m.jacobs1977 | 13.03.2015 16:49 | Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by Jacobs at 2015-03-13 14:00:37
Running from C:\Users\Jacobs\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Ad-Aware Antivirus (Disabled - Out of date) {D87B6541-12A1-DAEA-0033-9B8057AAB996}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Internet Security 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Ad-Aware Antivirus (Disabled - Out of date) {631A84A5-349B-D564-3A83-A0F22C2DF32B}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security 2015 (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}
FW: Ad-Aware Firewall (Disabled) {E040E464-58CE-DBB2-2B6C-32B5A979FEED}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Ad-Aware Antivirus (HKLM\...\{FF054A8C-C0A4-4C78-8910-E2A459BEFF05}_AdAwareUpdater) (Version: 11.6.306.7947 - Lavasoft)
Ad-Aware Web Companion (x32 Version: 1.1.913.1833 - Lavasoft) Hidden
AdAwareInstaller (Version: 11.6.306.7947 - Lavasoft) Hidden
AdAwareUpdater (Version: 11.6.306.7947 - Lavasoft) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
AntimalwareEngine (Version: 3.0.98.0 - Lavasoft) Hidden
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5751 - AVG Technologies)
AVG 2015 (Version: 15.0.4306 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5751 - AVG Technologies) Hidden
Avira (HKLM-x32\...\{d9ed6dcf-6bfc-4fbb-802e-81dd5b767d6e}) (Version: 1.1.32.25147 - Avira Operations & Co. KG)
Avira (x32 Version: 1.1.32.25147 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 15.0.8.650 - Avira)
Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.50 - Conexant)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.21 - Lenovo)
Energy Manager (x32 Version: 1.5.0.21 - Lenovo) Hidden
EPSON WF-3520 Series Printer Uninstall (HKLM\...\EPSON WF-3520 Series) (Version: - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
Google Drive (HKLM-x32\...\{65EACBB4-B0B8-4A5B-AE46-22DBE15C70B5}) (Version: 1.19.8406.6504 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Sideband Fabric Device Driver (HKLM-x32\...\C5A8BC6E-723A-4C0F-96E1-C426D1A4BCA9) (Version: 1.0.0.1002 - Intel Corporation)
Intel(R) Trusted Execution Engine (HKLM\...\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation)
LavasoftTcpService (x32 Version: 2.3.3.0 - Lavasoft) Hidden
Lenovo Browser Guard (HKLM-x32\...\LenovoBrowserGuard) (Version: 2.16.50.5 - ClientConnect LTD)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.25.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.)
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.0.19.0 - Lenovo)
Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.43.4 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited)
Lenovo Solution Center (HKLM\...\{4C2B6F96-3AED-4E3F-8DCE-917863D1E6B1}) (Version: 2.7.003.00 - Lenovo Group Limited)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.0.0.65 - Lenovo)
Lenovo Updates (x32 Version: 1.0.0.65 - Lenovo) Hidden
Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo)
Lenovo Web Start (HKU\S-1-5-21-535057637-212020618-1516021077-1001\...\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1) (Version: 1.0.2.53457 - Pokki)
Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
NetWorx 5.3.3 (HKLM\...\NetWorx_is1) (Version: - Softperfect Research)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.311.0 - Tracker Software Products Ltd)
Pokki (HKU\S-1-5-21-535057637-212020618-1516021077-1001\...\Pokki) (Version: 0.269.5.460 - Pokki)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.805.806.012214 - REALTEK Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.39053 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0238 - REALTEK Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Web Companion (HKLM-x32\...\{9B487475-49A6-468F-B6A0-41F3F1086E31}_WebCompanion) (Version: 1.1.913.1833 - Lavasoft)
Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-535057637-212020618-1516021077-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
==================== Restore Points =========================
10-03-2015 17:40:32 Windows Update
11-03-2015 23:04:28 AA11
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {27138665-BF1E-4EBF-BA8D-1A310E612EBB} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2015-01-08] (Lenovo)
Task: {2BDEED55-15BF-4EDA-8005-19108210276B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-03-11] (Microsoft Corporation)
Task: {2C535220-5DD6-4B1B-8427-B426F590A0C7} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {52C15B28-F6AE-479D-A1A2-AB3D27D22B6C} - System32\Tasks\GoogleUpdateTaskMachineUA1d04311693af254 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08] (Google Inc.)
Task: {5D7AA1EB-5F58-45D9-BA75-EB7CE9B38834} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-10-16] ()
Task: {5D994713-8207-4619-88DD-95F4C7AAB665} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [2014-10-16] (Lenovo)
Task: {6ADA58E1-C43D-440E-9D44-E2A16C739DD6} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-10-16] (Lenovo)
Task: {799F2A79-7C7E-45B8-8623-DAE6B3DDC880} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2014-05-21] ()
Task: {893215BC-FC3D-4E42-AD99-5A911B1518F4} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-10-16] (Lenovo)
Task: {97E5405F-3DB6-4EF6-971A-B11667BFDF20} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08] (Google Inc.)
Task: {A0BA1D94-E4DA-4A04-A4AB-9A83C0FDC7F7} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {ABF8305F-68DF-41FD-AF6D-A2D4B113F5DF} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] ()
Task: {DD2FA879-8CC1-4FDB-9991-BE04260E3546} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08] (Google Inc.)
Task: {FB567A4E-97C6-4D04-BAAF-181CF5E190C4} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d04311693af254.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2014-11-26 23:27 - 2014-01-22 14:04 - 00084992 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2015-03-10 18:47 - 2015-03-10 18:47 - 00720760 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareService.exe
2015-03-10 18:51 - 2015-03-10 18:51 - 00107024 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_thread-vc100-mt-1_57.dll
2015-03-10 18:51 - 2015-03-10 18:51 - 00024080 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_system-vc100-mt-1_57.dll
2015-03-10 18:51 - 2015-03-10 18:51 - 00055320 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_date_time-vc100-mt-1_57.dll
2015-03-10 18:51 - 2015-03-10 18:51 - 00125464 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_filesystem-vc100-mt-1_57.dll
2015-03-10 18:51 - 2015-03-10 18:51 - 00033296 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_chrono-vc100-mt-1_57.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 12745216 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareServiceKernel.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 03396064 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\RCF.dll
2015-03-10 18:51 - 2015-03-10 18:51 - 00785936 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_regex-vc100-mt-1_57.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00744960 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareActivation.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00480272 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareApplicationUpdater.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00812032 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareGamingMode.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00099312 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareReset.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00119792 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareTime.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00963088 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareDefinitionsUpdater.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00868896 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareDefinitionsUpdaterScheduler.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01108992 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareIgnoreList.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00247808 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareQuarantine.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01013256 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareAntiMalwareEngine.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00211464 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareAntiRootkitEngine.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01177608 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareScannerHistory.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01302008 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareScanner.dll
2015-03-10 18:51 - 2015-03-10 18:51 - 00034832 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_timer-vc100-mt-1_57.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00977416 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareScannerScheduler.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01143824 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareRealTimeProtection.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00237568 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareIncompatibles.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00893432 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareAntiSpam.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00847872 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareAntiPhishing.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 03104776 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareParentalControl.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 02958848 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareWebProtection.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01288712 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareEmailProtection.dll
2015-03-10 18:51 - 2015-03-10 18:51 - 00053272 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_iostreams-vc100-mt-1_57.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01293832 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareNetworkProtection.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00969200 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwarePromo.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00366584 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareFeedback.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 02787344 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareThreatWorkAlliance.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01232888 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwarePinCode.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00969208 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareNotice.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00963576 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareAvcEngine.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 01184792 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareRealTimeProtectionHistory.dll
2014-11-27 00:15 - 2012-04-24 11:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-03-09 11:31 - 2015-03-09 11:31 - 00017768 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
2015-03-09 11:31 - 2015-03-09 11:31 - 00012144 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Service.Logger.dll
2015-03-09 11:31 - 2015-03-09 11:31 - 00034152 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WcfService.dll
2014-11-27 00:21 - 2014-11-27 00:21 - 00067856 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
2014-11-27 00:21 - 2014-11-27 00:21 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll
2014-11-27 00:21 - 2014-11-27 00:21 - 00815104 _____ () C:\Program Files\Lenovo PhoneCompanion\adb.exe
2015-03-10 18:50 - 2015-03-10 18:50 - 02756616 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareShellExtension.dll
2014-11-26 23:24 - 2010-10-26 05:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2014-03-26 12:50 - 2014-11-27 00:27 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2015-03-11 15:09 - 2014-06-06 15:41 - 00718336 _____ () C:\Program Files\NetWorx\sqlite.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 09566192 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareTray.exe
2015-03-10 18:51 - 2015-03-10 18:51 - 00499728 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\boost_locale-vc100-mt-1_57.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 02144248 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\HtmlFramework.dll
2015-03-10 18:50 - 2015-03-10 18:50 - 00869896 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareTrayDefaultSkin.dll
2015-03-13 13:52 - 2015-03-13 13:52 - 00050477 _____ () C:\Users\Jacobs\Desktop\Defogger.exe
2014-10-16 17:13 - 2014-10-16 17:13 - 00290184 _____ () C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCTaskService.exe
2014-10-16 17:13 - 2014-10-16 17:13 - 00032544 _____ () C:\Program Files\Lenovo\Lenovo Solution Center\App\Data.dll
2014-10-16 17:13 - 2014-10-16 17:13 - 00014624 _____ () C:\Program Files\Lenovo\Lenovo Solution Center\App\DataInterface.dll
2014-10-16 17:13 - 2014-10-16 17:13 - 00012664 _____ () C:\Program Files\Lenovo\Lenovo Solution Center\App\Aspect.dll
2014-10-16 17:13 - 2014-10-16 17:13 - 00081184 _____ () C:\Program Files\Lenovo\Lenovo Solution Center\App\DiskPartitionInterface.dll
2014-10-16 17:13 - 2014-10-16 17:13 - 00013088 _____ () C:\Program Files\Lenovo\Lenovo Solution Center\App\WindowsRegistry.dll
2015-03-13 13:47 - 2015-03-13 13:47 - 00098816 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32api.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00110080 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\pywintypes27.dll
2015-03-13 13:47 - 2015-03-13 13:47 - 00364544 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\pythoncom27.dll
2015-03-13 13:47 - 2015-03-13 13:47 - 00045568 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\_socket.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 01160704 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\_ssl.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00320512 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32com.shell.shell.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00713216 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\_hashlib.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 01175040 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\wx._core_.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00805888 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\wx._gdi_.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00811008 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\wx._windows_.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 01062400 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\wx._controls_.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00735232 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\wx._misc_.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00557056 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\pysqlite2._sqlite.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00128512 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\_elementtree.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00127488 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\pyexpat.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00087552 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\_ctypes.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00119808 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32file.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00108544 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32security.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00007168 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\hashobjs_ext.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00167936 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32gui.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00018432 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32event.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00038912 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32inet.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00011264 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32crypt.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00070656 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\wx._html2.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00027136 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\_multiprocessing.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00035840 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32process.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00686080 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\unicodedata.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00122368 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\wx._wizard.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00024064 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32pipe.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00025600 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32pdh.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00525640 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\windows._lib_cacheinvalidation.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00010240 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\select.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00017408 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32profile.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00022528 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\win32ts.pyd
2015-03-13 13:47 - 2015-03-13 13:47 - 00078336 _____ () C:\Users\Jacobs\AppData\Local\Temp\_MEI91722\wx._animate.pyd
2015-02-24 21:16 - 2015-02-17 23:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libglesv2.dll
2015-02-24 21:16 - 2015-02-17 23:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libegl.dll
2015-03-09 11:31 - 2015-03-09 11:31 - 00077120 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.dll
2015-03-09 11:31 - 2015-03-09 11:31 - 00179560 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll
2015-03-09 11:31 - 2015-03-09 11:31 - 00046920 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.adblocker.dll
2015-03-09 11:31 - 2015-03-09 11:31 - 00033136 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll
2015-03-09 11:31 - 2015-03-09 11:31 - 00015696 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll
2015-03-09 11:32 - 2015-03-09 11:32 - 00123224 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.PUP.Management.dll
2015-03-09 11:32 - 2015-03-09 11:32 - 00073544 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SysInfo.dll
2015-03-09 11:31 - 2015-03-09 11:31 - 00039256 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.CSharp.Utilities.dll
2015-02-24 21:16 - 2015-02-17 23:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll
2015-02-19 19:02 - 2015-02-19 19:02 - 00569856 _____ () C:\Users\Jacobs\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll
2015-02-19 19:02 - 2015-02-19 19:02 - 01400846 _____ () C:\Users\Jacobs\AppData\Local\Pokki\Engine\avcodec-54.dll
2015-02-19 19:02 - 2015-02-19 19:02 - 00151054 _____ () C:\Users\Jacobs\AppData\Local\Pokki\Engine\avutil-51.dll
2015-02-19 19:02 - 2015-02-19 19:02 - 00222734 _____ () C:\Users\Jacobs\AppData\Local\Pokki\Engine\avformat-54.dll
2015-02-24 21:16 - 2015-02-17 23:44 - 14965064 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows:nlsPreferences
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-535057637-212020618-1516021077-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 192.168.1.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-535057637-212020618-1516021077-500 - Administrator - Disabled)
Gast (S-1-5-21-535057637-212020618-1516021077-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-535057637-212020618-1516021077-1003 - Limited - Enabled)
Jacobs (S-1-5-21-535057637-212020618-1516021077-1001 - Administrator - Enabled) => C:\Users\Jacobs
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/13/2015 11:39:24 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Error: (03/13/2015 11:39:24 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Error: (03/11/2015 11:01:10 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Error: (03/11/2015 11:01:09 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Error: (03/11/2015 07:59:58 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (03/10/2015 05:40:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddWin32ServiceFiles: Unable to back up image of service Lenovo Browser Guard Service since QueryServiceConfig API failed
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (03/10/2015 08:46:32 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (03/04/2015 11:14:01 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (03/03/2015 10:57:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Lenovo-PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (03/03/2015 10:57:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.3.9600.17031 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 904
Startzeit: 01d055fcfc405256
Endzeit: 4294967295
Anwendungspfad: C:\WINDOWS\system32\wwahost.exe
Berichts-ID: 446c4a97-c1f0-11e4-8261-7429af7ce308
Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Microsoft.WindowsLive.Mail
System errors:
=============
Error: (03/13/2015 11:35:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "VisualDiscovery" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/12/2015 00:14:12 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "VisualDiscovery" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/12/2015 00:09:39 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Error: (03/12/2015 00:08:44 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB3024755)
Error: (03/12/2015 00:08:41 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB3025417)
Error: (03/12/2015 00:08:18 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB3036562)
Error: (03/12/2015 00:08:18 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB3012702)
Error: (03/12/2015 00:08:14 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Sicherheitsupdate für Windows 8.1 für x64-basierte Systeme (KB3046049)
Error: (03/12/2015 00:07:38 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Sicherheitsupdate für Windows 8.1 für x64-basierte Systeme (KB3034344)
Error: (03/12/2015 00:07:38 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8007045b fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB3012235)
Microsoft Office Sessions:
=========================
Error: (03/13/2015 11:39:24 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Jacobs\AppData\Local\Pokki\Engine\HostAppService.exe
Error: (03/13/2015 11:39:24 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Jacobs\AppData\Local\Pokki\Engine\HostAppService.exe
Error: (03/11/2015 11:01:10 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Jacobs\AppData\Local\Pokki\Engine\HostAppService.exe
Error: (03/11/2015 11:01:09 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Jacobs\AppData\Local\Pokki\Engine\HostAppService.exe
Error: (03/11/2015 07:59:58 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (03/10/2015 05:40:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service Lenovo Browser Guard Service since QueryServiceConfig API failed
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (03/10/2015 08:46:32 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (03/04/2015 11:14:01 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (03/03/2015 10:57:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Lenovo-PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2144927142
Error: (03/03/2015 10:57:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.1703190401d055fcfc4052564294967295C:\WINDOWS\system32\wwahost.exe446c4a97-c1f0-11e4-8261-7429af7ce308microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbweMicrosoft.WindowsLive.Mail
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU N2830 @ 2.16GHz
Percentage of memory in use: 66%
Total physical RAM: 3979.21 MB
Available physical RAM: 1317.51 MB
Total Pagefile: 4683.21 MB
Available Pagefile: 1002.64 MB
Total Virtual: 131072 MB
Available Virtual: 131071.78 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:257.5 GB) (Free:223.13 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.1 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 49E05B9C)
Partition: GPT Partition Type.
==================== End Of Log ============================ GMER.txt Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-13 14:49:19
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000001f ST320LT012-1DG14C rev.0002LVM1 298,09GB
Running: Gmer-19357.exe; Driver: C:\Users\Jacobs\AppData\Local\Temp\fxrirpog.sys
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\dashost.exe[1916] C:\WINDOWS\system32\KERNEL32.DLL!SetFileCompletionNotificationModes 00007ff8f631ba00 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareService.exe[2000] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8f84a169a 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareService.exe[2000] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8f84a16a2 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareService.exe[2000] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8f84a181a 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareService.exe[2000] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8f84a1832 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files\Elantech\ETDCtrl.exe[3916] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\system32\taskhostex.exe[3992] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\Explorer.EXE[3128] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\Explorer.EXE[3128] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8f84a169a 4 bytes [4A, F8, F8, 7F]
.text C:\WINDOWS\Explorer.EXE[3128] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8f84a16a2 4 bytes [4A, F8, F8, 7F]
.text C:\WINDOWS\Explorer.EXE[3128] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8f84a181a 4 bytes [4A, F8, F8, 7F]
.text C:\WINDOWS\Explorer.EXE[3128] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8f84a1832 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe[4520] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\system32\SearchIndexer.exe[5044] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\system32\svchost.exe[1236] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe[1404] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\system32\svchost.exe[3156] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe[4412] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\system32\igfxEM.exe[5212] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\system32\igfxHK.exe[5296] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Windows\System32\WUDFHost.exe[5376] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\WINDOWS\system32\igfxTray.exe[5396] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[5488] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\CONEXANT\ForteConfig\fmapp.exe[5600] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[5736] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Windows\RTFTrack.exe[5864] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\Elantech\ETDIntelligent.exe[5872] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe[5960] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe[5988] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe[6000] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\NetWorx\networx.exe[6092] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\NetWorx\networx.exe[6092] C:\WINDOWS\SYSTEM32\wsock32.dll!setsockopt + 194 00007ff8da021f6a 4 bytes [02, DA, F8, 7F]
.text C:\Program Files\NetWorx\networx.exe[6092] C:\WINDOWS\SYSTEM32\wsock32.dll!setsockopt + 218 00007ff8da021f82 4 bytes [02, DA, F8, 7F]
.text C:\Program Files\NetWorx\networx.exe[6092] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff8f84a169a 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files\NetWorx\networx.exe[6092] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff8f84a16a2 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files\NetWorx\networx.exe[6092] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff8f84a181a 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files\NetWorx\networx.exe[6092] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff8f84a1832 4 bytes [4A, F8, F8, 7F]
.text C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareTray.exe[6112] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Users\Jacobs\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe[4912] C:\WINDOWS\system32\KERNEL32.DLL!SetFileCompletionNotificationModes 00007ff8f631ba00 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Users\Jacobs\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe[4912] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIJJE.EXE[5900] C:\WINDOWS\system32\KERNEL32.DLL!SetFileCompletionNotificationModes 00007ff8f631ba00 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIJJE.EXE[5900] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIJJE.EXE[5888] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[7464] C:\WINDOWS\system32\KERNEL32.DLL!SetFileCompletionNotificationModes 00007ff8f631ba00 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[7464] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[7464] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff8da021f6a 4 bytes [02, DA, F8, 7F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[7464] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff8da021f82 4 bytes [02, DA, F8, 7F]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[7588] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8f5ec68c0 5 bytes JMP 00007ff9e4861270
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [816:840] fffff960009b3b90
Thread C:\WINDOWS\system32\svchost.exe [1012:256] 000000cc90d0f210
Thread C:\WINDOWS\system32\svchost.exe [1012:440] 000000cc90d0f210
Thread C:\WINDOWS\system32\svchost.exe [452:1456] 000000d691aff210
Thread C:\WINDOWS\system32\svchost.exe [452:1460] 000000d691aff210
Thread C:\WINDOWS\System32\svchost.exe [1164:3712] 000000c7615bf210
Thread C:\WINDOWS\System32\svchost.exe [1164:1508] 000000c7615bf210
Thread C:\WINDOWS\System32\spoolsv.exe [1484:1512] 000000000096f210
Thread C:\WINDOWS\System32\spoolsv.exe [1484:1516] 000000000096f210
Thread C:\WINDOWS\system32\svchost.exe [1552:1708] 00000096c231f210
Thread C:\WINDOWS\system32\svchost.exe [1552:1712] 00000096c231f210
Thread C:\WINDOWS\system32\dashost.exe [1916:5160] 0000006a3574f210
Thread C:\WINDOWS\system32\dashost.exe [1916:5164] 0000006a3574f210
Thread C:\WINDOWS\system32\dashost.exe [1916:5172] 0000006a3576ec50
Thread C:\WINDOWS\system32\dashost.exe [1916:5192] 0000006a3576ec50
Thread C:\WINDOWS\system32\svchost.exe [3156:4612] 0000006ebbeaf210
Thread C:\WINDOWS\system32\svchost.exe [3156:4616] 0000006ebbeaf210
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [7464:7520] 00000024f336f210
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [7464:7524] 00000024f336f210
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [7464:7532] 00000024f338ec50
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [7464:7544] 00000024f338ec50
---- Processes - GMER 2.1 ----
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\python27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316] (Python Core/Python Software Foundation)(2015-03-13 13:41:42) 000000001e000000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32api.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001e8c0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\pywintypes27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001e7a0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\pythoncom27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000000310000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\_socket.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 00000000002c0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\_ssl.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000010000000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32com.shell.shell.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001e800000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\_hashlib.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 00000000031c0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wx._core_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000003e90000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wxbase294u_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316] (wxWidgets for MSW/wxWidgets development team)(2015-03-13 13:41:42) 0000000003fc0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wxbase294u_net_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316] (wxWidgets for MSW/wxWidgets development team)(2015-03-13 13:41:43) 0000000000380000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wxmsw294u_core_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316] (wxWidgets for MSW/wxWidgets development team)(2015-03-13 13:41:43) 00000000041b0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wxmsw294u_adv_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316] (wxWidgets for MSW/wxWidgets development team)(2015-03-13 13:41:43) 0000000004650000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wx._gdi_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000004790000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wx._windows_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000005060000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wxmsw294u_html_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316] (wxWidgets for MSW/wxWidgets development team)(2015-03-13 13:41:43) 0000000005130000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wx._controls_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 00000000053f0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wx._misc_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:41) 0000000005500000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\pysqlite2._sqlite.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 00000000051d0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\_elementtree.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001d100000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\pyexpat.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 00000000055c0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\_ctypes.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001d1a0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32file.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001ea10000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32security.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001ec80000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\hashobjs_ext.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 00000000008f0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32gui.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001ea40000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32event.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001e9b0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32inet.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001eaa0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32crypt.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:41) 000000001e980000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wx._html2.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 00000000065c0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wxmsw294u_webview_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316] (wxWidgets for MSW/wxWidgets development team)(2015-03-13 13:41:43) 00000000065f0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\_multiprocessing.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000006610000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32process.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:40) 000000001ebf0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\unicodedata.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000006620000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wx._wizard.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:41) 00000000066d0000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32pipe.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001eb90000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32pdh.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001eb60000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\select.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000006730000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32profile.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001ec20000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\win32ts.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 000000001ed40000
Library C:\Users\Jacobs\AppData\Local\Temp\_MEI56362\wx._animate.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [6316](2015-03-13 13:41:42) 0000000006740000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |