Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 25.06.2015
Suchlauf-Zeit: 20:51:03
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.25.05
Rootkit Datenbank: v2015.06.22.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Saskia
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 399381
Verstrichene Zeit: 19 Min, 9 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.XTab.A, C:\Program Files (x86)\MiuiTab\ProtectService.exe, 1240, Löschen bei Neustart, [97e28eb50b7f85b175dc9975b250ca36]
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1348, Löschen bei Neustart, [b9c081c2f09afd390f90e9977f84f40c]
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 23
PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, In Quarantäne, [97e28eb50b7f85b175dc9975b250ca36],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [19609ca758323df9eb4ad44d7b88a65a],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [19609ca758323df9eb4ad44d7b88a65a],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [19609ca758323df9eb4ad44d7b88a65a],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [1564350ecebcdb5bbb49e14035ce4cb4],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [1564350ecebcdb5bbb49e14035ce4cb4],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [1564350ecebcdb5bbb49e14035ce4cb4],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\WajIntEnhance, In Quarantäne, [b7c2d3706525d75fd7ef0ca0ae5524dc],
PUP.Optional.VideoHigh.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\video-high, In Quarantäne, [caaf1f24642669cde12afeec04ff6997],
PUP.Optional.HomeTab.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\HomeTab, In Quarantäne, [91e87bc8aae089adcd7381584cb70ef2],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\SearchProtectWS, In Quarantäne, [4930c87b5a3061d59cf121883ac99868],
PUP.Optional.TNT.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\TNT2, In Quarantäne, [dd9cfc47701ace688fdfd3d8976cdd23],
PUP.Optional.Wajam.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\WajIEnhance, In Quarantäne, [6910ac97b0dadd597139832fd132c53b],
PUP.Optional.Wajam.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\WajIntEnhance, In Quarantäne, [bfbadf64424872c42f98a507fd067789],
PUP.Optional.MultiIE.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, In Quarantäne, [e990d2717317a59190beca5e2dd8c040],
PUP.Optional.ReMarkit.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\APPDATALOW\SOFTWARE\Re_markit, In Quarantäne, [e99072d1f892f83ec7c3932dcd3645bb],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IMBoosterARP, In Quarantäne, [6019380bd8b287af5a17772e61a22ed2],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IminentToolbar, In Quarantäne, [7603ca798505e353284a2d78877c23dd],
PUP.Optional.Linkey.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Linkey, In Quarantäne, [6811b78c573377bff67d5a4ba55ed52b],
PUP.Optional.Vosteran.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Vosteran.com, In Quarantäne, [186144ff3f4b6cca284c2382c73cf010],
PUP.Optional.Wajam.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WajIntEnhance, In Quarantäne, [cdac3310167449ed393cdbca17ecaf51],
PUP.Optional.HomeTab.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\SIMPLYTECH\HomeTab, In Quarantäne, [f0890f34038715210365f9f8de25af51],
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [b9c081c2f09afd390f90e9977f84f40c],
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 16
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106),Ersetzt,[255492b1fa903105318b20b6e025ce32]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}),Ersetzt,[3940073c95f52214d83e5b7a73924eb2]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106),Ersetzt,[ceabe063dfab59dda3731cb9f70e659b]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}),Ersetzt,[61185be87a1049edee287d58996c0ef2]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106),Ersetzt,[fc7db09359314cea04128d48bd48966a]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[ee8b83c00b7fcb6b8515f7ea61a4ab55]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106),Ersetzt,[2257d46f2a6013230dafbf1738cd629e]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}),Ersetzt,[ef8a71d23753eb4bbb5ba0354db8a060]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106),Ersetzt,[d5a4ce7558325dd928ee6d68e421a15f]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106),Ersetzt,[b1c8142f662415218195eee7e71e7e82]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}),Ersetzt,[1267f54e2e5cde582aec53828a7bc13f]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[413820234248ec4ab0eac120c34259a7]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}),Ersetzt,[90e9af943d4df14524f07d589e67857b]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106),Ersetzt,[36439ca77e0c64d227ed4590ec19ae52]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106),Ersetzt,[e39689babbcf0036c0542baa8b7a6e92]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3299057831-706162602-1696328398-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1435231037&z=47bf10f5f3d4e614ec0f04fgbz9c4wcoaccg8e5c6q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}),Ersetzt,[a0d9b68dee9c072f64b074615da89f61]
Ordner: 2
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [b9c081c2f09afd390f90e9977f84f40c],
PUP.Optional.FileTypeAssistant, C:\Program Files (x86)\File Type Assistant, In Quarantäne, [4831e65dec9e40f6e324dab2cc379769],
Dateien: 8
PUP.Optional.XTab.A, C:\Program Files (x86)\MiuiTab\ProtectService.exe, Löschen bei Neustart, [97e28eb50b7f85b175dc9975b250ca36],
PUP.Optional.SmartBar, C:\Users\Saskia\AppData\Local\LPT\LPTInstaller.msi, In Quarantäne, [582165de99f1be78a4ed99c49c64946c],
PUP.Optional.SmartBar, c:\users\saskia\appdata\local\lpt\smartbar.monetization.proxy.proxyremover.exe, In Quarantäne, [4732f84bed9dc3734051baa311efc53b],
PUP.Optional.VeriStaff, c:\users\saskia\appdata\local\lpt\srptm.exe, In Quarantäne, [f386142f028852e4702583daea16659b],
PUP.Optional.SnapDo.A, C:\Windows\Installer\2b9f7288.msi, In Quarantäne, [0d6cc47fcbbf57df21ec7b34fc058e72],
PUP.Optional.IStartSurf.A, C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.istartsurf.com_0.localstorage, In Quarantäne, [f88168db0e7c1e1870f43007ba4b6b95],
PUP.Optional.IStartSurf.A, C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.istartsurf.com_0.localstorage-journal, In Quarantäne, [aecb241fddaddd59fc6863d40cf9ed13],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [b9c081c2f09afd390f90e9977f84f40c],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.207 - Bericht erstellt 25/06/2015 um 21:32:14
# Aktualisiert 21/06/2015 von Xplode
# Datenbank : 2015-06-23.1 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : Saskia - SASSLPOGI
# Gestarted von : C:\Users\Saskia\Downloads\AdwCleaner_4.207.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\Program Files (x86)\miuitab
Ordner Gelöscht : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\FileTypeAssistant
Ordner Gelöscht : C:\Users\Saskia\AppData\Local\FileTypeAssistant
Datei Gelöscht : C:\Users\Saskia\AppData\Local\AnyProtectScannerSetup.exe
***** [ Geplante Tasks ] *****
Task Gelöscht : APSnotifierCA
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4D82643C-6E97-475C-A34C-3E4945B61B6D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Bitberry Software
Schlüssel Gelöscht : HKCU\Software\Bitberry
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKLM\SOFTWARE\Taronja
Schlüssel Gelöscht : HKLM\SOFTWARE\SpeedBit
Schlüssel Gelöscht : HKLM\SOFTWARE\searchult
Schlüssel Gelöscht : HKU\.DEFAULT\Software\AskPartnerNetwork
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Google Chrome v43.0.2357.130
[C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.istartsurf.com/web/?type=dspp&ts=1435231117&z=dd991957733fcfbc7a74096gfzfc8w4oec2gag2g9q&from=air&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD635106&q={searchTerms}
*************************
AdwCleaner[R0].txt - [15292 Bytes] - [23/03/2014 21:59:16]
AdwCleaner[R1].txt - [6123 Bytes] - [25/06/2015 21:28:16]
AdwCleaner[S0].txt - [11096 Bytes] - [23/03/2014 22:03:23]
AdwCleaner[S1].txt - [5136 Bytes] - [25/06/2015 21:32:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5195 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.1.4 (06.25.2015:1)
OS: Windows 8.1 x64
Ran by Saskia on 25.06.2015 at 21:43:46,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-4300-7A786E7484D7}
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-4300-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-4300-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{41564952-412D-5637-4300-7A786E7484D7}
~~~ Files
Successfully deleted: [File] C:\Users\Saskia\appdata\local\nsx9D02.tmp
~~~ Folders
~~~ Chrome
[C:\Users\Saskia\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Saskia\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Saskia\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Saskia\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
mkfokfffehpeedafpekjeddnmnjhmcmk
]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.06.2015 at 21:49:10,00
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015
Ran by Saskia (administrator) on SASSLPOGI on 25-06-2015 21:55:20
Running from C:\Users\Saskia\Desktop
Loaded Profiles: Saskia (Available Profiles: Saskia & Administrator)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsCmdServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\livecomm.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894152 2013-11-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Bitcasa] => C:\Program Files\Bitcasa\Bitcasa.exe [3965904 2013-06-06] ()
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [597576 2013-07-05] (Copyright 2013 SAMSUNG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [134784 2014-06-17] (Atheros Communications)
HKU\S-1-5-21-3299057831-706162602-1696328398-1001\...\Run: [Skype] => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [1EldosIconOverlay] -> {81F51070-A426-4160-A9F9-AB9B7C99F900} => C:\windows\SYSTEM32\CbFsMntNtf3.dll [2013-02-11] (EldoS Corporation)
ShellIconOverlayIdentifiers: [BitcasaIconOverlay] -> {A6975448-A999-49BB-B3E4-7730CF6A82C0} => C:\Program Files\Bitcasa\ExplorerMenu.dll [2013-06-06] ()
ShellIconOverlayIdentifiers: [BitcasaProgressOverlay] -> {6FB8D52A-0064-45B2-B687-F596FEAD09C2} => C:\Program Files\Bitcasa\ExplorerMenu.dll [2013-06-06] ()
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\windows\system32\CbFsMntNtf3.dll [2013-02-11] (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-05-28] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-05-28] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-05-28] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [1EldosIconOverlay] -> {81F51070-A426-4160-A9F9-AB9B7C99F900} => C:\windows\SysWOW64\CbFsMntNtf3.dll [2013-02-11] (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\windows\SysWow64\CbFsMntNtf3.dll [2013-02-11] (EldoS Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3299057831-706162602-1696328398-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/
hxxp://www.bwl.hm.edu/
hxxp://www.moodle.hm.edu/
hxxp://www.facebook.de/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-05-19] (Microsoft Corporation)
BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-4300-7A786E7484D7} -> "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-05-28] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-05-12] (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-05-28] (Microsoft Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll" No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-02-17] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-01-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin-x32: samsung.com/SamsungLinkPCPlugin -> C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll [2013-07-05] (Samsung)
Chrome:
=======
CHR Profile: C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20]
CHR Extension: (Google Drive) - C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20]
CHR Extension: (YouTube) - C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20]
CHR Extension: (Adblock Plus) - C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-23]
CHR Extension: (Google Search) - C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-20]
CHR Extension: (Gmail) - C:\Users\Saskia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.14\AllShareFrameworkManagerDMS.exe [404360 2013-06-18] (Samsung) [File not signed]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [450808 2015-06-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-25] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-25] (Avira Operations GmbH & Co. KG)
S2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [322176 2014-06-17] (Windows (R) Win 7 DDK provider) [File not signed]
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2739888 2015-05-19] (Microsoft Corporation)
S2 ETDService; C:\Program Files\Elantech\ETDService.exe [100104 2013-09-05] (ELAN Microelectronics Corp.)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [605768 2013-07-05] (Copyright 2013 SAMSUNG)
S2 Settings Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe [1593664 2014-02-14] (Samsung Electronics CO., LTD.)
S2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3020120 2015-04-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-06-17] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [219360 2013-04-18] (AppEx Networks Corporation)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-12] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [153256 2015-06-25] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132656 2015-06-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43576 2015-03-14] (Avira Operations GmbH & Co. KG)
R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [223432 2014-06-17] (Qualcomm Atheros)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-06-17] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R1 cbfs3; C:\windows\system32\drivers\cbfs3.sys [352448 2013-02-11] (EldoS Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-06-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-25 21:55 - 2015-06-25 21:55 - 00016853 _____ C:\Users\Saskia\Desktop\FRST.txt
2015-06-25 21:49 - 2015-06-25 21:49 - 00001902 _____ C:\Users\Saskia\Desktop\JRT.txt
2015-06-25 21:43 - 2015-06-25 21:43 - 00000207 _____ C:\WINDOWS\tweaking.com-regbackup-SASSLPOGI-Windows-8.1-(64-bit).dat
2015-06-25 21:43 - 2015-06-25 21:43 - 00000000 ____D C:\RegBackup
2015-06-25 21:38 - 2015-06-25 21:39 - 02952250 _____ (Malwarebytes Corporation) C:\Users\Saskia\Desktop\JRT.exe
2015-06-25 21:36 - 2015-06-25 21:36 - 00005311 _____ C:\Users\Saskia\Desktop\AdwCleaner.txt
2015-06-25 21:36 - 2015-06-25 21:36 - 00000000 ___RD C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-06-25 21:26 - 2015-06-25 21:26 - 02244096 _____ C:\Users\Saskia\Downloads\AdwCleaner_4.207.exe
2015-06-25 21:13 - 2015-06-25 21:25 - 00014124 _____ C:\Users\Saskia\Desktop\mbam.txt
2015-06-25 20:50 - 2015-06-25 21:35 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-06-25 20:50 - 2015-06-25 20:50 - 00001114 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-25 20:50 - 2015-06-25 20:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-25 20:50 - 2015-06-25 20:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-25 20:50 - 2015-06-25 20:50 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-25 20:50 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-06-25 20:50 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-06-25 20:50 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-06-25 20:47 - 2015-06-25 20:49 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Saskia\Downloads\mbam-setup-2.1.6.1022.exe
2015-06-25 20:31 - 2015-06-25 20:31 - 00001280 _____ C:\Users\Saskia\Desktop\Revo Uninstaller.lnk
2015-06-25 20:31 - 2015-06-25 20:31 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-06-25 20:30 - 2015-06-25 20:30 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Saskia\Downloads\revosetup95.exe
2015-06-25 15:44 - 2015-06-25 21:35 - 00005144 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for SASSLPOGI-Saskia SasslPogi
2015-06-25 15:22 - 2015-06-25 21:55 - 00000000 ____D C:\FRST
2015-06-25 15:21 - 2015-06-25 15:21 - 02112512 _____ (Farbar) C:\Users\Saskia\Desktop\FRST64.exe
2015-06-25 14:15 - 2015-06-25 14:15 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-06-25 14:05 - 2015-06-25 14:05 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Avira
2015-06-25 14:00 - 2015-06-25 14:05 - 00000000 ____D C:\Users\Administrator\AppData\Local\SAMSUNG
2015-06-25 14:00 - 2015-06-25 14:00 - 00001214 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\S Agent.lnk
2015-06-25 14:00 - 2015-06-25 14:00 - 00000000 ____D C:\Users\Administrator\Documents\Bluetooth Folder
2015-06-25 14:00 - 2015-06-25 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Atheros
2015-06-25 14:00 - 2015-06-25 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Local\GWX
2015-06-25 14:00 - 2015-06-25 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Local\BMExplorer
2015-06-25 14:00 - 2015-06-25 14:00 - 00000000 ____D C:\Users\Administrator\.swt
2015-06-25 13:59 - 2015-06-25 14:03 - 00002267 _____ C:\Users\Administrator\Desktop\Google Chrome.lnk
2015-06-25 13:59 - 2015-06-25 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Local\Packages
2015-06-25 13:59 - 2015-06-25 14:00 - 00000000 ____D C:\Users\Administrator
2015-06-25 13:59 - 2015-06-25 13:59 - 00001450 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-25 13:59 - 2015-06-25 13:59 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Vorlagen
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Startmenü
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2015-06-25 13:59 - 2015-06-25 13:59 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2015-06-25 13:59 - 2015-03-16 18:25 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-06-25 13:59 - 2015-01-12 03:16 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-25 13:59 - 2015-01-12 03:16 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-06-25 13:59 - 2014-08-26 05:58 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\ATI
2015-06-25 13:59 - 2014-08-26 05:58 - 00000000 ____D C:\Users\Administrator\AppData\Local\ATI
2015-06-25 13:59 - 2014-03-18 12:11 - 00000369 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-06-25 13:59 - 2014-03-18 12:11 - 00000369 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-06-25 13:59 - 2013-08-22 17:36 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-06-25 13:46 - 2015-06-25 13:46 - 00003152 _____ C:\WINDOWS\System32\Tasks\{DA517BC8-E302-4D62-9C78-C0C70CEBE134}
2015-06-25 13:23 - 2015-06-25 13:43 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Steganos
2015-06-25 13:23 - 2015-06-25 13:23 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Steganos VPN
2015-06-25 13:18 - 2015-06-25 13:18 - 00000000 _____ C:\WINDOWS\prleth.sys
2015-06-25 13:18 - 2015-06-25 13:18 - 00000000 _____ C:\WINDOWS\hgfs.sys
2015-06-25 12:43 - 2015-06-25 12:43 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-06-11 00:06 - 2015-06-11 00:06 - 00001136 _____ C:\Users\Public\Desktop\Avira.lnk
2015-06-04 15:01 - 2015-06-04 15:01 - 00000000 ____D C:\Users\Saskia\AppData\Local\GWX
2015-06-04 13:44 - 2015-06-04 13:44 - 00612955 _____ C:\Users\Saskia\Downloads\docx (1)
2015-06-04 13:43 - 2015-06-04 13:44 - 00612955 _____ C:\Users\Saskia\Downloads\docx
2015-06-04 11:11 - 2015-06-04 11:11 - 00059392 _____ C:\Users\Saskia\Desktop\Aufgabenblatt 3_Lösung.xls
2015-06-04 11:09 - 2015-06-04 12:15 - 00065024 _____ C:\Users\Saskia\Desktop\Aufgabenblatt 3.xls
2015-06-04 10:49 - 2015-06-04 10:49 - 00001910 _____ C:\Users\Public\Desktop\SW Update.lnk
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-25 21:55 - 2014-08-26 05:15 - 02053049 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-25 21:40 - 2014-02-16 17:04 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3299057831-706162602-1696328398-1001
2015-06-25 21:38 - 2014-03-18 12:03 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-06-25 21:38 - 2014-03-18 11:25 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat
2015-06-25 21:38 - 2014-03-18 11:25 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat
2015-06-25 21:35 - 2014-08-26 05:53 - 00000000 ___DO C:\Users\Saskia\OneDrive
2015-06-25 21:35 - 2014-03-20 22:41 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-25 21:33 - 2014-10-15 22:05 - 00009146 _____ C:\WINDOWS\setupact.log
2015-06-25 21:33 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-25 21:32 - 2014-10-15 23:40 - 00971468 _____ C:\WINDOWS\PFRO.log
2015-06-25 21:32 - 2014-03-23 21:59 - 00000000 ____D C:\AdwCleaner
2015-06-25 21:32 - 2013-08-22 15:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-06-25 21:14 - 2014-08-26 05:17 - 00000000 ____D C:\Users\Saskia
2015-06-25 21:04 - 2014-03-20 22:41 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-25 21:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-06-25 19:08 - 2014-09-27 19:26 - 00003938 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{082AE942-C95F-4BA7-A7DA-04E01F80A059}
2015-06-25 17:48 - 2014-02-18 00:48 - 00000000 ____D C:\Users\Saskia\AppData\Local\CrashDumps
2015-06-25 16:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-06-25 15:27 - 2014-02-16 20:45 - 00000000 ____D C:\ProgramData\Avira
2015-06-25 14:17 - 2014-02-16 16:59 - 00000000 ____D C:\Users\Saskia\Documents\Bluetooth Folder
2015-06-25 14:15 - 2014-08-26 05:09 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2015-06-25 14:05 - 2013-07-05 06:28 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3299057831-706162602-1696328398-500
2015-06-25 14:02 - 2015-04-18 17:43 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-06-25 14:02 - 2015-04-18 17:43 - 00000000 ____D C:\ProgramData\Skype
2015-06-25 14:00 - 2015-02-24 17:53 - 00000000 ____D C:\ProgramData\Atheros
2015-06-25 14:00 - 2014-02-16 16:56 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2015-06-25 13:48 - 2014-08-26 05:48 - 00001450 _____ C:\Users\Saskia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-25 13:22 - 2015-04-18 17:43 - 00000000 ____D C:\Users\Saskia\AppData\Roaming\Skype
2015-06-25 13:14 - 2014-02-16 16:54 - 00000000 ____D C:\Users\Saskia\AppData\Local\Packages
2015-06-25 13:10 - 2015-01-12 07:13 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-06-25 12:46 - 2014-02-16 20:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-06-25 12:44 - 2014-02-16 20:45 - 00153256 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2015-06-25 12:44 - 2014-02-16 20:45 - 00132656 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2015-06-11 00:06 - 2014-08-18 15:16 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-11 00:06 - 2014-02-16 20:45 - 00000000 ____D C:\Program Files (x86)\Avira
2015-06-04 10:50 - 2014-11-27 06:35 - 00002970 _____ C:\WINDOWS\System32\Tasks\SamsungLinkPC
2015-06-04 10:50 - 2013-07-05 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2015-06-04 10:50 - 2013-07-05 00:54 - 00000000 ____D C:\Program Files (x86)\Samsung
==================== Files in the root of some directories =======
2014-02-16 16:55 - 2014-02-18 00:31 - 0001516 _____ () C:\Users\Saskia\AppData\Roaming\AbsoluteReminder.xml
2014-03-21 00:10 - 2014-03-23 20:10 - 0000065 _____ () C:\Users\Saskia\AppData\Roaming\WB.CFG
2015-02-23 23:52 - 2015-02-23 23:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2013-07-05 04:08 - 2013-02-19 09:34 - 2064264 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe
2013-07-05 04:08 - 2013-01-12 16:51 - 0003004 _____ () C:\ProgramData\MakeMarkerFile.xml
Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe
Some files in TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Saskia\AppData\Local\Temp\avgnt.exe
C:\Users\Saskia\AppData\Local\Temp\Quarantine.exe
C:\Users\Saskia\AppData\Local\Temp\SkypeUpdateSetup.exe
C:\Users\Saskia\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-25 16:19
==================== End of log ============================ --- --- ---
[CODE]Additional
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:24-06-2015
Ran by Saskia at 2015-06-25 21:56:32
Running from C:\Users\Saskia\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3299057831-706162602-1696328398-500 - Administrator - Disabled) => C:\Users\Administrator
Gast (S-1-5-21-3299057831-706162602-1696328398-501 - Limited - Disabled)
Saskia (S-1-5-21-3299057831-706162602-1696328398-1001 - Administrator - Enabled) => C:\Users\Saskia
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Action Replay PowerSaves 3DS Version 1.21 (HKLM-x32\...\{CD24B06F-0A4D-410A-AEF2-DFE6A28AB4C0}_is1) (Version: 1.21 - Datel Design & Development)
Adobe Reader XI (11.0.11) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
AllShare Framework DMS (HKLM\...\{C5850BE4-67AA-4CFB-894B-27F1172E42E0}) (Version: 1.3.14 - Samsung)
AMD Catalyst Install Manager (HKLM\...\{8D819115-F915-F5B3-3D4F-032A8DF32F5C}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.4.2 - AppEx Networks)
Avira (HKLM-x32\...\{0696cc37-db90-4000-be99-4a173ca7c8af}) (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG)
Bitcasa version 1.0.1.5011 (HKLM\...\{EDA09459-AD7D-4434-BA0C-647F6703EA12}_is1) (Version: 1.0.1.5011 - Bitcasa Inc.)
ETDWare X64 11.7.19.9_WHQL (HKLM\...\Elantech) (Version: 11.7.19.9 - ELAN Microelectronic Corp.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Help Desk (HKLM\...\{AEC9D273-E162-4614-83F1-722B8C74B185}) (Version: 1.0.96 - Samsung Electronics CO., LTD.)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 15.0.4727.1003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-3299057831-706162602-1696328398-1001\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4727.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4727.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4727.1003 - Microsoft Corporation) Hidden
Phone Screen Sharing (HKLM-x32\...\{DF02C515-40B5-45AC-A601-5DC69D03885C}) (Version: 2.0.0.21 - RSUPPORT)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.326 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Quick Starter (HKLM\...\{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}) (Version: 1.0.2 - Samsung Electronics CO., LTD.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7045 - Realtek Semiconductor Corp.)
Realtek USB Card Reader (HKLM-x32\...\{1E496A68-4943-424E-829D-5C3C85B7B8F2}) (Version: 1.00.0000 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
S Agent (Version: 1.1.52 - Samsung Electronics CO., LTD.) Hidden
Samsung Link (HKLM-x32\...\{82EC241F-DFCA-4166-A8C3-EA5D2B9A41C4}) (Version: 1.8.0.44 - Samsung Electronics CO., LTD.)
Samsung Link 1.6.0.1307060147 (HKLM\...\8474-7877-9059-0204) (Version: 1.6.0.1307060147 - Copyright 2013 SAMSUNG)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.25.0 - SAMSUNG Electronics Co., Ltd.)
Settings (HKLM-x32\...\{3BB58176-B3A7-47FD-9F18-C3576431D193}) (Version: 2.2.0 - Samsung Electronics CO., LTD.)
SideSync (HKLM-x32\...\{59687468-8CE9-4ABF-9C6A-5C31F0E09F8B}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Support Center (HKLM\...\{711DE117-767F-48A8-9864-66C525B9539F}) (Version: 2.1.1223 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.17 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\...\{AAFEFB05-CF98-48FC-985E-F04CD8AD620D}) (Version: 2.2.9 - Samsung Electronics CO., LTD.)
Teachmaster 4.3 (nur Entfernen) (HKLM-x32\...\Teachmaster 4.3) (Version: - )
Windows-Treiberpaket - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass (08/23/2013 6.2.8400.4218) (HKLM\...\26BFE384C802803107F583AE1A739E4FEB56134B) (Version: 08/23/2013 6.2.8400.4218 - Samsung Electronics Co. Ltd.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3299057831-706162602-1696328398-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Saskia\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3299057831-706162602-1696328398-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Saskia\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3299057831-706162602-1696328398-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Saskia\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3299057831-706162602-1696328398-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Saskia\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3299057831-706162602-1696328398-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Saskia\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\FileSyncApi64.dll (Microsoft Corporation)
==================== Restore Points =========================
04-06-2015 10:48:46 Installed SW Update
13-06-2015 21:07:55 Geplanter Prüfpunkt
25-06-2015 14:01:55 Removed Skype™ 7.5
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08AC5898-9465-4390-A2DC-883C979FC96D} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-3299057831-706162602-1696328398-1001
Task: {23FEACAE-4B4F-4DFF-846E-E82B5E1506BC} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {29BA5F80-880C-46A5-9741-07A7A1459078} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {2DABA4A0-C8F1-4CCD-8158-E2FD400FB987} - System32\Tasks\SamsungLinkPC => C:\Program Files (x86)\Samsung\HomeSync Lite\RefreshToken.exe
Task: {30B9AB09-F397-46D9-A7FA-5B351C771A5C} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {3E0860B8-0CED-44B1-A35D-8818AA260AF3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-05-15] (Microsoft Corporation)
Task: {45AD4C3F-28B1-432B-9F1F-7CE1335B8DE1} - \video-high-enabler No Task File <==== ATTENTION
Task: {53085854-AA2A-47C0-B737-1A826ED4E9CC} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-09-24] (Realtek Semiconductor)
Task: {5AAF3239-F4CD-4FCE-86F4-837937F7C960} - \video-high-updater No Task File <==== ATTENTION
Task: {661F16D4-F2E8-4CFC-96C8-7D1887C7CF5D} - System32\Tasks\LaunchSettings => C:\Program Files (x86)\Samsung\Settings\Settings.exe [2014-02-14] ()
Task: {677CCFE1-9F00-4995-9EA0-DD79079842E6} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2015-02-04] (Samsung Electronics CO., LTD.)
Task: {67F3908F-2A6A-4C83-B582-8CC4734458A9} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {6B94B2EE-4693-4E60-A06F-D01639F6B39A} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {705563F9-702F-4E69-8822-4AF908BDBCE8} - System32\Tasks\SettingsHibernateMonitor => C:\Program Files (x86)\Samsung\Settings\SettingsHibernateMonitor.exe [2014-02-14] (Samsung Electronics CO., LTD.)
Task: {75216A85-0989-4FE4-858D-ECF90F3BF9BD} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-09-16] (Realtek Semiconductor)
Task: {76249A4C-3142-495C-B62D-599031E34852} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20] (Google Inc.)
Task: {7800A56F-63FA-48AF-AEA8-58291DDCDB80} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-05-28] (Microsoft Corporation)
Task: {7E819FE9-A14C-4C63-9DCF-699427B5C8B5} - \video-high-codedownloader No Task File <==== ATTENTION
Task: {8C2A980E-6B6B-4DDA-B584-180A73DD96F4} - System32\Tasks\{DA517BC8-E302-4D62-9C78-C0C70CEBE134} => pcalua.exe -a C:\Users\Saskia\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=air
Task: {8E186891-3DD7-41F6-9532-367B71293998} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-05-12] (Microsoft Corporation)
Task: {97F5CA00-FFEC-4BC7-A37B-553EBC501C3E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20] (Google Inc.)
Task: {A639A484-7040-466E-AED4-E276CB95D5AA} - \video-high-firefoxinstaller No Task File <==== ATTENTION
Task: {B292E20E-5CE5-47DB-AD71-011A6BD8FCA6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated)
Task: {C0942911-A3AF-4B6A-9815-3D01B2B2E6A8} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-05-19] (Microsoft Corporation)
Task: {D0DB6C78-BE1D-4EBA-B719-3BA567F2F989} - \video-high-chromeinstaller No Task File <==== ATTENTION
Task: {DED6EFB3-CE73-4F0A-99F7-8D4E461DCE59} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-05-19] (Microsoft Corporation)
Task: {E232F266-EF7C-4D7C-9FD6-FF5FD288E1F5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-05-12] (Microsoft Corporation)
Task: {EE9D218F-2F42-4E03-8E77-027CE58EAB34} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {FB396963-5DF4-4BC0-A867-B0AC8D7E905F} - System32\Tasks\SettingsEventHandlerMonitor => C:\Program Files (x86)\Samsung\Settings\CmdServer\RSSettingEventHandler.exe [2014-02-14] (Samsung Electronics CO., LTD.)
Task: {FD55300F-3A98-4E0D-96C4-0C059B1D98A7} - System32\Tasks\Microsoft Office 15 Sync Maintenance for SASSLPOGI-Saskia SasslPogi => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-05-28] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2013-07-05 03:49 - 2013-06-06 06:15 - 00288720 _____ () C:\Program Files\Bitcasa\ExplorerMenu.dll
2013-07-05 03:49 - 2013-06-06 06:23 - 01645056 _____ () C:\Program Files\Bitcasa\bitcasaui.dll
2015-01-12 07:13 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-05-09 22:49 - 2015-05-09 22:49 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\ErrorReporting.dll
2015-06-25 13:06 - 2015-06-20 07:46 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libglesv2.dll
2015-06-25 13:06 - 2015-06-20 07:46 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Saskia\OneDrive:ms-properties
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-3299057831-706162602-1696328398-1001\...\sharepoint.com -> hxxps://hmedu.sharepoint.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3299057831-706162602-1696328398-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Saskia\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\spring shoes.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{6393F501-9947-4F7B-B42A-5D068F99C072}] => (Allow) C:\Users\Saskia\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{EE0DAC83-559C-4807-AFE5-62EB539678C2}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
FirewallRules: [{C2051B3E-56B0-4154-99E9-9C40EF5373D0}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
FirewallRules: [{AA762439-11B4-43BE-AB8C-B42B5B86962C}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
FirewallRules: [{FFCDA525-7122-4C83-9ED4-FF37F0177BBC}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
FirewallRules: [{9C66F574-37C8-4D02-AEF4-D90D229BC475}] => (Allow) LPort=1900
FirewallRules: [{A12A7005-52FD-4AB0-86AA-1D0A2AC7D5FF}] => (Allow) LPort=7900
FirewallRules: [{BBED4E5D-0CB6-492F-8DEB-909FF2D32D41}] => (Allow) LPort=24234
FirewallRules: [{2737478A-81E4-4A42-9E1F-5A92B36BD392}] => (Allow) LPort=7679
FirewallRules: [{7E646746-2DD9-4BC2-9C73-02EA9BEDE741}] => (Allow) LPort=7676
FirewallRules: [{864DC9AA-709F-4A13-A38D-F9FA31531914}] => (Allow) LPort=8643
FirewallRules: [{45852E01-27FE-41C2-9B7E-EBA686E65012}] => (Allow) LPort=8743
FirewallRules: [{EEB1D163-6687-4C3D-A537-8F41A18A47CF}] => (Allow) C:\Program Files\Samsung\AllShare Framework DMS\1.3.14\AllShareFrameworkDMS.exe
FirewallRules: [{5C63FCF9-0629-4480-BE93-C911055D62AE}] => (Allow) C:\Program Files\Samsung\AllShare Framework DMS\1.3.14\AllShareFrameworkDMS.exe
FirewallRules: [{A4D45E9B-A7DC-4920-B055-EA6C1DE185E5}] => (Allow) C:\Program Files\Samsung\AllShare Framework DMS\1.3.14\AllShareFrameworkDMS.exe
FirewallRules: [{D91C0179-D70D-4121-BA3B-045FADD0B342}] => (Allow) C:\Program Files\Samsung\AllShare Framework DMS\1.3.14\AllShareFrameworkDMS.exe
FirewallRules: [{0130E8B4-4232-47D7-8A2F-38BB01227C1E}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
FirewallRules: [{87589BF5-1258-40D1-85CE-794AE052E713}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
FirewallRules: [{506B5859-0764-4669-BE25-95946006389C}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
FirewallRules: [{40EEBD33-D125-43C3-89A4-EA7BA722EC58}] => (Allow) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
FirewallRules: [{DB75861B-C55E-48BD-B2B2-F0996BF4BD22}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{D3D76BA6-BBF9-4B48-BAF6-FDA919E167DC}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{C810FB50-DCA7-4AF9-B09A-B3064ADB05B8}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{F7874245-319E-4329-8674-7272EBE258A4}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{8595852E-F354-42B7-BA03-6366BA2B8E8C}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{59AFDACB-4C7F-4C65-BD4D-1FCBB32B5579}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{26DA443F-422E-4D01-ACB1-9C5A6B2922BE}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{EDD70935-225F-46B3-8BCD-9ED86010ABC0}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{EBD703E0-8F57-458B-90CB-F4401B67662C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/25/2015 09:51:17 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/25/2015 06:17:59 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/25/2015 06:12:50 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/25/2015 05:59:49 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/25/2015 05:59:49 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/25/2015 05:58:27 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/25/2015 05:48:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 43.0.2357.130, Zeitstempel: 0x5584cfea
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17736, Zeitstempel: 0x550f42c2
Ausnahmecode: 0xc0000142
Fehleroffset: 0x0009d4f2
ID des fehlerhaften Prozesses: 0x20cc
Startzeit der fehlerhaften Anwendung: 0xchrome.exe0
Pfad der fehlerhaften Anwendung: chrome.exe1
Pfad des fehlerhaften Moduls: chrome.exe2
Berichtskennung: chrome.exe3
Vollständiger Name des fehlerhaften Pakets: chrome.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: chrome.exe5
Error: (06/25/2015 05:45:01 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/25/2015 05:41:41 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Das Volume "\\?\Volume{92d29096-332f-4ac5-b1f4-63d04c56a1f3}\" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057)
Error: (06/25/2015 05:41:40 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Das Volume "Windows RE tools" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057)
System errors:
=============
Error: (06/25/2015 09:44:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "AllShare Framework DMS" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/25/2015 09:44:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/25/2015 09:44:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "ZAtheros Bt and Wlan Coex Agent" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/25/2015 09:44:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "SW Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/25/2015 09:44:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Settings Launcher" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/25/2015 09:44:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Samsung Link Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/25/2015 09:44:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/25/2015 09:44:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMScheduler" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/25/2015 09:44:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Elan Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/25/2015 09:44:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Microsoft Office-Klick-und-Los-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Microsoft Office:
=========================
Error: (06/25/2015 09:51:17 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"C:\Program Files\Microsoft Office 15\root\office15\lync.exe.ManifestC:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL1
Error: (06/25/2015 06:17:59 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"C:\Program Files\Microsoft Office 15\root\office15\lync.exe.ManifestC:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL1
Error: (06/25/2015 06:12:50 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"C:\Program Files\Microsoft Office 15\root\office15\lync.exe.ManifestC:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL1
Error: (06/25/2015 05:59:49 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"C:\Program Files\Microsoft Office 15\root\office15\lync.exe.ManifestC:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL1
Error: (06/25/2015 05:59:49 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"C:\Program Files\Microsoft Office 15\root\office15\lync.exe.ManifestC:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL1
Error: (06/25/2015 05:58:27 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"C:\Program Files\Microsoft Office 15\root\office15\lync.exe.ManifestC:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL1
Error: (06/25/2015 05:48:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe43.0.2357.1305584cfeantdll.dll6.3.9600.17736550f42c2c00001420009d4f220cc01d0af5e544f16a7C:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\WINDOWS\SYSTEM32\ntdll.dll925fc544-1b51-11e5-826b-48d2243efdd0
Error: (06/25/2015 05:45:01 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"C:\Program Files\Microsoft Office 15\root\office15\lync.exe.ManifestC:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL1
Error: (06/25/2015 05:41:41 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: \\?\Volume{92d29096-332f-4ac5-b1f4-63d04c56a1f3}\Falscher Parameter. (0x80070057)
Error: (06/25/2015 05:41:40 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Windows RE toolsFalscher Parameter. (0x80070057)
==================== Memory info ===========================
Processor: Quad-Core Processor (up to 1.4GHz)
Percentage of memory in use: 39%
Total physical RAM: 3526.71 MB
Available physical RAM: 2143.95 MB
Total Pagefile: 5126.71 MB
Available Pagefile: 3421.36 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:98.59 GB) (Free:65.7 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: BEA15CA0)
Partition: GPT Partition Type.
==================== End of log ============================ --- --- --- |