Haus meister | 15.11.2014 02:04 | Win7 64bit: Firefox neue Tabs mit Werbung, Umleitung von Seitenaurufen, Popup Fenster Hallo Forum,
habe hier ein Laptop von meinem Kumpel bei dem das Surfen eine Qual geworden ist.
Ständig werden Seitenaurufe umgelenkt, Popup Windows oder neue Tabs mit Werbung erscheinen.
Bisher habe ich die zuletzt insallierten Programme (ca. 10 Stück) über die Systemsteuerung deinstalliert. Ansonsten habe ich noch nichts weiteres unternommen, ausser die empfohlenen Logfiles erstellt.
defogger_disable: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 23:27 on 14/11/2014 (Lapp)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- FRST: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2014
Ran by Lapp (administrator) on LAPP-PC on 14-11-2014 23:30:18
Running from C:\Users\Lapp\Downloads
Loaded Profiles: Lapp & Paul (Available profiles: Lapp & Paul)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
() C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe
() C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
() C:\ProgramData\89c775be-12de-4e15-846c-6b3e6a8c39a2\maintainer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\SupTab\HpUI.exe
() C:\Program Files (x86)\SupTab\Loader64.exe
() C:\Program Files (x86)\SupTab\Loader32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Probit Software LTD) C:\Program Files (x86)\Probit Software\Easy Speed PC\ESPCSmartScan.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(NETGEAR) C:\Program Files (x86)\NETGEAR\WN111v2\WN111v2.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-07-23] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-07-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-07-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2010-04-28] ()
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [jswtrayutil] => "C:\Program Files (x86)\NETGEAR\WN111v2\jswtrayutil.exe"
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-02-09] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642728 2012-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [mbot_de_195] => [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mysearchpage.net
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1eeK7l24Ey_peMn2wnP0QyCO5K5XmXCpPyor6qMH8RGuKgGmZGWtbUMCItj6rO-_QaxL2WErrEjNI-6ScrhhpvLgkvgt_6iaB2Hd28jLJ_gANpVDW65bEXD6k0IU29bZofSzngGQvKJlgSCueKZ2piaqjvouootPDhzJrVlbodHcNJH4m&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1eeK7l24Ey_peMn2wnP0QyCO5K5XmXCpPyor6qMH8RGuKgGmZGWtbUMCItj6rO-_QaxL2WErrEjNI-6ScrhhpvLgkvgt_6iaB2Hd28jLJ_gANpVDW65bEXD6k0IU29bZofSzngGQvKJlgSCueKZ2piaqjvouootPDhzJrVlbodHcNJH4m&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.omiga-plus.com/?type=hp&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.omiga-plus.com/?type=hp&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295&q={searchTerms}
SearchScopes: HKLM - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1414341193&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WXE1A511029510295&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1eeK7l24Ey_peMn2wnP0QyCO5K5XmXCpPyor6qMH8RGuKgGmZGWtbUMCItj6rO-_QaxL2WErrEjNI-6ScrhhpvLgkvgt_6iaB2Hd28jLJ_gANpVDW65bEXD6k0IU29bZofSzngGQvKJlgSCueKZ2piaqjvouootPDhzJrVlbodHcNJH4h&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1eeK7l24Ey_peMn2wnP0QyCO5K5XmXCpPyor6qMH8RGuKgGmZGWtbUMCItj6rO-_QaxL2WErrEjNI-6ScrhhpvLgkvgt_6iaB2Hd28jLJ_gANpVDW65bEXD6k0IU29bZofSzngGQvKJlgSCueKZ2piaqjvouootPDhzJrVlbodHcNJH4h&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1eeK7l24Ey_peMn2wnP0QyCO5K5XmXCpPyor6qMH8RGuKgGmZGWtbUMCItj6rO-_QaxL2WErrEjNI-6ScrhhpvLgkvgt_6iaB2Hd28jLJ_gANpVDW65bEXD6k0IU29bZofSzngGQvKJlgSCueKZ2piaqjvouootPDhzJrVlbodHcNJH4m&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1eeK7l24Ey_peMn2wnP0QyCO5K5XmXCpPyor6qMH8RGuKgGmZGWtbUMCItj6rO-_QaxL2WErrEjNI-6ScrhhpvLgkvgt_6iaB2Hd28jLJ_gANpVDW65bEXD6k0IU29bZofSzngGQvKJlgSCueKZ2piaqjvouootPDhzJrVlbodHcNJH4m&q={searchTerms}
SearchScopes: HKCU - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1eeK7l24Ey_peMn2wnP0QyCO5K5XmXCpPyor6qMH8RGuKgGmZGWtbUMCItj6rO-_QaxL2WErrEjNI-6ScrhhpvLgkvgt_6iaB2Hd28jLJ_gANpVDW65bEXD6k0IU29bZofSzngGQvKJlgSCueKZ2piaqjvouootPDhzJrVlbodHcNJH4h&q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\gwpsj8lv.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: Astromenda
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\gwpsj8lv.default\user.js
FF SearchPlugin: C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\gwpsj8lv.default\searchplugins\Astromenda.xml
FF SearchPlugin: C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\gwpsj8lv.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\omiga-plus.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: videosMediaPlayersversion2.1 - C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\gwpsj8lv.default\Extensions\975af956-6d8c-4897-837a-25c267d2cec1@gmail.com [2014-10-31]
FF Extension: Fast Start - C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\gwpsj8lv.default\Extensions\faststartff@gmail.com [2014-10-26]
FF Extension: Astro New Tab - C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\gwpsj8lv.default\Extensions\{f2548724-373f-45fe-be6a-3a85e87b7711}.xpi [2014-10-31]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\gwpsj8lv.default\extensions\faststartff@gmail.com
Chrome:
=======
CHR Profile: C:\Users\Lapp\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Lapp\AppData\Local\Google\Chrome\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg [2013-12-18]
CHR HKLM-x32\...\Chrome\Extension: [epojlgbehpaeekopencdagbdamnkppci] - C:\Program Files (x86)\LyriXeeker\128.crx []
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173272 2013-11-01] (Microsoft Corp.)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [2231616 2010-07-19] ()
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [714208 2014-10-26] (Cherished Technololgy LIMITED)
S3 jswpsapi; C:\Program Files (x86)\NETGEAR\WN111v2\jswpsapi.exe [942080 2008-02-29] (Atheros Communications, Inc.) [File not signed]
R2 MaintainerSvc2.61.4907295; C:\ProgramData\89c775be-12de-4e15-846c-6b3e6a8c39a2\maintainer.exe [123640 2014-11-14] ()
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2010-06-10] (CACE Technologies)
S3 PCAMp50a64; C:\Windows\System32\Drivers\PCAMp50a64.sys [43328 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 PCASp50a64; C:\Windows\System32\Drivers\PCASp50a64.sys [41280 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [228224 2010-10-21] (Vimicro Corporation)
R3 vmuvcflt; C:\Windows\System32\Drivers\vmuvcflt.sys [8320 2010-08-16] (Vimicro Corporation)
S3 WFMC_VAD; C:\Windows\System32\DRIVERS\wfmcvad.sys [24064 2010-02-08] (WiFi Media Connect)
S3 WN111v2; C:\Windows\System32\DRIVERS\WN111v2w7x.sys [767488 2009-10-21] (Atheros Communications, Inc.)
R1 {8431bbbd-4243-4758-beab-348411cd1e12}Gw64; C:\Windows\System32\drivers\{8431bbbd-4243-4758-beab-348411cd1e12}Gw64.sys [48792 2014-11-14] (StdLib)
R1 {9255f1e2-1754-4887-b5d8-8ea035831546}Gw64; C:\Windows\System32\drivers\{9255f1e2-1754-4887-b5d8-8ea035831546}Gw64.sys [48792 2014-10-31] (StdLib)
U3 BcmSqlStartupSvc; No ImagePath
U2 CLKMSVC10_3A60B698; No ImagePath
U2 CLKMSVC10_C3B3B687; No ImagePath
S3 cpuz134; \??\C:\Users\Lapp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
U2 DriverService; No ImagePath
U2 iATAgentService; No ImagePath
U2 idealife Update Service; No ImagePath
U3 IGRS; No ImagePath
U2 IviRegMgr; No ImagePath
S1 lfputvzi; \??\C:\windows\system32\drivers\lfputvzi.sys [X]
U2 nvUpdatusService; No ImagePath
U2 Oasis2Service; No ImagePath
U2 PCCarerService; No ImagePath
U2 ReadyComm.DirectRouter; No ImagePath
U2 RichVideo; No ImagePath
U2 RtLedService; No ImagePath
U2 SeaPort; No ImagePath
U2 SoftwareService; No ImagePath
U3 SQLWriter; No ImagePath
U2 Stereo Service; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-14 23:30 - 2014-11-14 23:30 - 00020220 _____ () C:\Users\Lapp\Downloads\FRST.txt
2014-11-14 23:30 - 2014-11-14 23:30 - 00000000 ____D () C:\FRST
2014-11-14 23:29 - 2014-11-14 23:29 - 02116608 _____ (Farbar) C:\Users\Lapp\Downloads\FRST64.exe
2014-11-14 23:27 - 2014-11-14 23:27 - 00000470 _____ () C:\Users\Lapp\Downloads\defogger_disable.log
2014-11-14 23:27 - 2014-11-14 23:27 - 00000000 _____ () C:\Users\Lapp\defogger_reenable
2014-11-14 23:26 - 2014-11-14 23:26 - 00050477 _____ () C:\Users\Lapp\Downloads\Defogger.exe
2014-11-14 23:15 - 2014-11-14 23:17 - 00000000 ____D () C:\Users\Lapp\Desktop\cleanen
2014-11-14 22:55 - 2014-11-14 22:55 - 00000000 ____D () C:\ProgramData\374311380
2014-11-14 22:54 - 2014-11-14 22:54 - 00003142 _____ () C:\windows\System32\Tasks\{DFEE10EA-24B7-49A2-A080-0C4F5AC8DE75}
2014-11-14 22:54 - 2014-11-14 22:54 - 00000000 ____D () C:\Program Files (x86)\predm
2014-11-14 22:10 - 2014-11-14 22:10 - 04918960 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2014-11-14 22:10 - 2014-11-14 22:10 - 00025701 _____ () C:\windows\system32\ScanResults.xml
2014-11-14 22:08 - 2014-11-14 22:08 - 00001408 _____ () C:\Users\Paul\Desktop\Registry kostenlos entrümpeln!.lnk
2014-11-14 22:07 - 2014-11-14 03:33 - 00048792 _____ (StdLib) C:\windows\system32\Drivers\{8431bbbd-4243-4758-beab-348411cd1e12}Gw64.sys
2014-11-14 22:01 - 2014-11-14 22:01 - 00000464 _____ () C:\windows\system32\ScannerSettings
2014-10-31 19:09 - 2014-11-14 22:01 - 00000000 ____D () C:\ProgramData\89c775be-12de-4e15-846c-6b3e6a8c39a2
2014-10-31 18:39 - 2014-10-31 02:45 - 00048792 _____ (StdLib) C:\windows\system32\Drivers\{9255f1e2-1754-4887-b5d8-8ea035831546}Gw64.sys
2014-10-31 18:35 - 2014-11-14 22:52 - 00000000 ____D () C:\Program Files\Reimage
2014-10-31 18:32 - 2014-10-31 18:32 - 00756712 _____ (Reimage®) C:\Users\Paul\Downloads\ReimageRepair(2).exe
2014-10-31 18:32 - 2014-10-31 18:32 - 00756712 _____ (Reimage®) C:\Users\Paul\Downloads\ReimageRepair(1).exe
2014-10-31 17:42 - 2014-10-31 17:42 - 00000000 ____D () C:\Users\Lapp\Documents\PC Speed Maximizer
2014-10-31 17:37 - 2014-11-14 22:49 - 00000000 ____D () C:\Program Files (x86)\PC Speed Maximizer
2014-10-31 17:37 - 2014-10-31 17:38 - 00000267 _____ () C:\Users\Lapp\Desktop\Cut the Rope.url
2014-10-31 17:37 - 2014-10-31 17:37 - 01055936 _____ (Adobe) C:\Users\Lapp\Downloads\flashplayer_setup.exe
2014-10-31 17:36 - 2014-10-31 17:36 - 00783096 _____ ( ) C:\Users\Paul\Downloads\adobe_flash_setup(3).exe
2014-10-31 17:23 - 2014-11-14 22:59 - 00002038 _____ () C:\Users\Lapp\Desktop\Search.lnk
2014-10-30 16:04 - 2014-10-30 16:04 - 01326976 _____ () C:\Users\Paul\Downloads\Player_Setup.exe
2014-10-29 16:28 - 2014-10-31 18:37 - 00000165 _____ () C:\windows\Reimage.ini
2014-10-29 16:28 - 2014-10-29 16:28 - 00752920 _____ (Reimage®) C:\Users\Paul\Downloads\ReimageRepair.exe
2014-10-29 16:22 - 2014-10-29 16:22 - 00783096 _____ ( ) C:\Users\Paul\Downloads\adobe_flash_setup(2).exe
2014-10-29 16:22 - 2014-10-29 16:22 - 00783096 _____ ( ) C:\Users\Paul\Downloads\adobe_flash_setup(1).exe
2014-10-29 16:20 - 2014-10-29 16:20 - 00785760 _____ ( ) C:\Users\Paul\Downloads\adobe_flash_setup.exe
2014-10-29 16:16 - 2014-10-29 16:16 - 00000000 ____D () C:\Users\Paul\AppData\Roaming\Systweak
2014-10-29 16:16 - 2014-10-29 16:16 - 00000000 ____D () C:\Users\Paul\AppData\Local\SearchProtect
2014-10-29 16:11 - 2014-11-14 22:53 - 00000000 ____D () C:\Users\Lapp\AppData\Roaming\Systweak
2014-10-29 16:11 - 2014-10-29 16:11 - 00000000 ____D () C:\Users\Lapp\AppData\Local\SearchProtect
2014-10-29 16:11 - 2014-08-05 19:14 - 00020328 _____ () C:\windows\system32\roboot64.exe
2014-10-29 16:10 - 2014-11-14 22:01 - 00000000 ____D () C:\Program Files (x86)\ORBTR
2014-10-29 16:09 - 2014-10-29 16:09 - 00756712 _____ (Reimage®) C:\Users\Lapp\Downloads\ReimageRepair.exe
2014-10-29 16:09 - 2014-10-29 16:09 - 00756712 _____ (Reimage®) C:\Users\Lapp\Downloads\ReimageRepair(1).exe
2014-10-29 16:06 - 2014-11-14 23:00 - 00000000 ____D () C:\Users\Lapp\AppData\Roaming\Probit Software
2014-10-29 16:06 - 2014-10-29 16:06 - 00001087 _____ () C:\Users\Lapp\Desktop\Continue Live Installation.lnk
2014-10-27 19:18 - 2014-10-27 19:18 - 00000000 ____D () C:\Users\Paul\AppData\Local\fastplayer
2014-10-27 19:18 - 2014-10-27 19:18 - 00000000 ____D () C:\Users\Paul\AppData\Local\com
2014-10-27 19:17 - 2014-10-27 19:17 - 00365936 _____ () C:\Users\Paul\Downloads\Setup.exe
2014-10-26 17:42 - 2014-10-26 17:42 - 00000000 ____D () C:\Users\Paul\AppData\Local\mbot_de_195
2014-10-26 17:37 - 2014-10-26 17:37 - 00000000 ____D () C:\windows\SysWOW64\Flash
2014-10-26 17:36 - 2014-10-26 17:36 - 00612324 _____ (CMI Limited) C:\Users\Lapp\AppData\Local\nsw25CA.tmp
2014-10-26 17:36 - 2014-10-26 17:36 - 00000000 __SHD () C:\Users\Lapp\AppData\Roaming\AnyProtectEx
2014-10-26 17:34 - 2014-11-14 22:53 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-10-26 17:34 - 2014-11-14 22:45 - 00001332 _____ () C:\windows\Tasks\RBSWI.job
2014-10-26 17:34 - 2014-11-14 22:45 - 00001326 _____ () C:\windows\Tasks\OG.job
2014-10-26 17:34 - 2014-10-26 17:34 - 02006432 _____ (enter) C:\Users\Paul\AppData\Roaming\RBSWI.exe
2014-10-26 17:34 - 2014-10-26 17:34 - 01519520 _____ (enter) C:\Users\Paul\AppData\Roaming\OG.exe
2014-10-26 17:34 - 2014-10-26 17:34 - 00004354 _____ () C:\windows\System32\Tasks\RBSWI
2014-10-26 17:34 - 2014-10-26 17:34 - 00004348 _____ () C:\windows\System32\Tasks\OG
2014-10-26 17:34 - 2014-10-26 17:34 - 00000000 ____D () C:\Users\Lapp\AppData\Local\globalUpdate
2014-10-26 17:34 - 2014-10-26 17:34 - 00000000 ____D () C:\Users\Lapp\AppData\Local\com
2014-10-26 17:34 - 2014-10-26 17:34 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-10-26 17:33 - 2014-11-14 22:56 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-10-26 17:33 - 2014-11-14 22:55 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-10-26 17:33 - 2014-10-31 17:16 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-10-26 17:33 - 2014-10-26 17:33 - 00004022 _____ () C:\windows\System32\Tasks\LaunchSignup
2014-10-26 17:32 - 2014-10-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Probit Software
2014-10-26 17:31 - 2014-10-26 17:31 - 00365936 _____ () C:\Users\Paul\Downloads\Player.exe
2014-10-25 21:56 - 2014-10-25 21:56 - 00000000 ____D () C:\Users\Lapp\AppData\Local\{6817D6FD-5E64-42E2-9D75-E578B19EBC6B}
2014-10-24 23:38 - 2014-10-24 23:39 - 01054912 _____ (Adobe) C:\Users\Paul\Downloads\install_flashplayer15x32au_mssa_aaa_aih.exe
2014-10-17 15:12 - 2014-09-20 01:09 - 17867776 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-17 15:12 - 2014-09-20 00:55 - 02339328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-17 15:12 - 2014-09-20 00:54 - 10920960 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-17 15:12 - 2014-09-20 00:50 - 01385472 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-17 15:12 - 2014-09-20 00:49 - 01392128 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-17 15:12 - 2014-09-20 00:48 - 01494016 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-17 15:12 - 2014-09-20 00:48 - 00237056 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2014-10-17 15:12 - 2014-09-20 00:48 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-17 15:12 - 2014-09-20 00:47 - 02157056 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-17 15:12 - 2014-09-20 00:47 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-10-17 15:12 - 2014-09-20 00:47 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-17 15:12 - 2014-09-20 00:47 - 00599040 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-17 15:12 - 2014-09-20 00:47 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-17 15:12 - 2014-09-20 00:46 - 02382848 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-17 15:12 - 2014-09-20 00:46 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-17 15:12 - 2014-09-20 00:46 - 00282112 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-17 15:12 - 2014-09-20 00:46 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-17 15:12 - 2014-09-20 00:46 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2014-10-17 15:12 - 2014-09-20 00:46 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2014-10-17 15:12 - 2014-09-20 00:45 - 00248320 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-17 15:12 - 2014-09-20 00:45 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2014-10-17 15:12 - 2014-09-19 23:53 - 12364288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-17 15:12 - 2014-09-19 23:44 - 01810432 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-17 15:12 - 2014-09-19 23:41 - 09739776 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-17 15:12 - 2014-09-19 23:39 - 01138688 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-17 15:12 - 2014-09-19 23:38 - 01129472 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-17 15:12 - 2014-09-19 23:37 - 01427968 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-17 15:12 - 2014-09-19 23:36 - 00231936 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2014-10-17 15:12 - 2014-09-19 23:36 - 00142848 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-17 15:12 - 2014-09-19 23:36 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-17 15:12 - 2014-09-19 23:35 - 01802752 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-17 15:12 - 2014-09-19 23:35 - 00717824 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-10-17 15:12 - 2014-09-19 23:35 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-17 15:12 - 2014-09-19 23:35 - 00421376 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-17 15:12 - 2014-09-19 23:35 - 00041472 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
2014-10-17 15:12 - 2014-09-19 23:34 - 02382848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-17 15:12 - 2014-09-19 23:34 - 00353792 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-17 15:12 - 2014-09-19 23:34 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-17 15:12 - 2014-09-19 23:34 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-17 15:12 - 2014-09-19 23:34 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe
2014-10-17 15:12 - 2014-09-19 23:34 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe
2014-10-17 15:12 - 2014-09-19 23:33 - 00176640 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-17 15:11 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-10-17 15:11 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-10-17 15:11 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-10-17 15:11 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-17 15:11 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-10-17 15:11 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2014-10-17 15:11 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2014-10-17 15:11 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2014-10-17 15:11 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2014-10-17 15:11 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2014-10-17 15:11 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDYAK.DLL
2014-10-17 15:11 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDTAT.DLL
2014-10-17 15:11 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU1.DLL
2014-10-17 15:11 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU.DLL
2014-10-17 15:11 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDBASH.DLL
2014-10-17 15:11 - 2014-07-08 23:38 - 00419992 _____ () C:\windows\system32\locale.nls
2014-10-17 15:11 - 2014-07-08 23:30 - 00419992 _____ () C:\windows\SysWOW64\locale.nls
2014-10-17 15:11 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-17 15:11 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-17 15:11 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-17 15:11 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-17 15:11 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-17 15:11 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-17 15:08 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2014-10-17 15:08 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2014-10-17 15:08 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-17 15:08 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2014-10-17 15:08 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-10-17 15:08 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-10-17 15:08 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-17 15:08 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-17 15:08 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-17 15:08 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-17 15:08 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-17 15:08 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-17 15:08 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-17 15:08 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-17 15:08 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-17 15:08 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-17 15:08 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-17 15:08 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-17 15:08 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-14 23:27 - 2011-08-09 19:03 - 00000000 ____D () C:\Users\Lapp
2014-11-14 23:10 - 2014-04-18 16:53 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-11-14 22:59 - 2014-04-18 15:35 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-14 22:59 - 2014-04-18 15:35 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-14 22:56 - 2011-07-23 02:44 - 01795385 _____ () C:\windows\WindowsUpdate.log
2014-11-14 22:45 - 2011-08-09 19:03 - 03440972 _____ () C:\FaceProv.log
2014-11-14 22:45 - 2011-07-23 03:32 - 00186665 _____ () C:\windows\system32\fastboot.set
2014-11-14 22:23 - 2014-09-24 22:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-14 22:23 - 2014-04-18 15:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-14 22:13 - 2009-07-14 05:45 - 00028704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-14 22:13 - 2009-07-14 05:45 - 00028704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-14 22:11 - 2014-04-18 16:53 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-11-14 22:11 - 2014-04-18 16:52 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-11-14 22:11 - 2014-04-18 16:52 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-14 22:08 - 2011-07-22 18:37 - 00713954 _____ () C:\windows\system32\perfh007.dat
2014-11-14 22:08 - 2011-07-22 18:37 - 00154006 _____ () C:\windows\system32\perfc007.dat
2014-11-14 22:08 - 2009-07-14 06:13 - 01647544 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-14 22:07 - 2009-07-14 03:34 - 00000580 _____ () C:\windows\win.ini
2014-11-14 22:00 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-14 21:59 - 2009-07-14 05:51 - 00115209 _____ () C:\windows\setupact.log
2014-10-31 18:38 - 2013-08-05 22:56 - 00000177 _____ () C:\Users\Lapp\AppData\Roaming\WB.CFG
2014-10-31 17:23 - 2014-07-31 22:29 - 00000000 ____D () C:\Users\Lapp\AppData\Local\Adobe
2014-10-31 17:23 - 2011-07-23 03:19 - 00000000 ____D () C:\ProgramData\McAfee
2014-10-31 17:20 - 2011-08-31 12:33 - 00003922 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{22EC8DB8-E9FB-4135-AF4A-B2C108DD28BE}
2014-10-30 12:25 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-10-29 16:14 - 2010-11-21 04:47 - 00111998 _____ () C:\windows\PFRO.log
2014-10-26 17:34 - 2011-07-23 03:17 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-26 17:33 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-10-26 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-10-20 23:07 - 2014-04-30 21:08 - 00000000 ____D () C:\Users\Paul\AppData\Local\Windows Live
2014-10-18 22:01 - 2009-07-14 05:45 - 00412688 _____ () C:\windows\system32\FNTCACHE.DAT
2014-10-18 21:59 - 2014-04-25 21:56 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-10-17 16:20 - 2011-08-10 20:42 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-17 15:15 - 2013-08-14 17:13 - 00000000 ____D () C:\windows\system32\MRT
2014-10-17 15:01 - 2011-08-10 21:33 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Lapp\AppData\Local\Temp\BackupSetup.exe
C:\Users\Lapp\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Lapp\AppData\Local\Temp\install_reader11_de_gtba_chra_dy_aih.exe
C:\Users\Lapp\AppData\Local\Temp\KUIU.EXE
C:\Users\Lapp\AppData\Local\Temp\Notification.exe
C:\Users\Lapp\AppData\Local\Temp\pnLA7.dll
C:\Users\Lapp\AppData\Local\Temp\pnLA7.exe
C:\Users\Lapp\AppData\Local\Temp\QtraxNotification.exe
C:\Users\Lapp\AppData\Local\Temp\Quarantine.exe
C:\Users\Lapp\AppData\Local\Temp\ReimagePackage.exe
C:\Users\Lapp\AppData\Local\Temp\RUEB5.exe
C:\Users\Lapp\AppData\Local\Temp\setup_fsu_cid.exe
C:\Users\Lapp\AppData\Local\Temp\uninst1.exe
C:\Users\Lapp\AppData\Local\Temp\uninstall.exe
C:\Users\Lapp\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Lapp\AppData\Local\Temp\_isCFBD.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-18 14:40
==================== End Of Log ============================
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2014
Ran by Lapp at 2014-11-14 23:31:46
Running from C:\Users\Lapp\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.0.2.12610 - Adobe Systems Inc.)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Reader X (10.1.12) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{1BC4B13F-E8DC-495B-EC8F-6701438612C2}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.36 - Atheros Communications Inc.)
ATI Uninstaller (HKLM\...\ATI Uninstaller) (Version: 8.981-120704a-156763C-Lenovo - Advanced Micro Devices, Inc.)
Benutzerhandbuch (x32 Version: 1.0.0.6 - Lenovo) Hidden
Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.347.0 - Microsoft Corporation)
Brother MFL-Pro Suite DCP-J315W (HKLM-x32\...\{FB83EAC4-E3F6-4666-B45B-44522F2344B6}) (Version: 1.0.3.0 - Brother Industries, Ltd.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.4.51 - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
devolo dLAN Cockpit (HKLM-x32\...\dlancockpit) (Version: 1.0 - devolo AG)
dLAN Cockpit (x32 Version: 1.19.07 - devolo AG) Hidden
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.0 - Lenovo)
Energy Management (x32 Version: 6.0.2.0 - Lenovo) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3086 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Internet-TV für Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lenovo DirectShare (HKLM-x32\...\InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}) (Version: 1.0.1.38 - ArcSoft)
Lenovo DirectShare (x32 Version: 1.0.1.38 - ArcSoft) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 13.10.1201.1 - Vimicro)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo Games Console (HKLM-x32\...\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3728 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Metric Collection SDK (x32 Version: 1.1.0005.00 - Lenovo Group Limited) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 33.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0.2 (x86 de)) (Version: 33.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7108 - CyberLink Corp.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Qtrax Connection Manager (HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\...\Qtrax Connection Manager) (Version: 20.13.07.02 - Qtrax Inc)
Qtrax Player (HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\...\548901595.portal.qtrax.com) (Version: - portal.qtrax.com)
RangeMax Wireless-N USB Adapter WN111v2 (HKLM-x32\...\InstallShield_{1C0E9C6B-D4D5-4D3C-8A10-F10A3E7BEEA5}) (Version: 3.0.0.3 - NETGEAR)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10003 - Realtek Semiconductor Corp.)
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.17.26.7 - Client Connect LTD) <==== ATTENTION
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.0.0 - Synaptics Incorporated)
Update for Zip Opener (HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\...\DigitalSite) (Version: - ) <==== ATTENTION
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo)
VeriFace (HKLM-x32\...\VeriFace) (Version: 4.0.0.1224 - Lenovo)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Media Center Add-in for Silverlight (HKLM-x32\...\{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}) (Version: 4.7.3.0 - Microsoft Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)
WN111v2 (x32 Version: 3.0.0.3 - NETGEAR) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
23-09-2014 23:52:31 Windows Update
27-09-2014 22:14:17 Windows Update
01-10-2014 14:04:41 Windows-Sicherung
01-10-2014 15:01:53 Windows Update
05-10-2014 06:29:43 Windows Update
09-10-2014 22:19:34 Windows Update
14-10-2014 13:52:37 Windows Update
17-10-2014 14:00:34 Windows Update
17-10-2014 15:17:24 Windows Update
21-10-2014 22:23:14 Windows Update
24-10-2014 22:48:51 Windows Update
30-10-2014 15:09:29 Windows Update
31-10-2014 16:28:53 RCP Fr, Okt 31, 14 17:28
31-10-2014 18:00:32 Windows-Sicherung
14-11-2014 21:05:52 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {074F98AD-EBEA-445A-ACD8-A54B733DB5C3} - \LaunchApp No Task File <==== ATTENTION
Task: {16250943-5383-4E08-88B4-C1B694667428} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-14] (Adobe Systems Incorporated)
Task: {3F4DA857-E313-4699-B714-841759A29382} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29] (CyberLink)
Task: {4A462167-2CFA-4DCA-B827-0B371E94C4D0} - System32\Tasks\TVT\LenovoWERMonitor => C:\Program Files (x86)\Common Files\lenovo\SUP\sup_wermonitor.exe [2014-05-27] (Lenovo)
Task: {625530AA-9E1A-4BDE-BB27-73BE1A687C80} - \DealPly No Task File <==== ATTENTION
Task: {6D92A19B-11B6-4072-8231-76D82B725BA7} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-02-13] (Lenovo)
Task: {C14CF2FA-5058-4342-AACC-3E2BBD342BEF} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {CB5A2F8F-5B89-499C-99E3-E1CCF095F174} - System32\Tasks\RBSWI => C:\Users\Paul\AppData\Roaming\RBSWI.exe [2014-10-26] (enter) <==== ATTENTION
Task: {CD795ADE-029A-4471-AC3B-22AEAAD3FA0C} - System32\Tasks\OG => C:\Users\Paul\AppData\Roaming\OG.exe [2014-10-26] (enter) <==== ATTENTION
Task: {D164BE0E-6487-4FD5-99D3-A2B152128314} - \BitGuard No Task File <==== ATTENTION
Task: {E2873648-F629-42A4-BE4D-91E9CA4F133B} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\OG.job => C:\Users\Paul\AppData\Roaming\OG.exe <==== ATTENTION
Task: C:\windows\Tasks\RBSWI.job => C:\Users\Paul\AppData\Roaming\RBSWI.exe <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
2010-07-19 18:57 - 2010-07-19 18:57 - 02231616 _____ () C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe
2011-08-25 14:01 - 2005-04-22 05:36 - 00143360 ____R () C:\windows\system32\BrSNMP64.dll
2014-10-30 18:33 - 2014-10-30 18:33 - 05559648 _____ () C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
2014-10-30 23:49 - 2014-11-14 22:01 - 00123640 _____ () C:\ProgramData\89c775be-12de-4e15-846c-6b3e6a8c39a2\maintainer.exe
2014-10-20 17:26 - 2014-10-26 17:34 - 00104928 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll
2014-10-20 17:26 - 2014-10-26 17:34 - 00732128 _____ () C:\Program Files (x86)\SupTab\HpUI.exe
2014-07-16 10:55 - 2014-07-16 10:55 - 00073216 _____ () C:\Program Files (x86)\SupTab\Loader64.exe
2014-07-16 11:16 - 2014-07-16 11:16 - 00064000 _____ () C:\Program Files (x86)\SupTab\Loader32.exe
2008-12-20 04:20 - 2011-07-23 03:35 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2008-12-20 04:20 - 2011-07-23 03:35 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2011-07-23 02:54 - 2011-03-25 10:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-07-04 20:33 - 2012-07-04 20:33 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-07-23 03:24 - 2011-07-23 03:24 - 01508192 _____ () C:\windows\system32\IcnOvrly.dll
2011-07-23 03:24 - 2011-07-23 03:24 - 00628064 _____ () C:\windows\system32\SimpleExt.dll
2011-08-25 14:01 - 2009-02-27 15:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2014-10-18 22:48 - 2014-10-18 22:48 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\ce48f93e668f33a9aae851e512cfbf2a\IsdiInterop.ni.dll
2011-07-23 02:54 - 2011-02-18 09:16 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-10-20 17:26 - 2014-10-26 17:34 - 00022496 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll
2014-09-24 22:51 - 2014-11-14 22:23 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-11-14 22:11 - 2014-11-14 22:11 - 16840880 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: BingDesktopUpdate => 2
MSCONFIG\startupreg: BingDesktop => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
MSCONFIG\startupreg: VeriFaceManager => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
MSCONFIG\startupreg: YouCam Tray => "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe" /s
========================= Accounts: ==========================
Administrator (S-1-5-21-2147732465-1013433442-3662694159-500 - Administrator - Disabled)
Gast (S-1-5-21-2147732465-1013433442-3662694159-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2147732465-1013433442-3662694159-1002 - Limited - Enabled)
Lapp (S-1-5-21-2147732465-1013433442-3662694159-1000 - Administrator - Enabled) => C:\Users\Lapp
Paul (S-1-5-21-2147732465-1013433442-3662694159-1003 - Limited - Enabled) => C:\Users\Paul
tvsu_tmp_zdesrSIJUT (S-1-5-21-2147732465-1013433442-3662694159-1006 - Administrator - Enabled)
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Microsoft Composite Battery
Description: Microsoft Composite Battery
Class Guid: {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
Manufacturer: Microsoft
Service: Compbatt
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/14/2014 10:49:12 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: Lapp-PC)
Description: Die Anwendung oder der Dienst "linmsl" konnte nicht heruntergefahren werden.
Error: (11/14/2014 10:42:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 33.0.2.5413, Zeitstempel: 0x544ef530
Name des fehlerhaften Moduls: mozalloc.dll, Version: 33.0.2.5413, Zeitstempel: 0x544ed089
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001425
ID des fehlerhaften Prozesses: 0xad4
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (11/14/2014 10:18:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: RegCleanPro.exe, Version: 6.21.65.62, Zeitstempel: 0x53e0df7a
Name des fehlerhaften Moduls: RegCleanPro.exe, Version: 6.21.65.62, Zeitstempel: 0x53e0df7a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00042f21
ID des fehlerhaften Prozesses: 0x130c
Startzeit der fehlerhaften Anwendung: 0xRegCleanPro.exe0
Pfad der fehlerhaften Anwendung: RegCleanPro.exe1
Pfad des fehlerhaften Moduls: RegCleanPro.exe2
Berichtskennung: RegCleanPro.exe3
Error: (11/14/2014 10:01:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/31/2014 07:16:11 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Am Sicherungsspeicherort ist nicht genügend freier Speicherplatz verfügbar, um die Daten zu sichern. (0x80780048)"
Error: (10/31/2014 06:40:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 32.0.3.5379, Zeitstempel: 0x54224e6b
Name des fehlerhaften Moduls: mozalloc.dll, Version: 32.0.3.5379, Zeitstempel: 0x54221b67
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0x1e94
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (10/31/2014 06:40:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 32.0.3.5379, Zeitstempel: 0x54224e6b
Name des fehlerhaften Moduls: mozalloc.dll, Version: 32.0.3.5379, Zeitstempel: 0x54221b67
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0x249c
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (10/31/2014 05:37:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 32.0.3.5379, Zeitstempel: 0x54224e6b
Name des fehlerhaften Moduls: mozalloc.dll, Version: 32.0.3.5379, Zeitstempel: 0x54221b67
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0x10c0
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (10/31/2014 05:23:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 32.0.3.5379, Zeitstempel: 0x54224e6b
Name des fehlerhaften Moduls: mozalloc.dll, Version: 32.0.3.5379, Zeitstempel: 0x54221b67
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0x2a88
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (10/31/2014 05:22:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 32.0.3.5379, Zeitstempel: 0x54224e6b
Name des fehlerhaften Moduls: mozalloc.dll, Version: 32.0.3.5379, Zeitstempel: 0x54221b67
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0x2fc
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
System errors:
=============
Error: (11/14/2014 10:51:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Update SunriseBrowse" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/14/2014 10:51:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Util SunriseBrowse" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/14/2014 10:45:40 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (11/14/2014 10:44:34 PM) (Source: DCOM) (EventID: 10016) (User: Lapp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Lapp-PCPaulS-1-5-21-2147732465-1013433442-3662694159-1003LocalHost (unter Verwendung von LRPC)
Error: (11/14/2014 10:44:26 PM) (Source: DCOM) (EventID: 10016) (User: Lapp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Lapp-PCPaulS-1-5-21-2147732465-1013433442-3662694159-1003LocalHost (unter Verwendung von LRPC)
Error: (11/14/2014 10:37:20 PM) (Source: DCOM) (EventID: 10016) (User: Lapp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Lapp-PCPaulS-1-5-21-2147732465-1013433442-3662694159-1003LocalHost (unter Verwendung von LRPC)
Error: (11/14/2014 10:34:47 PM) (Source: DCOM) (EventID: 10016) (User: Lapp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Lapp-PCPaulS-1-5-21-2147732465-1013433442-3662694159-1003LocalHost (unter Verwendung von LRPC)
Error: (11/14/2014 10:28:38 PM) (Source: DCOM) (EventID: 10016) (User: Lapp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Lapp-PCPaulS-1-5-21-2147732465-1013433442-3662694159-1003LocalHost (unter Verwendung von LRPC)
Error: (11/14/2014 10:28:30 PM) (Source: DCOM) (EventID: 10016) (User: Lapp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Lapp-PCPaulS-1-5-21-2147732465-1013433442-3662694159-1003LocalHost (unter Verwendung von LRPC)
Error: (11/14/2014 10:28:17 PM) (Source: DCOM) (EventID: 10016) (User: Lapp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Lapp-PCPaulS-1-5-21-2147732465-1013433442-3662694159-1003LocalHost (unter Verwendung von LRPC)
Microsoft Office Sessions:
=========================
Error: (11/14/2014 10:49:12 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: Lapp-PC)
Description: 2C:\Program Files (x86)\LPT\linmsl.exelinmsl0521710560
Error: (11/14/2014 10:42:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe33.0.2.5413544ef530mozalloc.dll33.0.2.5413544ed0898000000300001425ad401d000515d6296aaC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll29c9f139-6c47-11e4-8aa1-b870f4234108
Error: (11/14/2014 10:18:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: RegCleanPro.exe6.21.65.6253e0df7aRegCleanPro.exe6.21.65.6253e0df7ac000000500042f21130c01d0004e2a68b3f2C:\Program Files (x86)\RCP\RegCleanPro.exeC:\Program Files (x86)\RCP\RegCleanPro.exed47692cb-6c43-11e4-8aa1-b870f4234108
Error: (11/14/2014 10:01:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/31/2014 07:16:11 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Am Sicherungsspeicherort ist nicht genügend freier Speicherplatz verfügbar, um die Daten zu sichern. (0x80780048)
Error: (10/31/2014 06:40:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe32.0.3.537954224e6bmozalloc.dll32.0.3.537954221b67800000030000141b1e9401cff53143e4faeeC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll046d3e58-6125-11e4-85bb-b870f4234108
Error: (10/31/2014 06:40:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe32.0.3.537954224e6bmozalloc.dll32.0.3.537954221b67800000030000141b249c01cff52a5a276667C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll046d6568-6125-11e4-85bb-b870f4234108
Error: (10/31/2014 05:37:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe32.0.3.537954224e6bmozalloc.dll32.0.3.537954221b67800000030000141b10c001cff52825be7bbcC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll4519ca73-611c-11e4-85bb-b870f4234108
Error: (10/31/2014 05:23:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe32.0.3.537954224e6bmozalloc.dll32.0.3.537954221b67800000030000141b2a8801cff526eab1375eC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll34a1ccf1-611a-11e4-85bb-b870f4234108
Error: (10/31/2014 05:22:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe32.0.3.537954224e6bmozalloc.dll32.0.3.537954221b67800000030000141b2fc01cff5263d1a39f2C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll178f82c8-611a-11e4-85bb-b870f4234108
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 41%
Total physical RAM: 6087.86 MB
Available physical RAM: 3565.38 MB
Total Pagefile: 12173.9 MB
Available Pagefile: 9404.98 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:654.69 GB) (Free:591.56 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:2.96 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 640F91AA)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=654.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)
==================== End Of Log ============================ Gmer (hat nur im abgesicherten Modus funktioniert): Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-11-15 00:46:44
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD75 rev.02.0 698,64GB
Running: Gmer-19357.exe; Driver: C:\Users\Lapp\AppData\Local\Temp\kxldapoc.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076fc1a13
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076fc1a13 (not active ControlSet)
---- EOF - GMER 2.1 ----
Ich hoffe alles ist korrekt und jemand kann mir helfen.
Viele Grüße
Hausmeister |