Hallo Sandra,
riesengroßes Sorry dass ich mich jetzt erst wieder melde!! Ich werde die nächsten Male nicht mehr als eine Woche verstreichen lassen bis ich die Schritte durchgeführt habe.
Also weiter im Text:
Ich habe keine Ahnung wieso der jetzt wieder voll mit Adware ist.. Hab ihn ganz normal benutzt :wtf:
Zu Schritt 1: leider konnte ich weder über "systemsteuerung" noch über den Revouninstaller GNotes Extension deinstallieren. Das Programm ist trotzdem noch drauf.
Schritt 2: Code:
Fix result of Farbar Recovery Scan Tool (x64) Version:13-06-2015
Ran by Iris at 2015-06-16 16:20:44 Run:2
Running from C:\Users\Iris\Desktop
Loaded Profiles: Iris (Available Profiles: Iris)
Boot Mode: Normal
==============================================
fixlist content:
*****************
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-3450306727-158836411-271950113-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3450306727-158836411-271950113-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49461;https=127.0.0.1:49461
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: ApppttoU -> {966aaa80-04b5-425e-bf92-1210e8b20af0} -> C:\Program Files (x86)\ApppttoU\ik6sagbY2Ht8i6.dll No File
FF SearchPlugin: C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\searchplugins\trovi.xml
FF Extension: CinPlus-2.4c - C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com [2015-03-02]
FF Extension: Security Protection - C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\detgdp@gmail.com [2014-12-31]
FF Extension: iWebar1.1 - C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\ROUAILDE73397174@UXGZI17268980.com [2015-03-02]
FF Extension: youtubeit_aechiaragmailcom - FF Extension: youtubeit_aechiaragmailcom - C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\youtubeit_aechiara@gmail.com [2015-02-24][2015-02-24]
FF HKLM-x32\...\Firefox\Extensions: [detgdp@gmail.com] - C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\extensions\detgdp@gmail.com
CHR Extension: (No Name) - C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\plgljbjjfdpaboeflppnamegkoohadeh [2015-02-02]
CHR HKLM\...\Chrome\Extension: [hpljfflibaokjcndmchkfjalpjjblioc] - C:\Users\Iris\AppData\Local\MyMovieMagnet.crx [2013-07-30]
CHR HKU\S-1-5-21-3450306727-158836411-271950113-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hpljfflibaokjcndmchkfjalpjjblioc] - C:\Users\Iris\AppData\Local\MyMovieMagnet.crx [2013-07-30]
CHR HKLM-x32\...\Chrome\Extension: [hpljfflibaokjcndmchkfjalpjjblioc] - C:\Users\Iris\AppData\Local\MyMovieMagnet.crx [2013-07-30]
S2 59191eaf; c:\Program Files (x86)\SystemLift\SystemLift.dll [1637376 2015-02-02] () [File not signed]
S2 gsEyZbUfv; C:\ProgramData\EiTVjiBBmwA\gsEyZbUfv.exe [2726776 2014-11-09] (Time Lapse Solutions)
C:\Users\Iris\AppData\Local\MyMovieMagnet.crx
C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\plgljbjjfdpaboeflppnamegkoohadeh
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\youtubeit_aechiara@gmail.com
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\extensions\detgdp@gmail.com
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\youtubeit_aechiara@gmail.com
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\ROUAILDE73397174@UXGZI17268980.com
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com
C:\Program Files (x86)\ApppttoU
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\detgdp@gmail.com
c:\Program Files (x86)\SystemLift\SystemLift.dll
C:\ProgramData\EiTVjiBBmwA\gsEyZbUfv.exe
REG: reg query "HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings"
REG: reg query "HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections"
emptytemp:
*****************
HKLM\SOFTWARE\Policies\Google => key not found.
HKU\S-1-5-21-3450306727-158836411-271950113-1001\SOFTWARE\Policies\Google => key not found.
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found.
HKU\S-1-5-21-3450306727-158836411-271950113-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value not found.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{966aaa80-04b5-425e-bf92-1210e8b20af0} => key not found.
HKCR\Wow6432Node\CLSID\{966aaa80-04b5-425e-bf92-1210e8b20af0} => key not found.
"FF SearchPlugin: C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\searchplugins\trovi.xml" => not found.
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com not found.
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\detgdp@gmail.com not found.
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\ROUAILDE73397174@UXGZI17268980.com not found.
C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\youtubeit_aechiara@gmail.com not found.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\detgdp@gmail.com => value not found.
C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\plgljbjjfdpaboeflppnamegkoohadeh folder not found
HKLM\SOFTWARE\Google\Chrome\Extensions\hpljfflibaokjcndmchkfjalpjjblioc => key not found.
"C:\Users\Iris\AppData\Local\MyMovieMagnet.crx" => File/Folder not found.
HKU\S-1-5-21-3450306727-158836411-271950113-1001\SOFTWARE\Google\Chrome\Extensions\hpljfflibaokjcndmchkfjalpjjblioc => key not found.
"C:\Users\Iris\AppData\Local\MyMovieMagnet.crx" => File/Folder not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hpljfflibaokjcndmchkfjalpjjblioc => key not found.
"C:\Users\Iris\AppData\Local\MyMovieMagnet.crx" => File/Folder not found.
59191eaf => Service not found.
gsEyZbUfv => Service not found.
"C:\Users\Iris\AppData\Local\MyMovieMagnet.crx" => File/Folder not found.
"C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\plgljbjjfdpaboeflppnamegkoohadeh" => File/Folder not found.
"C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\youtubeit_aechiara@gmail.com" => File/Folder not found.
"C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\extensions\detgdp@gmail.com" => File/Folder not found.
"C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\youtubeit_aechiara@gmail.com" => File/Folder not found.
"C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\ROUAILDE73397174@UXGZI17268980.com" => File/Folder not found.
"C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com" => File/Folder not found.
"C:\Program Files (x86)\ApppttoU" => File/Folder not found.
"C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\detgdp@gmail.com" => File/Folder not found.
"c:\Program Files (x86)\SystemLift\SystemLift.dll" => File/Folder not found.
"C:\ProgramData\EiTVjiBBmwA\gsEyZbUfv.exe" => File/Folder not found.
========= reg query "HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings" =========
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
EnableNegotiate REG_DWORD 0x1
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
ZonesSecurityUpgrade REG_BINARY B6A118893F04CA01
ProxyOverride REG_SZ <-loopback>
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
========= End of Reg: =========
========= reg query "HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections" =========
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings REG_BINARY 46000000FF080000030000002A000000687474703D3132372E302E302E313A34393436313B68747470733D3132372E302E302E313A34393436310B0000003C2D6C6F6F706261636B3E000000000000000000000000721064A417D5CF010000000000000000000000000200000002000000C0A801120000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001700000000000000200100009D386ABD3404177AA27E80A10000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
DefaultConnectionSettings REG_BINARY 4600000006030000030000002A000000687474703D3132372E302E302E313A34393436313B68747470733D3132372E302E302E313A34393436310B0000003C2D6C6F6F706261636B3E000000000000000000000000721064A417D5CF010000000000000000000000000200000002000000C0A801120000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001700000000000000200100009D386ABD3404177AA27E80A10000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
========= End of Reg: =========
EmptyTemp: => 752.7 MB temporary data Removed.
The system needed a reboot..
==== End of Fixlog 16:22:50 ==== Schritt 3 Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 16.06.2015 17:56:32, SYSTEM, IRIS-PC, Manual, Remediation Database, 2015.3.9.1, 2015.6.15.1,
Update, 16.06.2015 17:56:32, SYSTEM, IRIS-PC, Manual, IP Database, 0.0.0.0, 2015.6.12.1,
Update, 16.06.2015 17:56:32, SYSTEM, IRIS-PC, Manual, Domain Database, 0.0.0.0, 2015.6.12.1,
Update, 16.06.2015 17:56:32, SYSTEM, IRIS-PC, Manual, Rootkit Database, 2015.2.25.1, 2015.6.15.1,
Update, 16.06.2015 17:56:39, SYSTEM, IRIS-PC, Manual, Malware Database, 2015.3.9.5, 2015.6.16.4,
Scan, 16.06.2015 18:47:06, SYSTEM, IRIS-PC, Manual, Start: 16.06.2015 17:57:06, Dauer: 42 Minuten 58 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, "252" nicht-Malwareerkennung,
Error, 16.06.2015 18:50:16, SYSTEM, IRIS-PC, Protection, IsLicensed, 13,
Protection, 16.06.2015 18:50:16, SYSTEM, IRIS-PC, Protection, Malware Protection, Stopping,
Protection, 16.06.2015 18:50:16, SYSTEM, IRIS-PC, Protection, Malware Protection, Stopped,
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 16.06.2015
Suchlauf-Zeit: 17:57:06
Logdatei: mbam2.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.16.04
Rootkit Datenbank: v2015.06.15.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Iris
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 486566
Verstrichene Zeit: 42 Min, 58 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert schritt 4: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-06-2015
Ran by Iris (administrator) on IRIS-PC on 16-06-2015 19:05:08
Running from C:\Users\Iris\Desktop
Loaded Profiles: Iris (Available Profiles: Iris)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Program Files (x86)\Fujitsu\AIS Connect\bin\qsaMain.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccsvchst.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccsvchst.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Spotify Ltd) C:\Users\Iris\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHndHkb.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Spotify Ltd) C:\Users\Iris\AppData\Roaming\Spotify\Spotify.exe
(FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe
(Dropbox, Inc.) C:\Users\Iris\AppData\Roaming\Dropbox\bin\Dropbox.exe
(FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe
(Fujitsu Technology Solutions) C:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe
(Fujitsu) C:\Program Files (x86)\Fujitsu\AIS Connect\bin\AISMessageForYou.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe
(Spotify Ltd) C:\Users\Iris\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Iris\AppData\Roaming\Spotify\Spotify.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\osk.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-09] (Synaptics Incorporated)
HKLM\...\Run: [PfNet] => C:\Program Files\Fujitsu\Plugfree NETWORK\PfNet.exe [6310912 2010-06-24] (FUJITSU LIMITED)
HKLM\...\Run: [PSUTility] => C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [188264 2009-07-30] (FUJITSU LIMITED)
HKLM\...\Run: [FDM7] => C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe [164712 2009-11-26] (FUJITSU LIMITED)
HKLM\...\Run: [LoadFujitsuQuickTouch] => C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [157544 2009-10-15] (FUJITSU LIMITED)
HKLM\...\Run: [LoadBtnHnd] => C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [35176 2009-10-15] (FUJITSU LIMITED)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-28] (Realtek Semiconductor)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [LoadFUJ02E3] => C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe [36712 2009-10-08] (FUJITSU LIMITED)
HKLM-x32\...\Run: [IndicatorUtility] => C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [47976 2009-10-09] (FUJITSU LIMITED)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe [162912 2009-07-08] (CyberLink Corp.)
HKLM-x32\...\Run: [DeskUpdateNotifier] => c:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe [97560 2010-10-13] (Fujitsu Technology Solutions)
HKLM-x32\...\Run: [AIS_MessageForYou] => C:\Program Files (x86)\Fujitsu\AIS Connect\bin\AISMessageForYou.exe [1965056 2010-03-18] (Fujitsu)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-18] (Apple Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3450306727-158836411-271950113-1001\...\Run: [Spotify Web Helper] => C:\Users\Iris\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2021944 2015-06-16] (Spotify Ltd)
HKU\S-1-5-21-3450306727-158836411-271950113-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-08-25] (Google Inc.)
HKU\S-1-5-21-3450306727-158836411-271950113-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22041192 2014-08-27] (Skype Technologies S.A.)
HKU\S-1-5-21-3450306727-158836411-271950113-1001\...\Run: [Spotify] => C:\Users\Iris\AppData\Roaming\Spotify\Spotify.exe [7323192 2015-06-16] (Spotify Ltd)
Startup: C:\Users\Iris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2013-06-28]
ShortcutTarget: Dropbox.lnk -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled
ProxyServer: [.DEFAULT] => http=127.0.0.1:49461;https=127.0.0.1:49461
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3450306727-158836411-271950113-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3450306727-158836411-271950113-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=FTSG&bmod=FTSG
SearchScopes: HKU\S-1-5-21-3450306727-158836411-271950113-1001 -> {C612C47D-1465-4C0C-9B8D-E6A12DE7A613} URL = hxxp://www.bing.com/search?q={searchTerms}&r=711
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-06-16] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Symantec NCO BHO -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll [2012-06-07] (Symantec Corporation)
BHO-x32: Symantec Intrusion Prevention -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\IPS\IPSBHO.DLL [2011-03-31] (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-06-16] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-06-16] (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll [2012-06-07] (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-06-16] (Google Inc.)
Toolbar: HKU\S-1-5-21-3450306727-158836411-271950113-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-3450306727-158836411-271950113-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-06-16] (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-06-16] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-16] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-01-09] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3450306727-158836411-271950113-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll [2012-12-07] (Amazon.com, Inc.)
FF Extension: compatibilityaddonsmozillaorg - C:\Users\Iris\AppData\Roaming\Mozilla\Firefox\Profiles\26b5hbxq.default-1412446074992\Extensions\compatibility@addons.mozilla.org [2015-01-29]
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPlgn
FF Extension: Symantec Intrusion Prevention - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPlgn [2012-08-25]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn_2011_7_13_2
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn_2011_7_13_2 [2015-06-16]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-19]
CHR Extension: (Google Docs) - C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-19]
CHR Extension: (Google Drive) - C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-19]
CHR Extension: (YouTube) - C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-19]
CHR Extension: (Google Search) - C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-19]
CHR Extension: (Google Sheets) - C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-19]
CHR Extension: (Gmail) - C:\Users\Iris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-19]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AISConnect; C:\Program Files (x86)\Fujitsu\AIS Connect\bin\qsaMain.exe [32768 2009-01-26] () [File not signed]
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed]
R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-11-01] (Intel Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation)
R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [330240 2010-06-24] (FUJITSU LIMITED) [File not signed]
R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63336 2009-07-30] (FUJITSU LIMITED)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143072 2012-05-29] (TuneUp Software)
R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-11-01] (Intel Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20130116.013\BHDrvx64.sys [1388120 2013-01-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-12-04] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-01-23] (Symantec Corporation)
R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED)
R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20130126.002\IDSvia64.sys [513184 2012-12-02] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-06-16] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20130128.032\ENG64.SYS [126192 2013-01-23] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20130128.032\EX64.SYS [2087664 2013-01-23] (Symantec Corporation)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1207020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1207020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1207020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1207020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2012-09-15] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [171128 2011-01-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-05-08] (TuneUp Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
U2 wuaserv; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-16 19:02 - 2015-06-16 19:02 - 00062724 _____ C:\Users\Iris\Desktop\mbam2.txt
2015-06-16 19:00 - 2015-06-16 19:00 - 00001009 _____ C:\Users\Iris\Desktop\mbam.txt
2015-06-16 17:56 - 2015-06-16 18:58 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-16 17:56 - 2015-06-16 17:56 - 00001108 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-16 17:56 - 2015-06-16 17:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-16 17:56 - 2015-06-16 17:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-16 17:56 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-16 17:56 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-16 17:53 - 2015-06-16 17:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Iris\Desktop\mbam-setup-2.1.6.1022.exe
2015-06-16 14:42 - 2015-06-16 17:44 - 00000000 ____D C:\ProgramData\7fee0af45c734d07
2015-06-15 15:23 - 2015-06-15 15:23 - 00000000 ____D C:\Users\Iris\AppData\Local\{B0C300E8-8885-4C47-ACAD-F42A948553C0}
2015-06-15 11:44 - 2015-06-15 11:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-06-15 10:37 - 2015-06-15 10:37 - 00003026 _____ C:\Windows\avmadd32.log
2015-06-15 10:37 - 2015-06-15 10:37 - 00002542 _____ C:\Windows\avmadd321.log
2015-06-15 10:37 - 2015-06-15 10:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FRITZ!Box
2015-06-15 10:37 - 2015-06-15 10:37 - 00000000 ____D C:\Program Files (x86)\FRITZ!BoxPrint
2015-06-15 10:37 - 2015-06-15 10:37 - 00000000 ____D C:\Program Files (x86)\FRITZ!Box
2015-06-15 10:37 - 2006-12-14 14:42 - 00069120 ____R (AVM Berlin) C:\Windows\SysWOW64\avmadd32.dll
2015-06-15 10:37 - 2006-05-29 03:00 - 00016384 ____R (AVM Berlin GmbH) C:\Windows\SysWOW64\avmprmon.dll
2015-06-15 10:26 - 2015-06-15 10:26 - 00017480 _____ C:\Windows\AVMInstall.Log
2015-06-15 10:26 - 2015-06-15 10:26 - 00000370 _____ C:\Windows\avmacc.log
2015-06-15 10:26 - 2015-06-15 10:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FRITZ!WLAN
2015-06-15 10:26 - 2015-06-15 10:26 - 00000000 ____D C:\Program Files (x86)\avmwlanstick
2015-06-15 10:12 - 2015-06-15 10:12 - 00000000 ____D C:\Users\Iris\AppData\Local\Apps\2.0
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-16 19:06 - 2015-01-31 20:45 - 00022654 _____ C:\Users\Iris\Desktop\FRST.txt
2015-06-16 19:05 - 2015-01-31 20:45 - 00000000 ____D C:\FRST
2015-06-16 19:03 - 2012-08-25 13:36 - 01556892 _____ C:\Windows\WindowsUpdate.log
2015-06-16 19:00 - 2009-07-14 06:45 - 00031536 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-16 19:00 - 2009-07-14 06:45 - 00031536 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-16 18:53 - 2013-01-29 01:06 - 00000000 ___RD C:\Users\Iris\Dropbox
2015-06-16 18:53 - 2013-01-29 01:02 - 00000000 ____D C:\Users\Iris\AppData\Roaming\Dropbox
2015-06-16 18:52 - 2013-01-28 20:22 - 00000000 ____D C:\Users\Iris\AppData\Roaming\Skype
2015-06-16 18:52 - 2012-11-05 20:10 - 00000000 ____D C:\Users\Iris\AppData\Roaming\Spotify
2015-06-16 18:51 - 2012-11-05 20:10 - 00000000 ____D C:\Users\Iris\AppData\Local\Spotify
2015-06-16 18:50 - 2012-08-25 13:41 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-16 18:50 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-16 18:50 - 2009-07-14 06:45 - 00416312 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-16 18:49 - 2010-11-21 05:47 - 00243108 _____ C:\Windows\PFRO.log
2015-06-16 18:49 - 2009-07-14 06:51 - 00105841 _____ C:\Windows\setupact.log
2015-06-16 18:47 - 2015-02-03 00:30 - 00000000 ____D C:\Program Files (x86)\YouTube Flags
2015-06-16 18:47 - 2015-02-02 23:26 - 00000000 ____D C:\Program Files (x86)\GNotes Extension
2015-06-16 18:47 - 2015-01-31 14:26 - 00000000 ____D C:\Program Files (x86)\Contrast Theme for Gmail
2015-06-16 18:22 - 2012-09-15 12:26 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-16 18:17 - 2012-08-25 13:41 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-16 17:56 - 2012-12-04 02:26 - 00000000 ____D C:\Users\Iris\AppData\Roaming\Malwarebytes
2015-06-16 17:56 - 2012-12-04 02:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-16 17:56 - 2012-12-04 02:26 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-06-16 16:25 - 2012-09-18 19:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-16 16:23 - 2012-09-15 12:29 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-16 16:12 - 2012-08-25 13:41 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-06-16 16:12 - 2012-08-25 13:41 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-06-16 15:46 - 2012-09-18 01:03 - 00000000 ____D C:\Users\Iris\AppData\Local\CrashDumps
2015-06-16 15:45 - 2015-02-03 00:09 - 00000000 ____D C:\Program Files (x86)\SystemLift
2015-06-16 15:43 - 2015-02-03 02:47 - 00000000 ____D C:\Users\Iris\Desktop\FRST-OlderVersion
2015-06-16 15:43 - 2015-01-30 01:40 - 02109952 _____ (Farbar) C:\Users\Iris\Desktop\FRST64.exe
2015-06-16 14:22 - 2012-09-15 12:26 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-16 14:22 - 2012-09-15 12:26 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-16 14:22 - 2012-09-15 12:26 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-16 13:23 - 2013-12-14 00:20 - 01838573 _____ C:\Windows\IE11_main.log
2015-06-15 17:04 - 2012-12-19 18:30 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-06-15 13:58 - 2015-03-19 00:33 - 00000020 _____ C:\Users\Iris\AppData\Roaming\appdataFr3.bin
2015-06-15 13:32 - 2011-02-14 14:57 - 00699666 _____ C:\Windows\system32\perfh007.dat
2015-06-15 13:32 - 2011-02-14 14:57 - 00149774 _____ C:\Windows\system32\perfc007.dat
2015-06-15 13:32 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-15 11:28 - 2012-08-25 13:56 - 00000000 ____D C:\Windows\System32\Tasks\Fujitsu
==================== Files in the root of some directories =======
2015-03-19 00:33 - 2015-06-15 13:58 - 0000020 _____ () C:\Users\Iris\AppData\Roaming\appdataFr3.bin
2015-03-02 15:20 - 2015-03-02 15:20 - 0000081 _____ () C:\Users\Iris\AppData\Roaming\mbam.context.scan
2013-07-27 00:47 - 2015-02-02 22:47 - 0000092 _____ () C:\Users\Iris\AppData\Roaming\WB.CFG
2013-07-06 14:54 - 2013-07-06 14:54 - 0000005 _____ () C:\Users\Iris\AppData\Roaming\WBPU-Q3-TTL.DAT
2013-07-09 20:52 - 2013-07-09 20:52 - 0000005 _____ () C:\Users\Iris\AppData\Roaming\WBPU-Q4-TTL.DAT
2013-07-15 17:56 - 2014-01-03 01:55 - 0000005 _____ () C:\Users\Iris\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-06-26 13:47 - 2014-01-31 09:47 - 0000005 _____ () C:\Users\Iris\AppData\Roaming\WBPU-TTL.DAT
Some files in TEMP:
====================
C:\Users\Iris\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5tdqnm.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-06 21:27
==================== End of log ============================ Addition:
[CODE]Additional
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:13-06-2015
Ran by Iris at 2015-06-16 19:07:06
Running from C:\Users\Iris\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3450306727-158836411-271950113-500 - Administrator - Disabled)
Gast (S-1-5-21-3450306727-158836411-271950113-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3450306727-158836411-271950113-1002 - Limited - Enabled)
Iris (S-1-5-21-3450306727-158836411-271950113-1001 - Administrator - Enabled) => C:\Users\Iris
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Norton Internet Security (Disabled - Out of date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Disabled - Out of date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
AIS Connect (HKLM-x32\...\AIS Connect) (Version: 1.1.1.6 - Fujitsu Technology Solutions GmbH)
AIS Connect (x32 Version: 1.1.1.6 - Fujitsu Technology Solutions GmbH) Hidden
Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC)
Apple Application Support (HKLM-x32\...\{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}) (Version: 2.3.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version: - AVM Berlin)
AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version: - AVM Berlin)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: - AVM Berlin)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.1908.7636 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DeskUpdate 4.11 (HKLM-x32\...\DeskUpdate_is1) (Version: 4.11.0074 - Fujitsu Technology Solutions)
Dropbox (HKU\S-1-5-21-3450306727-158836411-271950113-1001\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.)
ffdshow v1.2.4422 [2012-04-09] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4422.0 - )
Free Studio version 5.7.3.917 (HKLM-x32\...\Free Studio_is1) (Version: 5.7.3.917 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.11.33.1005 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.33.1005 - DVDVideoSoft Ltd.)
Fujitsu Display Manager (HKLM-x32\...\InstallShield_{4108974B-DE87-4AD4-9167-930C62C45691}) (Version: - )
Fujitsu Display Manager (Version: 7.01.00.210 - FUJITSU LIMITED) Hidden
Fujitsu Hotkey Utility (HKLM-x32\...\InstallShield_{BA0CC975-682B-4678-A35C-05E607F36387}) (Version: 3.60.1.0 - FUJITSU LIMITED)
Fujitsu Hotkey Utility (x32 Version: 3.60.1.0 - FUJITSU LIMITED) Hidden
Fujitsu MobilityCenter Extension Utility (HKLM-x32\...\InstallShield_{EC314CDF-3521-482B-A21C-65AC95664814}) (Version: - )
Fujitsu MobilityCenter Extension Utility (Version: 3.01.00.000 - Ihr Firmenname) Hidden
Fujitsu System Extension Utility (HKLM-x32\...\InstallShield_{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}) (Version: - )
Fujitsu System Extension Utility (Version: 3.1.1.0 - FUJITSU LIMITED) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.124 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2025 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
iTunes (HKLM\...\{5FE78439-7CAA-45FE-A808-2D7A0FC98643}) (Version: 11.0.2.25 - Apple Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LifeBook Application Panel (HKLM-x32\...\InstallShield_{6226477E-444F-4DFE-BA19-9F4F7D4565BC}) (Version: - )
LifeBook Application Panel (Version: 8.1.0.0 - FUJITSU LIMITED) Hidden
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 38.0.5 (x86 de) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 18.7.2.3 - Symantec Corporation)
PDF24 Creator 5.7.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
Plugfree NETWORK (HKLM\...\{7BA64D21-EE46-4a9a-8145-52B0175C3F86}) (Version: 5.3.0.1 - FUJITSU LIMITED)
Plugfree NETWORK (Version: 5.3.001 - FUJITSU LIMITED) Hidden
Power Saving Utility (HKLM-x32\...\InstallShield_{7254349B-460B-488F-B4DB-A96100C5C48B}) (Version: - )
Power Saving Utility (Version: 31.01.11.013 - FUJITSU LIMITED) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5969 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30087 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-3450306727-158836411-271950113-1001\...\Spotify) (Version: 1.0.6.80.g2a801a53 - Spotify AB)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.10.0 - Synaptics Incorporated)
TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3600.73 - TuneUp Software)
TuneUp Utilities 2012 (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3450306727-158836411-271950113-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Iris\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
==================== Restore Points =========================
09-04-2015 20:34:22 Windows Update
10-04-2015 21:12:19 Windows Update
10-04-2015 23:55:05 Windows Update
11-04-2015 21:19:44 Windows Update
12-04-2015 00:24:41 Windows Update
10-05-2015 22:18:40 Windows Update
10-05-2015 23:58:54 Windows Update
15-06-2015 15:37:09 Windows Update
15-06-2015 20:40:18 Windows Update
16-06-2015 13:17:48 Windows Update
16-06-2015 14:48:52 Revo Uninstaller's restore point - GNotes Extension
16-06-2015 15:06:26 Revo Uninstaller's restore point - GNotes Extension
16-06-2015 15:09:08 Revo Uninstaller's restore point - GNotes Extension
16-06-2015 15:10:18 Revo Uninstaller's restore point - GNotes Extension
16-06-2015 15:13:21 Revo Uninstaller's restore point - GNotes Extension
16-06-2015 17:43:07 Revo Uninstaller's restore point - GNotes Extension
16-06-2015 18:23:58 Windows Update
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2015-03-02 15:38 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0E6AA818-5BFA-4F03-883C-5FCF6A91EC65} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {3D61946B-23BE-42F2-A9DE-54450EA48419} - System32\Tasks\Symantec\Norton Error Analyzer 18.7.2.3 => C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\SymErr.exe [2012-06-08] (Symantec Corporation)
Task: {450A4E0B-A288-4CCC-9D6C-BFCB50FA2186} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-16] (Adobe Systems Incorporated)
Task: {60DFF8E0-C4B6-488B-8031-28526C9F4C52} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-16] (Google Inc.)
Task: {8C87204A-94CC-43A4-99FD-E026397614C5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {BC27A4D8-5960-45B0-95B0-AB399C32C614} - System32\Tasks\Symantec\Norton Error Processor 18.7.2.3 => C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\SymErr.exe [2012-06-08] (Symantec Corporation)
Task: {E044AD13-0F00-42E1-ADC0-B9BCE2CB5970} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-05-29] (TuneUp Software)
Task: {E57DCCFA-155A-4510-909B-EE72BC0A842C} - System32\Tasks\Fujitsu\DeskUpdate => c:\Fujitsu\Programs\DeskUpdate\ducmd.exe [2010-10-13] (Fujitsu Technology Solutions)
Task: {E8FDE3E0-5B7E-499F-9BD6-E7EF2DD6BE08} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2013-02-16] (Microsoft Corporation)
Task: {FE922BD5-19C5-4753-B863-65E979E82ECC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-16] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2009-01-26 17:49 - 2009-01-26 17:49 - 00032768 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\qsaMain.exe
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2008-10-14 13:38 - 2008-10-14 13:38 - 00014336 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\schedutils.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00014336 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\cutils.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00025088 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\osal.dll
2009-01-26 17:49 - 2009-01-26 17:49 - 00229376 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\serviceagent.dll
2009-01-26 17:46 - 2009-01-26 17:46 - 00204800 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\messaging.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00017920 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\cmessaging.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00009216 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\threadpool.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00014336 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\utils.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00011264 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\cuxml.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00057344 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\transports.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00208896 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\ssl.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00876544 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\crypto.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00077824 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\expat.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00081920 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\registration.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00090112 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\remoteaccess.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00057344 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\scheduler.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00053248 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\pollingserver.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00045056 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\acm.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00021504 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\httpbroker.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00086016 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\monitormanager.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00053248 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\filetransfer.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00013312 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\urischeme.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00155648 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\filerepository.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00008192 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\md5c.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00258048 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\swupdate.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00053248 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\commoncfg.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00045056 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\usagejob.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00008192 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\sslinit.dll
2009-01-15 15:50 - 2009-01-15 15:50 - 00017408 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\c2sLogger.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00043008 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\httpServerConnDS.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00012288 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\sctunnel.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00017408 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\ttunnel.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00057344 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\totalaccess.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00010240 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\qsaversions.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00014336 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\stdinstallers.dll
2009-03-25 11:23 - 2009-03-25 11:23 - 00029184 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\exectaDS.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00026112 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\winwmids.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00009728 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\pstoreds.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00057344 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\winsysinfods.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00057344 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\winvmstatds.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00025600 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\winfsinfods.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00026112 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\cmdds.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00006656 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\uadfw.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00016896 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\stdrules.dll
2008-10-14 13:38 - 2008-10-14 13:38 - 00008192 _____ () C:\Program Files (x86)\Fujitsu\AIS Connect\bin\rulelib.dll
2012-08-27 21:33 - 2012-08-27 21:33 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-08-27 21:33 - 2012-08-27 21:33 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-03-05 04:09 - 2015-06-16 13:05 - 41287224 _____ () C:\Users\Iris\AppData\Roaming\Spotify\libcef.dll
2015-06-16 18:51 - 2015-06-16 18:51 - 00043008 _____ () c:\users\iris\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5tdqnm.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00750080 _____ () C:\Users\Iris\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00047616 _____ () C:\Users\Iris\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00865280 _____ () C:\Users\Iris\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00200704 _____ () C:\Users\Iris\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2015-03-05 04:09 - 2015-06-16 13:05 - 01488440 _____ () C:\Users\Iris\AppData\Roaming\Spotify\libglesv2.dll
2015-03-05 04:09 - 2015-06-16 13:05 - 00079928 _____ () C:\Users\Iris\AppData\Roaming\Spotify\libegl.dll
2015-03-05 04:09 - 2015-03-05 04:09 - 09305656 _____ () C:\Users\Iris\AppData\Roaming\Spotify\pdf.dll
2015-06-16 14:22 - 2015-06-16 14:22 - 16867504 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MyOSProtect => ""="service" <==== ATTENTION
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3450306727-158836411-271950113-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Iris\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{3463A621-0476-41C3-B104-79360348A239}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{80F8FBF2-A3F1-4758-988B-A9BE50F12FD6}] => (Allow) LPort=2869
FirewallRules: [{250BCB3A-04C3-4322-AA5F-478C912CBB78}] => (Allow) LPort=1900
FirewallRules: [{5BED5BF1-0B39-462F-A717-2AB5255C8837}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{82BC0D85-7D68-4B2A-8DDC-97F3F0CDE57E}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{FE49B5AE-6911-498F-ACF9-ED422B7530D9}] => (Allow) C:\Program Files (x86)\Fujitsu\AIS Connect\bin\qsaMain.exe
FirewallRules: [{AB6195E4-7CD4-40C8-9C27-C15D16D63B6A}] => (Allow) C:\Program Files (x86)\Fujitsu\AIS Connect\UltraVNC\winvnc.exe
FirewallRules: [{5D1B2A80-075E-4199-8FEA-CA7EF942D726}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{556C4B7E-439F-410D-B9F1-319284AE55C7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7A05AA52-252A-4AAA-B252-99959B93782C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3090294F-040B-450F-B986-4F10B0E6C04C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A521F4FE-E15D-4954-B061-CAFFF7B12C56}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{32C7E965-991B-48BC-A2C0-DFC840255E53}C:\users\iris\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\iris\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{42C66296-3019-42D8-8097-1B50E026753D}C:\users\iris\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\iris\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{E31E8B6D-926F-46BE-A01D-FDEDE69CAAB8}C:\users\iris\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\iris\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{867794A5-F181-46C2-8D67-E9E09ED67EB9}C:\users\iris\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\iris\appdata\roaming\spotify\spotify.exe
FirewallRules: [{2CCE55CB-FDEA-48BC-BF67-77E1A62E0BD7}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{A0D297C0-2C65-4456-98C1-CC9782EFB380}] => (Allow) C:\Users\Iris\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{2FCA4B2C-672D-4B44-9D7C-FC825683C0FA}] => (Allow) C:\Users\Iris\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{91940B5E-03DA-422A-AE37-418304E9132D}C:\users\iris\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\iris\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{38A7C870-35DA-472C-B2AB-3D7CAB4F54AF}C:\users\iris\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\iris\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{94576F00-0E3C-4BD3-B881-AFC1E4AF1D70}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{F4BF226B-52DA-4CEC-B2E3-1529B824022D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{039D6338-7CFC-4687-9F37-40B716DF3232}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{99110F47-0FA0-42BD-9623-67D847C171AD}] => (Allow) F:\fsetup.exe
FirewallRules: [{421C2E06-823D-420D-917E-76254FD32B62}] => (Allow) F:\fsetup.exe
FirewallRules: [{FC00B7A1-3B43-4A3B-9A81-FC226B5F93F0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/16/2015 06:51:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/16/2015 04:27:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/16/2015 04:18:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 13.6.2015.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 27b8
Startzeit: 01d0a83a7d0a71b0
Endzeit: 14
Anwendungspfad: C:\Users\Iris\Desktop\FRST64.exe
Berichts-ID: 93eb2bff-1432-11e5-952c-e0ca94beb0f6
Error: (06/16/2015 03:45:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 38.0.5.5623, Zeitstempel: 0x5563c49a
Name des fehlerhaften Moduls: mozalloc.dll, Version: 38.0.5.5623, Zeitstempel: 0x5563b229
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001aa1
ID des fehlerhaften Prozesses: 0x17d8
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (06/16/2015 03:44:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 38.0.5.5623, Zeitstempel: 0x5563c49a
Name des fehlerhaften Moduls: mozalloc.dll, Version: 38.0.5.5623, Zeitstempel: 0x5563b229
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001aa1
ID des fehlerhaften Prozesses: 0x1dc4
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (06/16/2015 01:05:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/15/2015 07:09:14 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 937956
Error: (06/15/2015 07:09:14 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 937956
Error: (06/15/2015 07:09:14 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/15/2015 07:09:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 936957
System errors:
=============
Error: (06/16/2015 06:56:56 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (06/16/2015 06:47:17 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {60A90A2F-858D-42AF-8929-82BE9D99E8A1}
Error: (06/16/2015 04:23:56 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {60A90A2F-858D-42AF-8929-82BE9D99E8A1}
Error: (06/16/2015 01:23:54 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Internet Explorer 11 für Windows 7 für x64-basierte Systeme
Error: (06/16/2015 01:10:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (06/15/2015 09:50:39 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {005A3A96-BAC4-4B0A-94EA-C0CE100EA736}
Error: (05/11/2015 00:02:31 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Internet Explorer 11 für Windows 7 für x64-basierte Systeme
Error: (05/10/2015 10:11:02 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (04/30/2015 02:26:47 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (04/30/2015 02:18:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Adobe Flash Player Update Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%109
Microsoft Office:
=========================
Error: (06/16/2015 06:51:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/16/2015 04:27:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/16/2015 04:18:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe13.6.2015.027b801d0a83a7d0a71b014C:\Users\Iris\Desktop\FRST64.exe93eb2bff-1432-11e5-952c-e0ca94beb0f6
Error: (06/16/2015 03:45:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe38.0.5.56235563c49amozalloc.dll38.0.5.56235563b2298000000300001aa117d801d0a82603a8c769C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dlle60642a1-142d-11e5-952c-e0ca94beb0f6
Error: (06/16/2015 03:44:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe38.0.5.56235563c49amozalloc.dll38.0.5.56235563b2298000000300001aa11dc401d0a82f1df7dd11C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dlle1131913-142d-11e5-952c-e0ca94beb0f6
Error: (06/16/2015 01:05:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/15/2015 07:09:14 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 937956
Error: (06/15/2015 07:09:14 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 937956
Error: (06/15/2015 07:09:14 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/15/2015 07:09:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 936957
CodeIntegrity Errors:
===================================
Date: 2015-03-02 14:36:18.022
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-03-02 14:36:17.850
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-02 22:12:58.659
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\nethfdrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-02 22:12:58.481
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\nethfdrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-02 22:04:36.712
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\nethfdrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-02 22:04:36.493
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\nethfdrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-02 21:34:28.489
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\nethfdrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-02 21:34:28.302
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\nethfdrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-02 21:26:56.727
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\nethfdrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-02 21:26:56.555
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\nethfdrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Percentage of memory in use: 68%
Total physical RAM: 3892.55 MB
Available physical RAM: 1213.19 MB
Total Pagefile: 7783.29 MB
Available Pagefile: 4954 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:463.76 GB) (Free:188.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: F424250E)
Partition 1: (Active) - (Size=2 GB) - (Type=27)
Partition 2: (Not Active) - (Size=463.8 GB) - (Type=07 NTFS)
==================== End of log ============================ --- --- ---
Ich hoffe die aktuellen Ergebnisse sehen nicht ganz so schlimm aus:confused::o
Danke dir!! |