 17.07.2015 12:09, SYSTEM, LENOVO-PC, Update, Bad md5 or size: akadomains, 11, 
Error, 17.07.2015 12:09, SYSTEM, LENOVO-PC, Update, akaips: inflate, 4294967291, 
Update, 17.07.2015 12:09, SYSTEM, LENOVO-PC, Manual, AKA IP Database, 2015.7.15.1, 2015.7.15.1, 
Error, 17.07.2015 12:11, SYSTEM, LENOVO-PC, Manual, 0, 
Update, 17.07.2015 12:11, SYSTEM, LENOVO-PC, Manual, AKA Domain Database, Failed, Unable to access update server, 0.0.0.0, 2015.7.16.1, 
Update, 17.07.2015 12:23, SYSTEM, LENOVO-PC, Manual, Malware Database, 2015.6.3.3, 2015.7.17.2, 
Error, 17.07.2015 13:53, SYSTEM, LENOVO-PC, Update, Bad md5 or size: akadomains, 11, 
Update, 17.07.2015 13:54, SYSTEM, LENOVO-PC, Manual, Malware Database, 2015.7.17.2, 2015.7.17.3, 
Update, 17.07.2015 13:55, SYSTEM, LENOVO-PC, Manual, AKA Domain Database, 0.0.0.0, 2015.7.16.1, 
Scan, 17.07.2015 14:40, SYSTEM, LENOVO-PC, Manual, Start: 17.07.2015 13:55, Dauer: 43 Min. 3 Sek., Bedrohungssuchlauf, Abgeschlossen, 0 Malware-Erkennung, 82 Nicht-Malware-Erkennungen, 
Error, 17.07.2015 14:43, SYSTEM, LENOVO-PC, Protection, IsLicensed, 13, 
Protection, 17.07.2015 14:43, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopping, 
Protection, 17.07.2015 14:43, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopped, 
Error, 17.07.2015 14:46, SYSTEM, LENOVO-PC, Protection, IsLicensed, 13, 
Protection, 17.07.2015 14:46, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopping, 
Protection, 17.07.2015 14:46, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopped, 
Error, 17.07.2015 20:50, SYSTEM, LENOVO-PC, Protection, IsLicensed, 13, 
Protection, 17.07.2015 20:50, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopping, 
Protection, 17.07.2015 20:50, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopped, 

(end)
         
Wenn ich Malwarebytes Antimalware öffne, auf den Verlauf gehe steht da an oberster Stelle 'Schutz-log' und zwei mal darunter 'Suchlaufprotokoll'. Das ist jetzt das vom Schutz-log, ist das richtig?

Ich hatte mich vorher bei CHIP.de erkundigt:
hxxp://forum.chip.de/viren-trojaner-wuermer/bka-virus-trojaner-keine-veraenderung-1838152.html


Alt 18.07.2015, 10:24   #6
M-K-D-B
/// TB-Ausbilder
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Zitat:
Zitat von ihekne95 Beitrag anzeigen
Wenn ich Malwarebytes Antimalware öffne, auf den Verlauf gehe steht da an oberster Stelle 'Schutz-log' und zwei mal darunter 'Suchlaufprotokoll'. Das ist jetzt das vom Schutz-log, ist das richtig?
Ich brauche beide Suchlaufprotokolle...



Zitat:
Zitat von ihekne95 Beitrag anzeigen
Ich hatte mich vorher bei CHIP.de erkundigt:
hxxp://forum.chip.de/viren-trojaner-wuermer/bka-virus-trojaner-keine-veraenderung-1838152.html
ok, danke für den Link.



Gibt es aktuell irgendwelche Einschränkungen/Probleme mit dem Rechner?
__________________
--> BKA-Trojaner aber keine Sperrungen

Alt 18.07.2015, 11:58   #7
ihekne95
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Achso Okay

Das erste Suchlaufprotokoll:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 17.07.2015
Suchlaufzeit: 11:12
Protokolldatei: Suchlaufverlaufsprotokoll 1.txt
Administrator: Ja

Version: 2.1.8.1057
Malware-Datenbank: v2015.06.03.03
Rootkit-Datenbank: v2015.07.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: 

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 358347
Abgelaufene Zeit: 46 Min., 34 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 57
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\Superfish Inc. VisualDiscovery, , [ce811d999eecbe786be8b9304eb518e8], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\LENOVO\VisualDiscovery, , [df705c5a1872d1650551ffea28db718f], 
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}, , [53fce4d29eec58dee7ef7076d82b6f91], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, , [93bc9e18e4a6cb6b29546080fe05cd33], 

Registrierungswerte: 4
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|FaviconURL, hxxp://homepage-web.com/favicon.ico, , [53fce4d29eec58dee7ef7076d82b6f91]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|FaviconURLFallback, hxxp://homepage-web.com/favicon.ico, , [f55acfe7305a171f22b4885e976c9c64]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|TopResultURL, hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}, , [113ef9bd4b3f59dd6a6c3bab689b52ae]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|URL, hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}, , [5ef1d9dd1575e74f983e4c9a34cf6997]

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 1
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery, , [93bc9e18e4a6cb6b29546080fe05cd33], 

Dateien: 20
PUP.Optional.APNToolBar.A, C:\Windows\Temp\7zS871A.tmp\Offercast343_AVG_.exe, , [2f2001b59af0b08602bc174cd0327e82], 
PUP.Optional.Winsock.HijackBoot, C:\Windows\System32\VisualDiscoveryOff.ini, , [e76863537d0dd06629284f9ab54ecd33], 
PUP.Optional.Winsock.HijackBoot, C:\Windows\SysWOW64\VisualDiscoveryOff.ini, , [aba45f570c7ed75f48096f7add26ea16], 
PUP.Optional.VisualDiscovery.A, C:\Windows\SysWOW64\VisualDiscovery.ini, , [70df773fb2d892a474dec920dc279070], 
PUP.Optional.VisualDiscovery.A, C:\Windows\Temp\VisualDiscoveryr.log, , [c689a31305856ec80153aa3fb15205fb], 
PUP.Optional.VisualDiscovery.A, C:\Windows\Temp\VisualDiscovery.log, , [410ed0e6becc6bcbda7ba64330d39967], 
PUP.Optional.WebSearch.A, C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\searchplugins\Web Search.xml, , [68e7674f6e1c072fedd20d1d16eec040], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\freebl3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libnspr4.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libplc4.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libplds4.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nss3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssckbi.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssdbm3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssutil3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\smime3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\softokn3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\sqlite3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\ssl3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\VisualDiscovery.tlb, , [93bc9e18e4a6cb6b29546080fe05cd33], 

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         

Das zweite:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 17.07.2015
Suchlaufzeit: 13:55
Protokolldatei: Suchlaufverlaufsprotokoll 2.txt
Administrator: Ja

Version: 2.1.8.1057
Malware-Datenbank: v2015.07.17.03
Rootkit-Datenbank: v2015.07.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: 

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 353491
Abgelaufene Zeit: 43 Min., 3 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 57
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\Superfish Inc. VisualDiscovery, In Quarantäne, [ac2b36ac55357cbaadcd9773c241b947], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\LENOVO\VisualDiscovery, In Quarantäne, [4c8b25bd0a803105750863a74eb57789], 
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}, In Quarantäne, [c90e12d05f2bdd590ff7c246758e936d], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 

Registrierungswerte: 4
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|FaviconURL, hxxp://homepage-web.com/favicon.ico, In Quarantäne, [c90e12d05f2bdd590ff7c246758e936d]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|FaviconURLFallback, hxxp://homepage-web.com/favicon.ico, In Quarantäne, [dbfc885a0b7fee48679f2fd923e025db]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|TopResultURL, hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}, In Quarantäne, [8750c220c9c170c652b45eaad62ddd23]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|URL, hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}, In Quarantäne, [815639a97911d561b4522eda719225db]

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 1
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 

Dateien: 20
PUP.Optional.APNToolBar.A, C:\Windows\Temp\7zS871A.tmp\Offercast343_AVG_.exe, In Quarantäne, [2bace8fa800af046c98cfaad6998817f], 
PUP.Optional.Winsock.HijackBoot, C:\Windows\System32\VisualDiscoveryOff.ini, In Quarantäne, [8b4ce2008703c3738eeac1491de61de3], 
PUP.Optional.Winsock.HijackBoot, C:\Windows\SysWOW64\VisualDiscoveryOff.ini, In Quarantäne, [1eb98062f89245f1f5837991d13221df], 
PUP.Optional.VisualDiscovery.A, C:\Windows\SysWOW64\VisualDiscovery.ini, In Quarantäne, [f9deaf330684cc6a54250efc0300e917], 
PUP.Optional.VisualDiscovery.A, C:\Windows\Temp\VisualDiscoveryr.log, In Quarantäne, [b6218d554b3f62d4ee8d1af03bc88977], 
PUP.Optional.VisualDiscovery.A, C:\Windows\Temp\VisualDiscovery.log, In Quarantäne, [934469793a502e0805772fdb778c3cc4], 
PUP.Optional.WebSearch.A, C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\searchplugins\Web Search.xml, In Quarantäne, [ae29dd05c4c65dd9e10ee85d748ff60a], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\freebl3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libnspr4.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libplc4.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libplds4.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nss3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssckbi.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssdbm3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssutil3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\smime3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\softokn3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\sqlite3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\ssl3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 
PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\VisualDiscovery.tlb, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], 

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         


Zitat:
Zitat von M-K-D-B Beitrag anzeigen
Gibt es aktuell irgendwelche Einschränkungen/Probleme mit dem Rechner?
Nein, mein Laptop funktioniert einwandfrei, genauso wie immer.

Alt 18.07.2015, 12:01   #8
M-K-D-B
/// TB-Ausbilder
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Servus,


da MBAM etwas Adware gefunden hat, schauen wir diesbezüglich nochmal nach, sollte relativ zügig gehen:




Schritt 1
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).






Schritt 2
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.







Schritt 3

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.







Schritt 4
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Scan.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei von AdwCleaner,
  • die Logdatei von MBAM,
  • die Logdatei von JRT,
  • die beiden neuen Logdateien von FRST.

Alt 18.07.2015, 13:55   #9
ihekne95
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Hat doch ein wenig länger gedauert als ich dachte

Logdatei von AdwCleaner:
Code:
ATTFilter
# AdwCleaner v4.208 - Bericht erstellt 18/07/2015 um 13:24:11
# Aktualisiert 09/07/2015 von Xplode
# Datenbank : 2015-07-15.1 [Server]
# Betriebssystem : Windows 8.1  (x64)
# Benutzername : Franziska - LENOVO-PC
# Gestarted von : C:\Users\Franziska\Desktop\AdwCleaner_4.208.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : vToolbarUpdater18.7.0

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\AVG Secure Search
Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar
Ordner Gelöscht : C:\ProgramData\pokki
Ordner Gelöscht : C:\ProgramData\Avg_Update_0215tb
Ordner Gelöscht : C:\ProgramData\Avg_Update_1214tb
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Users\Franziska\AppData\Local\pokki
Ordner Gelöscht : C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\Avg@toolbar
Ordner Gelöscht : C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn
Datei Gelöscht : C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage
Datei Gelöscht : C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage-journal
Datei Gelöscht : C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml

***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
Schlüssel Gelöscht : HKCU\Software\Classes\Directory\shell\pokki
Schlüssel Gelöscht : HKCU\Software\Classes\Drive\shell\pokki
Schlüssel Gelöscht : HKCU\Software\Classes\lnkfile\shell\pokki
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_34e8f5c0c9e5744bf2cdb514283762dd0524776b
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Pokki
Schlüssel Gelöscht : HKCU\Software\Avg Secure Update
Schlüssel Gelöscht : HKLM\SOFTWARE\VisualDiscovery
Schlüssel Gelöscht : HKU\.DEFAULT\Software\Avg Secure Update
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\AVG Secure Search

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v39.0 (x86 de)

[s8645vto.default-1423061599285\prefs.js] - Zeile Gelöscht : user_pref("browser.search.hiddenOneOffs", "Yahoo,AVG Secure Search,Bing");
[s8645vto.default-1423061599285\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "AVG Secure Search");

-\\ Google Chrome v43.0.2357.134

[C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}
[C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"blacklist_state":0,"commands":{"_execute_page_action":{"suggested_key":"Alt+Shift+P","was_assigned":true}},"content_settings":[],"creation_flags":9,"disable_reasons":1,"events":[],"extension_can_script_all_urls":true,"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["browsingData","cookies","downloads","downloadsInternal","history","homepage","management","nativeMessaging","searchProvider","startupPages","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13080309618149074","lastpingday":"13081590000423643","location":1,"manifest":{"background":{"page":"background.html","persistent":true},"chrome_settings_overrides":{"homepage":"hxxps://mysearch.avg.com/?rvt=1","search_provider":{"encoding":"UTF-8","favicon_url":"hxxps://mysearch.avg.com/favicon.ico","is_default":true,"keyword":"hxxps://mysearch.avg.com","name":"AVG Secure Search

*************************

AdwCleaner[R0].txt - [8155 Bytes] - [18/07/2015 13:17:40]
AdwCleaner[S0].txt - [7815 Bytes] - [18/07/2015 13:24:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7874  Bytes] ##########
         
Von MBAM:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 18.07.2015
Suchlaufzeit: 13:34
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.1.8.1057
Malware-Datenbank: v2015.07.18.02
Rootkit-Datenbank: v2015.07.17.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Franziska

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 349011
Abgelaufene Zeit: 36 Min., 59 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
JRT:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.1 (07.16.2015:1)
OS: Windows 8.1 x64
Ran by Franziska on 18.07.2015 at 14:18:03,77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\Users\Franziska\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\pc app store.lnk



~~~ Folders

Failed to delete: [Folder] C:\Users\Franziska\Appdata\Local\pokki



~~~ Chrome


[C:\Users\Franziska\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Franziska\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Franziska\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Franziska\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.07.2015 at 14:32:42,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

Jetzt habe ich allerdings ein Problem. Als ich FRST64 starten wollte, hatte er zuerst nach Updates gesucht und ich konnte den Scan nicht starten. Das Programm hat sich aufgehangen und ich musste es schließen. Habe es dann noch einmal geöffnet und zu Ende nach Updates suchen lassen. Als es fertig war, konnte ich auf 'OK' drücken und wollte den Scan nun endlich starten, doch das Programm hat sich nur wieder aufgehangen und jetzt kann ich es gar nicht mehr öffnen. Wenn ich es versuche, zeigt mir Windows nur ein Fenster wo drin steht: 'Die App kann auf dem PC nicht ausgeführt werden. Wenden Sie sich an den Softwarehersteller, um eine geeignete Version für ihren PC zu finden.'
Neu herunterladen habe ich auch versucht aber es kommt immer die gleiche Meldung.

Ein weiteres Problem ist das ich in der Taskleiste nicht mehr auf das Startmenü und den PC App Store zugreifen kann. an der Stelle der Icons ist nur noch ein weißes Blatt mit Eselsohr. Ein Neustart konnte es auch nicht beheben. Habe ich etwas falsch gemacht?

Alt 18.07.2015, 14:43   #10
M-K-D-B
/// TB-Ausbilder
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Servus,


FRST löschen, nochmal herunterladen und einen Suchlauf durchführen.

Alt 18.07.2015, 16:22   #11
ihekne95
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Okay hat geklappt

FRST:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-07-2015 01
Ran by Franziska (administrator) on LENOVO-PC on 18-07-2015 17:12:44
Running from C:\Users\Franziska\Desktop
Loaded Profiles: Franziska (Available Profiles: Franziska)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2014-02-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-08-15] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-08-15] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-08-15] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [snp2uvc] => C:\WINDOWS\vsnp2uvc.exe
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-06-30] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://lenovo13.msn.com/?pc=LCJB
hxxp://www.lenovo.com
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {97CB315F-D830-4B49-92BC-986D9C008592} URL = 
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-17] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-17] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{126079A8-E17A-4F05-894B-2B5B8A051737}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{E6F50CE2-672B-468B-BF96-C59F56340331}: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-17] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-17] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-17] (Oracle Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18]

Chrome: 
=======
CHR Profile: C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-17]
CHR Extension: (Google Docs) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-17]
CHR Extension: (Google Drive) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-17]
CHR Extension: (YouTube) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-17]
CHR Extension: (Google Search) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-17]
CHR Extension: (Google Sheets) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-17]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-19]
CHR Extension: (Cath Kidston) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndlpkmaeinmnbiadacenijnhlolneopm [2014-10-19]
CHR Extension: (Google Wallet) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-17]
CHR Extension: (Gmail) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-06-30] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-06-30] (AVG Technologies CZ, s.r.o.)
S2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
S2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.)
S2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-08-15] (Lenovo(beijing) Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] ()
S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software)
S2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-08-15] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-08-15] (Lenovo)
S2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.)
S2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-08-15] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1195920 2015-07-12] ()

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. )
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [107736 2015-07-17] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-15] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3593432 2014-10-07] (Realtek Semiconductor Corporation                           )
R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [2853400 2014-01-23] (Sonix Co. Ltd.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-18 17:12 - 2015-07-18 17:13 - 00016798 _____ C:\Users\Franziska\Desktop\FRST.txt
2015-07-18 17:11 - 2015-07-18 17:12 - 02134528 _____ (Farbar) C:\Users\Franziska\Desktop\FRST64.exe
2015-07-18 14:37 - 2015-07-18 14:37 - 00000000 ____D C:\Users\Franziska\Desktop\FRST-OlderVersion
2015-07-18 14:32 - 2015-07-18 14:32 - 00002013 _____ C:\Users\Franziska\Desktop\JRT.txt
2015-07-18 14:16 - 2015-07-18 14:16 - 00001201 _____ C:\Users\Franziska\Desktop\mbam.txt..txt
2015-07-18 13:56 - 2015-07-18 14:01 - 01798288 _____ (Malwarebytes Corporation) C:\Users\Franziska\Desktop\JRT.exe
2015-07-18 13:33 - 2015-07-18 13:33 - 00007986 _____ C:\Users\Franziska\Desktop\AdwCleaner[S0].txt
2015-07-18 13:17 - 2015-07-18 13:25 - 00000000 ____D C:\AdwCleaner
2015-07-18 13:06 - 2015-07-18 13:08 - 02248704 _____ C:\Users\Franziska\Desktop\AdwCleaner_4.208.exe
2015-07-18 12:51 - 2015-07-18 12:51 - 00014615 _____ C:\Users\Franziska\Desktop\Suchlaufverlaufsprotokoll 2.txt
2015-07-18 12:50 - 2015-07-18 12:50 - 00013550 _____ C:\Users\Franziska\Desktop\Suchlaufverlaufsprotokoll 1.txt
2015-07-17 17:00 - 2015-07-17 17:03 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Franziska\Desktop\tdsskiller.exe
2015-07-17 16:52 - 2015-07-18 17:12 - 00000000 ____D C:\FRST
2015-07-17 16:18 - 2015-05-07 17:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-17 16:18 - 2015-05-07 17:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2015-07-17 16:18 - 2015-05-03 02:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-07-17 16:18 - 2015-04-30 01:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-17 16:13 - 2015-05-07 19:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-07-17 16:13 - 2015-05-07 19:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-17 16:13 - 2015-05-07 18:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-07-17 16:13 - 2015-05-07 18:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-07-17 16:07 - 2015-06-30 00:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-17 16:07 - 2015-06-29 17:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-07-17 16:07 - 2015-06-29 17:07 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-07-17 16:07 - 2015-06-29 17:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-07-17 16:07 - 2015-06-29 17:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-07-17 16:07 - 2015-06-29 17:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-07-17 16:07 - 2015-06-27 01:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-07-17 16:07 - 2015-06-27 01:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-07-17 16:07 - 2015-05-11 20:17 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-07-17 16:07 - 2015-04-25 04:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys
2015-07-17 16:07 - 2014-11-04 21:25 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
2015-07-17 16:07 - 2014-11-04 21:25 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
2015-07-17 16:07 - 2014-11-04 08:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-07-17 16:07 - 2014-11-04 08:54 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-07-17 16:07 - 2014-11-04 08:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-07-17 16:07 - 2014-11-04 08:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-07-17 16:06 - 2015-05-03 17:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-17 16:06 - 2015-05-03 16:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-17 16:06 - 2015-05-03 16:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-07-17 16:06 - 2015-05-03 16:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-07-17 16:03 - 2015-05-11 18:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2015-07-17 16:03 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls
2015-07-17 16:03 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls
2015-07-17 16:03 - 2015-04-23 17:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-07-17 16:03 - 2015-04-23 17:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-07-17 16:02 - 2015-05-12 15:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-17 16:01 - 2015-05-02 01:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-07-17 16:00 - 2015-05-03 17:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-17 16:00 - 2015-05-03 16:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2015-07-17 14:23 - 2015-07-17 14:43 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-07-17 14:17 - 2015-07-17 14:48 - 00000000 ____D C:\Users\Franziska\Desktop\mbar
2015-07-17 13:54 - 2015-07-17 14:11 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Franziska\Downloads\mbar-1.09.1.1004.exe
2015-07-17 12:46 - 2015-07-17 12:46 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-07-17 12:46 - 2015-07-17 12:46 - 00002078 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-07-17 11:08 - 2015-07-18 14:15 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-07-17 11:03 - 2015-07-17 14:17 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-07-17 11:03 - 2015-07-17 11:03 - 00001125 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-07-17 11:03 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-07-17 11:03 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-07-17 10:46 - 2015-07-17 10:57 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Franziska\Downloads\mbam-setup-2.1.8.1057.exe
2015-07-17 00:54 - 2015-07-17 00:54 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Sun
2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\ProgramData\Oracle
2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\Program Files (x86)\Java
2015-07-17 00:15 - 2015-07-17 00:15 - 00563296 _____ (Oracle Corporation) C:\Users\Franziska\Downloads\chromeinstall-8u51.exe
2015-07-16 21:58 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-07-16 21:58 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-07-16 21:57 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-07-16 21:57 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-07-16 21:57 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-07-16 21:57 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-07-16 21:57 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-07-16 21:57 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-07-16 21:42 - 2015-07-02 00:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-07-16 21:41 - 2015-07-01 23:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-07-16 21:41 - 2015-06-16 00:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-07-16 21:41 - 2015-06-16 00:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-07-16 21:41 - 2015-06-16 00:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-07-16 21:41 - 2015-06-16 00:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-07-16 21:41 - 2015-06-16 00:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2015-07-16 21:41 - 2015-06-15 23:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2015-07-16 21:41 - 2015-06-15 23:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-07-16 21:41 - 2015-06-15 23:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-07-16 21:41 - 2015-06-15 23:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-07-16 21:41 - 2015-06-15 23:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-07-16 21:41 - 2015-06-15 23:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-07-16 21:41 - 2015-06-15 23:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-07-16 21:41 - 2015-06-15 23:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-07-16 21:41 - 2015-06-15 23:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-07-16 21:41 - 2015-06-15 23:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-07-16 21:41 - 2015-06-15 23:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-07-16 21:41 - 2015-06-15 23:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-07-16 21:41 - 2015-06-15 23:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-07-16 21:41 - 2015-06-15 23:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-07-16 21:41 - 2015-06-15 22:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-07-16 21:41 - 2015-06-15 22:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2015-07-16 21:41 - 2015-06-15 22:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2015-07-16 21:41 - 2015-06-15 22:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-07-16 21:41 - 2015-06-15 22:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-07-16 21:41 - 2015-06-15 22:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-07-16 21:41 - 2015-06-15 22:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-07-16 21:41 - 2015-06-15 22:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-07-16 21:41 - 2015-06-15 22:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-07-16 21:41 - 2015-06-15 22:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-07-16 21:41 - 2015-06-15 22:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-07-16 21:41 - 2015-06-15 22:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-07-16 21:41 - 2015-06-15 22:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-07-16 21:41 - 2015-06-15 22:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-07-16 21:30 - 2015-07-09 21:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-07-16 21:30 - 2015-07-09 20:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-07-16 21:30 - 2015-07-09 18:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-07-16 21:30 - 2015-07-09 17:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-07-16 21:30 - 2015-07-09 17:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-07-16 21:30 - 2015-07-09 17:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-16 21:30 - 2015-07-09 17:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-07-16 21:30 - 2015-07-09 17:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-07-16 21:30 - 2015-07-09 17:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-07-16 21:30 - 2015-07-09 17:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-07-16 21:30 - 2015-07-09 17:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-07-16 21:30 - 2015-07-09 17:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-07-16 21:30 - 2015-07-09 17:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-07-16 21:30 - 2015-06-27 05:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-07-16 21:30 - 2015-06-27 05:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-07-16 21:30 - 2015-06-27 04:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-07-16 21:29 - 2015-07-03 15:52 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-07-16 21:29 - 2015-07-03 15:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-07-16 21:29 - 2015-07-03 15:50 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-07-16 21:29 - 2015-07-03 15:50 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-07-16 21:29 - 2015-06-28 07:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2015-07-16 21:29 - 2015-06-28 07:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-07-16 21:29 - 2015-06-28 07:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-07-16 21:29 - 2015-06-28 07:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2015-07-16 21:29 - 2015-06-27 18:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-07-16 21:29 - 2015-06-27 05:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2015-07-16 21:29 - 2015-06-27 05:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2015-07-16 21:29 - 2015-06-27 05:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2015-07-16 21:29 - 2015-06-27 04:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-07-16 21:29 - 2015-06-27 04:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-07-16 21:29 - 2015-06-27 04:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-07-16 21:29 - 2015-06-27 03:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-07-16 21:29 - 2015-06-27 03:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-07-16 21:29 - 2015-06-25 04:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-07-16 21:29 - 2015-06-16 00:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-07-16 21:29 - 2015-06-16 00:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-07-16 21:29 - 2015-06-15 23:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-07-16 21:29 - 2015-06-15 23:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-07-16 21:29 - 2015-06-15 22:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-07-16 21:29 - 2015-06-15 21:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-07-16 21:29 - 2015-05-30 23:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-16 21:29 - 2015-05-30 21:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-16 21:29 - 2015-05-30 21:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-07-16 21:13 - 2015-06-16 07:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2015-07-16 21:13 - 2015-06-16 07:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2015-07-16 21:13 - 2015-06-11 05:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-07-16 21:13 - 2015-06-10 18:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-07-16 21:13 - 2015-05-07 18:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2015-07-13 00:30 - 2015-07-13 00:45 - 33832046 _____ C:\Users\Franziska\Downloads\Adel Tawil - Lieder (Parodie)     Luke Mockridge - Pimmelbingo    .mp4
2015-07-11 22:33 - 2015-07-11 22:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-11 21:20 - 2015-07-11 21:20 - 00001957 _____ C:\Users\Public\Desktop\Lenovo Updates.lnk
2015-06-29 14:05 - 2015-06-29 14:05 - 00000000 ____D C:\Users\Franziska\Desktop\pdf
2015-06-27 18:18 - 2015-06-27 18:18 - 00025592 _____ C:\Users\Franziska\Desktop\Kündigung Mama und Oma Wohnung.odt
2015-06-27 15:08 - 2015-06-27 15:08 - 00000000 ____D C:\Users\Franziska\AppData\Local\GWX
2015-06-26 09:49 - 2015-06-26 09:49 - 00293296 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2015-06-22 21:09 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-06-19 12:50 - 2015-06-19 12:50 - 00000000 ____D C:\Program Files\Common Files\AV
2015-06-19 12:38 - 2015-07-11 21:15 - 00001279 _____ C:\Users\Franziska\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-18 17:12 - 2014-10-17 15:22 - 00000000 __RDO C:\Users\Franziska\OneDrive
2015-07-18 17:08 - 2014-10-17 15:34 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-18 17:08 - 2014-10-17 15:20 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2372557226-1662704196-739550879-1002
2015-07-18 17:04 - 2014-10-17 15:34 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-18 17:04 - 2014-08-15 00:39 - 01107907 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-18 17:03 - 2014-10-17 15:14 - 00425704 _____ C:\Users\Franziska\AppData\Local\BTServer.log
2015-07-18 17:03 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-07-18 15:40 - 2014-11-18 14:43 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-18 14:24 - 2013-08-22 16:46 - 00112978 _____ C:\WINDOWS\setupact.log
2015-07-18 14:20 - 2014-08-15 02:18 - 00008704 _____ C:\WINDOWS\system32\VfService.trf
2015-07-18 14:20 - 2014-08-15 01:25 - 06377788 _____ C:\Users\Public\CAFADEBUG.log
2015-07-18 14:20 - 2014-08-15 01:22 - 10673535 _____ C:\WINDOWS\SysWOW64\rootpa.e2e
2015-07-18 14:14 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-18 14:12 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-07-18 13:25 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska\AppData\Local\Pokki
2015-07-18 12:53 - 2014-10-17 15:25 - 00003950 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{26E0C7CA-7B0C-4D1A-8D47-19EEFF6E6754}
2015-07-18 12:52 - 2014-10-17 16:02 - 00000000 ____D C:\ProgramData\MFAData
2015-07-17 20:50 - 2013-08-22 16:44 - 00423904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-07-17 18:13 - 2014-12-28 20:41 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-07-17 18:13 - 2014-10-23 22:24 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-07-17 18:13 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-07-17 18:13 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\WinStore
2015-07-17 18:08 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-07-17 17:44 - 2015-04-14 17:33 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-07-17 17:44 - 2015-04-14 17:33 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-07-17 14:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-07-17 14:45 - 2014-03-18 11:44 - 00022568 _____ C:\WINDOWS\PFRO.log
2015-07-17 14:40 - 2014-08-15 01:35 - 00000000 ____D C:\Program Files (x86)\Lenovo
2015-07-17 13:07 - 2014-11-15 14:48 - 00000000 ____D C:\Users\Franziska\AppData\Local\Adobe
2015-07-17 12:47 - 2015-04-10 20:50 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\ProgramData\Adobe
2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-07-17 11:17 - 2014-11-18 14:43 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-07-17 10:45 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-07-16 21:33 - 2015-01-23 12:49 - 00000000 ____D C:\Users\Franziska\Documents\Dok. Schule
2015-07-16 21:12 - 2014-10-17 15:34 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-16 21:03 - 2014-10-17 15:34 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-16 21:03 - 2014-10-17 15:34 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-13 23:10 - 2015-05-04 18:53 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-07-13 23:10 - 2015-05-04 18:53 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-13 00:47 - 2014-11-13 22:52 - 00141824 ___SH C:\Users\Franziska\Downloads\Thumbs.db
2015-07-12 23:02 - 2014-11-06 22:27 - 00000000 ____D C:\Users\Franziska\AppData\Local\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2015-07-12 16:53 - 2014-11-08 18:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-11 22:21 - 2014-08-15 02:31 - 00000000 ____D C:\ProgramData\LU
2015-07-11 22:19 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-07-11 22:18 - 2014-08-15 01:22 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-07-10 16:42 - 2014-10-17 16:15 - 00001008 _____ C:\Users\Public\Desktop\AVG 2015.lnk
2015-07-10 16:42 - 2014-10-17 16:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-07-08 14:35 - 2015-03-19 16:13 - 00000000 ____D C:\Users\Franziska\Documents\gescannte Objekte
2015-06-30 23:31 - 2014-10-18 19:32 - 00603136 ___SH C:\Users\Franziska\Desktop\Thumbs.db
2015-06-27 18:20 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska
2015-06-27 14:34 - 2014-10-23 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-06-27 14:23 - 2014-10-23 17:55 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-06-22 20:48 - 2014-08-15 10:23 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat
2015-06-22 20:48 - 2014-08-15 10:23 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat
2015-06-22 20:48 - 2014-03-18 11:53 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-06-21 20:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-06-21 14:09 - 2015-02-04 16:50 - 00000000 ____D C:\Users\Franziska\Desktop\Neuer Ordner

==================== Files in the root of some directories =======

2014-10-17 15:14 - 2015-07-18 17:03 - 0425704 _____ () C:\Users\Franziska\AppData\Local\BTServer.log
2014-10-20 17:20 - 2014-11-01 17:39 - 0007596 _____ () C:\Users\Franziska\AppData\Local\resmon.resmoncfg
2014-08-15 01:24 - 2014-08-15 01:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Franziska\AppData\Local\Temp\1_flashplayer.exe
C:\Users\Franziska\AppData\Local\Temp\2_flashplayer.exe
C:\Users\Franziska\AppData\Local\Temp\AutoRun.exe
C:\Users\Franziska\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Franziska\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Franziska\AppData\Local\Temp\drm_dyndata_7360010.dll
C:\Users\Franziska\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Franziska\AppData\Local\Temp\eauninstall.exe
C:\Users\Franziska\AppData\Local\Temp\oct3EA.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct4F2C.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct51DB.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct53B0.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct549A.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct5B9A.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct641E.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct6475.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct72B1.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct801A.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\oct948E.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\octE19D.tmp.exe
C:\Users\Franziska\AppData\Local\Temp\Quarantine.exe
C:\Users\Franziska\AppData\Local\Temp\sqlite3.dll
C:\Users\Franziska\AppData\Local\Temp\The Sims 2 Pets_uninst.exe
C:\Users\Franziska\AppData\Local\Temp\VP6Install.exe
C:\Users\Franziska\AppData\Local\Temp\VP6VFW.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-07-17 12:28

==================== End of log ============================
         
--- --- ---


Addition:
[CODE]Additional
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x64) Version:18-07-2015 01
Ran by Franziska at 2015-07-18 17:14:46
Running from C:\Users\Franziska\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2372557226-1662704196-739550879-500 - Administrator - Disabled)
Franziska (S-1-5-21-2372557226-1662704196-739550879-1002 - Administrator - Enabled) => C:\Users\Franziska
Gast (S-1-5-21-2372557226-1662704196-739550879-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2372557226-1662704196-739550879-1004 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3D-Schach 2.0 (HKLM-x32\...\{CE057820-2732-11D4-A8C5-0050DA353A30}) (Version:  - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{665D4B18-EA91-BE16-3212-218C63F5DC4E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.8.0 - AppEx Networks)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6081 - AVG Technologies)
AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.4.948 - AVG Technologies)
Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden
CEP - Color Enable Package (HKLM-x32\...\CEP - Colour Enable Packages_is1) (Version: 6.0b (beta) - Numenor, for ModTheSims2)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.52 - Conexant)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Die Sims 2: Open For Business (HKLM-x32\...\{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}) (Version:  - )
Die Sims 2: Wilde Campus-Jahre (HKLM-x32\...\{01521746-02A6-4A72-00BD-A285DF6B80C6}) (Version:  - )
Die Sims™ 2 Apartment-Leben (HKLM-x32\...\{B6F5B704-06D3-4687-90F3-6195304AD755}) (Version:  - Electronic Arts)
Die Sims™ 2 Gute Reise (HKLM-x32\...\{F248ADFA-64E0-4b03-8A83-059078BED6A0}) (Version:  - Electronic Arts)
Die Sims™ 2 Haustiere (HKLM-x32\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version:  - )
Die Sims™ 2 Super Deluxe (HKLM-x32\...\{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}) (Version:  - Electronic Arts)
Die Sims™ 2 Vier Jahreszeiten (HKLM-x32\...\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) (Version:  - )
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Druckerdeinstallation für EPSON BX305 Series (HKLM\...\EPSON BX305 Series) (Version:  - SEIKO EPSON Corporation)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.17 - Lenovo)
Energy Manager (x32 Version: 1.5.0.17 - Lenovo) Hidden
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1321.0_WHQL - Sonix)
Lenovo FusionEngine  (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.2 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.2 - Lenovo) Hidden
Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.36.1 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited)
Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo)
LibreOffice 4.3.4.1 (HKLM-x32\...\{7D983A32-F645-48AB-8E38-4ACD234F40BC}) (Version: 4.3.4.1 - The Document Foundation)
Little Alchemy (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\littlealchemy-c7de5d8adcfd810d98ec68069ab57bd9) (Version: 1.1.1 - Recloak)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.3 - Mozilla)
Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro)
OEM Application Profile (HKLM-x32\...\{8F92E0CF-620B-5C20-F292-59C93567B06D}) (Version: 1.00.0000 - Ihr Firmenname)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.805.806.012214 - REALTEK Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.20.243 - REALTEK Semiconductor Corp.)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)

==================== Restore Points =========================

27-06-2015 14:21:49 Windows Update
10-07-2015 21:32:10 Windows Update
11-07-2015 22:17:33 Installiert REALTEK PCIE Wireless LAN Driver
17-07-2015 12:28:57 Windows Update
18-07-2015 14:18:09 JRT Pre-Junkware Removal

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {059FF85A-96A7-4F30-A151-025BF8D10B64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
Task: {0C6938DC-5060-47BB-A244-9A5EB9241201} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo)
Task: {12470315-4A24-4A46-978B-34FE10051EE7} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {13842334-9265-4B05-9B11-BB24C42F8DC4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {2C817108-BF13-4F80-A785-9C358584854F} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {307BD0C3-750A-40EF-A3F9-4288EDF529BD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-17] (Adobe Systems Incorporated)
Task: {35FDB4CA-8E11-4760-899E-1C6B82C96F61} - System32\Tasks\{808CE7D6-F887-46A4-8EAC-78FDCF14B029} => pcalua.exe -a E:\Setup.exe -d E:\
Task: {3F25A2CE-84E0-4B57-8CD6-D67BEBA2A6E4} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {4E3DA8B7-52C1-44FF-8494-9303931DF0B1} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: {9523A3F0-9354-4859-AB26-D73344A8B4FA} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] ()
Task: {AE485BC0-FDB5-4ECA-9875-A86CD8B8DBAE} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo)
Task: {B8114FCD-1409-421C-B736-0F019EE4C980} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] ()
Task: {CF99EECC-97CB-45EF-836C-DEF2AFC71F69} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-06-27] (Microsoft Corporation)
Task: {FA2727FE-C2D9-4520-B56D-97513B9D0DAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2014-08-15 01:24 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2014-03-26 12:50 - 2014-08-15 02:23 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2014-04-18 22:12 - 2014-04-18 22:12 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2015-07-16 21:12 - 2015-07-13 23:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
2015-07-16 21:12 - 2015-07-13 23:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\Users\Franziska\OneDrive:ms-properties

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VisualDiscovery => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run32: => "snp2uvc"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{AFBD7067-D2F6-4D3C-85B3-88A008C18967}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{663A46B4-3414-4F48-A319-A422F7F43977}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{AC2767B5-A536-457E-B67B-50A79A754C46}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{77D8B7D4-27EC-4437-A263-031784DFAC63}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{55376DCC-D006-4A28-AA16-B85FAC106F3E}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{084835F4-19BE-43D6-BEB8-78503B45965C}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
FirewallRules: [{1F9F0BC2-0CF8-4AA0-974C-7BA40E438A95}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{EE98E101-3C74-4620-AE02-3ADF1B6FA0CD}] => (Allow) LPort=55100
FirewallRules: [{0798E54B-7073-4647-8B2A-685DE6EC27D3}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{0A8AAECB-B085-4693-8040-C11384793642}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{AB42E82B-FAD0-4683-B81E-CBA57E9CE423}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{DA68199A-F30C-4B34-B07D-55BC97A1320D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BEE4CC4D-667E-4F8F-A4B9-C3191BCA1FC5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{7FADA343-E843-4133-A0D4-4BC7788FC0A5}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{518A6693-CCCD-4A4B-B9D9-01F793BF96AE}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{1C8585A3-15F7-4FF0-A443-C7D6A06A964A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{D1DD6BFC-A9A7-4E39-BCE5-7A467EDBD48B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{D53DDE3E-9291-4381-BFBE-4405895AD9D4}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{A02C96FC-1AC8-4B35-AB3B-3530569EF51D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{28841159-30B7-405D-9466-DA3C044D5BE5}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{43A83805-ED93-4F21-B195-E5CB8AE4B9DD}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{6929263B-9A5C-42DA-835C-976C8D9937FE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: Dell 3333dn
Description: Dell 3333dn
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Dell
Service: usbscan
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/18/2015 02:36:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 13.7.2015.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: a10

Startzeit: 01d0c1565baf8bc1

Endzeit: 78

Anwendungspfad: C:\Users\Franziska\Desktop\FRST64.exe

Berichts-ID: a610097f-2d49-11e5-8394-28d244c25993

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (07/18/2015 02:36:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 13.7.2015.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 320

Startzeit: 01d0c15627a7966a

Endzeit: 15

Anwendungspfad: C:\Users\Franziska\Desktop\FRST64.exe

Berichts-ID: 93d18442-2d49-11e5-8394-28d244c25993

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (07/18/2015 01:24:13 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8

Error: (07/17/2015 05:08:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: tdsskiller.exe, Version: 3.0.0.44, Zeitstempel: 0x54c08a45
Name des fehlerhaften Moduls: tdsskiller.exe, Version: 3.0.0.44, Zeitstempel: 0x54c08a45
Ausnahmecode: 0x40000015
Fehleroffset: 0x0014348c
ID des fehlerhaften Prozesses: 0x830
Startzeit der fehlerhaften Anwendung: 0xtdsskiller.exe0
Pfad der fehlerhaften Anwendung: tdsskiller.exe1
Pfad des fehlerhaften Moduls: tdsskiller.exe2
Berichtskennung: tdsskiller.exe3
Vollständiger Name des fehlerhaften Pakets: tdsskiller.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: tdsskiller.exe5

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 02:43:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „Microsoft.WindowsAlarms_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 02:41:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (07/17/2015 01:00:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: LENOVO-PC)
Description: Produkt: Adobe Reader XI (11.0.11) - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011012}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127


System errors:
=============
Error: (07/18/2015 05:09:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 05:08:28 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 05:07:44 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 05:06:00 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 05:03:26 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 03:46:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 03:46:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 03:46:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 03:46:32 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 03:46:31 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll


Microsoft Office:
=========================
Error: (07/18/2015 02:36:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe13.7.2015.1a1001d0c1565baf8bc178C:\Users\Franziska\Desktop\FRST64.exea610097f-2d49-11e5-8394-28d244c25993

Error: (07/18/2015 02:36:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe13.7.2015.132001d0c15627a7966a15C:\Users\Franziska\Desktop\FRST64.exe93d18442-2d49-11e5-8394-28d244c25993

Error: (07/18/2015 01:24:13 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8

Error: (07/17/2015 05:08:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: tdsskiller.exe3.0.0.4454c08a45tdsskiller.exe3.0.0.4454c08a45400000150014348c83001d0c0a22cdb0476C:\Users\Franziska\Desktop\tdsskiller.exeC:\Users\Franziska\Desktop\tdsskiller.exea4b11beb-2c95-11e5-8390-28d244c25993

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

Error: (07/17/2015 02:43:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Microsoft.WindowsAlarms_8wekyb3d8bbwe!App-2144927141

Error: (07/17/2015 02:41:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

Error: (07/17/2015 01:00:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: LENOVO-PC)
Description: Adobe Reader XI (11.0.11) - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011012}1625(NULL)(NULL)(NULL)


==================== Memory info =========================== 

Processor: AMD A6-6310 APU with AMD Radeon R4 Graphics 
Percentage of memory in use: 25%
Total physical RAM: 7128.26 MB
Available physical RAM: 5294.6 MB
Total Virtual: 8280.26 MB
Available Virtual: 6220.7 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:890.1 GB) (Free:829.63 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.14 GB) NTFS
Drive f: () (Removable) (Total:3.68 GB) (Free:0.14 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: E07FA830)

Partition: GPT Partition Type.

========================================================
Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End of log ============================
         
--- --- ---



Hat das jetzt eigentlich, dass ich nicht mehr auf das Startmenü zugreifen kann etwas mit den Scans oder dem Trojaner zutun?

Alt 18.07.2015, 21:52   #12
M-K-D-B
/// TB-Ausbilder
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Servus,



Zitat:
Zitat von ihekne95 Beitrag anzeigen
Hat das jetzt eigentlich, dass ich nicht mehr auf das Startmenü zugreifen kann etwas mit den Scans oder dem Trojaner zutun?
Ich vermute eher mit den Scans... ich würde gerne noch ein paar Kontrollen durchführen und dann versuchen wir, dein Startmenü wieder hinzubekommen.





Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern.
Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg.




Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:
ATTFilter
start
CloseProcesses:
C:\Users\Franziska\AppData\Local\pokki
C:\ProgramData\pokki
SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {97CB315F-D830-4B49-92BC-986D9C008592} URL = 
RemoveProxy:
EmptyTemp:
end
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.






Schritt 2

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset






Schritt 3
Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.






Schritt 4
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Scan.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei des FRST-Fix,
  • die Logdatei von ESET,
  • die Logdatei von SecurityCheck,
  • die beiden neuen Logdateien von FRST.

Alt 19.07.2015, 10:41   #13
ihekne95
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Hier ist alles

FRST-Fix:
Code:
ATTFilter
Fix result of Farbar Recovery Scan Tool (x64) Version:18-07-2015 01
Ran by Franziska at 2015-07-18 23:35:59 Run:1
Running from C:\Users\Franziska\Desktop
Loaded Profiles: Franziska (Available Profiles: Franziska)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CloseProcesses:
C:\Users\Franziska\AppData\Local\pokki
C:\ProgramData\pokki
SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {97CB315F-D830-4B49-92BC-986D9C008592} URL = 
RemoveProxy:
EmptyTemp:
end
*****************

Processes closed successfully.
C:\Users\Franziska\AppData\Local\pokki => moved successfully.
"C:\ProgramData\pokki" => File/Folder not found.
"HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{97CB315F-D830-4B49-92BC-986D9C008592}" => key removed successfully
HKCR\CLSID\{97CB315F-D830-4B49-92BC-986D9C008592} => key not found. 

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========

EmptyTemp: => 3 GB temporary data Removed.


The system needed a reboot.. 

==== End of Fixlog 23:37:33 ====
         
ESET:
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=ca11530520c3c045aa0e13441a94a717
# end=init
# utc_time=2015-07-18 09:49:58
# local_time=2015-07-18 11:49:58 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT 
Update Init
Update Download
Update Finalize
Updated modules version: 24869
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=ca11530520c3c045aa0e13441a94a717
# end=updated
# utc_time=2015-07-18 09:53:08
# local_time=2015-07-18 11:53:08 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT 
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=ca11530520c3c045aa0e13441a94a717
# engine=24869
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-07-18 11:46:20
# local_time=2015-07-19 01:46:20 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT 
# compatibility_mode_1='AVG AntiVirus Free Edition 2015'
# compatibility_mode=1055 16777213 100 100 46480 124397164 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 9708080 29171842 0 0
# scanned=266370
# found=3
# cleaned=0
# scan_time=6791
sh=06CAA13FC95025FA7EFD9F029ADBC587B9A72E67 ft=1 fh=f46472aab4e6620b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Franziska\Downloads\7 Zip 32 Bit - CHIP-Installer.exe"
sh=EAEA54893BE2EB862A63F69CD9A3D290C8F85AB6 ft=1 fh=d3c0a1d1c4202a6f vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Franziska\Downloads\7 Zip 64 Bit - CHIP-Installer.exe"
sh=6A1F7B56BF1FB13D31E6C8A9CD0128170E8B6B04 ft=1 fh=84d35e6595887ed5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Franziska\Downloads\OpenOffice - CHIP-Installer.exe"
         
SecurityCheck:
Code:
ATTFilter
 Results of screen317's Security Check version 1.004  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Windows Defender                  
AVG AntiVirus Free Edition 2015   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 AVG Web TuneUp   
 Java 8 Update 51  
 Java version 32-bit out of Date! 
 Adobe Flash Player 	18.0.0.209  
 Mozilla Firefox (39.0) 
 Google Chrome (43.0.2357.132) 
 Google Chrome (43.0.2357.134) 
````````Process Check: objlist.exe by Laurent````````  
 AVG avgwdsvc.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log``````````````````````
         
FRST.txt.:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-07-2015 01
Ran by Franziska (administrator) on LENOVO-PC on 19-07-2015 11:31:30
Running from C:\Users\Franziska\Desktop
Loaded Profiles: Franziska (Available Profiles: Franziska)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Program Files\Lenovo PhoneCompanion\adb.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Franziska\Desktop\SecurityCheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2014-02-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-08-15] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-08-15] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-08-15] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [snp2uvc] => C:\WINDOWS\vsnp2uvc.exe
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-06-30] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://lenovo13.msn.com/?pc=LCJB
hxxp://www.lenovo.com
HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-17] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-17] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{126079A8-E17A-4F05-894B-2B5B8A051737}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{E6F50CE2-672B-468B-BF96-C59F56340331}: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-17] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-17] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-17] (Oracle Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18]

Chrome: 
=======
CHR Profile: C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-17]
CHR Extension: (Google Docs) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-17]
CHR Extension: (Google Drive) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-17]
CHR Extension: (YouTube) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-17]
CHR Extension: (Google Search) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-17]
CHR Extension: (Google Sheets) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-17]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-19]
CHR Extension: (Cath Kidston) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndlpkmaeinmnbiadacenijnhlolneopm [2014-10-19]
CHR Extension: (Google Wallet) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-17]
CHR Extension: (Gmail) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-06-30] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-06-30] (AVG Technologies CZ, s.r.o.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-08-15] (Lenovo(beijing) Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] ()
S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-08-15] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-08-15] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-08-15] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1195920 2015-07-12] ()

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. )
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [107736 2015-07-17] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-15] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3593432 2014-10-07] (Realtek Semiconductor Corporation                           )
R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [2853400 2014-01-23] (Sonix Co. Ltd.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-19 11:27 - 2015-07-19 11:27 - 00852662 _____ C:\Users\Franziska\Desktop\SecurityCheck.exe
2015-07-18 23:49 - 2015-07-18 23:49 - 02870984 _____ (ESET) C:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe
2015-07-18 23:49 - 2015-07-18 23:49 - 00000000 ____D C:\Program Files (x86)\ESET
2015-07-18 17:12 - 2015-07-19 11:32 - 00017910 _____ C:\Users\Franziska\Desktop\FRST.txt
2015-07-18 17:11 - 2015-07-18 17:12 - 02134528 _____ (Farbar) C:\Users\Franziska\Desktop\FRST64.exe
2015-07-18 14:37 - 2015-07-18 14:37 - 00000000 ____D C:\Users\Franziska\Desktop\FRST-OlderVersion
2015-07-18 14:32 - 2015-07-18 14:32 - 00002013 _____ C:\Users\Franziska\Desktop\JRT.txt
2015-07-18 14:16 - 2015-07-18 14:16 - 00001201 _____ C:\Users\Franziska\Desktop\mbam.txt..txt
2015-07-18 13:56 - 2015-07-18 14:01 - 01798288 _____ (Malwarebytes Corporation) C:\Users\Franziska\Desktop\JRT.exe
2015-07-18 13:33 - 2015-07-18 13:33 - 00007986 _____ C:\Users\Franziska\Desktop\AdwCleaner[S0].txt
2015-07-18 13:17 - 2015-07-18 13:25 - 00000000 ____D C:\AdwCleaner
2015-07-18 13:06 - 2015-07-18 13:08 - 02248704 _____ C:\Users\Franziska\Desktop\AdwCleaner_4.208.exe
2015-07-18 12:51 - 2015-07-18 12:51 - 00014615 _____ C:\Users\Franziska\Desktop\Suchlaufverlaufsprotokoll 2.txt
2015-07-18 12:50 - 2015-07-18 12:50 - 00013550 _____ C:\Users\Franziska\Desktop\Suchlaufverlaufsprotokoll 1.txt
2015-07-17 17:00 - 2015-07-17 17:03 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Franziska\Desktop\tdsskiller.exe
2015-07-17 16:52 - 2015-07-19 11:31 - 00000000 ____D C:\FRST
2015-07-17 16:18 - 2015-05-07 17:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-17 16:18 - 2015-05-07 17:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2015-07-17 16:18 - 2015-05-03 02:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-07-17 16:18 - 2015-04-30 01:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-17 16:13 - 2015-05-07 19:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-07-17 16:13 - 2015-05-07 19:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-17 16:13 - 2015-05-07 18:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-07-17 16:13 - 2015-05-07 18:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-07-17 16:07 - 2015-06-30 00:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-17 16:07 - 2015-06-29 17:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-07-17 16:07 - 2015-06-29 17:07 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-07-17 16:07 - 2015-06-29 17:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-07-17 16:07 - 2015-06-29 17:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-07-17 16:07 - 2015-06-29 17:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-07-17 16:07 - 2015-06-27 01:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-07-17 16:07 - 2015-06-27 01:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-07-17 16:07 - 2015-05-11 20:17 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-07-17 16:07 - 2015-04-25 04:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys
2015-07-17 16:07 - 2014-11-04 21:25 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
2015-07-17 16:07 - 2014-11-04 21:25 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
2015-07-17 16:07 - 2014-11-04 08:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-07-17 16:07 - 2014-11-04 08:54 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-07-17 16:07 - 2014-11-04 08:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-07-17 16:07 - 2014-11-04 08:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-07-17 16:06 - 2015-05-03 17:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-17 16:06 - 2015-05-03 16:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-17 16:06 - 2015-05-03 16:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-07-17 16:06 - 2015-05-03 16:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-07-17 16:03 - 2015-05-11 18:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2015-07-17 16:03 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls
2015-07-17 16:03 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls
2015-07-17 16:03 - 2015-04-23 17:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-07-17 16:03 - 2015-04-23 17:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-07-17 16:02 - 2015-05-12 15:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-17 16:01 - 2015-05-02 01:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-07-17 16:00 - 2015-05-03 17:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-17 16:00 - 2015-05-03 16:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2015-07-17 14:23 - 2015-07-17 14:43 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-07-17 14:17 - 2015-07-17 14:48 - 00000000 ____D C:\Users\Franziska\Desktop\mbar
2015-07-17 13:54 - 2015-07-17 14:11 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Franziska\Downloads\mbar-1.09.1.1004.exe
2015-07-17 12:46 - 2015-07-17 12:46 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-07-17 12:46 - 2015-07-17 12:46 - 00002078 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-07-17 11:08 - 2015-07-18 14:15 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-07-17 11:03 - 2015-07-17 14:17 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-07-17 11:03 - 2015-07-17 11:03 - 00001125 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-07-17 11:03 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-07-17 11:03 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-07-17 10:46 - 2015-07-17 10:57 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Franziska\Downloads\mbam-setup-2.1.8.1057.exe
2015-07-17 00:54 - 2015-07-17 00:54 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Sun
2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\ProgramData\Oracle
2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\Program Files (x86)\Java
2015-07-17 00:15 - 2015-07-17 00:15 - 00563296 _____ (Oracle Corporation) C:\Users\Franziska\Downloads\chromeinstall-8u51.exe
2015-07-16 21:58 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-07-16 21:58 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-07-16 21:57 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-07-16 21:57 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-07-16 21:57 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-07-16 21:57 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-07-16 21:57 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-07-16 21:57 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-07-16 21:42 - 2015-07-02 00:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-07-16 21:41 - 2015-07-01 23:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-07-16 21:41 - 2015-06-16 00:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-07-16 21:41 - 2015-06-16 00:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-07-16 21:41 - 2015-06-16 00:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-07-16 21:41 - 2015-06-16 00:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-07-16 21:41 - 2015-06-16 00:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2015-07-16 21:41 - 2015-06-15 23:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2015-07-16 21:41 - 2015-06-15 23:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-07-16 21:41 - 2015-06-15 23:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-07-16 21:41 - 2015-06-15 23:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-07-16 21:41 - 2015-06-15 23:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-07-16 21:41 - 2015-06-15 23:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-07-16 21:41 - 2015-06-15 23:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-07-16 21:41 - 2015-06-15 23:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-07-16 21:41 - 2015-06-15 23:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-07-16 21:41 - 2015-06-15 23:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-07-16 21:41 - 2015-06-15 23:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-07-16 21:41 - 2015-06-15 23:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-07-16 21:41 - 2015-06-15 23:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-07-16 21:41 - 2015-06-15 23:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-07-16 21:41 - 2015-06-15 22:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-07-16 21:41 - 2015-06-15 22:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2015-07-16 21:41 - 2015-06-15 22:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2015-07-16 21:41 - 2015-06-15 22:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-07-16 21:41 - 2015-06-15 22:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-07-16 21:41 - 2015-06-15 22:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-07-16 21:41 - 2015-06-15 22:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-07-16 21:41 - 2015-06-15 22:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-07-16 21:41 - 2015-06-15 22:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-07-16 21:41 - 2015-06-15 22:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-07-16 21:41 - 2015-06-15 22:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-07-16 21:41 - 2015-06-15 22:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-07-16 21:41 - 2015-06-15 22:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-07-16 21:41 - 2015-06-15 22:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-07-16 21:30 - 2015-07-09 21:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-07-16 21:30 - 2015-07-09 20:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-07-16 21:30 - 2015-07-09 18:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-07-16 21:30 - 2015-07-09 17:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-07-16 21:30 - 2015-07-09 17:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-07-16 21:30 - 2015-07-09 17:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-16 21:30 - 2015-07-09 17:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-07-16 21:30 - 2015-07-09 17:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-07-16 21:30 - 2015-07-09 17:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-07-16 21:30 - 2015-07-09 17:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-07-16 21:30 - 2015-07-09 17:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-07-16 21:30 - 2015-07-09 17:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-07-16 21:30 - 2015-07-09 17:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-07-16 21:30 - 2015-06-27 05:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-07-16 21:30 - 2015-06-27 05:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-07-16 21:30 - 2015-06-27 04:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-07-16 21:29 - 2015-07-03 15:52 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-07-16 21:29 - 2015-07-03 15:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-07-16 21:29 - 2015-07-03 15:50 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-07-16 21:29 - 2015-07-03 15:50 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-07-16 21:29 - 2015-06-28 07:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2015-07-16 21:29 - 2015-06-28 07:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-07-16 21:29 - 2015-06-28 07:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-07-16 21:29 - 2015-06-28 07:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2015-07-16 21:29 - 2015-06-27 18:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-07-16 21:29 - 2015-06-27 05:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2015-07-16 21:29 - 2015-06-27 05:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2015-07-16 21:29 - 2015-06-27 05:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2015-07-16 21:29 - 2015-06-27 04:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-07-16 21:29 - 2015-06-27 04:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-07-16 21:29 - 2015-06-27 04:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-07-16 21:29 - 2015-06-27 03:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-07-16 21:29 - 2015-06-27 03:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-07-16 21:29 - 2015-06-25 04:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-07-16 21:29 - 2015-06-16 00:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-07-16 21:29 - 2015-06-16 00:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-07-16 21:29 - 2015-06-15 23:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-07-16 21:29 - 2015-06-15 23:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-07-16 21:29 - 2015-06-15 22:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-07-16 21:29 - 2015-06-15 21:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-07-16 21:29 - 2015-05-30 23:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-16 21:29 - 2015-05-30 21:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-16 21:29 - 2015-05-30 21:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-07-16 21:13 - 2015-06-16 07:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2015-07-16 21:13 - 2015-06-16 07:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2015-07-16 21:13 - 2015-06-11 05:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-07-16 21:13 - 2015-06-10 18:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-07-16 21:13 - 2015-05-07 18:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2015-07-13 00:30 - 2015-07-13 00:45 - 33832046 _____ C:\Users\Franziska\Downloads\Adel Tawil - Lieder (Parodie)     Luke Mockridge - Pimmelbingo    .mp4
2015-07-11 22:33 - 2015-07-11 22:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-11 21:20 - 2015-07-11 21:20 - 00001957 _____ C:\Users\Public\Desktop\Lenovo Updates.lnk
2015-06-29 14:05 - 2015-06-29 14:05 - 00000000 ____D C:\Users\Franziska\Desktop\pdf
2015-06-27 18:18 - 2015-06-27 18:18 - 00025592 _____ C:\Users\Franziska\Desktop\Kündigung Mama und Oma Wohnung.odt
2015-06-27 15:08 - 2015-06-27 15:08 - 00000000 ____D C:\Users\Franziska\AppData\Local\GWX
2015-06-26 09:49 - 2015-06-26 09:49 - 00293296 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2015-06-22 21:09 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-06-19 12:50 - 2015-06-19 12:50 - 00000000 ____D C:\Program Files\Common Files\AV
2015-06-19 12:38 - 2015-07-11 21:15 - 00001279 _____ C:\Users\Franziska\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-19 11:30 - 2014-10-17 16:02 - 00000000 ____D C:\ProgramData\MFAData
2015-07-19 11:29 - 2014-10-17 15:25 - 00003950 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{26E0C7CA-7B0C-4D1A-8D47-19EEFF6E6754}
2015-07-19 11:28 - 2014-08-15 00:39 - 01207383 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-19 11:25 - 2014-10-17 15:14 - 00427871 _____ C:\Users\Franziska\AppData\Local\BTServer.log
2015-07-19 11:25 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-07-19 01:51 - 2014-10-17 15:20 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2372557226-1662704196-739550879-1002
2015-07-19 01:40 - 2014-11-18 14:43 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-19 01:08 - 2014-10-17 15:34 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-18 23:49 - 2013-08-22 16:46 - 00113392 _____ C:\WINDOWS\setupact.log
2015-07-18 23:40 - 2014-10-17 15:22 - 00000000 ___DO C:\Users\Franziska\OneDrive
2015-07-18 23:40 - 2014-08-15 01:22 - 10705205 _____ C:\WINDOWS\SysWOW64\rootpa.e2e
2015-07-18 23:39 - 2014-10-18 19:32 - 00603136 ___SH C:\Users\Franziska\Desktop\Thumbs.db
2015-07-18 23:39 - 2014-10-17 15:34 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-18 23:39 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-18 23:38 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-07-18 23:36 - 2014-08-15 01:25 - 06414416 _____ C:\Users\Public\CAFADEBUG.log
2015-07-18 14:20 - 2014-08-15 02:18 - 00008704 _____ C:\WINDOWS\system32\VfService.trf
2015-07-17 20:50 - 2013-08-22 16:44 - 00423904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-07-17 18:13 - 2014-12-28 20:41 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-07-17 18:13 - 2014-10-23 22:24 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-07-17 18:13 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-07-17 18:13 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\WinStore
2015-07-17 18:08 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-07-17 17:44 - 2015-04-14 17:33 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-07-17 17:44 - 2015-04-14 17:33 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-07-17 14:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-07-17 14:45 - 2014-03-18 11:44 - 00022568 _____ C:\WINDOWS\PFRO.log
2015-07-17 14:40 - 2014-08-15 01:35 - 00000000 ____D C:\Program Files (x86)\Lenovo
2015-07-17 13:07 - 2014-11-15 14:48 - 00000000 ____D C:\Users\Franziska\AppData\Local\Adobe
2015-07-17 12:47 - 2015-04-10 20:50 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\ProgramData\Adobe
2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-07-17 11:17 - 2014-11-18 14:43 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-07-17 10:45 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-07-16 21:33 - 2015-01-23 12:49 - 00000000 ____D C:\Users\Franziska\Documents\Dok. Schule
2015-07-16 21:12 - 2014-10-17 15:34 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-16 21:03 - 2014-10-17 15:34 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-16 21:03 - 2014-10-17 15:34 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-13 23:10 - 2015-05-04 18:53 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-07-13 23:10 - 2015-05-04 18:53 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-13 00:47 - 2014-11-13 22:52 - 00141824 ___SH C:\Users\Franziska\Downloads\Thumbs.db
2015-07-12 23:02 - 2014-11-06 22:27 - 00000000 ____D C:\Users\Franziska\AppData\Local\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2015-07-12 16:53 - 2014-11-08 18:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-11 22:21 - 2014-08-15 02:31 - 00000000 ____D C:\ProgramData\LU
2015-07-11 22:19 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-07-11 22:18 - 2014-08-15 01:22 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-07-10 16:42 - 2014-10-17 16:15 - 00001008 _____ C:\Users\Public\Desktop\AVG 2015.lnk
2015-07-10 16:42 - 2014-10-17 16:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-07-08 14:35 - 2015-03-19 16:13 - 00000000 ____D C:\Users\Franziska\Documents\gescannte Objekte
2015-06-27 18:20 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska
2015-06-27 14:34 - 2014-10-23 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-06-27 14:23 - 2014-10-23 17:55 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-06-22 20:48 - 2014-08-15 10:23 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat
2015-06-22 20:48 - 2014-08-15 10:23 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat
2015-06-22 20:48 - 2014-03-18 11:53 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-06-21 20:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-06-21 14:09 - 2015-02-04 16:50 - 00000000 ____D C:\Users\Franziska\Desktop\Neuer Ordner

==================== Files in the root of some directories =======

2014-10-17 15:14 - 2015-07-19 11:25 - 0427871 _____ () C:\Users\Franziska\AppData\Local\BTServer.log
2014-10-20 17:20 - 2014-11-01 17:39 - 0007596 _____ () C:\Users\Franziska\AppData\Local\resmon.resmoncfg
2014-08-15 01:24 - 2014-08-15 01:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-07-17 12:28

==================== End of log ============================
         
--- --- ---


Addition.txt.:
[CODE]Additional
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x64) Version:18-07-2015 01
Ran by Franziska at 2015-07-19 11:33:29
Running from C:\Users\Franziska\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2372557226-1662704196-739550879-500 - Administrator - Disabled)
Franziska (S-1-5-21-2372557226-1662704196-739550879-1002 - Administrator - Enabled) => C:\Users\Franziska
Gast (S-1-5-21-2372557226-1662704196-739550879-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2372557226-1662704196-739550879-1004 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3D-Schach 2.0 (HKLM-x32\...\{CE057820-2732-11D4-A8C5-0050DA353A30}) (Version:  - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{665D4B18-EA91-BE16-3212-218C63F5DC4E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.8.0 - AppEx Networks)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6081 - AVG Technologies)
AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.4.948 - AVG Technologies)
Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden
CEP - Color Enable Package (HKLM-x32\...\CEP - Colour Enable Packages_is1) (Version: 6.0b (beta) - Numenor, for ModTheSims2)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.52 - Conexant)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Die Sims 2: Open For Business (HKLM-x32\...\{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}) (Version:  - )
Die Sims 2: Wilde Campus-Jahre (HKLM-x32\...\{01521746-02A6-4A72-00BD-A285DF6B80C6}) (Version:  - )
Die Sims™ 2 Apartment-Leben (HKLM-x32\...\{B6F5B704-06D3-4687-90F3-6195304AD755}) (Version:  - Electronic Arts)
Die Sims™ 2 Gute Reise (HKLM-x32\...\{F248ADFA-64E0-4b03-8A83-059078BED6A0}) (Version:  - Electronic Arts)
Die Sims™ 2 Haustiere (HKLM-x32\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version:  - )
Die Sims™ 2 Super Deluxe (HKLM-x32\...\{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}) (Version:  - Electronic Arts)
Die Sims™ 2 Vier Jahreszeiten (HKLM-x32\...\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) (Version:  - )
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Druckerdeinstallation für EPSON BX305 Series (HKLM\...\EPSON BX305 Series) (Version:  - SEIKO EPSON Corporation)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.17 - Lenovo)
Energy Manager (x32 Version: 1.5.0.17 - Lenovo) Hidden
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1321.0_WHQL - Sonix)
Lenovo FusionEngine  (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.2 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.2 - Lenovo) Hidden
Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.36.1 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited)
Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo)
LibreOffice 4.3.4.1 (HKLM-x32\...\{7D983A32-F645-48AB-8E38-4ACD234F40BC}) (Version: 4.3.4.1 - The Document Foundation)
Little Alchemy (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\littlealchemy-c7de5d8adcfd810d98ec68069ab57bd9) (Version: 1.1.1 - Recloak)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.3 - Mozilla)
Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro)
OEM Application Profile (HKLM-x32\...\{8F92E0CF-620B-5C20-F292-59C93567B06D}) (Version: 1.00.0000 - Ihr Firmenname)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.805.806.012214 - REALTEK Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.20.243 - REALTEK Semiconductor Corp.)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation)

==================== Restore Points =========================

27-06-2015 14:21:49 Windows Update
10-07-2015 21:32:10 Windows Update
11-07-2015 22:17:33 Installiert REALTEK PCIE Wireless LAN Driver
17-07-2015 12:28:57 Windows Update
18-07-2015 14:18:09 JRT Pre-Junkware Removal

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {059FF85A-96A7-4F30-A151-025BF8D10B64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
Task: {0C6938DC-5060-47BB-A244-9A5EB9241201} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo)
Task: {12470315-4A24-4A46-978B-34FE10051EE7} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {13842334-9265-4B05-9B11-BB24C42F8DC4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {2C817108-BF13-4F80-A785-9C358584854F} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {307BD0C3-750A-40EF-A3F9-4288EDF529BD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-17] (Adobe Systems Incorporated)
Task: {35FDB4CA-8E11-4760-899E-1C6B82C96F61} - System32\Tasks\{808CE7D6-F887-46A4-8EAC-78FDCF14B029} => pcalua.exe -a E:\Setup.exe -d E:\
Task: {3F25A2CE-84E0-4B57-8CD6-D67BEBA2A6E4} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {4E3DA8B7-52C1-44FF-8494-9303931DF0B1} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: {9523A3F0-9354-4859-AB26-D73344A8B4FA} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] ()
Task: {AE485BC0-FDB5-4ECA-9875-A86CD8B8DBAE} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo)
Task: {B8114FCD-1409-421C-B736-0F019EE4C980} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] ()
Task: {CF99EECC-97CB-45EF-836C-DEF2AFC71F69} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-06-27] (Microsoft Corporation)
Task: {FA2727FE-C2D9-4520-B56D-97513B9D0DAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-02-25 17:02 - 2015-07-12 23:02 - 01195920 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2014-04-18 22:12 - 2014-04-18 22:12 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2014-08-15 01:27 - 2014-01-22 14:04 - 00084992 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2014-08-15 02:13 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-08-15 02:18 - 2014-08-15 02:18 - 00067856 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
2014-08-15 02:18 - 2014-08-15 02:18 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll
2014-08-15 01:24 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2014-03-26 12:50 - 2014-08-15 02:23 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2014-04-18 22:12 - 2014-04-18 22:12 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-08-15 02:18 - 2014-08-15 02:18 - 00815104 _____ () C:\Program Files\Lenovo PhoneCompanion\adb.exe
2015-07-19 11:27 - 2015-07-19 11:27 - 00852662 _____ () C:\Users\Franziska\Desktop\SecurityCheck.exe
2015-07-16 21:12 - 2015-07-13 23:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
2015-07-16 21:12 - 2015-07-13 23:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\Users\Franziska\OneDrive:ms-properties

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VisualDiscovery => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run32: => "snp2uvc"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{AFBD7067-D2F6-4D3C-85B3-88A008C18967}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{663A46B4-3414-4F48-A319-A422F7F43977}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{AC2767B5-A536-457E-B67B-50A79A754C46}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{77D8B7D4-27EC-4437-A263-031784DFAC63}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{55376DCC-D006-4A28-AA16-B85FAC106F3E}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{084835F4-19BE-43D6-BEB8-78503B45965C}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
FirewallRules: [{1F9F0BC2-0CF8-4AA0-974C-7BA40E438A95}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{EE98E101-3C74-4620-AE02-3ADF1B6FA0CD}] => (Allow) LPort=55100
FirewallRules: [{0798E54B-7073-4647-8B2A-685DE6EC27D3}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{0A8AAECB-B085-4693-8040-C11384793642}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{AB42E82B-FAD0-4683-B81E-CBA57E9CE423}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{DA68199A-F30C-4B34-B07D-55BC97A1320D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BEE4CC4D-667E-4F8F-A4B9-C3191BCA1FC5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{7FADA343-E843-4133-A0D4-4BC7788FC0A5}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{518A6693-CCCD-4A4B-B9D9-01F793BF96AE}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{1C8585A3-15F7-4FF0-A443-C7D6A06A964A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{D1DD6BFC-A9A7-4E39-BCE5-7A467EDBD48B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{D53DDE3E-9291-4381-BFBE-4405895AD9D4}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{A02C96FC-1AC8-4B35-AB3B-3530569EF51D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{28841159-30B7-405D-9466-DA3C044D5BE5}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{43A83805-ED93-4F21-B195-E5CB8AE4B9DD}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{6929263B-9A5C-42DA-835C-976C8D9937FE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: Dell 3333dn
Description: Dell 3333dn
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Dell
Service: usbscan
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/19/2015 01:49:08 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (07/19/2015 01:22:50 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (07/18/2015 11:49:53 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (07/18/2015 11:49:51 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (07/18/2015 11:49:41 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (07/18/2015 11:49:41 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (07/18/2015 11:49:22 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (07/18/2015 11:49:18 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest.

Error: (07/18/2015 02:36:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 13.7.2015.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: a10

Startzeit: 01d0c1565baf8bc1

Endzeit: 78

Anwendungspfad: C:\Users\Franziska\Desktop\FRST64.exe

Berichts-ID: a610097f-2d49-11e5-8394-28d244c25993

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (07/18/2015 02:36:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 13.7.2015.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 320

Startzeit: 01d0c15627a7966a

Endzeit: 15

Anwendungspfad: C:\Users\Franziska\Desktop\FRST64.exe

Berichts-ID: 93d18442-2d49-11e5-8394-28d244c25993

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:


System errors:
=============
Error: (07/18/2015 11:50:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1275

Error: (07/18/2015 11:50:56 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\FRANZI~1\AppData\Local\Temp\ehdrv.sys

Error: (07/18/2015 11:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1275

Error: (07/18/2015 11:50:55 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\FRANZI~1\AppData\Local\Temp\ehdrv.sys

Error: (07/18/2015 11:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1275

Error: (07/18/2015 11:50:55 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\FRANZI~1\AppData\Local\Temp\ehdrv.sys

Error: (07/18/2015 11:38:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 11:38:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 11:38:13 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll

Error: (07/18/2015 11:36:30 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: 
%%1056


Microsoft Office:
=========================
Error: (07/19/2015 01:49:08 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe

Error: (07/19/2015 01:22:50 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestc:\users\franziska\desktop\esetsmartinstaller_deu.exe

Error: (07/18/2015 11:49:53 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe

Error: (07/18/2015 11:49:51 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe

Error: (07/18/2015 11:49:41 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe

Error: (07/18/2015 11:49:41 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe

Error: (07/18/2015 11:49:22 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe

Error: (07/18/2015 11:49:18 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Downloads\esetsmartinstaller_deu.exe

Error: (07/18/2015 02:36:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe13.7.2015.1a1001d0c1565baf8bc178C:\Users\Franziska\Desktop\FRST64.exea610097f-2d49-11e5-8394-28d244c25993

Error: (07/18/2015 02:36:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe13.7.2015.132001d0c15627a7966a15C:\Users\Franziska\Desktop\FRST64.exe93d18442-2d49-11e5-8394-28d244c25993


==================== Memory info =========================== 

Processor: AMD A6-6310 APU with AMD Radeon R4 Graphics 
Percentage of memory in use: 36%
Total physical RAM: 7128.26 MB
Available physical RAM: 4543.01 MB
Total Virtual: 8280.26 MB
Available Virtual: 5375.44 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:890.1 GB) (Free:831.82 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.14 GB) NTFS
Drive f: () (Removable) (Total:3.68 GB) (Free:0.14 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: E07FA830)

Partition: GPT Partition Type.

========================================================
Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End of log ============================
         
--- --- ---

Alt 19.07.2015, 11:36   #14
M-K-D-B
/// TB-Ausbilder
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Servus,

  • Lade Dir bitte Windows Repair - All in one von tweaking.com hier herunter und installiere es.
  • Deaktiviere bitte (wenn möglich) Dein Antivirusprogramm.
  • Bedenke, dass die einzelnen Reparaturen einige Zeit benötigen. Starte keine anderen Anwendungen in dieser Zeit.
  • Starte das Programm und führe die Punkte 1-7 durch. (Siehe Bildanleitung)
  • Unter dem Punkt Repairs > Open Repairs setze zusätzlich einen Haken bei 11 - Repair start menu icons, folge ansonst der Anleitung.


Danach berichten, wie es mit dem Startmenü aussieht.

Alt 19.07.2015, 14:05   #15
ihekne95
 
BKA-Trojaner aber keine Sperrungen - Standard

BKA-Trojaner aber keine Sperrungen



Das Programm ist fertig, hat auch heruntergefahren. Hab den Laptop dann wieder hoch gefahren aber es zeigt mir leider immer noch 'Verknüpfungsproblem. Die Laufwerk-oder Netzwerkverbindung, auf die sich die Verknüpfung "Start Menu.Ink" bezieht, ist nicht verfügbar. Stellen sie sicher, dass der Datenträger richtig eingelegt bzw. die Netzwerkressource verfügbar ist, und wiederholen sie den Vorgang.' an, wenn ich drauf klicke. Das Symbol hat sich auch nicht verändert

Antwort

Themen zu BKA-Trojaner aber keine Sperrungen
antimalware, anzeige, browser, computer, ergebnis, flash player, gesperrt, hintergrund, laptop, malwarebytes, neustart, programm, pup.optional.apntoolbar.a, pup.optional.homepagehelper.a, pup.optional.visualdiscovery.a, pup.optional.websearch.a, pup.optional.winsock.hijackboot, rechtsklick, schließen, windows



Ähnliche Themen: BKA-Trojaner aber keine Sperrungen


  1. Windows 7 , Bildschirm bleibt schwarz Maus vorhanden aber keine Funktion, keine Anmeldemaske
    Log-Analyse und Auswertung - 23.11.2014 (9)
  2. BKA- Trojaner aber keine Symptome oder Probleme?
    Plagegeister aller Art und deren Bekämpfung - 05.02.2014 (3)
  3. GVU Tojaner aber keine Sperrung
    Plagegeister aller Art und deren Bekämpfung - 12.08.2012 (3)
  4. Virenscanner zeigt 8 Trojaner und zig Verfolgungscookies an. Aber eigentlich keine Viren
    Plagegeister aller Art und deren Bekämpfung - 11.07.2012 (3)
  5. BKA Trojaner o.ä. mit OTL entfernt aber nun keine Schrift mehr in Win7
    Log-Analyse und Auswertung - 06.04.2012 (2)
  6. Trojaner an Bord oder nicht? html/malicious.pdf.gen gefunden - aber bisher keine Probleme
    Plagegeister aller Art und deren Bekämpfung - 27.03.2012 (37)
  7. 4 Trojaner und keine Ende, sind in Quarantäne, lassen sich aber nicht löschen
    Plagegeister aller Art und deren Bekämpfung - 04.12.2010 (23)
  8. DVDShrink Virus oder TRojaner keine Funde aber sehr merkwürdig
    Plagegeister aller Art und deren Bekämpfung - 28.05.2010 (0)
  9. habe einige trojaner aber keine infos
    Mülltonne - 31.03.2007 (0)
  10. Mailversand, aber keine Lösung
    Log-Analyse und Auswertung - 24.12.2006 (6)
  11. Habe Trojaner problem aber keine Ahnung :-o
    Log-Analyse und Auswertung - 27.07.2006 (2)
  12. Habe Trojaner aber keine Infos darüber
    Plagegeister aller Art und deren Bekämpfung - 07.09.2005 (1)
  13. Keine Kritik....aber ne Frage !!!
    Lob, Kritik und Wünsche - 16.10.2004 (1)
  14. Ist zwar keine Software, aber...
    Antiviren-, Firewall- und andere Schutzprogramme - 26.07.2003 (2)
  15. keine firewall, aber was sonst!
    Antiviren-, Firewall- und andere Schutzprogramme - 18.03.2003 (13)

Zum Thema BKA-Trojaner aber keine Sperrungen - Hallo, Ich kenne mich überhaupt nicht mit Computern aus und hoffe, dass mir jemand weiterhelfen kann. Zum Thema: Ich wollte mir gestern einen Film auf eine dieser Streaming-Seiten ansehen, auf - BKA-Trojaner aber keine Sperrungen...
Archiv
Du betrachtest: BKA-Trojaner aber keine Sperrungen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.