gabihaus | 23.02.2015 20:23 | Internetprogramme lassen sich nicht öffnen oder die Verbindung wird abgebrochen Hallo und Guten Tag den vielen Hilfsbereiten hier.
Ich habe folgendes Problem: mehrere Internetprogramme lassen sich seit einigen Tagen auf meinem PC nicht mehr öffnen, so z.B. mein emailcenter von t-online. Googlemail dagegen funktioniert.
Bei einem Browserspiel, das ich manchmal spiele (RisingCity) kann ich mich nur schwer einloggen, es sind mehrere Versuche nötig. Wenn ich dann endlich das Spiel zum Laufen gebracht habe, bricht sehr häufig die Internetverbindung ab. Auch das aktuelle Wetter u.ä. funktioniert nicht. Der Zugang zu meinem Bankkonto dagegen geht. Ich bin ziemlich ratlos und für jede Hilfe sehr dankbar.
Die logfiles: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-02-2015
Ran by User (administrator) on PC-23821 on 23-02-2015 19:15:58
Running from C:\Users\User\Desktop
Loaded Profiles: User & UpdatusUser (Available profiles: User & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Lavasoft Limited) C:\Program Files\Lavasoft\Web Companion\TcpService\2.3.2.7\LavasoftTcpService.exe
(VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Lavasoft) C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
() C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Apple Inc.) C:\Program Files\iTunes\iTunes.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\ATH.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [3921552 2012-06-04] (VIA)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-12-23] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-11-15] ()
HKLM\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [517392 2014-04-25] (McAfee, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-05-15] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKU\S-1-5-21-2337261035-4237212436-276764820-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30878816 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-2337261035-4237212436-276764820-1000\...\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe [1298240 2015-02-18] (Lavasoft)
HKU\S-1-5-21-2337261035-4237212436-276764820-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5496600 2015-01-20] (Piriform Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2337261035-4237212436-276764820-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D022215-A6B219395BABB4E59ADF&form=CONMHP&conlogo=CT3332005
HKU\S-1-5-21-2337261035-4237212436-276764820-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2337261035-4237212436-276764820-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D022215-A6B219395BABB4E59ADF&form=CONBDF&conlogo=CT3332005&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2337261035-4237212436-276764820-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D022215-A6B219395BABB4E59ADF&form=CONBDF&conlogo=CT3332005&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2337261035-4237212436-276764820-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Windows\system32\LavasoftTcpService.dll [326240] (Lavasoft Limited)
Winsock: Catalog9 02 C:\Windows\system32\LavasoftTcpService.dll [326240] (Lavasoft Limited)
Winsock: Catalog9 03 C:\Windows\system32\LavasoftTcpService.dll [326240] (Lavasoft Limited)
Winsock: Catalog9 04 C:\Windows\system32\LavasoftTcpService.dll [326240] (Lavasoft Limited)
Winsock: Catalog9 23 C:\Windows\system32\LavasoftTcpService.dll [326240] (Lavasoft Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A8985A77-4CE0-42F5-BA3B-EAE5464256A3}: [NameServer] 8.8.8.8,8.8.4.4
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default
FF NewTab: about:blank
FF DefaultSearchEngine: Bing
FF Homepage: https://de.yahoo.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Easy YouTube MP3 Downloader - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\5@thumbpro.net.xpi [2014-02-14]
FF Extension: Ghostery - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\firefox@ghostery.com.xpi [2014-02-14]
FF Extension: ClixAddon - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\jid1-wKRSK9TpFpr9Hw@jetpack.xpi [2014-06-14]
FF Extension: YouTube to MP3 - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\youtube2mp3@mondayx.de.xpi [2014-02-14]
FF Extension: Integrated Inbox for Gmail & Google Apps - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}.xpi [2014-02-14]
FF Extension: Updated Ad Blocker for Firefox 11+ - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi [2014-02-14]
FF Extension: Speed Dial - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi [2014-02-14]
FF Extension: Date Picker/Calendar - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\{A6A0B3F6-6D2D-4c55-96C1-7481BEA2EBF8}.xpi [2014-02-14]
FF Extension: Adblock Plus - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jtjjhqi3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-14]
FF HKLM\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-03-20]
FF HKU\S-1-5-21-2337261035-4237212436-276764820-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-29]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-29]
CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-29]
CHR Extension: (Page Eraser) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekofpchjmoalonajopdeegdappocgcmj [2014-12-06]
CHR Extension: (NCapture) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgomjifbpjfhpodjhihemafahhmegbek [2014-12-06]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-29]
CHR Extension: (Minimal Memory) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\oipgklkggfaokcoipmecomffdpebimle [2014-11-29]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-29]
CHR Extension: (BuyNsave) - C:\ProgramData\mklnhcinkfhmcbmboaimenmhkjdolpcc\ [2014-03-29]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 LavasoftTcpService; C:\Program Files\Lavasoft\Web Companion\TcpService\2.3.2.7\LavasoftTcpService.exe [1516104 2015-02-18] (Lavasoft Limited)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [145568 2014-04-25] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [472072 2014-09-04] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [655936 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [169800 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [179600 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [503080 2010-05-04] (Nero AG)
R2 SearchProtectionService; C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [15208 2015-02-18] ()
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 A2DDA; C:\EEK\BIN\a2ddax86.sys [22056 2014-12-06] (Emsisoft GmbH)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [62832 2014-06-20] (McAfee, Inc.)
S3 cleanhlp; C:\EEK\bin\cleanhlp32.sys [50200 2014-12-06] (Emsisoft GmbH)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-02-23] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [135968 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [238176 2014-06-20] (McAfee, Inc.)
S3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [67816 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [369248 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [576048 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [350240 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [81296 2014-08-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [217224 2014-06-20] (McAfee, Inc.)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1832560 2012-05-04] (VIA Technologies, Inc.)
R2 WinRing0_1_2_0; C:\Users\User\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries25.gadget\WinRing0.sys [14416 2014-02-13] (OpenLibSys.org)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-23 19:15 - 2015-02-23 19:16 - 00018587 _____ () C:\Users\User\Desktop\FRST.txt
2015-02-23 19:15 - 2015-02-23 19:15 - 00000000 ____D () C:\Users\User\Desktop\FRST-OlderVersion
2015-02-23 19:12 - 2015-02-23 19:14 - 00000470 _____ () C:\Users\User\Desktop\defogger_disable.log
2015-02-23 19:12 - 2015-02-23 19:12 - 00000000 _____ () C:\Users\User\defogger_reenable
2015-02-23 19:05 - 2015-02-23 19:05 - 00050477 _____ () C:\Users\User\Desktop\Defogger.exe
2015-02-23 17:47 - 2015-02-23 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-02-23 07:34 - 2015-02-23 18:52 - 00043929 _____ () C:\Windows\WindowsUpdate.log
2015-02-22 07:39 - 2015-02-22 07:39 - 00000969 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-02-22 07:39 - 2015-02-22 07:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-02-22 07:39 - 2015-02-22 07:39 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-22 07:33 - 2015-02-22 07:33 - 00005160 _____ () C:\Windows\system32\LavasoftTcpService.ini
2015-02-22 07:33 - 2015-02-22 07:33 - 00002856 _____ () C:\Windows\system32\LavasoftTcpServiceOff.ini
2015-02-22 07:33 - 2015-02-22 07:33 - 00000000 ____D () C:\Users\User\AppData\Local\Lavasoft
2015-02-22 07:33 - 2015-02-18 11:55 - 00326240 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService.dll
2015-02-22 07:28 - 2015-02-22 07:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-02-22 07:28 - 2015-02-22 07:28 - 00000000 ____D () C:\Program Files\Lavasoft
2015-02-22 07:24 - 2015-02-22 07:24 - 00000000 ____D () C:\Users\User\AppData\Roaming\Lavasoft
2015-02-22 07:24 - 2015-02-22 07:24 - 00000000 ____D () C:\ProgramData\Lavasoft
2015-02-22 07:19 - 2015-02-22 07:19 - 00668120 _____ () C:\Users\User\Downloads\ccsetup502_CB-DL-Manager.exe
2015-02-17 18:21 - 2015-01-09 03:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-02-17 18:21 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-02-17 18:21 - 2015-01-09 03:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-02-12 09:31 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-12 09:31 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-11 07:15 - 2015-01-15 08:46 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 07:15 - 2015-01-15 08:46 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 07:15 - 2015-01-15 08:43 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 07:15 - 2015-01-15 08:43 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 07:15 - 2015-01-15 08:42 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 07:15 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 07:15 - 2015-01-15 08:42 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 07:15 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 07:15 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 07:15 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 07:15 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 07:15 - 2015-01-15 05:21 - 00369968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 07:15 - 2015-01-09 02:45 - 02380288 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 07:13 - 2015-02-04 03:54 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 07:13 - 2015-02-04 03:53 - 00767488 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 07:13 - 2015-02-04 03:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 07:13 - 2015-02-04 03:53 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 07:13 - 2015-02-04 03:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 07:13 - 2015-02-04 03:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-11 07:13 - 2015-02-04 03:49 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 07:13 - 2015-01-28 00:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-11 07:13 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-02-11 07:13 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 07:13 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 07:13 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 07:13 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 07:13 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 07:13 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 07:13 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 07:13 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 07:13 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 07:12 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 07:12 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 07:12 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 07:12 - 2015-01-12 03:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 07:12 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 07:12 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 07:12 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 07:12 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 07:12 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 07:12 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 07:12 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 07:12 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 07:12 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 07:12 - 2015-01-12 02:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 07:12 - 2015-01-12 02:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 07:12 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 07:12 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 07:12 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 07:12 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 07:12 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 07:12 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 07:12 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 07:12 - 2015-01-12 02:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 07:12 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 07:12 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 07:12 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 07:12 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 07:12 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 07:11 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 07:11 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-11 07:11 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-11 07:11 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-02-11 07:11 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-01-30 09:47 - 2015-01-30 09:47 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-01-26 19:50 - 2015-01-26 19:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-23 19:16 - 2015-01-06 11:16 - 00000000 ____D () C:\FRST
2015-02-23 19:15 - 2015-01-06 11:15 - 01126912 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2015-02-23 19:14 - 2014-03-29 17:48 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-23 18:34 - 2014-02-13 19:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-23 18:27 - 2014-02-21 14:44 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype
2015-02-23 17:38 - 2014-12-30 19:47 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-23 17:38 - 2014-03-29 17:48 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-23 07:39 - 2009-07-14 05:34 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-23 07:39 - 2009-07-14 05:34 - 00028896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-23 07:31 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-22 18:34 - 2015-01-10 18:07 - 00000000 ____D () C:\Users\User\Documents\neorefs
2015-02-22 07:41 - 2014-02-13 12:03 - 00000000 ____D () C:\Windows\Panther
2015-02-18 16:31 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing
2015-02-16 21:42 - 2015-01-11 16:38 - 00000000 ____D () C:\Users\User\Documents\BFZ2015
2015-02-15 21:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-02-12 09:19 - 2009-07-14 05:33 - 00296688 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-12 09:18 - 2014-12-11 07:54 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-12 09:18 - 2014-05-25 02:22 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-12 09:18 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-02-11 22:46 - 2014-02-13 14:47 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 22:40 - 2014-02-13 14:47 - 113756392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-05 08:34 - 2014-02-13 19:16 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-02-05 08:34 - 2014-02-13 19:16 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-02-05 07:05 - 2014-03-20 13:12 - 00000000 ____D () C:\Program Files\McAfee
2015-01-30 09:45 - 2014-10-17 10:05 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-01-30 09:45 - 2014-02-13 19:18 - 00000000 ____D () C:\Program Files\Java
2015-01-27 06:55 - 2014-02-13 19:20 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-24 10:15 - 2015-01-10 17:51 - 00001334 _____ () C:\Users\Public\Desktop\Neobux Referrals Handy Manager.lnk
2015-01-24 10:15 - 2015-01-10 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neobux Referrals Handy Manager
2015-01-24 10:15 - 2015-01-10 17:50 - 00000000 ____D () C:\Program Files\Neobux Referrals Handy Manager
==================== Files in the root of some directories =======
2014-08-14 20:07 - 2014-08-14 20:07 - 0007597 _____ () C:\Users\User\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-15 21:15
==================== End Of Log ============================ Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-02-2015
Ran by User at 2015-02-23 19:17:33
Running from C:\Users\User\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Ad-Aware Web Companion (Version: 1.1.885.1766 - Lavasoft) Hidden
Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Amazon Kindle (HKU\S-1-5-21-2337261035-4237212436-276764820-1000\...\Amazon Kindle) (Version: - Amazon)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CasinoClub (HKLM\...\CasinoClub ) (Version: - GtechG2)
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
D-i-v-X AVI Codec Pack Pro 2.4.0 (HKLM\...\D-i-v-X - AVI Codec Pack Pro) (Version: - D-i-v-X AVI Codec Pack Pro)
DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC)
Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
LavasoftTcpService (Version: 2.3.2.7 - Lavasoft) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Internet Security (HKLM\...\MSC) (Version: 12.8.992 - McAfee, Inc.)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60831.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Neobux Referrals Handy Manager Version 2.4 (HKLM\...\{6A289DA0-E862-4C0A-BDD6-7FED910C1906}_is1) (Version: - yahiatnt)
Neobux Referrals Handy Manager Version 2.4 (HKLM\...\{7D33B4DE-6D1A-4E03-B0C8-1BD4DA5C4194}_is1) (Version: - yahiatnt)
Nero BurnLite 10 (HKLM\...\{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}) (Version: 10.0.10600 - Nero AG)
Nero BurnLite 10 (HKLM\...\{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}) (Version: 10.0.10500.5.100 - Nero AG)
Nero Update (HKLM\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA Grafiktreiber 307.83 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 307.83 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
OpenOffice 4.0.1 (HKLM\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Platform (Version: 1.39 - VIA Technologies, Inc.) Hidden
Shark007 Advanced Codecs (HKLM\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 4.4.2 - Shark007)
Simple Sudoku 4.2 (HKLM\...\Simple Sudoku_is1) (Version: - )
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN)
Web Companion (HKLM\...\{0CCC3DEB-F976-4477-AD38-520A692B9F4D}_WebCompanion) (Version: 1.1.885.1766 - Lavasoft)
WinRAR 5.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2337261035-4237212436-276764820-1000_Classes\CLSID\{07474513-7B58-45c7-B3E6-13A3669B1AFD}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2337261035-4237212436-276764820-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\Users\User\AppData\Local\Temp\4A27eF\temp\Download.exe No File
==================== Restore Points =========================
16-01-2015 09:01:34 McAfee Vulnerability Scanner
27-01-2015 18:53:36 Geplanter Prüfpunkt
30-01-2015 09:42:09 McAfee Vulnerability Scanner
11-02-2015 22:37:07 Windows Update
12-02-2015 21:43:14 Windows Update
17-02-2015 21:58:36 Windows Update
22-02-2015 07:25:05 LavasoftWeCompanion
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {060E67A7-1A1F-4986-B7AA-9A0653C9AD4E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-03-29] (Google Inc.)
Task: {3A334196-B827-468B-803B-0C1DA237E654} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-03-29] (Google Inc.)
Task: {7F2039DA-9ACE-41B2-9EBB-73CEA82419B9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
Task: {9700A53C-3B50-49E6-84CF-838C9B0F11E2} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2337261035-4237212436-276764820-1000
Task: {A87CEA36-5183-4EBC-8B05-B6826E0D926B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A9CF4785-967B-42F9-815F-457CBDCE5760} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {F94E5ADC-722F-4E36-A006-BDA517DFEAF4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2014-02-13 12:46 - 2013-01-31 10:00 - 00079648 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2006-12-08 12:59 - 2006-12-08 12:59 - 00022723 _____ () C:\Windows\System32\sugi1l3.dll
2014-02-12 19:58 - 2014-02-12 19:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-02-13 13:29 - 2012-06-04 10:25 - 00080528 _____ () C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
2014-02-13 13:29 - 2012-06-04 10:25 - 00113296 _____ () C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
2013-11-15 01:48 - 2013-11-15 01:48 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2013-11-15 01:49 - 2013-11-15 01:49 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00072512 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.Utils.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00176488 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00046408 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.adblocker.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00033136 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00015696 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll
2015-02-18 11:54 - 2015-02-18 11:54 - 00120152 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.PUP.Management.dll
2015-02-18 11:54 - 2015-02-18 11:54 - 00069960 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SysInfo.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00039256 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.CSharp.Utilities.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00015208 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
2015-02-18 11:53 - 2015-02-18 11:53 - 00012144 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Service.Logger.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00034152 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WcfService.dll
2015-01-21 03:06 - 2015-01-21 03:06 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2009-07-14 01:56 - 2009-07-14 02:16 - 00159232 _____ () C:\Windows\system32\SaMinDrv.dll
2015-01-26 19:50 - 2015-01-26 19:50 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2015-02-05 08:34 - 2015-02-05 08:34 - 16852144 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 00237352 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2337261035-4237212436-276764820-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-2337261035-4237212436-276764820-500 - Administrator - Disabled)
Gast (S-1-5-21-2337261035-4237212436-276764820-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2337261035-4237212436-276764820-1003 - Limited - Enabled)
UpdatusUser (S-1-5-21-2337261035-4237212436-276764820-1001 - Limited - Enabled) => C:\Users\UpdatusUser
User (S-1-5-21-2337261035-4237212436-276764820-1000 - Administrator - Enabled) => C:\Users\User
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5772
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5772
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4727
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4727
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3697
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3697
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1030
System errors:
=============
Error: (02/23/2015 05:45:06 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {209500FC-6B45-4693-8871-6296C4843751}
Microsoft Office Sessions:
=========================
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5772
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5772
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4727
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4727
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3697
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3697
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1030
CodeIntegrity Errors:
===================================
Date: 2014-04-09 10:46:59.625
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.622
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.619
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.577
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.573
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.571
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.554
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.552
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.548
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.420
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: AMD Athlon(tm) II X2 220 Processor
Percentage of memory in use: 85%
Total physical RAM: 2015.37 MB
Available physical RAM: 292.95 MB
Total Pagefile: 5037.37 MB
Available Pagefile: 2114.85 MB
Total Virtual: 2047.88 MB
Available Virtual: 1888.09 MB
==================== Drives ================================
Drive c: (Win7) (Fixed) (Total:465.66 GB) (Free:422.61 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 32A4CD5D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-02-2015
Ran by User at 2015-02-23 19:17:33
Running from C:\Users\User\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Ad-Aware Web Companion (Version: 1.1.885.1766 - Lavasoft) Hidden
Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Amazon Kindle (HKU\S-1-5-21-2337261035-4237212436-276764820-1000\...\Amazon Kindle) (Version: - Amazon)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CasinoClub (HKLM\...\CasinoClub ) (Version: - GtechG2)
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
D-i-v-X AVI Codec Pack Pro 2.4.0 (HKLM\...\D-i-v-X - AVI Codec Pack Pro) (Version: - D-i-v-X AVI Codec Pack Pro)
DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC)
Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
LavasoftTcpService (Version: 2.3.2.7 - Lavasoft) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Internet Security (HKLM\...\MSC) (Version: 12.8.992 - McAfee, Inc.)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60831.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Neobux Referrals Handy Manager Version 2.4 (HKLM\...\{6A289DA0-E862-4C0A-BDD6-7FED910C1906}_is1) (Version: - yahiatnt)
Neobux Referrals Handy Manager Version 2.4 (HKLM\...\{7D33B4DE-6D1A-4E03-B0C8-1BD4DA5C4194}_is1) (Version: - yahiatnt)
Nero BurnLite 10 (HKLM\...\{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}) (Version: 10.0.10600 - Nero AG)
Nero BurnLite 10 (HKLM\...\{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}) (Version: 10.0.10500.5.100 - Nero AG)
Nero Update (HKLM\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA Grafiktreiber 307.83 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 307.83 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
OpenOffice 4.0.1 (HKLM\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Platform (Version: 1.39 - VIA Technologies, Inc.) Hidden
Shark007 Advanced Codecs (HKLM\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 4.4.2 - Shark007)
Simple Sudoku 4.2 (HKLM\...\Simple Sudoku_is1) (Version: - )
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN)
Web Companion (HKLM\...\{0CCC3DEB-F976-4477-AD38-520A692B9F4D}_WebCompanion) (Version: 1.1.885.1766 - Lavasoft)
WinRAR 5.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2337261035-4237212436-276764820-1000_Classes\CLSID\{07474513-7B58-45c7-B3E6-13A3669B1AFD}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2337261035-4237212436-276764820-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\Users\User\AppData\Local\Temp\4A27eF\temp\Download.exe No File
==================== Restore Points =========================
16-01-2015 09:01:34 McAfee Vulnerability Scanner
27-01-2015 18:53:36 Geplanter Prüfpunkt
30-01-2015 09:42:09 McAfee Vulnerability Scanner
11-02-2015 22:37:07 Windows Update
12-02-2015 21:43:14 Windows Update
17-02-2015 21:58:36 Windows Update
22-02-2015 07:25:05 LavasoftWeCompanion
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {060E67A7-1A1F-4986-B7AA-9A0653C9AD4E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-03-29] (Google Inc.)
Task: {3A334196-B827-468B-803B-0C1DA237E654} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-03-29] (Google Inc.)
Task: {7F2039DA-9ACE-41B2-9EBB-73CEA82419B9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
Task: {9700A53C-3B50-49E6-84CF-838C9B0F11E2} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2337261035-4237212436-276764820-1000
Task: {A87CEA36-5183-4EBC-8B05-B6826E0D926B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A9CF4785-967B-42F9-815F-457CBDCE5760} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {F94E5ADC-722F-4E36-A006-BDA517DFEAF4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2014-02-13 12:46 - 2013-01-31 10:00 - 00079648 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2006-12-08 12:59 - 2006-12-08 12:59 - 00022723 _____ () C:\Windows\System32\sugi1l3.dll
2014-02-12 19:58 - 2014-02-12 19:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-02-13 13:29 - 2012-06-04 10:25 - 00080528 _____ () C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
2014-02-13 13:29 - 2012-06-04 10:25 - 00113296 _____ () C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
2013-11-15 01:48 - 2013-11-15 01:48 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2013-11-15 01:49 - 2013-11-15 01:49 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00072512 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.Utils.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00176488 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00046408 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.adblocker.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00033136 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00015696 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll
2015-02-18 11:54 - 2015-02-18 11:54 - 00120152 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.PUP.Management.dll
2015-02-18 11:54 - 2015-02-18 11:54 - 00069960 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SysInfo.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00039256 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.CSharp.Utilities.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00015208 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
2015-02-18 11:53 - 2015-02-18 11:53 - 00012144 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Service.Logger.dll
2015-02-18 11:53 - 2015-02-18 11:53 - 00034152 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WcfService.dll
2015-01-21 03:06 - 2015-01-21 03:06 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2009-07-14 01:56 - 2009-07-14 02:16 - 00159232 _____ () C:\Windows\system32\SaMinDrv.dll
2015-01-26 19:50 - 2015-01-26 19:50 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2015-02-05 08:34 - 2015-02-05 08:34 - 16852144 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 00237352 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2337261035-4237212436-276764820-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-2337261035-4237212436-276764820-500 - Administrator - Disabled)
Gast (S-1-5-21-2337261035-4237212436-276764820-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2337261035-4237212436-276764820-1003 - Limited - Enabled)
UpdatusUser (S-1-5-21-2337261035-4237212436-276764820-1001 - Limited - Enabled) => C:\Users\UpdatusUser
User (S-1-5-21-2337261035-4237212436-276764820-1000 - Administrator - Enabled) => C:\Users\User
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5772
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5772
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4727
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4727
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3697
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3697
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1030
System errors:
=============
Error: (02/23/2015 05:45:06 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {209500FC-6B45-4693-8871-6296C4843751}
Microsoft Office Sessions:
=========================
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5772
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5772
Error: (02/23/2015 03:57:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4727
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4727
Error: (02/23/2015 03:57:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3697
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3697
Error: (02/23/2015 03:57:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/23/2015 03:57:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1030
CodeIntegrity Errors:
===================================
Date: 2014-04-09 10:46:59.625
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.622
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.619
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.577
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.573
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.571
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.554
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.552
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.548
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-04-09 10:46:59.420
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: AMD Athlon(tm) II X2 220 Processor
Percentage of memory in use: 85%
Total physical RAM: 2015.37 MB
Available physical RAM: 292.95 MB
Total Pagefile: 5037.37 MB
Available Pagefile: 2114.85 MB
Total Virtual: 2047.88 MB
Available Virtual: 1888.09 MB
==================== Drives ================================
Drive c: (Win7) (Fixed) (Total:465.66 GB) (Free:422.61 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 32A4CD5D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
==================== End Of Log ============================<?xml version="1.0" encoding="UTF-8"?>
-<logs>
<record subtype="Malware Protection" result="Starting" last_modified_tag="195dd55f-36e0-43d2-ac09-4e91843062f5" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:31:51.510800+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malware Protection" result="Started" last_modified_tag="44ddf6cf-cb45-492e-a593-bb74ed57582c" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:31:51.542000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Starting" last_modified_tag="50b77138-6db7-4e66-8b27-7c6ee0789190" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:31:51.573200+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Started" last_modified_tag="7cdf4fe1-1e05-48a3-aff5-4c3034aa1f4e" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:32:30.130800+01:00" LoggingEventType="2" severity="debug"/>
<record last_modified_tag="090fa7d4-c390-4985-a752-213fa67f28be" systemname="PC-23821" username="SYSTEM" type="Update" source="Scheduler" datetime="2015-02-23T07:37:38.086800+01:00" LoggingEventType="1" severity="debug" toVersion="2015.2.23.1" name="Malware Database" fromVersion="2015.2.22.6"/>
<record subtype="Refresh" result="Starting" last_modified_tag="8acb6da1-26bf-4435-b303-9c81419b3c2b" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:37:38.406800+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="35e72922-807e-4764-bc94-7058833a0129" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:37:38.426800+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="978ffa7f-c426-4938-9519-707621a2fd0f" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:37:39.120800+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Refresh" result="Success" last_modified_tag="cdba7aae-0b38-412c-a58d-57e7272e5ea8" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:38:30.044800+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Starting" last_modified_tag="f86c6782-47da-4892-b7b0-53c36f030ae3" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:38:30.084800+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Started" last_modified_tag="79aaec2c-35a9-4c01-9394-bbada5174235" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T07:38:38.753800+01:00" LoggingEventType="2" severity="debug"/>
<record last_modified_tag="8b69c63d-7fcb-45fc-b019-d7e6f76023b8" systemname="PC-23821" username="SYSTEM" type="Update" source="Scheduler" datetime="2015-02-23T08:41:53.505000+01:00" LoggingEventType="1" severity="debug" toVersion="2015.2.23.2" name="Malware Database" fromVersion="2015.2.23.1"/>
<record subtype="Refresh" result="Starting" last_modified_tag="7058c88d-470f-41f3-9685-abcff15cc758" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T08:41:54.586000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="3945a825-b3d5-4bf9-b215-43d58ee8af82" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T08:41:54.642000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="9dff2368-72d1-4c46-b3a2-74237d5844ef" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T08:41:56.090000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Refresh" result="Success" last_modified_tag="a5ea3f11-6316-44a5-b34d-7c8ffc92f4b9" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T08:42:44.709000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Starting" last_modified_tag="3241a657-bbf5-42fa-83c8-a03389db2e32" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T08:42:44.785000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Started" last_modified_tag="5c5fa7c8-9ad8-4dd5-b400-48fa2b02e91e" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T08:42:59.537000+01:00" LoggingEventType="2" severity="debug"/>
<record last_modified_tag="88e929fa-b2ff-459d-b244-bdaab8d9664d" systemname="PC-23821" username="SYSTEM" type="Update" source="Scheduler" datetime="2015-02-23T12:31:05.124000+01:00" LoggingEventType="1" severity="debug" toVersion="2015.2.23.3" name="Malware Database" fromVersion="2015.2.23.2"/>
<record subtype="Refresh" result="Starting" last_modified_tag="8b19fc81-7249-423c-89a8-97b0c75217cd" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T12:31:06.955000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="de7a1bd8-7171-413c-ba90-ca1448deb59a" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T12:31:07.006000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="87379077-b35f-4c15-a7fa-1100c8e9f605" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T12:31:10.047000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Refresh" result="Success" last_modified_tag="3b96f4e4-0621-46e8-af9a-c86b297e5a9d" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T12:32:06.081000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Starting" last_modified_tag="1d85227b-e453-483c-9f03-50fa738ab9c0" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T12:32:06.977000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Started" last_modified_tag="acf3e8d0-8483-4408-a1d5-23521adf59ec" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T12:32:19.499000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" last_modified_tag="fa8a7951-3fce-4ac9-9546-89e5e9ca57cc" systemname="PC-23821" username="SYSTEM" type="Detection" source="Protection" datetime="2015-02-23T13:16:18.498000+01:00" LoggingEventType="0" severity="debug" port="58184" malwaretype="IP" ip="80.252.188.229" domain="3b9cc85dcf732d5.se" direction="Outbound" process="C:\Program Files\Google\Chrome\Application\chrome.exe"/>
<record subtype="Malicious Website Protection" last_modified_tag="e0e83675-7323-496f-b1d0-9a2ff21fa310" systemname="PC-23821" username="SYSTEM" type="Detection" source="Protection" datetime="2015-02-23T13:16:20.990000+01:00" LoggingEventType="0" severity="debug" port="58184" malwaretype="IP" ip="80.252.188.229" domain="3b9cc85dcf732d5.se" direction="Outbound" process="C:\Program Files\Google\Chrome\Application\chrome.exe"/>
<record subtype="Malicious Website Protection" last_modified_tag="21cf071b-28f2-41cb-822f-90aa71cfd02c" systemname="PC-23821" username="SYSTEM" type="Detection" source="Protection" datetime="2015-02-23T13:16:24.237000+01:00" LoggingEventType="0" severity="debug" port="58185" malwaretype="IP" ip="80.252.188.229" domain="3b9cc85dcf732d5.se" direction="Outbound" process="C:\Program Files\Google\Chrome\Application\chrome.exe"/>
<record subtype="Malicious Website Protection" last_modified_tag="d34e25b9-dcc8-41a9-8fe4-889f3ae43be8" systemname="PC-23821" username="SYSTEM" type="Detection" source="Protection" datetime="2015-02-23T13:16:24.286000+01:00" LoggingEventType="0" severity="debug" port="58186" malwaretype="IP" ip="80.252.188.229" domain="3b9cc85dcf732d5.se" direction="Outbound" process="C:\Program Files\Google\Chrome\Application\chrome.exe"/>
<record subtype="Malicious Website Protection" last_modified_tag="58dc36c8-3292-461d-8169-2c224afca2f9" systemname="PC-23821" username="SYSTEM" type="Detection" source="Protection" datetime="2015-02-23T13:16:28.258000+01:00" LoggingEventType="0" severity="debug" port="58239" malwaretype="IP" ip="5.153.38.133" domain="omr.topfyspafyce.com" direction="Outbound" process="C:\Program Files\Google\Chrome\Application\chrome.exe"/>
<record subtype="Malicious Website Protection" last_modified_tag="89d4f42b-3f17-4097-adef-05fd5d4aa557" systemname="PC-23821" username="SYSTEM" type="Detection" source="Protection" datetime="2015-02-23T13:16:28.916000+01:00" LoggingEventType="0" severity="debug" port="58239" malwaretype="IP" ip="5.153.38.133" domain="omr.topfyspafyce.com" direction="Outbound" process="C:\Program Files\Google\Chrome\Application\chrome.exe"/>
<record last_modified_tag="2c40642c-cf8c-4126-8ed6-1a3b7a6513c2" systemname="PC-23821" username="SYSTEM" type="Update" source="Scheduler" datetime="2015-02-23T17:38:24.368000+01:00" LoggingEventType="1" severity="debug" toVersion="2015.2.23.4" name="Malware Database" fromVersion="2015.2.23.3"/>
<record subtype="Refresh" result="Starting" last_modified_tag="3ad41913-24fa-44a0-84cf-d49a6d0c02e1" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T17:38:26.158000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="49ccf5d8-60a9-469c-9ead-d0988acad185" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T17:38:26.178000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="4d5426c8-f5b0-4634-a548-22c212d2761e" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T17:38:28.608000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Refresh" result="Success" last_modified_tag="8618fc5e-cd6c-4d84-a9a4-9a0542cd69d0" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T17:39:40.071000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Starting" last_modified_tag="5bcde606-5f67-4811-92bc-951175e6ae8d" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T17:39:40.142000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Started" last_modified_tag="84871435-3db9-4e8f-8550-904e0eb661e3" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T17:39:58.413000+01:00" LoggingEventType="2" severity="debug"/>
<record last_modified_tag="58d988da-3ffd-48f0-927e-701ea000ce56" systemname="PC-23821" username="SYSTEM" type="Update" source="Scheduler" datetime="2015-02-23T19:39:56.382000+01:00" LoggingEventType="1" severity="debug" toVersion="2015.2.23.6" name="Malware Database" fromVersion="2015.2.23.4"/>
<record subtype="Refresh" result="Starting" last_modified_tag="9f811d5e-d98b-42a5-ac8c-336f3ed6bd0f" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T19:39:57.783000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopping" last_modified_tag="9bae3069-2d00-4b20-acad-fe41a193e0b2" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T19:39:57.831000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Stopped" last_modified_tag="e0981aae-aa32-430e-8ccb-039683fb2c58" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T19:39:59.983000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Refresh" result="Success" last_modified_tag="7b934118-6bc2-4267-9ebf-b19d031d462c" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T19:40:51.493000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Starting" last_modified_tag="f473127c-f86d-4623-8f5a-9cde945b732c" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T19:40:51.574000+01:00" LoggingEventType="2" severity="debug"/>
<record subtype="Malicious Website Protection" result="Started" last_modified_tag="8544784c-5d83-47c0-86f1-79f351f0e9fb" systemname="PC-23821" username="SYSTEM" type="Protection" source="Protection" datetime="2015-02-23T19:40:54.257000+01:00" LoggingEventType="2" severity="debug"/>
</logs> So, ich hoffe, dass ich alles Nötige angehängt habe und hoffe auf Hilfe
Gabriela |