Ich hoffe ich habe alles
AdwCleaner Logfile: Code:
# AdwCleaner v3.212 - Bericht erstellt am 19/06/2014 um 13:01:22
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : ww - WW-PC
# Gestartet von : C:\Users\ww\Desktop\adwcleaner_3.212.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\user.js
Ordner Gefunden : C:\Users\ww\AppData\Local\Temp\OCS
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\APN PIP
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\MYSEAR~1_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\MYSEAR~1_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\MySearchDial_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\MySearchDial_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Schlüssel Gefunden : HKLM\Software\PIP
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\prefs.js ]
Zeile gefunden : user_pref("extensions.fvd_single.surfcanyon.ramp.start_time", "1394046262739");
Zeile gefunden : user_pref("extensions.irmysearch.aflt", "irmsd0103aw");
Zeile gefunden : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtCzyyCyC0Azy0F0A0FyEyEtBzzyCtN0D0Tzu0SyByBtAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
Zeile gefunden : user_pref("extensions.irmysearch.cr", "1014372858");
Zeile gefunden : user_pref("extensions.irmysearch.instlRef", "");
Zeile gefunden : user_pref("keyword.URL", "hxxp://www.sm.de/?q=");
*************************
AdwCleaner[R0].txt - [2182 octets] - [19/06/2014 13:01:22]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2242 octets] ########## --- --- ---
AdwCleaner Logfile: Code:
# AdwCleaner v3.212 - Bericht erstellt am 19/06/2014 um 13:02:24
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : ww - WW-PC
# Gestartet von : C:\Users\ww\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\ww\AppData\Local\Temp\OCS
Datei Gelöscht : C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MYSEAR~1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MYSEAR~1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MySearchDial_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MySearchDial_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\Software\PIP
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.fvd_single.surfcanyon.ramp.start_time", "1394046262739");
Zeile gelöscht : user_pref("extensions.irmysearch.aflt", "irmsd0103aw");
Zeile gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtCzyyCyC0Azy0F0A0FyEyEtBzzyCtN0D0Tzu0SyByBtAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
Zeile gelöscht : user_pref("extensions.irmysearch.cr", "1014372858");
Zeile gelöscht : user_pref("extensions.irmysearch.instlRef", "");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://www.sm.de/?q=");
*************************
AdwCleaner[R0].txt - [2322 octets] - [19/06/2014 13:01:22]
AdwCleaner[S0].txt - [2247 octets] - [19/06/2014 13:02:24]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2307 octets] ########## --- --- ---
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by ww on 19.06.2014 at 13:09:14,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\ww\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\taskbar\startfenster.lnk"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Emptied folder: C:\Users\ww\AppData\Roaming\mozilla\firefox\profiles\mek5vdek.default\minidumps [114 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.06.2014 at 13:34:24,62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- --- Code:
Zoek.exe v5.0.0.0 Updated 16-June-2014
Tool run by ww on 19.06.2014 at 13:42:09,80.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\ww\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
19.06.2014 13:44:24 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.de");
user_pref("browser.search.defaultenginename", "Bing");
user_pref("browser.search.selectedEngine", "Bing");
user_pref("browser.search.order.1", "SuchMaschine");
Added to C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1415_.backup
==== Deleting Files \ Folders ======================
C:\Users\ww\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk deleted
C:\Users\ww\AppData\Roaming\temp.ini deleted
C:\PROGRA~2\ProductData deleted
C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\searchplugins\search_engine.xml deleted
"C:\Users\ww\AppData\Roaming\deskjet" deleted
"C:\Users\ww\AppData\Roaming\docInfo" deleted
"C:\Users\ww\AppData\Roaming\filter" deleted
"C:\ProgramData\Ambient" deleted
"C:\ProgramData\Analog Pad" deleted
"C:\ProgramData\Analog Sync" deleted
"C:\ProgramData\howto" deleted
"C:\ProgramData\images" deleted
"C:\ProgramData\laserjet" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"online_banking@kaspersky.com"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com" [19.05.2014 10:30]
==== Firefox Extensions ======================
ProfilePath: C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default
- Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
- Flash Video Downloader - Full HD Download - %ProfilePath%\extensions\artur.dubovoy@gmail.com
- Google Docs Viewer - %ProfilePath%\extensions\adonis.cuhk@gmail.com.xpi
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default
FB5621842FDABF9F8359775573498FBC - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
A58DE0A570148AF5FF3512B2A340D09F - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll - Shockwave Flash
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
CEBC703D0423C181A2BA4AEB06AA874A - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll - PDF-XChange Viewer
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
dchlnpcodkpfdpacogkljefecpegganj - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx[25.10.2012 13:44]
hakdifolhalapjijoafobooafbilfakh - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx[25.10.2012 13:44]
hghkgaeecgjhjkannahfamoehjmkjail - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx[25.10.2012 13:44]
jagncdcchgajhfhijbbhecadmaiegcmh - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx[12.02.2014 00:30]
lpoimibckejjdjcfbdnajaicnklhfplh - https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh[]
pjldcfjmnllhmgjclecdnfampinooman - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx[25.10.2012 13:44]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.de/"
"Default_Page_URL"="hxxp://www.dell.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://www.google.de/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{9F3821CB-6478-43B1-AF44-D6BE0C418911} SuchMaschine Url="hxxp://www.sm.de/?q={searchTerms}"
==== Reset Google Chrome ======================
Nothing found to reset
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyEnable"=dword:00000000
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\lpoimibckejjdjcfbdnajaicnklhfplh deleted successfully
==== Empty IE Cache ======================
C:\Users\ww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\ww\AppData\Local\Mozilla\Firefox\Profiles\mek5vdek.default\Cache emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache is not empty, a reboot is needed
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=5 folders=1 67581 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\ww\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\ww\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\ww\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YZRRTUCN\play.snacktv.de" not found
==== EOF on 19.06.2014 at 14:37:26,96 ======================
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:18-06-2014
Ran by ww (administrator) on WW-PC on 19-06-2014 14:44:28
Running from C:\Users\ww\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
() C:\Users\ww\AppData\Local\Temp\updatepackasc.exe
(Opera Software) C:\Program Files\Opera\opera.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AVP] => C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2014-02-12] (Kaspersky Lab ZAO)
HKLM\...\Run: [emsisoft anti-malware] => c:\program files\emsisoft anti-malware\a2guard.exe [4833048 2014-06-18] (Emsisoft GmbH)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {9F3821CB-6478-43B1-AF44-D6BE0C418911} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {9F3821CB-6478-43B1-AF44-D6BE0C418911} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Flash Video Downloader - Full HD Download - C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\Extensions\artur.dubovoy@gmail.com [2014-05-09]
FF Extension: Google Docs Viewer - C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\Extensions\adonis.cuhk@gmail.com.xpi [2014-02-13]
FF Extension: NoScript - C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-02-12]
FF Extension: Adblock Plus - C:\Users\ww\AppData\Roaming\Mozilla\Firefox\Profiles\mek5vdek.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-06]
FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2014-02-12]
FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2014-02-12]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2014-02-12]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2014-02-12]
FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2014-02-12]
FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2014-02-12]
========================== Services (Whitelisted) =================
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4716152 2014-06-18] (Emsisoft GmbH)
R2 AdobeActiveFileMonitor7.0; C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated)
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2014-02-12] (Kaspersky Lab ZAO)
S4 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION)
S4 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION)
S4 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2014-02-28] (Macrovision Europe Ltd.) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2175264 2014-05-24] (IObit)
==================== Drivers (Whitelisted) ====================
R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [58200 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [18552 2014-05-12] (Emsisoft GmbH)
R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-12-04] (Emsisoft GmbH)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-02-12] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [597600 2014-05-19] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2014-02-12] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25696 2014-02-12] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2014-02-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [44000 2014-02-12] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [145040 2014-02-12] (Kaspersky Lab ZAO)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2012-02-15] (Samsung Electronics) [File not signed]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2014-05-19] (Kaspersky Lab ZAO)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-19 14:38 - 2014-06-19 14:38 - 00000024 _____ () C:\Users\ww\AppData\Roaming\temp.ini
2014-06-19 14:31 - 2014-06-19 13:41 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-19 13:44 - 2014-06-19 14:37 - 00008949 _____ () C:\zoek-results.log
2014-06-19 13:41 - 2014-06-19 14:16 - 00000000 ____D () C:\zoek_backup
2014-06-19 13:37 - 2014-06-19 13:37 - 01285120 _____ () C:\Users\ww\Desktop\zoek.exe
2014-06-19 13:34 - 2014-06-19 13:34 - 00000962 _____ () C:\Users\ww\Desktop\JRT.txt
2014-06-19 13:09 - 2014-06-19 13:09 - 00000000 ____D () C:\Windows\ERUNT
2014-06-19 13:06 - 2014-06-19 13:06 - 01016261 _____ (Thisisu) C:\Users\ww\Desktop\JRT.exe
2014-06-19 13:01 - 2014-06-19 13:02 - 00000000 ____D () C:\AdwCleaner
2014-06-19 13:00 - 2014-06-19 13:00 - 01333465 _____ () C:\Users\ww\Desktop\adwcleaner_3.212.exe
2014-06-19 11:58 - 2014-06-19 11:59 - 00021436 _____ () C:\Users\ww\Desktop\Addition.txt
2014-06-19 11:57 - 2014-06-19 14:45 - 00010692 _____ () C:\Users\ww\Desktop\FRST.txt
2014-06-19 11:57 - 2014-06-19 14:44 - 00000000 ____D () C:\FRST
2014-06-19 11:56 - 2014-06-19 11:56 - 01072128 _____ (Farbar) C:\Users\ww\Desktop\FRST.exe
2014-06-19 08:14 - 2014-06-19 08:14 - 00001222 _____ () C:\Users\ww\Desktop\Revo Uninstaller.lnk
2014-06-19 08:14 - 2014-06-19 08:14 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-06-19 08:12 - 2014-06-19 08:12 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\ww\Downloads\revosetup95.exe
2014-06-19 07:06 - 2014-06-19 07:06 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-06-18 15:47 - 2014-06-18 15:47 - 00000000 ____D () C:\Users\Public\Documents\sun
2014-06-18 15:43 - 2014-06-18 15:43 - 00001426 _____ () C:\Users\Public\Desktop\LibreOffice 4.2.lnk
2014-06-18 15:43 - 2014-06-18 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-06-18 15:42 - 2014-06-18 15:43 - 00000000 ____D () C:\Program Files\LibreOffice 4
2014-06-18 15:18 - 2014-06-18 15:34 - 219451392 _____ () C:\Users\ww\Downloads\libreoffice_4.2.4_win_x86.msi
2014-06-17 21:32 - 2014-06-17 21:50 - 256314176 _____ () C:\Users\ww\Downloads\kis14.0.0.4651abDE_5155.exe
2014-06-17 19:12 - 2014-06-17 19:12 - 03673664 _____ (Piriform Ltd) C:\Users\ww\Downloads\ccsetup414_slim.exe
2014-06-17 19:07 - 2014-06-17 19:07 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-17 18:33 - 2014-06-17 18:33 - 00000000 ____D () C:\Users\ww\Downloads\win81-1-msu
2014-06-17 17:36 - 2014-06-17 18:31 - 807793968 _____ () C:\Users\ww\Downloads\win81-1-msu.zip
2014-06-13 12:45 - 2014-06-13 12:45 - 00000000 ____D () C:\Users\ww\Downloads\WHOIS
2014-06-13 07:24 - 2014-06-13 07:25 - 16895204 _____ () C:\Users\ww\Downloads\q-katalog-rgb.7z
2014-06-12 13:17 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 13:16 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 13:16 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 13:16 - 2014-05-30 11:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 13:16 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-12 13:16 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 13:16 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-12 13:16 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 13:16 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 13:16 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 13:16 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 13:16 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-12 13:16 - 2014-05-30 10:28 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-12 13:16 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-12 13:16 - 2014-05-30 10:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 13:16 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 13:16 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 13:16 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 13:16 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 13:16 - 2014-05-30 09:57 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 13:16 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 13:16 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 13:16 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-12 13:16 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 13:16 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 13:16 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 13:16 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 13:16 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-12 13:14 - 2014-06-08 10:48 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 13:14 - 2014-06-08 10:43 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-12 13:14 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 13:14 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 13:14 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 13:14 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 13:14 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 13:14 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 13:14 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 07:01 - 2014-06-12 07:01 - 01058200 _____ (Adobe) C:\Users\ww\Downloads\install_flashplayer14x32au_mssd_aaa_aih.exe
2014-06-08 17:18 - 2014-06-08 17:18 - 00000000 ____D () C:\Users\ww\Downloads\beta-contentlion
2014-06-08 16:55 - 2014-06-08 16:55 - 02233353 _____ () C:\Users\ww\Downloads\beta-contentlion.zip
2014-06-07 09:09 - 2014-06-07 09:09 - 04996210 _____ (Tim Kosse) C:\Users\ww\Downloads\FileZilla_3.8.1_win32-setup.exe
2014-06-03 18:21 - 2014-06-03 20:33 - 00000000 ____D () C:\Users\ww\Downloads\mybb_1613_de
2014-06-03 18:19 - 2014-06-03 18:19 - 02501214 _____ () C:\Users\ww\Downloads\mybb_1613_de.zip
2014-05-31 19:48 - 2014-05-31 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2014-05-31 19:44 - 2014-05-31 19:48 - 00000000 ____D () C:\ProgramData\EPSON
2014-05-31 19:44 - 2008-08-08 02:09 - 00086528 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_FLBFAE.DLL
2014-05-31 19:44 - 2007-12-07 02:01 - 00078848 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_FD4BFAE.DLL
2014-05-31 19:44 - 2007-04-10 01:06 - 00008192 _____ (SEIKO EPSON CORP.) C:\Windows\system32\E_DCINST.DLL
2014-05-31 19:41 - 2014-05-31 19:42 - 15784960 _____ () C:\Users\ww\Downloads\epson375166eu.exe
2014-05-24 06:55 - 2014-05-24 06:55 - 00000000 ____D () C:\Users\ww\AppData\Roaming\ProductData
2014-05-24 06:53 - 2014-05-24 06:54 - 00000000 ____D () C:\ProgramData\IObit
2014-05-24 06:53 - 2014-05-24 06:53 - 00001210 _____ () C:\Users\ww\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-05-24 06:53 - 2014-05-24 06:53 - 00001186 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-05-24 06:53 - 2014-05-24 06:53 - 00000000 ____D () C:\Users\ww\AppData\Roaming\IObit
2014-05-24 06:53 - 2014-05-24 06:53 - 00000000 ____D () C:\Program Files\IObit
2014-05-24 06:51 - 2014-05-24 06:52 - 12906784 _____ (IObit) C:\Users\ww\Downloads\iobituninstaller_3.3.8.exe
2014-05-24 06:43 - 2014-05-24 06:43 - 02953520 _____ (AVAST Software) C:\Users\ww\Downloads\avast-browser-cleanup.exe
2014-05-23 16:31 - 2014-06-19 07:07 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-23 16:30 - 2014-05-23 16:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-23 16:30 - 2014-05-23 16:30 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-05-23 16:30 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-23 16:30 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-23 16:27 - 2014-05-23 16:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\ww\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-23 14:02 - 2014-05-23 14:02 - 03296476 _____ (Jens Duttke ) C:\Users\ww\Downloads\PhotoME08Beta2Setup.exe
2014-05-22 12:30 - 2014-05-22 12:30 - 00001049 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2014-05-22 12:30 - 2014-05-22 12:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2014-05-22 12:29 - 2014-06-19 14:37 - 00000000 ____D () C:\Program Files\Emsisoft Anti-Malware
2014-05-22 12:29 - 2014-05-22 12:29 - 00000000 ____D () C:\Users\ww\Documents\Anti-Malware
2014-05-22 12:11 - 2014-05-22 12:28 - 231483040 _____ (Emsisoft GmbH ) C:\Users\ww\Downloads\EmsisoftAntiMalwareSetup.exe
2014-05-20 12:15 - 2014-05-20 12:15 - 00000000 ____D () C:\Users\ww\Downloads\S-VNX2__-020902WF-EURDE-32BIT_
2014-05-20 12:07 - 2014-05-20 12:14 - 99271856 _____ () C:\Users\ww\Downloads\S-VNX2__-020902WF-EURDE-32BIT_.exe
==================== One Month Modified Files and Folders =======
2014-06-19 14:45 - 2014-06-19 11:57 - 00010692 _____ () C:\Users\ww\Desktop\FRST.txt
2014-06-19 14:44 - 2014-06-19 11:57 - 00000000 ____D () C:\FRST
2014-06-19 14:44 - 2009-07-14 06:34 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-19 14:44 - 2009-07-14 06:34 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-19 14:41 - 2010-11-20 23:01 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-19 14:40 - 2014-02-11 23:53 - 01526162 _____ () C:\Windows\WindowsUpdate.log
2014-06-19 14:38 - 2014-06-19 14:38 - 00000024 _____ () C:\Users\ww\AppData\Roaming\temp.ini
2014-06-19 14:38 - 2014-02-12 00:10 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-19 14:37 - 2014-06-19 13:44 - 00008949 _____ () C:\zoek-results.log
2014-06-19 14:37 - 2014-05-22 12:29 - 00000000 ____D () C:\Program Files\Emsisoft Anti-Malware
2014-06-19 14:37 - 2014-04-25 17:04 - 00001086 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-19 14:37 - 2010-11-20 23:48 - 00060258 _____ () C:\Windows\PFRO.log
2014-06-19 14:37 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-19 14:37 - 2009-07-14 06:39 - 00041535 _____ () C:\Windows\setupact.log
2014-06-19 14:22 - 2014-04-25 17:04 - 00001090 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-19 14:21 - 2014-02-22 08:45 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-19 14:16 - 2014-06-19 13:41 - 00000000 ____D () C:\zoek_backup
2014-06-19 13:41 - 2014-06-19 14:31 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-19 13:37 - 2014-06-19 13:37 - 01285120 _____ () C:\Users\ww\Desktop\zoek.exe
2014-06-19 13:35 - 2014-02-12 01:43 - 00000000 ____D () C:\Users\ww\AppData\Roaming\FileZilla
2014-06-19 13:34 - 2014-06-19 13:34 - 00000962 _____ () C:\Users\ww\Desktop\JRT.txt
2014-06-19 13:09 - 2014-06-19 13:09 - 00000000 ____D () C:\Windows\ERUNT
2014-06-19 13:06 - 2014-06-19 13:06 - 01016261 _____ (Thisisu) C:\Users\ww\Desktop\JRT.exe
2014-06-19 13:02 - 2014-06-19 13:01 - 00000000 ____D () C:\AdwCleaner
2014-06-19 13:00 - 2014-06-19 13:00 - 01333465 _____ () C:\Users\ww\Desktop\adwcleaner_3.212.exe
2014-06-19 11:59 - 2014-06-19 11:58 - 00021436 _____ () C:\Users\ww\Desktop\Addition.txt
2014-06-19 11:56 - 2014-06-19 11:56 - 01072128 _____ (Farbar) C:\Users\ww\Desktop\FRST.exe
2014-06-19 11:13 - 2014-02-12 00:37 - 00000000 ____D () C:\Users\ww\AppData\Roaming\The Bat!
2014-06-19 08:14 - 2014-06-19 08:14 - 00001222 _____ () C:\Users\ww\Desktop\Revo Uninstaller.lnk
2014-06-19 08:14 - 2014-06-19 08:14 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-06-19 08:12 - 2014-06-19 08:12 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\ww\Downloads\revosetup95.exe
2014-06-19 07:13 - 2014-02-12 00:09 - 00066664 _____ () C:\Users\ww\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-19 07:07 - 2014-05-23 16:31 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-19 07:06 - 2014-06-19 07:06 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-06-18 22:32 - 2009-07-14 06:33 - 00303160 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-18 15:47 - 2014-06-18 15:47 - 00000000 ____D () C:\Users\Public\Documents\sun
2014-06-18 15:43 - 2014-06-18 15:43 - 00001426 _____ () C:\Users\Public\Desktop\LibreOffice 4.2.lnk
2014-06-18 15:43 - 2014-06-18 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.2
2014-06-18 15:43 - 2014-06-18 15:42 - 00000000 ____D () C:\Program Files\LibreOffice 4
2014-06-18 15:34 - 2014-06-18 15:18 - 219451392 _____ () C:\Users\ww\Downloads\libreoffice_4.2.4_win_x86.msi
2014-06-18 06:57 - 2014-02-12 01:15 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-06-17 21:50 - 2014-06-17 21:32 - 256314176 _____ () C:\Users\ww\Downloads\kis14.0.0.4651abDE_5155.exe
2014-06-17 19:12 - 2014-06-17 19:12 - 03673664 _____ (Piriform Ltd) C:\Users\ww\Downloads\ccsetup414_slim.exe
2014-06-17 19:07 - 2014-06-17 19:07 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-17 18:33 - 2014-06-17 18:33 - 00000000 ____D () C:\Users\ww\Downloads\win81-1-msu
2014-06-17 18:31 - 2014-06-17 17:36 - 807793968 _____ () C:\Users\ww\Downloads\win81-1-msu.zip
2014-06-15 16:26 - 2014-03-05 14:37 - 00000000 ____D () C:\Users\ww\Downloads\Archiv
2014-06-13 12:45 - 2014-06-13 12:45 - 00000000 ____D () C:\Users\ww\Downloads\WHOIS
2014-06-13 08:17 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-06-13 07:25 - 2014-06-13 07:24 - 16895204 _____ () C:\Users\ww\Downloads\q-katalog-rgb.7z
2014-06-12 20:06 - 2014-05-06 20:31 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-12 20:03 - 2014-02-14 21:12 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 20:00 - 2014-02-14 21:12 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 07:01 - 2014-06-12 07:01 - 01058200 _____ (Adobe) C:\Users\ww\Downloads\install_flashplayer14x32au_mssd_aaa_aih.exe
2014-06-09 07:13 - 2014-02-12 02:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2014-06-09 07:13 - 2014-02-12 02:12 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2014-06-08 17:18 - 2014-06-08 17:18 - 00000000 ____D () C:\Users\ww\Downloads\beta-contentlion
2014-06-08 16:55 - 2014-06-08 16:55 - 02233353 _____ () C:\Users\ww\Downloads\beta-contentlion.zip
2014-06-08 10:48 - 2014-06-12 13:14 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 10:43 - 2014-06-12 13:14 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-07 09:09 - 2014-06-07 09:09 - 04996210 _____ (Tim Kosse) C:\Users\ww\Downloads\FileZilla_3.8.1_win32-setup.exe
2014-06-03 20:33 - 2014-06-03 18:21 - 00000000 ____D () C:\Users\ww\Downloads\mybb_1613_de
2014-06-03 18:19 - 2014-06-03 18:19 - 02501214 _____ () C:\Users\ww\Downloads\mybb_1613_de.zip
2014-05-31 19:48 - 2014-05-31 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2014-05-31 19:48 - 2014-05-31 19:44 - 00000000 ____D () C:\ProgramData\EPSON
2014-05-31 19:42 - 2014-05-31 19:41 - 15784960 _____ () C:\Users\ww\Downloads\epson375166eu.exe
2014-05-30 20:49 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-05-30 11:18 - 2014-06-12 13:16 - 17271296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 11:02 - 2014-06-12 13:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 11:02 - 2014-06-12 13:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 10:44 - 2014-06-12 13:16 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 10:43 - 2014-06-12 13:16 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 10:42 - 2014-06-12 13:16 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 13:16 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 10:34 - 2014-06-12 13:16 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 13:16 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 10:30 - 2014-06-12 13:16 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 10:28 - 2014-06-12 13:16 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 10:28 - 2014-06-12 13:16 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 10:27 - 2014-06-12 13:16 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 10:21 - 2014-06-12 13:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 10:16 - 2014-06-12 13:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 13:17 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 13:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:04 - 2014-06-12 13:16 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 13:16 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 09:57 - 2014-06-12 13:16 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 09:56 - 2014-06-12 13:16 - 04244992 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 09:54 - 2014-06-12 13:16 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 13:16 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 13:16 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 09:40 - 2014-06-12 13:16 - 11725312 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:21 - 2014-06-12 13:16 - 01790976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:15 - 2014-06-12 13:16 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:13 - 2014-06-12 13:16 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 06:50 - 2014-02-18 19:07 - 00000020 ____H () C:\ProgramData\PKP_DLet.DAT
2014-05-24 06:55 - 2014-05-24 06:55 - 00000000 ____D () C:\Users\ww\AppData\Roaming\ProductData
2014-05-24 06:54 - 2014-05-24 06:53 - 00000000 ____D () C:\ProgramData\IObit
2014-05-24 06:53 - 2014-05-24 06:53 - 00001210 _____ () C:\Users\ww\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-05-24 06:53 - 2014-05-24 06:53 - 00001186 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-05-24 06:53 - 2014-05-24 06:53 - 00000000 ____D () C:\Users\ww\AppData\Roaming\IObit
2014-05-24 06:53 - 2014-05-24 06:53 - 00000000 ____D () C:\Program Files\IObit
2014-05-24 06:52 - 2014-05-24 06:51 - 12906784 _____ (IObit) C:\Users\ww\Downloads\iobituninstaller_3.3.8.exe
2014-05-24 06:43 - 2014-05-24 06:43 - 02953520 _____ (AVAST Software) C:\Users\ww\Downloads\avast-browser-cleanup.exe
2014-05-23 16:30 - 2014-05-23 16:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-23 16:30 - 2014-05-23 16:30 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-05-23 16:30 - 2014-02-14 20:27 - 00000000 ____D () C:\Users\ww\AppData\Roaming\Malwarebytes
2014-05-23 16:30 - 2014-02-14 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-23 16:28 - 2014-05-23 16:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\ww\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-23 14:02 - 2014-05-23 14:02 - 03296476 _____ (Jens Duttke ) C:\Users\ww\Downloads\PhotoME08Beta2Setup.exe
2014-05-22 12:30 - 2014-05-22 12:30 - 00001049 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2014-05-22 12:30 - 2014-05-22 12:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2014-05-22 12:29 - 2014-05-22 12:29 - 00000000 ____D () C:\Users\ww\Documents\Anti-Malware
2014-05-22 12:28 - 2014-05-22 12:11 - 231483040 _____ (Emsisoft GmbH ) C:\Users\ww\Downloads\EmsisoftAntiMalwareSetup.exe
2014-05-20 12:17 - 2014-03-31 14:46 - 00002049 _____ () C:\Users\Public\Desktop\ViewNX 2.lnk
2014-05-20 12:17 - 2014-03-31 14:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ViewNX 2
2014-05-20 12:17 - 2014-02-12 02:47 - 00000000 ____D () C:\Users\ww\AppData\Local\Downloaded Installations
2014-05-20 12:16 - 2014-02-18 19:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Link to Nikon
2014-05-20 12:15 - 2014-05-20 12:15 - 00000000 ____D () C:\Users\ww\Downloads\S-VNX2__-020902WF-EURDE-32BIT_
2014-05-20 12:14 - 2014-05-20 12:07 - 99271856 _____ () C:\Users\ww\Downloads\S-VNX2__-020902WF-EURDE-32BIT_.exe
2014-05-20 08:45 - 2014-03-14 10:31 - 00000000 ____D () C:\Users\ww\Documents\Erbe
Files to move or delete:
====================
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
Some content of TEMP:
====================
C:\Users\ww\AppData\Local\Temp\updatepackasc.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-18 09:57
==================== End Of Log ============================ --- --- ---
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:18-06-2014
Ran by ww at 2014-06-19 14:45:36
Running from C:\Users\ww\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
==================== Installed Programs ======================
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Photoshop Elements 7.0 (HKLM\...\Adobe Photoshop Elements 7) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Photoshop Elements 7.0 (Version: 7.0 - Adobe Systems Incorporated) Hidden
Aurelie 2.0 (HKLM\...\Aurelie) (Version: 2.0 - )
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
Common Desktop Agent (Version: 1.62.0 - OEM) Hidden
Druckerdeinstallation für EPSON S21 Series (HKLM\...\EPSON S21 Series) (Version: - SEIKO EPSON Corporation)
Emsisoft Anti-Malware (HKLM\...\{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1) (Version: 8.1 - Emsisoft GmbH)
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - )
Exif-Viewer 2.51 (HKLM\...\Exif-Viewer) (Version: 2.51 - Ralf Bibinger)
FastStone Image Viewer 4.9 (HKLM\...\FastStone Image Viewer) (Version: 4.9 - FastStone Soft)
FileZilla Client 3.8.1 (HKLM\...\FileZilla Client) (Version: 3.8.1 - Tim Kosse)
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
Greenshot 1.1.7.17 (HKLM\...\Greenshot_is1) (Version: 1.1.7.17 - Greenshot)
IObit Uninstaller (HKLM\...\IObitUninstall) (Version: 3.3.8.2663 - IObit)
jAlbum (HKLM\...\{E87F1FFB-A689-4AB4-B79C-4FC4AAF4A1FD}) (Version: 11.6.14 - Jalbum AB)
Kaspersky Internet Security 2013 (HKLM\...\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab)
Kaspersky Internet Security 2013 (Version: 13.0.1.4190 - Kaspersky Lab) Hidden
LibreOffice 4.2.4.2 (HKLM\...\{6B4977CB-5B9F-4B24-8310-3BA527A8AF22}) (Version: 4.2.4.2 - The Document Foundation)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Excel Viewer (HKLM\...\{95120000-003F-0407-0000-0000000FF1CE}) (Version: 12.0.6334.5000 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM\...\{90850407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 30.0 (x86 de) (HKLM\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nikon Message Center 2 (HKLM\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
Nikon Movie Editor (HKLM\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.9.2 - Nikon)
Opera 12.16 (HKLM\...\Opera 12.16.1860) (Version: 12.16.1860 - Opera Software ASA)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.2 - pdfforge)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.214.0 - Tracker Software Products Ltd)
PhotoME (HKLM\...\PhotoME_is1) (Version: 0.79R17 - Jens Duttke)
Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.5.1 - Nikon)
RAW PhotoStudio (HKLM\...\{DB110ACC-2210-42DB-8A3B-AFE08A58E46D}) (Version: 1.5.2.44 - ArcSoft)
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Samsung Easy Document Creator (HKLM\...\Samsung Easy Document Creator) (Version: 1.04.06 (07.08.2012) - Samsung Electronics Co., Ltd.)
Samsung Easy Printer Manager (HKLM\...\Samsung Easy Printer Manager) (Version: 1.02.63.01(09.08.2012) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Samsung Scan Process Machine (Version: 1.00.20.02 - Samsung Electronics Co., Ltd.) Hidden
SNS Upload for Easy Document Creator (HKLM\...\{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}) (Version: 1.0.0 - Samsung Electronics Co.,Ltd)
Some PDF to Txt Converter 2.0 (HKLM\...\Some PDF to Txt Converter_is1) (Version: - SomePDF.com)
The Bat! Professional v3.99.3 (HKLM\...\{40BF1520-BAB7-4B38-A2FB-C474A888FACA}) (Version: 3.99.3 - Ritlabs)
ViewNX 2 (HKLM\...\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.9.2 - Nikon)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
==================== Restore Points =========================
18-06-2014 13:38:47 Installed LibreOffice 4.2.4.2
19-06-2014 11:44:09 zoek.exe restore point
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {15944856-7528-4ED8-AE87-78523C487594} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-05-24] (IObit)
Task: {2C7CB202-6D23-486D-BFAF-13B9F1F55E11} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {63BEE3D2-9F80-413A-831D-93E4259F484E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-25] (Google Inc.)
Task: {7BA3FFA4-1941-4452-89DB-3C096BCB6ACE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-25] (Google Inc.)
Task: {A142860A-B01C-4110-A8B4-20B765943CB0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {A70382D0-C44E-491B-9D06-AF9422024DD0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-06-18 15:04 - 2014-06-18 15:04 - 00703800 _____ () C:\Program Files\Emsisoft Anti-Malware\fw32.dll
2013-07-26 11:42 - 2013-07-26 11:42 - 00024064 _____ () C:\Windows\System32\ssa3mlm.dll
2013-06-21 14:32 - 2013-06-21 14:32 - 00024064 _____ () C:\Windows\System32\sst6clm.dll
2012-08-17 22:39 - 2014-02-12 00:29 - 01310136 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll
2012-08-17 22:38 - 2012-08-17 22:38 - 00479160 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
2014-06-19 14:38 - 2014-06-19 14:38 - 00618024 _____ () C:\Users\ww\AppData\Local\Temp\updatepackasc.exe
2014-05-14 07:22 - 2014-05-14 07:22 - 16361136 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
MSCONFIG\Services: EPSON_EB_RPCV4_01 => 2
MSCONFIG\Services: EPSON_PM_RPCV4_01 => 2
MSCONFIG\Services: FLEXnet Licensing Service => 3
MSCONFIG\startupreg: CDAServer => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
MSCONFIG\startupreg: EPSON S21 Series => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIFAE.EXE /FU "C:\Windows\TEMP\E_S2D66.tmp" /EF "HKCU"
MSCONFIG\startupreg: Nikon Message Center 2 => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe -s
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/19/2014 02:38:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (06/19/2014 02:37:09 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active
Error: (06/19/2014 02:37:09 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (06/19/2014 02:37:06 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "H:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.
Error: (06/19/2014 02:37:05 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.
Error: (06/19/2014 02:15:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (06/19/2014 02:15:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (06/19/2014 02:15:32 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (06/19/2014 02:15:31 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (06/19/2014 02:15:23 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Microsoft Office Sessions:
=========================
Error: (06/19/2014 02:38:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
===================================
Date: 2014-06-18 10:01:45.625
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.625
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.625
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.609
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.609
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.609
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.593
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.593
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.593
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-18 10:01:45.578
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 49%
Total physical RAM: 2047.3 MB
Available physical RAM: 1037.39 MB
Total Pagefile: 4094.61 MB
Available Pagefile: 2291.51 MB
Total Virtual: 2047.88 MB
Available Virtual: 1913.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:75.38 GB) (Free:46.55 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Daten) (Fixed) (Total:157.45 GB) (Free:124.69 GB) NTFS
Drive e: (Backup) (Fixed) (Total:137.83 GB) (Free:35.41 GB) NTFS
Drive f: (Altdaten-Archive) (Fixed) (Total:15.09 GB) (Free:14.49 GB) NTFS
Drive g: (Fotos) (Fixed) (Total:312.83 GB) (Free:124.22 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 67FC5915)
Partition 1: (Active) - (Size=75 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=157 GB) - (Type=05)
========================================================
Disk: 1 (Size: 466 GB) (Disk ID: 00000001)
Partition 2: (Active) - (Size=466 GB) - (Type=05)
==================== End Of Log ============================ --- --- ---
Ich weiss nicht ob es wichtig ist, aber nach dem Neustart des Computers am Ende des zoek-Scans tauchte dieses Bild unten rechts wieder auf.
Gruß Werner |