Ok hier die textdateien Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.12.2014
Suchlauf-Zeit: 19:33:38
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.11.20.06
Rootkit Datenbank: v2014.12.08.03
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Lisa
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 315350
Verstrichene Zeit: 29 Min, 1 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
PUP.Optional.MaintainerSvc.A, C:\ProgramData\ecbaef90-5696-41e1-a1c3-3e8112ce2840\maintainer.exe, 1704, Löschen bei Neustart, [bb4b4cf289f357df8a6017c9bd4456aa]
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe, 1344, Löschen bei Neustart, [17efdf5f027a191dbb6e5b71719055ab]
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.exe, 5400, Löschen bei Neustart, [61a52d11ea92c86edd4c666650b12dd3]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 45
PUP.Optional.MaintainerSvc.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MaintainerSvc1.92.5302915, In Quarantäne, [bb4b4cf289f357df8a6017c9bd4456aa],
PUP.Optional.FramedDisplay.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Framed Display, In Quarantäne, [17efdf5f027a191dbb6e5b71719055ab],
PUP.Optional.FramedDisplay.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Framed Display, In Quarantäne, [61a52d11ea92c86edd4c666650b12dd3],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{27e75efd-4c4f-4531-95f9-2f8c618f8c75}, In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{27E75EFD-4C4F-4531-95F9-2F8C618F8C75}, In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\., In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\..9, In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\., In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\..9, In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.MultiPlug, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{27E75EFD-4C4F-4531-95F9-2F8C618F8C75}, In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{27E75EFD-4C4F-4531-95F9-2F8C618F8C75}, In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{27E75EFD-4C4F-4531-95F9-2F8C618F8C75}\INPROCSERVER32, In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [e521b787ee8e39fde8269f56aa58728e],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [e521b787ee8e39fde8269f56aa58728e],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{05b5ef3f-4c6a-426e-b77e-48ebb3e721f1}, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A6CEB2DE-65F7-46FE-89DA-446DD487F293}, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5B81129C-6563-411B-A509-6BBB01EC25FF}, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5B81129C-6563-411B-A509-6BBB01EC25FF}, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A6CEB2DE-65F7-46FE-89DA-446DD487F293}, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{05B5EF3F-4C6A-426E-B77E-48EBB3E721F1}, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.FramedDisplay.A, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{05B5EF3F-4C6A-426E-B77E-48EBB3E721F1}, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.FramedDisplay.A, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{05B5EF3F-4C6A-426E-B77E-48EBB3E721F1}, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{2859046f-5dca-482a-8c2d-37943d33a392}Gw64, In Quarantäne, [32d44ef09be14bebb9d30d3fe023c63a],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{29302da5-1178-40ac-a178-4cb57ebcc501}Gw64, In Quarantäne, [4abc48f62f4d0531bad2aaa2ba4923dd],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{5f0f49f4-526a-4e0c-b198-a0742c879601}Gw64, In Quarantäne, [6f97f945f08cbd79bececf7df310ff01],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{654352cf-1b15-4a56-bda1-f8f91d6491c6}Gw64, In Quarantäne, [b650f44a1567d75f800cb5971fe41be5],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{6db7eb66-a30b-41a3-809c-addb2341dafb}Gw64, In Quarantäne, [000679c51d5f7fb72f5d123a808342be],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{8c39d0b0-9b68-43ef-bc3c-2ef385fe5169}Gw64, In Quarantäne, [55b1a49a3a423afc8dff3b1161a236ca],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{9de7e012-74d3-4f9d-b4b0-2d3150073168}Gw64, In Quarantäne, [27dff648f785a294ef9d0e3ecb38857b],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{b30c55f2-a940-4907-8051-f13c9acdacdd}Gw64, In Quarantäne, [f6103b034f2daf877c109ab20df6f50b],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{cd63c300-b231-4a93-a479-5a1e96976d74}Gw64, In Quarantäne, [0bfb023c156720163c5014388c7742be],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{dda91daf-e6f8-4453-88d1-df18d861c904}Gw64, In Quarantäne, [b452d46a90ec45f1345877d5fc07d12f],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.DigitalSites.A, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DSiteproducts, In Quarantäne, [b6505fdfa1dbb185bd6b10a50ef6ea16],
PUP.Optional.Astromenda.A, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\wse_astromenda, In Quarantäne, [8680be80304c86b0e293b78fe51ebd43],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [32d46dd1d1ab75c1cc366c0a37cc8e72],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [f31367d75b213bfbf0471c70b54fea16],
PUP.Optional.SuperFish.A, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [8086211d314b9b9bacf1bf93ce353cc4],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-28134996-3150521088-3387063821-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0H1K1J1N2U0R1O1F, In Quarantäne, [f31367d75b213bfbf0471c70b54fea16]
Registrierungsdaten: 1
Rogue.Multiple, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, c:\progra~3\553939~1\bit82eb.tmp, Gut: (), Schlecht: (c:\progra~3\553939~1\bit82eb.tmp),Ersetzt,[a75f92ac116b44f2a66512e705fd9c64]
Ordner: 6
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display, Löschen bei Neustart, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin, Löschen bei Neustart, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\TEMP, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\dljdpmdnkpjdhfkjkcdacjdmpcbpojlc, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
Rogue.Multiple, C:\ProgramData\553939823, In Quarantäne, [a75f92ac116b44f2a66512e705fd9c64],
Dateien: 92
PUP.Optional.MaintainerSvc.A, C:\ProgramData\ecbaef90-5696-41e1-a1c3-3e8112ce2840\maintainer.exe, Löschen bei Neustart, [bb4b4cf289f357df8a6017c9bd4456aa],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe, Löschen bei Neustart, [17efdf5f027a191dbb6e5b71719055ab],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.exe, Löschen bei Neustart, [61a52d11ea92c86edd4c666650b12dd3],
PUP.Optional.MultiPlug, C:\ProgramData\SalesMagnet\PfmVvoEJFTsuVh.x64.dll, In Quarantäne, [3acc0e301d5f46f035b03c836a97cc34],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\FramedDisplayBHO.dll, In Quarantäne, [7690f24c0e6e033363d58e2b4cb6ff01],
PUP.Optional.MultiPlug, C:\ProgramData\SalesMagnet\PfmVvoEJFTsuVh.dll, In Quarantäne, [689e1c221765af874f963b84e91833cd],
PUP.Optional.InstalLCore, C:\Users\Lisa\AppData\Local\Temp\is765589038\52614A36_stp.EXE, In Quarantäne, [db2b3d0148347abcacf5b972fc096c94],
PUP.Optional.Giga, C:\Users\Lisa\Downloads\Car-Organizer-lnstall.exe, In Quarantäne, [e224cf6f324a37fff21d271a689db44c],
PUP.Optional.Astromenda.A, C:\Windows\Tasks\WSE_Astromenda.job, In Quarantäne, [ec1a5ee0df9dc670c33539ff877c4db3],
PUP.Optional.Astromenda.A, C:\Windows\System32\Tasks\WSE_Astromenda, In Quarantäne, [c14556e891eb64d26594b0888281a957],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{2859046f-5dca-482a-8c2d-37943d33a392}Gw64.sys, In Quarantäne, [32d44ef09be14bebb9d30d3fe023c63a],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{29302da5-1178-40ac-a178-4cb57ebcc501}Gw64.sys, In Quarantäne, [4abc48f62f4d0531bad2aaa2ba4923dd],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{5f0f49f4-526a-4e0c-b198-a0742c879601}Gw64.sys, In Quarantäne, [6f97f945f08cbd79bececf7df310ff01],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{654352cf-1b15-4a56-bda1-f8f91d6491c6}Gw64.sys, In Quarantäne, [b650f44a1567d75f800cb5971fe41be5],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{6db7eb66-a30b-41a3-809c-addb2341dafb}Gw64.sys, In Quarantäne, [000679c51d5f7fb72f5d123a808342be],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{8c39d0b0-9b68-43ef-bc3c-2ef385fe5169}Gw64.sys, In Quarantäne, [55b1a49a3a423afc8dff3b1161a236ca],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{9de7e012-74d3-4f9d-b4b0-2d3150073168}Gw64.sys, In Quarantäne, [27dff648f785a294ef9d0e3ecb38857b],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{b30c55f2-a940-4907-8051-f13c9acdacdd}Gw64.sys, In Quarantäne, [f6103b034f2daf877c109ab20df6f50b],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{cd63c300-b231-4a93-a479-5a1e96976d74}Gw64.sys, In Quarantäne, [0bfb023c156720163c5014388c7742be],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{dda91daf-e6f8-4453-88d1-df18d861c904}Gw64.sys, In Quarantäne, [b452d46a90ec45f1345877d5fc07d12f],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\FramedDisplay.ico, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\7za.exe, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\dljdpmdnkpjdhfkjkcdacjdmpcbpojlc.crx, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\enjhaaidnddoikhhakdaacbgakbaadlh.crx, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\updateFramedDisplay.InstallState, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\1d2109d867144ca18af8.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\1d2109d867144ca18af864.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\2859046f5dca482a8c2d.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\2859046f5dca482a8c2d64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\29302da5117840aca178.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\29302da5117840aca17864.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\5f0f49f4526a4e0cb198.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\5f0f49f4526a4e0cb19864.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\6db7eb66a30b41a3809c.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\6db7eb66a30b41a3809c64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\88155b61d5d0401c9c66.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\88155b61d5d0401c9c6664.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\8c39d0b09b6843efbc3c.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\8c39d0b09b6843efbc3c64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\9de7e01274d34f9db4b0.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\9de7e01274d34f9db4b064.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\b30c55f2a94049078051.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\b30c55f2a9404907805164.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.InstallState, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{1d2109d8-6714-4ca1-8af8-2ed86cea88e2}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{1d2109d8-6714-4ca1-8af8-2ed86cea88e2}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{2859046f-5dca-482a-8c2d-37943d33a392}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{2859046f-5dca-482a-8c2d-37943d33a392}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{29302da5-1178-40ac-a178-4cb57ebcc501}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{29302da5-1178-40ac-a178-4cb57ebcc501}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{5f0f49f4-526a-4e0c-b198-a0742c879601}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{5f0f49f4-526a-4e0c-b198-a0742c879601}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{6db7eb66-a30b-41a3-809c-addb2341dafb}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{6db7eb66-a30b-41a3-809c-addb2341dafb}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{88155b61-d5d0-401c-9c66-16b32c330fd8}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{88155b61-d5d0-401c-9c66-16b32c330fd8}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{8c39d0b0-9b68-43ef-bc3c-2ef385fe5169}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{9de7e012-74d3-4f9d-b4b0-2d3150073168}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{9de7e012-74d3-4f9d-b4b0-2d3150073168}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{b30c55f2-a940-4907-8051-f13c9acdacdd}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{b30c55f2-a940-4907-8051-f13c9acdacdd}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{cd63c300-b231-4a93-a479-5a1e96976d74}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{cd63c300-b231-4a93-a479-5a1e96976d74}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{dda91daf-e6f8-4453-88d1-df18d861c904}.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{dda91daf-e6f8-4453-88d1-df18d861c904}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\BrowserAdapter.7z, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\cd63c300b2314a93a479.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\cd63c300b2314a93a47964.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\dda91dafe6f8445388d1.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\dda91dafe6f8445388d164.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\FramedDisplay.BrowserAdapter.exe, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\FramedDisplay.BrowserAdapter64.exe, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\FramedDisplay.PurBrowse64.exe, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\FramedDisplay.PurBrowseG.zip, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\sqlite3.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\7za.exe, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\{8c39d0b0-9b68-43ef-bc3c-2ef385fe5169}64.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.Bromon.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.BroStats.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.BrowserAdapter.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.CompatibilityChecker.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.ExpExt.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.FFUpdate.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.GCUpdate.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.IEUpdate.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.Msvcmon.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.OptChecker.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.FramedDisplay.A, C:\Program Files (x86)\Framed Display\bin\plugins\FramedDisplay.PurBrowseG.dll, In Quarantäne, [53b31e204933df578ec9bef329db2ed2],
PUP.Optional.DigitalSites.A, C:\Windows\Tasks\Digital Sites.job, In Quarantäne, [7f87c579f488280e39f0e6cfad57d828],
PUP.Optional.DigitalSites.A, C:\Windows\System32\Tasks\Digital Sites, In Quarantäne, [8284390578040f2736f4cfe63bc9c63a],
Rogue.Multiple, C:\ProgramData\553939823\BIT82EB.tmp, In Quarantäne, [a75f92ac116b44f2a66512e705fd9c64],
PUP.Optional.Astromenda.A, C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://astromenda.com/?f=1&a=ast_ggfc_14_44_ch&cd=2XzuyEtN2Y1L1QzuyB0CyB0AzytCyC0AyDzz0ByEtDzz0EyEtN0D0Tzu0StCtDtAtBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyE0EyC0A0Fzy0EtDtGtD0F0E0DtGzy0Azz0DtG0D0CtDyBtGyEyEtDtBtD0Azy0EtB0DtB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyEtDtD0DyC0AtCtGyB0F0AtAtGyEyBtDtBtGzy0D0FzytGtBzyzztAtDyCtCtCtB0DtB0E2Q&cr=256917394&ir=",), Ersetzt,[de28dc62f3899e9813d8453f2ed7c43c]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 8.1 x64
Ran by Lisa on 12.12.2014 at 14:03:39,52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.12.2014 at 14:15:17,23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-12-2014 02
Ran by Lisa (administrator) on LENOVO-PC on 12-12-2014 22:06:56
Running from C:\Users\Lisa\Desktop
Loaded Profile: Lisa (Available profiles: Lisa)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
() C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Spotify Ltd) C:\Users\Lisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
() C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13664984 2014-01-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6340312 2013-10-17] (Realtek semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2781936 2013-12-19] (Synaptics Incorporated)
HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-03-01] (Lenovo)
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-03-01] ()
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2014-03-01] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-03-01] (Lenovo(beijing) Limited)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [456704 2012-02-20] ()
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119824 2013-12-02] (Lenovo)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-28134996-3150521088-3387063821-1001\...\Run: [Spotify Web Helper] => C:\Users\Lisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1514040 2014-10-09] (Spotify Ltd)
HKU\S-1-5-21-28134996-3150521088-3387063821-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-28134996-3150521088-3387063821-1001\...\MountPoints2: {38ff2082-7d7a-11e4-8274-7c7a916a58b4} - "E:\start.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-28134996-3150521088-3387063821-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-28134996-3150521088-3387063821-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-28134996-3150521088-3387063821-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: DiscountLocator -> {054d09a3-bbfb-4c66-944e-30c64efc4a3c} -> C:\ProgramData\DiscountLocator\K9LaynasE5Xdv9.x64.dll No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\k13smpfu.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\k13smpfu.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\k13smpfu.default\searchplugins\google-maps.xml
FF Extension: Framed Display 1.0.1 - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\k13smpfu.default\Extensions\{88155b61-d5d0-401c-9c66-16b32c330fd8}.xpi [2014-11-29]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-03-01]
FF HKU\S-1-5-21-28134996-3150521088-3387063821-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (TabCarousel) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddldimidiliclngjipajmjjiakhbcohn [2014-11-18]
CHR Extension: (Fruit Ninja Extended) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbhjemdpnfpjodjmfmcbfjlcihbgpikk [2014-12-04]
CHR Extension: (Absolute Radio Live Scores) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmkadilkeimcolingoooifhoknpkifi [2014-11-19]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2443960 2014-10-30] (Microsoft Corporation)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-03-01] (Lenovo)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-24] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-10-11] ()
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2013-11-04] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [285712 2014-03-01] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [304144 2014-03-01] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 Samsung Network Fax Server; C:\WINDOWS\system32\spool\drivers\x64\3\NetFaxServer64.exe [239616 2012-08-07] (Samsung Electronics Co., Ltd.) [File not signed]
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-03-01] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-03-01] (Lenovo)
R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2013-11-18] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3671792 2013-10-11] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [142280 2013-10-18] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-12] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3607520 2013-10-14] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8876248 2013-10-17] (Realtek Semiconductor Corp.)
R3 SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-12-19] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-12 22:08 - 2014-12-12 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-12-12 22:06 - 2014-12-12 22:08 - 00022864 _____ () C:\Users\Lisa\Desktop\FRST.txt
2014-12-12 16:06 - 2014-12-12 16:06 - 00001643 _____ () C:\Users\Lisa\Desktop\DivX Movies.lnk
2014-12-12 16:06 - 2014-12-12 16:06 - 00001089 _____ () C:\Users\Public\Desktop\DivX Player.lnk
2014-12-12 16:05 - 2014-12-12 16:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2014-12-12 16:05 - 2014-12-12 16:05 - 00001154 _____ () C:\Users\Public\Desktop\DivX Converter.lnk
2014-12-12 16:05 - 2014-12-12 16:05 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\DivX
2014-12-12 16:05 - 2014-12-12 16:05 - 00000000 ____D () C:\Program Files\DivX
2014-12-12 16:00 - 2014-12-12 16:06 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-12-12 15:23 - 2014-12-12 16:06 - 00000000 ____D () C:\ProgramData\DivX
2014-12-12 15:23 - 2014-11-12 16:24 - 00995648 _____ (DivX, LLC) C:\Users\Lisa\Desktop\DivXInstaller.exe
2014-12-12 14:15 - 2014-12-12 14:15 - 00000613 _____ () C:\Users\Lisa\Desktop\JRT.txt
2014-12-12 13:52 - 2014-12-12 13:58 - 00000000 ____D () C:\AdwCleaner
2014-12-11 13:50 - 2014-12-11 13:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-10 20:14 - 2014-12-10 20:17 - 00550691 _____ () C:\Users\Lisa\Downloads\AdwCleaner_4.105.exe
2014-12-10 20:08 - 2014-12-10 20:08 - 00024869 _____ () C:\Users\Lisa\Desktop\mbam.txt
2014-12-10 19:32 - 2014-12-12 22:04 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-12-10 19:32 - 2014-12-10 19:32 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-10 19:32 - 2014-12-10 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-10 19:31 - 2014-12-10 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-10 19:31 - 2014-12-10 19:31 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-10 19:31 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-12-10 19:31 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-12-10 19:31 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-12-10 19:28 - 2014-12-10 19:29 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-10 18:53 - 2014-12-10 18:53 - 00001291 _____ () C:\Users\Lisa\Desktop\Revo Uninstaller.lnk
2014-12-10 18:53 - 2014-12-10 18:53 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-12-10 18:47 - 2014-12-10 18:52 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lisa\Downloads\revosetup95.exe
2014-12-10 17:14 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2014-12-10 17:14 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2014-12-10 17:06 - 2014-11-07 05:16 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2014-12-10 17:06 - 2014-11-07 04:26 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2014-12-10 17:06 - 2014-10-13 03:43 - 00238912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2014-12-10 17:06 - 2014-10-13 03:43 - 00153920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2014-12-10 17:06 - 2014-10-13 03:43 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2014-12-10 17:06 - 2014-10-13 03:43 - 00039744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2014-12-10 16:56 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-12-10 16:56 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-12-10 16:56 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-12-10 16:56 - 2014-11-22 03:49 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-12-10 16:56 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-12-10 16:56 - 2014-11-22 03:35 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-12-10 16:56 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-12-10 16:56 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-12-10 16:56 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-12-10 16:56 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-12-10 16:56 - 2014-11-22 03:06 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2014-12-10 16:56 - 2014-11-22 03:06 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-12-10 16:56 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-12-10 16:56 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-12-10 16:56 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-12-10 16:56 - 2014-11-22 02:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2014-12-10 16:56 - 2014-11-22 02:55 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-12-10 16:56 - 2014-11-22 02:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2014-12-10 16:56 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-12-10 16:56 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-12-10 16:56 - 2014-11-22 02:49 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-12-10 16:56 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-12-10 16:56 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-12-10 16:56 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-12-10 16:56 - 2014-11-22 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2014-12-10 16:56 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-12-10 16:56 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-12-10 16:56 - 2014-11-22 02:29 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2014-12-10 16:56 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-12-10 16:56 - 2014-11-22 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2014-12-10 16:56 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-12-10 16:56 - 2014-11-22 02:23 - 00326656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-12-10 16:56 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-12-10 16:56 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-12-10 16:56 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-12-10 16:56 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-12-10 16:56 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-12-10 16:56 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-12-10 16:56 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-12-10 16:49 - 2014-12-10 16:49 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\FLEXnet
2014-12-08 21:06 - 2014-12-08 21:06 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\InstallShield
2014-12-08 21:06 - 2014-12-08 21:06 - 00000000 ____D () C:\ProgramData\InstallShield
2014-12-08 21:05 - 2014-12-08 21:05 - 00000000 ____D () C:\Program Files\Nuance
2014-12-08 21:04 - 2014-12-08 21:04 - 00000000 ____D () C:\ProgramData\zeon
2014-12-08 21:03 - 2014-12-10 18:39 - 00000000 ____D () C:\ProgramData\Nuance
2014-12-08 21:03 - 2014-12-08 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance PaperPort 12
2014-12-08 21:03 - 2014-12-08 21:04 - 00000000 ____D () C:\Program Files (x86)\Nuance
2014-12-08 21:03 - 2014-12-08 21:03 - 00001897 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Software Updates.lnk
2014-12-08 21:03 - 2014-12-08 21:03 - 00000000 ____D () C:\Users\Lisa\Documents\MeineWebSeiten
2014-12-08 21:03 - 2014-12-08 21:03 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\Nuance
2014-12-08 21:03 - 2014-12-08 21:03 - 00000000 ____D () C:\ProgramData\ScanSoft
2014-12-08 21:03 - 2014-12-08 21:03 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-12-08 20:58 - 2014-12-10 10:55 - 00000000 ____D () C:\ProgramData\Brother
2014-12-08 20:58 - 2014-12-08 20:58 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-12-06 19:47 - 2014-12-06 19:51 - 00027282 _____ () C:\Users\Lisa\Downloads\Addition.txt
2014-12-06 19:45 - 2014-12-12 22:07 - 00000000 ____D () C:\FRST
2014-12-06 19:45 - 2014-12-06 19:51 - 00058121 _____ () C:\Users\Lisa\Downloads\FRST.txt
2014-12-06 19:02 - 2014-12-06 19:02 - 02119168 _____ (Farbar) C:\Users\Lisa\Downloads\FRST64.exe
2014-12-06 18:41 - 2014-12-06 18:39 - 02119168 _____ (Farbar) C:\Users\Lisa\Desktop\FRST64.exe
2014-12-03 21:26 - 2014-12-04 01:14 - 00000618 _____ () C:\Users\Lisa\AppData\Roaming\AutoGK.ini
2014-12-01 11:32 - 2014-12-12 15:51 - 00013312 ___SH () C:\Users\Lisa\Desktop\Thumbs.db
2014-12-01 11:26 - 2014-12-01 11:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD
2014-12-01 11:26 - 2014-12-01 11:26 - 00000000 ____D () C:\Program Files (x86)\XviD
2014-12-01 11:25 - 2014-12-01 11:25 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VobSub
2014-12-01 11:25 - 2014-12-01 11:25 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
2014-12-01 11:25 - 2014-12-01 11:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VobSub
2014-12-01 11:25 - 2014-12-01 11:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
2014-12-01 11:25 - 2014-12-01 11:25 - 00000000 ____D () C:\Program Files (x86)\Gabest
2014-12-01 11:25 - 2014-12-01 11:25 - 00000000 ____D () C:\Program Files (x86)\AviSynth 2.5
2014-12-01 11:24 - 2014-12-01 23:42 - 00000000 ____D () C:\Program Files (x86)\AutoGK
2014-12-01 11:24 - 2014-12-01 11:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoGK
2014-12-01 11:21 - 2011-05-13 11:16 - 00493056 _____ ( datenhaus GmbH) C:\WINDOWS\SysWOW64\dhRichClient3.dll
2014-12-01 11:21 - 2011-03-25 19:42 - 00338432 _____ () C:\WINDOWS\SysWOW64\sqlite36_engine.dll
2014-12-01 11:19 - 2014-12-01 11:20 - 01174352 _____ () C:\Users\Lisa\Downloads\Auto Gordian Knot - CHIP-Installer.exe
2014-11-22 23:08 - 2014-11-22 23:08 - 00000000 ____D () C:\Users\Lisa\AppData\Local\Macromedia
2014-11-22 23:06 - 2014-11-22 23:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-11-22 23:06 - 2014-11-22 23:06 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-11-22 23:01 - 2014-12-12 21:29 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-22 23:01 - 2014-12-10 19:29 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-11-22 23:01 - 2014-11-22 23:06 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-11-22 23:01 - 2014-11-22 23:06 - 00000000 ____D () C:\Program Files (x86)\McAfee Security Scan
2014-11-22 23:00 - 2014-11-22 23:02 - 00000000 ____D () C:\Users\Lisa\AppData\Local\Adobe
2014-11-22 22:49 - 2014-12-12 22:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-22 22:49 - 2014-11-22 22:53 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\Mozilla
2014-11-22 22:49 - 2014-11-22 22:53 - 00000000 ____D () C:\Users\Lisa\AppData\Local\Mozilla
2014-11-22 22:49 - 2014-11-22 22:49 - 00001182 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-22 22:49 - 2014-11-22 22:49 - 00001170 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-22 22:49 - 2014-11-22 22:49 - 00000000 ____D () C:\ProgramData\Mozilla
2014-11-22 22:31 - 2014-11-22 22:31 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-11-22 22:29 - 2014-11-22 22:29 - 01707532 _____ (Thisisu) C:\Users\Lisa\Downloads\JRT_6.3.9.exe
2014-11-21 18:57 - 2014-11-21 18:57 - 00022528 _____ () C:\Users\Lisa\AppData\Local\dsisetup1587072502.exe
2014-11-19 20:29 - 2014-11-10 00:19 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2014-11-19 20:29 - 2014-11-10 00:19 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2014-11-19 20:29 - 2014-11-10 00:18 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2014-11-19 20:29 - 2014-11-10 00:18 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2014-11-19 12:09 - 2014-11-19 12:09 - 00001478 _____ () C:\Users\Lisa\Desktop\iexplore.exe - Verknüpfung.lnk
2014-11-19 12:02 - 2014-11-19 12:02 - 00000000 __SHD () C:\Users\Lisa\AppData\Local\EmieBrowserModeList
2014-11-19 07:45 - 2014-11-26 22:10 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-11-19 07:45 - 2014-11-26 22:10 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-19 07:30 - 2014-09-22 05:38 - 01519488 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2014-11-19 07:30 - 2014-09-22 04:06 - 00258368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-11-19 07:30 - 2014-09-22 04:06 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-11-19 07:30 - 2014-09-22 03:49 - 00035320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-11-19 07:30 - 2014-09-19 01:16 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2014-11-19 07:30 - 2014-09-02 23:08 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2014-11-19 07:30 - 2014-09-02 23:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
2014-11-19 07:27 - 2014-10-11 01:58 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-11-19 07:27 - 2014-10-11 01:53 - 03607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-11-19 07:26 - 2014-10-13 03:33 - 00116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2014-11-19 07:26 - 2014-10-08 08:30 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2014-11-19 07:26 - 2014-10-08 08:09 - 00428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2014-11-19 07:26 - 2014-10-08 07:27 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2014-11-19 07:26 - 2014-10-08 06:32 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-11-19 07:26 - 2014-10-08 06:19 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-11-19 07:24 - 2014-11-05 00:38 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-11-19 07:24 - 2014-11-04 01:10 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2014-11-19 07:24 - 2014-10-31 05:53 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2014-11-19 07:24 - 2014-10-31 05:49 - 00537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-11-19 07:24 - 2014-10-31 05:24 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2014-11-18 15:34 - 2014-10-10 02:58 - 00177472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2014-11-18 15:34 - 2014-10-10 02:58 - 00027456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2014-11-18 15:34 - 2014-10-10 02:44 - 00563976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-11-18 15:34 - 2014-10-08 08:37 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-11-18 15:34 - 2014-10-08 08:37 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2014-11-18 15:34 - 2014-10-08 08:34 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2014-11-18 15:34 - 2014-10-08 08:24 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2014-11-18 15:34 - 2014-10-08 07:56 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-11-18 15:34 - 2014-10-08 07:51 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-11-18 15:34 - 2014-10-08 07:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2014-11-18 15:34 - 2014-10-08 07:18 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-11-18 15:34 - 2014-10-08 07:17 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-11-18 15:34 - 2014-10-08 06:23 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-11-18 15:34 - 2014-09-27 08:13 - 00104336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2014-11-18 15:34 - 2014-09-27 06:24 - 00088800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2014-11-18 15:34 - 2014-09-27 04:38 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2014-11-18 15:34 - 2014-09-27 04:30 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2014-11-18 15:34 - 2014-09-27 04:17 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2014-11-18 15:32 - 2014-10-18 10:55 - 00055776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-11-18 15:32 - 2014-10-18 09:09 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-11-18 15:32 - 2014-10-18 09:09 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2014-11-18 15:32 - 2014-10-18 08:25 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2014-11-18 15:32 - 2014-10-18 07:50 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
2014-11-18 15:32 - 2014-10-18 07:38 - 03557376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-11-18 15:32 - 2014-10-18 07:27 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-11-18 15:32 - 2014-10-18 07:26 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-11-18 15:32 - 2014-10-18 07:23 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-11-18 15:32 - 2014-10-18 07:23 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-11-18 15:32 - 2014-10-18 07:21 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-11-18 15:32 - 2014-10-18 07:20 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-11-18 15:32 - 2014-10-18 07:14 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2014-11-18 15:32 - 2014-10-18 07:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2014-11-18 15:32 - 2014-10-18 07:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-11-18 15:32 - 2014-10-18 07:11 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-11-18 15:32 - 2014-10-17 08:01 - 00789184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2014-11-18 15:32 - 2014-10-17 07:58 - 00602768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2014-11-18 15:29 - 2014-10-31 06:12 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wextract.exe
2014-11-18 15:29 - 2014-10-31 06:12 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshta.exe
2014-11-18 15:29 - 2014-10-31 06:10 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iexpress.exe
2014-11-18 15:29 - 2014-10-31 06:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pngfilt.dll
2014-11-18 15:29 - 2014-10-31 06:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedssync.exe
2014-11-18 15:29 - 2014-10-31 06:06 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-11-18 15:29 - 2014-10-31 06:06 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-11-18 15:29 - 2014-10-31 06:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-11-18 15:29 - 2014-10-31 05:57 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-11-18 15:29 - 2014-10-31 05:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-11-18 15:29 - 2014-10-31 05:54 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\IEAdvpack.dll
2014-11-18 15:29 - 2014-10-31 05:53 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2014-11-18 15:29 - 2014-10-31 05:52 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2014-11-18 15:29 - 2014-10-31 05:51 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-11-18 15:29 - 2014-10-31 05:51 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-11-18 15:29 - 2014-10-31 05:50 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-11-18 15:29 - 2014-10-31 05:40 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-11-18 15:29 - 2014-10-31 05:38 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-11-18 15:29 - 2014-10-31 05:30 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-11-18 15:29 - 2014-10-31 05:29 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-11-18 15:29 - 2014-10-31 05:29 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2014-11-18 15:29 - 2014-10-31 05:28 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
2014-11-18 15:29 - 2014-10-31 05:25 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-11-18 15:29 - 2014-10-31 05:24 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-11-18 15:29 - 2014-10-31 05:19 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-11-18 15:29 - 2014-10-31 04:44 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-11-18 15:29 - 2014-10-31 04:42 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\imgutil.dll
2014-11-18 15:29 - 2014-10-31 04:28 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wextract.exe
2014-11-18 15:29 - 2014-10-31 04:28 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshta.exe
2014-11-18 15:29 - 2014-10-31 04:27 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iexpress.exe
2014-11-18 15:29 - 2014-10-31 04:26 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pngfilt.dll
2014-11-18 15:29 - 2014-10-31 04:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedssync.exe
2014-11-18 15:29 - 2014-10-31 04:24 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\url.dll
2014-11-18 15:29 - 2014-10-31 04:24 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-11-18 15:29 - 2014-10-31 04:23 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-11-18 15:29 - 2014-10-31 04:16 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-11-18 15:29 - 2014-10-31 04:15 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-11-18 15:29 - 2014-10-31 04:14 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IEAdvpack.dll
2014-11-18 15:29 - 2014-10-31 04:13 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2014-11-18 15:29 - 2014-10-31 04:13 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2014-11-18 15:29 - 2014-10-31 04:12 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-11-18 15:29 - 2014-10-31 04:11 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-11-18 15:29 - 2014-10-31 04:03 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licmgr10.dll
2014-11-18 15:29 - 2014-10-31 04:02 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-11-18 15:29 - 2014-10-31 03:57 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-18 15:29 - 2014-10-31 03:56 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inseng.dll
2014-11-18 15:29 - 2014-10-31 03:56 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-11-18 15:29 - 2014-10-31 03:56 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2014-11-18 15:29 - 2014-10-31 03:53 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-11-18 15:29 - 2014-10-31 03:53 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
2014-11-18 15:29 - 2014-10-31 03:48 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\occache.dll
2014-11-18 15:29 - 2014-10-31 03:26 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-11-18 15:29 - 2014-10-31 03:24 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imgutil.dll
2014-11-18 15:24 - 2014-10-23 06:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
2014-11-18 15:24 - 2014-10-23 06:05 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
2014-11-18 15:24 - 2014-10-07 07:28 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-11-18 15:24 - 2014-10-07 07:27 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-11-18 15:24 - 2014-10-07 07:27 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-11-18 15:24 - 2014-10-07 07:27 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-11-18 15:24 - 2014-10-07 07:27 - 00108432 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2014-11-18 15:24 - 2014-10-07 04:34 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2014-11-18 15:24 - 2014-10-07 04:34 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2014-11-18 15:24 - 2014-10-07 04:33 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2014-11-18 15:24 - 2014-10-07 04:30 - 04182016 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-11-18 15:24 - 2014-10-07 02:54 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-11-18 15:24 - 2014-10-07 02:46 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-11-18 15:24 - 2014-09-10 07:25 - 00474432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2014-11-18 15:24 - 2014-09-08 04:07 - 02497344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-11-18 15:24 - 2014-09-08 04:07 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-11-18 15:24 - 2014-09-07 23:08 - 00389176 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-11-18 15:24 - 2014-09-04 23:30 - 00822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-11-18 15:24 - 2014-09-04 23:21 - 01053184 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-11-18 15:24 - 2014-09-04 04:05 - 00836176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-11-18 15:24 - 2014-09-04 03:22 - 00670384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2014-11-18 15:24 - 2014-09-04 02:01 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2014-11-18 15:24 - 2014-09-04 01:32 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2014-11-18 15:24 - 2014-08-31 01:17 - 00148800 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2014-11-18 15:24 - 2014-08-31 01:15 - 21197152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-11-18 15:24 - 2014-08-30 23:59 - 18723112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-11-18 15:24 - 2014-08-30 23:05 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2014-11-18 15:24 - 2014-08-30 22:58 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll
2014-11-18 15:24 - 2014-08-30 22:04 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-11-18 15:24 - 2014-08-30 21:53 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
2014-11-18 15:24 - 2014-08-30 21:17 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2014-11-18 15:24 - 2014-08-28 03:55 - 07484224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-11-18 15:24 - 2014-08-28 01:21 - 02480128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2014-11-18 15:24 - 2014-08-28 01:06 - 02030592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2014-11-18 15:24 - 2014-08-23 06:18 - 02149376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-11-18 15:24 - 2014-08-23 06:14 - 13424128 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-11-18 15:24 - 2014-08-23 06:04 - 11820544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-11-18 15:24 - 2014-08-23 06:03 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-11-18 15:24 - 2014-08-23 05:50 - 02714112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-11-18 15:24 - 2014-08-02 01:51 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2014-11-18 15:24 - 2014-08-02 01:35 - 00485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-12 22:09 - 2014-08-27 13:00 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-28134996-3150521088-3387063821-1001
2014-12-12 22:04 - 2014-08-27 12:58 - 00000000 __RDO () C:\Users\Lisa\SkyDrive
2014-12-12 22:03 - 2014-03-01 00:56 - 00002560 _____ () C:\WINDOWS\system32\VfService.trf
2014-12-12 22:03 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-12-12 22:03 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-12-12 22:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-12-12 21:19 - 2014-03-01 09:03 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat
2014-12-12 21:19 - 2014-03-01 09:03 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat
2014-12-12 21:19 - 2013-10-07 19:27 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-12 19:23 - 2014-03-01 00:14 - 01882298 _____ () C:\WINDOWS\WindowsUpdate.log
2014-12-12 16:22 - 2014-10-24 22:13 - 00000000 ____D () C:\Users\Lisa\Desktop\Filme
2014-12-12 15:57 - 2013-10-07 19:23 - 00060532 _____ () C:\WINDOWS\PFRO.log
2014-12-12 14:35 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-12-12 14:11 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-12-12 13:59 - 2014-03-01 00:50 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-12-12 13:54 - 2014-03-01 00:50 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-12-12 13:53 - 2014-10-28 19:12 - 00000000 ____D () C:\ProgramData\ecbaef90-5696-41e1-a1c3-3e8112ce2840
2014-12-12 13:53 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-12-12 13:48 - 2014-08-27 12:59 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{312A9F2C-912C-4422-9331-0C0F10054C19}
2014-12-11 14:50 - 2014-10-29 19:16 - 00002233 _____ () C:\Users\Lisa\cinderella2-user.properties
2014-12-11 13:43 - 2014-08-27 12:54 - 00000000 ____D () C:\Users\Lisa\AppData\Local\Packages
2014-12-11 13:37 - 2014-11-11 09:49 - 00000745 _____ () C:\Users\Lisa\Desktop\Aufg. 27.cdy
2014-12-11 13:33 - 2014-10-19 23:32 - 00095744 ___SH () C:\Users\Lisa\Downloads\Thumbs.db
2014-12-10 20:45 - 2013-08-22 16:20 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-12-10 20:04 - 2014-09-03 21:36 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2014-12-10 18:32 - 2013-08-22 15:44 - 00512168 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-12-10 18:20 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-12-10 17:40 - 2013-08-22 15:46 - 00032799 _____ () C:\WINDOWS\setupact.log
2014-12-08 21:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\LiveKernelReports
2014-12-07 13:37 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-12-02 18:24 - 2014-11-02 22:25 - 00000000 ____D () C:\Users\Lisa\Desktop\Kram
2014-12-01 11:11 - 2013-08-22 14:25 - 00000194 _____ () C:\WINDOWS\win.ini
2014-11-25 21:11 - 2014-03-01 00:59 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Lenovo
2014-11-25 21:11 - 2014-03-01 00:58 - 00000000 ____D () C:\Program Files\Lenovo
2014-11-22 01:02 - 2014-10-28 18:57 - 00000196 _____ () C:\Users\Lisa\AppData\Roaming\WB.CFG
2014-11-21 18:57 - 2014-10-30 11:57 - 00000001 _____ () C:\Users\Lisa\AppData\Local\DSI.DAT
2014-11-19 22:51 - 2014-09-08 22:59 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-11-19 22:51 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-19 22:51 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-19 22:51 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-11-19 22:51 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-11-19 12:03 - 2014-09-03 21:47 - 00000000 ____D () C:\Program Files (x86)\Google
2014-11-19 07:38 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-11-19 07:38 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-11-19 07:36 - 2014-09-06 17:41 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-11-19 07:33 - 2014-09-06 17:41 - 103374192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-11-18 15:29 - 2014-11-07 21:36 - 00000000 ____D () C:\Program Files\Microsoft Office 15
Some content of TEMP:
====================
C:\Users\Lisa\AppData\Local\Temp\COMAP.EXE
C:\Users\Lisa\AppData\Local\Temp\Quarantine.exe
C:\Users\Lisa\AppData\Local\Temp\sdan.exe
C:\Users\Lisa\AppData\Local\Temp\sdapk.exe
C:\Users\Lisa\AppData\Local\Temp\sdaspwn.exe
C:\Users\Lisa\AppData\Local\Temp\sqlite3.dll
C:\Users\Lisa\AppData\Local\Temp\_is74A0.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-09 04:19
==================== End Of Log ============================ --- --- ---
[/CODE] |