Code:
Nico Mak Computing
WinZip Malware Protector
Datum der Überprüfung Donnerstag, 23. Juli 2015
Datenbankversion 2325
Gefundene Elemente insgesamt 94
Überprüfte Objekte: 366772
Abgelaufene Zeit: 00:01:42
Name Gefundene Elemente
Name der Infektion pup.optional
Kategorie Potentially Unwanted Application
Bedrohungsstufe High
Durchgeführte Aktion NoActionTaken
Elemente gefunden 1
Gefundener Bereich FileSystem
Details
Dateiname c:\users\alexandra\downloads\kies3setup.exe
MD5 12095843207507927641
Signatur 0
Md5hash: 9dd5bd2ff675d9a92447c28ec3532d55
Name der Infektion malware.trace
Kategorie Generic Malware
Bedrohungsstufe High
Durchgeführte Aktion NoActionTaken
Elemente gefunden 93
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
17.06.2014 at 18:48:11
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
17.06.2014 at 18:48:54
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
18.06.2014 at 09:14:16
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
18.06.2014 at 09:37:32
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
18.06.2014 at 09:38:06
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
18.06.2014 at 09:38:51
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
18.06.2014 at 09:38:58
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
19.06.2014 at 09:58:29
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
20.06.2014 at 12:06:43
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
21.06.2014 at 12:39:06
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
24.06.2014 at 12:34:51
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
25.06.2014 at 11:45:42
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
26.06.2014 at 14:24:23
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
27.06.2014 at 09:09:29
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
28.06.2014 at 15:59:04
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
28.06.2014 at 20:00:30
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
29.06.2014 at 11:24:06
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
30.06.2014 at 11:51:56
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
01.07.2014 at 10:01:09
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
02.07.2014 at 09:55:44
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
03.07.2014 at 12:49:31
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
05.07.2014 at 13:07:07
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
06.07.2014 at 19:58:52
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
07.07.2014 at 11:09:45
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
07.07.2014 at 17:46:39
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
08.07.2014 at 17:27:27
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
10.07.2014 at 10:25:33
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
16.07.2014 at 09:42:20
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
23.07.2014 at 09:43:04
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
24.07.2014 at 12:04:29
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
25.07.2014 at 13:36:18
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
27.07.2014 at 13:16:57
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
28.07.2014 at 12:09:35
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
29.07.2014 at 12:21:30
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
02.08.2014 at 12:22:42
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
03.08.2014 at 11:51:53
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
04.08.2014 at 16:48:51
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
06.08.2014 at 09:38:04
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
08.08.2014 at 12:48:43
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
11.08.2014 at 11:32:54
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
12.08.2014 at 11:14:54
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
14.08.2014 at 07:21:18
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
15.08.2014 at 10:46:02
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
15.08.2014 at 19:46:22
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
16.08.2014 at 11:22:26
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
21.08.2014 at 10:41:18
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
22.08.2014 at 11:19:18
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
23.08.2014 at 10:28:14
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
24.08.2014 at 11:00:10
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
27.08.2014 at 18:38:28
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
28.08.2014 at 10:31:32
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
29.08.2014 at 11:53:24
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
30.08.2014 at 11:02:38
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
03.09.2014 at 17:43:05
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
04.09.2014 at 10:54:50
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
06.09.2014 at 20:10:53
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
07.09.2014 at 11:26:03
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
18.09.2014 at 18:05:18
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
19.09.2014 at 08:32:29
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
20.09.2014 at 10:25:35
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
21.09.2014 at 13:27:01
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
22.09.2014 at 09:44:13
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
24.09.2014 at 16:57:12
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
25.09.2014 at 09:43:54
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
28.09.2014 at 11:25:46
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
29.09.2014 at 12:13:52
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
02.10.2014 at 09:25:16
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
03.10.2014 at 12:44:21
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
04.10.2014 at 20:16:15
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
05.10.2014 at 11:39:49
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
07.10.2014 at 17:04:22
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
08.10.2014 at 18:12:46
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
12.10.2014 at 11:26:29
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
13.10.2014 at 09:17:35
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
14.10.2014 at 17:14:37
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
16.10.2014 at 12:25:07
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
17.10.2014 at 12:30:41
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
19.10.2014 at 11:49:32
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
21.10.2014 at 16:51:07
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
24.10.2014 at 11:20:47
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
25.10.2014 at 13:13:26
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
27.10.2014 at 10:52:20
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
28.10.2014 at 17:13:25
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
31.10.2014 at 11:37:25
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
02.11.2014 at 12:29:58
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
03.11.2014 at 10:32:39
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
04.11.2014 at 17:10:14
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
05.11.2014 at 17:52:30
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
06.11.2014 at 10:10:26
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
07.11.2014 at 10:38:31
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
07.11.2014 at 21:55:24
Gefundener Bereich Registry
Details
Registrierungsschlüssel hkey_current_user
software\dc3_fexec
08.11.2014 at 10:02:30
© 2013 WinZip International LLC. All rights reserved. Schritt 1 kann nicht ohne kauf von Malware Protektor ausgeführt werden.
Das programm löscht nichts. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 23.07.2015
Suchlaufzeit: 17:32
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.07.23.04
Rootkit-Datenbank: v2015.07.22.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Alexandra
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 393127
Abgelaufene Zeit: 14 Min., 11 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 8
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\CLASSES\Helper.TemplateObject, In Quarantäne, [5ad64d9851396bcbc14bb2d37989af51],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\CLASSES\Helper.TemplateObject.1, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Helper.TemplateObject, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Helper.TemplateObject.1, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Helper.TemplateObject, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Helper.TemplateObject.1, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\${dtUserElevationPolicyID}, In Quarantäne, [9c943da876145ed818774a385da7b54b],
Malware.Trace, HKU\S-1-5-21-2422082488-33307941-859794934-1002\SOFTWARE\DC3_FEXEC, In Quarantäne, [b87809dcdeacff372c4f6192c340df21],
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 3
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
PUP.Optional.OptimizerPro.A, C:\Users\Alexandra\Documents\Optimizer Pro, In Quarantäne, [042ca243e4a652e4b49ee8af39cb768a],
PUP.Optional.DataMngr.A, C:\ProgramData\Datamngr, In Quarantäne, [32fe0bdaf5954beb53b49564e919df21],
Dateien: 91
Trojan.Dropper.SFXAI, C:\Users\Alexandra\AppData\Roaming\27072014.scr, In Quarantäne, [68c81cc90585c472aed162c6dd24ac54],
Misused.Legit.AI, C:\Users\Alexandra\265oyte47\.com, In Quarantäne, [cf6155903b4f57dfaf94939bc53c55ab],
Misused.Legit.AI, C:\Users\Alexandra\8fdhc8i6\OWryTUenk.exe, In Quarantäne, [e9472fb66228c274c52f6dc8837e39c7],
PUP.Optional.DownloadSponsor, C:\Users\Alexandra\Downloads\find-it.exe, In Quarantäne, [0b25b82d8bff4fe7e9b1b43cd82cc63a],
PUP.Optional.Conduit.A, C:\Users\Alexandra\Downloads\Kies3Setup.exe, In Quarantäne, [70c0479e2664fd39c1e756bbe120c739],
PUP.Optional.InstallCore.A, C:\Users\Alexandra\Downloads\MediaPlayerSetup.exe, In Quarantäne, [e14fd510cac065d17075e15219e7c23e],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-17-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-18-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-19-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-20-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-21-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-22-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-23-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-24-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-25-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-26-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-27-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-28-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-29-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-30-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-01-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-03-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-04-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-05-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-06-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-07-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-08-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-09-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-10-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-11-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-13-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-14-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-15-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-16-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-21-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-22-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-23-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-24-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-26-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-27-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-28-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-29-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-30-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-31-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-01-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-02-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-03-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-08-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-09-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-10-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-12-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-14-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-15-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-23-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-04-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-07-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-08-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-09-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-10-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-11-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-12-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-13-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-14-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-15-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-16-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-17-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-20-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-24-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-28-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-02-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-25-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-05-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-03-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-07-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-08-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-09-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-10-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-13-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-17-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-18-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-21-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-22-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-23-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-25-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-27-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-28-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-11-02-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-11-04-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-11-05-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-11-08-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
PUP.Optional.OptimizerPro.A, C:\Users\Alexandra\Documents\Optimizer Pro\CookiesException.txt, In Quarantäne, [042ca243e4a652e4b49ee8af39cb768a],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 23.07.2015
Suchlaufzeit: 17:32
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.07.23.04
Rootkit-Datenbank: v2015.07.22.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Alexandra
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 393127
Abgelaufene Zeit: 14 Min., 11 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 8
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\CLASSES\Helper.TemplateObject, In Quarantäne, [5ad64d9851396bcbc14bb2d37989af51],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\CLASSES\Helper.TemplateObject.1, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Helper.TemplateObject, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Helper.TemplateObject.1, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Helper.TemplateObject, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DNSErrorHelper.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Helper.TemplateObject.1, In Quarantäne, [042c02e356348bab69a37c09946e2ad6],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\${dtUserElevationPolicyID}, In Quarantäne, [9c943da876145ed818774a385da7b54b],
Malware.Trace, HKU\S-1-5-21-2422082488-33307941-859794934-1002\SOFTWARE\DC3_FEXEC, In Quarantäne, [b87809dcdeacff372c4f6192c340df21],
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 3
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
PUP.Optional.OptimizerPro.A, C:\Users\Alexandra\Documents\Optimizer Pro, In Quarantäne, [042ca243e4a652e4b49ee8af39cb768a],
PUP.Optional.DataMngr.A, C:\ProgramData\Datamngr, In Quarantäne, [32fe0bdaf5954beb53b49564e919df21],
Dateien: 91
Trojan.Dropper.SFXAI, C:\Users\Alexandra\AppData\Roaming\27072014.scr, In Quarantäne, [68c81cc90585c472aed162c6dd24ac54],
Misused.Legit.AI, C:\Users\Alexandra\265oyte47\.com, In Quarantäne, [cf6155903b4f57dfaf94939bc53c55ab],
Misused.Legit.AI, C:\Users\Alexandra\8fdhc8i6\OWryTUenk.exe, In Quarantäne, [e9472fb66228c274c52f6dc8837e39c7],
PUP.Optional.DownloadSponsor, C:\Users\Alexandra\Downloads\find-it.exe, In Quarantäne, [0b25b82d8bff4fe7e9b1b43cd82cc63a],
PUP.Optional.Conduit.A, C:\Users\Alexandra\Downloads\Kies3Setup.exe, In Quarantäne, [70c0479e2664fd39c1e756bbe120c739],
PUP.Optional.InstallCore.A, C:\Users\Alexandra\Downloads\MediaPlayerSetup.exe, In Quarantäne, [e14fd510cac065d17075e15219e7c23e],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-17-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-18-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-19-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-20-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-21-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-22-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-23-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-24-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-25-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-26-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-27-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-28-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-29-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-06-30-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-01-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-03-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-04-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-05-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-06-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-07-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-08-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-09-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-10-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-11-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-13-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-14-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-15-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-16-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-21-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-22-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-23-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-24-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-26-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-27-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-28-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-29-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-30-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-31-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-01-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-02-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-03-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-08-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-09-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-10-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-12-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-14-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-15-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-08-23-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-04-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-07-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-08-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-09-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-10-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-11-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-12-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-13-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-14-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-15-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-16-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-17-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-20-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-24-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-28-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-02-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-07-25-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-09-05-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-03-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-07-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-08-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-09-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-10-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-13-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-17-6.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-18-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-21-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-22-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-23-5.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-25-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-27-2.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-10-28-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-11-02-1.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-11-04-3.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-11-05-4.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
Stolen.Data, C:\Users\Alexandra\AppData\Roaming\dclogs\2014-11-08-7.dc, In Quarantäne, [ea46f6ef4b3f75c1914f77aa1be98d73],
PUP.Optional.OptimizerPro.A, C:\Users\Alexandra\Documents\Optimizer Pro\CookiesException.txt, In Quarantäne, [042ca243e4a652e4b49ee8af39cb768a],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.1 (07.16.2015:1)
OS: Windows 8.1 x64
Ran by Alexandra on 23.07.2015 at 18:09:14,86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\WinZip Malware Protector_startup
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7553EA3C-F8DA-4188-B7BC-956894EA54F5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Clients\StartMenuInternet\Torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7553EA3C-F8DA-4188-B7BC-956894EA54F5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7553EA3C-F8DA-4188-B7BC-956894EA54F5}
~~~ Files
Successfully deleted: [File] C:\Users\Public\Desktop\winzip malware protector.lnk
~~~ Folders
Successfully deleted: [Folder] C:\Program Files (x86)\myfree codec
Successfully deleted: [Folder] C:\ProgramData\nico mak computing
Successfully deleted: [Folder] C:\Users\Alexandra\AppData\Roaming\nico mak computing
~~~ FireFox
Emptied folder: C:\Users\Alexandra\AppData\Roaming\mozilla\firefox\profiles\8yi0niup.default\minidumps [9 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.07.2015 at 18:13:28,98
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
FRST Additions Logfile:
[CODE]Additional
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:20-07-2015
Ran by Alexandra at 2015-07-23 16:53:44
Running from C:\Users\Alexandra\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2422082488-33307941-859794934-500 - Administrator - Disabled)
Alexandra (S-1-5-21-2422082488-33307941-859794934-1002 - Administrator - Enabled) => C:\Users\Alexandra
Gast (S-1-5-21-2422082488-33307941-859794934-501 - Limited - Disabled)
UpdatusUser (S-1-5-21-2422082488-33307941-859794934-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
3DataManager (HKLM-x32\...\3DataManager) (Version: 3.5 - 3DataManager)
4500_G510gm_Help (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
4500G510gm (x32 Version: 140.0.001.000 - Hewlett-Packard) Hidden
4500G510gm_Software_Min (x32 Version: 140.0.001.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.05 - Piriform)
CHIP Best Deal (HKLM-x32\...\{7553EA3C-F8DA-4188-B7BC-956894EA54F5}) (Version: 1.4.21 - Ciuvo GmbH)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 140.0.185.000 - Hewlett-Packard) Hidden
Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) Hidden
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.)
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Officejet 4500 G510g-m 14.0 Rel. 6 (HKLM\...\{C55BF64E-60E1-494C-B1EB-97A008141A55}) (Version: 14.0 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)
HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
IT9130 Driver v12.2.3.1 (HKLM-x32\...\IT9130 DriverInstaller_12.2.3.1) (Version: - )
MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Mediathek (HKLM-x32\...\{EFFED0C0-5299-422E-AFE6-8B8066D18A2A}) (Version: 1.4.0 - Medion)
Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4675.1003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla)
Mozilla Thunderbird 38.0.1 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 38.0.1 (x86 de)) (Version: 38.0.1 - Mozilla)
MyFreeCodec (HKU\S-1-5-21-2422082488-33307941-859794934-1002\...\MyFreeCodec) (Version: - )
Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden
NVIDIA 3D Vision Treiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
PHotkey (HKLM-x32\...\{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}) (Version: 1.00.0081 - Pegatron Corporation)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6722 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Smart Switch v1.4.7 (HKLM-x32\...\Smart Switch) (Version: v1.4.7 - GIGABYTE TECHNOLOGY CO.,LTD.)
SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip Malware Protector (HKLM-x32\...\WinZip Malware Protector_is1) (Version: 2.1.1000.14260 - WinZip International LLC)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2422082488-33307941-859794934-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
==================== Restore Points =========================
17-07-2015 15:15:16 Uniblue PC Mechanic installation
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {026E154A-52C6-4815-92D4-6072D677E1C0} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {0438F22F-32A1-4FF4-AA2C-1FD6D396A466} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe [2015-03-13] (Nico Mak Computing)
Task: {08BE7C4C-4FE2-4BBD-8C0A-AF0F145F0F45} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {39D0F636-137E-48E1-A754-84AB3DD7A79B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
Task: {5DE4DF0D-A73B-42B4-92FB-230BA846D24E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {6C101D18-DAA6-4799-8928-978661752FB2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated)
Task: {8703140F-CB23-400D-B984-9D0DB88C0ADB} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {951DCF2F-0A04-40A5-8B36-6152848BB900} - System32\Tasks\chipSWU => Cscript.exe "C:\Program Files (x86)\chip\Internet Explorer\swu.vbs"
Task: {A8894C2C-511B-4DF0-A580-3CF0D6057CFD} - System32\Tasks\Installer for avg_safeguard => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\thirdpartyinstaller.exe <==== ATTENTION
Task: {ACA00654-4D80-465B-B5B9-0E62712D5865} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {CCCB1A73-B348-48A3-98EA-0DAB644BAA6B} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {DA08D4DF-9078-40B6-910F-4DF57D471E2F} - System32\Tasks\{67AA193C-B398-40E7-B3AF-48489F8A5BCE} => pcalua.exe -a "C:\Program Files (x86)\3DataManager\Uninstaller.exe"
Task: {DC136A3D-DDEF-4AD7-B72A-C9B70D663120} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-25] (Avast Software s.r.o.)
Task: {ED3D0FFD-C9B7-4CF2-B8DF-A5C9544514B2} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {F8EB148D-41AD-4A29-A282-5350C47E51AF} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-06-11] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Installer for avg_safeguard.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\thirdpartyinstaller.exe C:\Users\ALEXAN~1\AppData\Local\Temp\Uniblue\Offers\AVG_Safeguard.exe --stat-prefix sp --installer-type web --offer-name avg_safeguard --params /PASSWORD=TB38GF9P66 /DISTRIBUTIONSOURCE=ub011 /FINISHURL=http:/toolbar.avg.com <==== ATTENTION
==================== Loaded Modules (Whitelisted) ==============
2013-10-27 09:03 - 2013-10-27 09:03 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2015-06-23 19:18 - 2013-10-23 10:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-11-29 15:32 - 2012-11-29 15:53 - 00805888 _____ () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2014-04-20 19:08 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2013-09-26 09:18 - 2012-07-05 06:03 - 00343024 ____N () C:\Program Files (x86)\3DataManager\WTGService.exe
2012-11-29 15:32 - 2012-11-27 17:18 - 02215424 _____ () C:\Program Files (x86)\PHotkey\PHotkey.exe
2013-09-26 09:18 - 2012-07-10 15:38 - 00506864 ____N () C:\Program Files (x86)\3DataManager\3DataManager_Launcher.exe
2012-11-29 15:32 - 2010-01-12 19:36 - 00117256 _____ () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2012-11-29 15:32 - 2010-01-12 19:36 - 00121864 _____ () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2012-11-29 15:32 - 2010-12-17 16:04 - 00449032 _____ () C:\Program Files (x86)\PHotkey\ATouch64.exe
2012-11-29 15:32 - 2012-10-23 20:07 - 03471872 _____ () C:\Program Files (x86)\PHotkey\POSD.exe
2012-11-29 15:32 - 2012-08-08 20:10 - 07536128 _____ () C:\Program Files (x86)\PHotkey\GPMTray.exe
2015-05-09 11:35 - 2015-05-09 11:35 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-05-09 11:34 - 2015-05-09 11:34 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-07-21 14:17 - 2015-07-21 14:17 - 02957312 _____ () C:\Program Files\AVAST Software\Avast\defs\15072100\algo.dll
2015-07-23 12:56 - 2015-07-23 12:56 - 02957312 _____ () C:\Program Files\AVAST Software\Avast\defs\15072300\algo.dll
2013-10-27 09:03 - 2013-10-27 09:03 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2015-07-18 14:10 - 2013-02-28 16:53 - 00886272 _____ () C:\Program Files (x86)\WinZip Malware Protector\System.Data.SQLite.dll
2015-07-18 14:10 - 2015-03-13 14:34 - 01717936 _____ () C:\Program Files (x86)\WinZip Malware Protector\aspsys.dll
2015-07-18 14:10 - 2013-02-28 16:53 - 00168448 _____ () C:\Program Files (x86)\WinZip Malware Protector\UNRAR.DLL
2012-11-29 15:32 - 2009-12-18 17:36 - 00973432 _____ () C:\Program Files (x86)\PHotkey\acAuth.dll
2012-11-29 15:32 - 2009-12-18 17:41 - 00129544 _____ () C:\Program Files (x86)\PHotkey\GFNEX.dll
2015-05-09 11:35 - 2015-05-09 11:35 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-07-02 17:11 - 2015-07-02 17:11 - 00016384 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\f95a84be655dce46534e2570f3b8bef6\PSIClient.ni.dll
2012-11-14 10:20 - 2012-06-25 11:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-09-26 09:18 - 2012-07-13 14:19 - 00073728 ____N () C:\Program Files (x86)\3DataManager\WtgDriverInstall.dll
2013-09-26 09:18 - 2012-07-13 14:21 - 00745472 ____N () C:\Program Files (x86)\3DataManager\WtgCore.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00110592 ____N () C:\Program Files (x86)\3DataManager\WtgDatabase.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00208896 ____N () C:\Program Files (x86)\3DataManager\WtgDetection.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00086016 ____N () C:\Program Files (x86)\3DataManager\WtgDialup.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00098304 ____N () C:\Program Files (x86)\3DataManager\WtgPorts.dll
2013-09-26 09:18 - 2012-07-13 14:19 - 00098304 ____N () C:\Program Files (x86)\3DataManager\WtgUtil.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00139264 ____N () C:\Program Files (x86)\3DataManager\WtgBluetooth.dll
2013-09-26 09:18 - 2012-07-13 14:19 - 00012288 ____N () C:\Program Files (x86)\3DataManager\WTGDebugs.dll
2013-09-26 09:18 - 2011-11-10 09:48 - 01105920 ____N () C:\Program Files (x86)\3DataManager\NDISAPI.dll
2013-09-26 09:19 - 2011-06-09 10:44 - 00602112 ____N () C:\Program Files (x86)\3DataManager\WTGXMLUtil.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00274432 ____N () C:\Program Files (x86)\3DataManager\WTGSMSPCClient.Dll
2013-09-26 09:18 - 2012-07-13 14:21 - 00012800 ____N () C:\Program Files (x86)\3DataManager\WTGDriverInstallX.Dll
2013-09-26 09:18 - 2012-06-12 10:02 - 00249856 ____N () C:\Program Files (x86)\3DataManager\WtgMobileBroadband7.dll
2015-04-04 14:55 - 2015-06-08 21:23 - 00153712 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2015-04-04 14:55 - 2015-06-08 21:23 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:373E1720
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2422082488-33307941-859794934-1001\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-2422082488-33307941-859794934-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme2\img8.jpg
DNS Servers: 213.94.78.16 - 213.94.78.17
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk"
HKLM\...\StartupApproved\Run32: => "HP Software Update"
HKLM\...\StartupApproved\Run32: => "SaferSurf Tray"
HKLM\...\StartupApproved\Run32: => "BingDesktop"
HKU\S-1-5-21-2422082488-33307941-859794934-1002\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-2422082488-33307941-859794934-1002\...\StartupApproved\Run: => "iMesh"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{43B91403-4632-40CE-B2E0-4B153C50B59A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{EC5FA963-0DDE-4CF8-8848-0334902805B4}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [UDP Query User{70784348-A80B-434C-818A-ACB9E460DD93}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{83893365-AAFB-4F4E-8893-D33E9367C725}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{937F8D4B-DA1F-4B32-A386-CB433FB07ABB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F873DA5C-D77D-4729-99A3-8A9B353B9CD5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{87086A43-1DEE-46F3-8D71-B57884A97A61}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{D4A39ACA-F147-4674-ADD8-40E3625667C9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{928AE05C-65F3-474B-9850-F92563006BDE}] => (Allow) C:\Users\Alexandra\AppData\Local\Torch\Application\torch.exe
FirewallRules: [{EE45D7EA-FEFC-4F45-AE39-B21EA50040D1}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{525A74F7-2291-458D-84F6-AC7F612072A8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{C841C1C6-3D67-4199-94EA-C2AFFA1C59E5}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{C337F121-6331-44E4-B154-F923E1C4DFC1}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{F96C6669-290F-4370-B3E8-26FFBFDAEF7D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{4D5BF7EF-EEF6-4910-8DFD-FB1E1307BBC4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{A483BAE6-6F91-4FD6-9EF3-14A69F5D08FB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{CBE20616-B267-4F02-8B71-827F85C5C957}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{0E36A7E9-1D0A-4D55-BFD4-C21EEDE1FD62}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{1AFE496F-2A21-46D5-A3C2-01FD001E8665}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{715171B6-D864-4B74-9749-85BF3052A34A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{8FA09228-E7B1-42FF-8F29-31D2D8744AEF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{DF5773C0-A2F2-4C0A-A01E-7F27CA58377E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{1B8A3DD5-FA4B-42EC-A0D8-0BFA9398A0EA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{C8CDF691-BAC5-4A27-B9BB-6BF5DA16FF35}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{F15C6FBF-FBD7-49DF-9A26-E9EB431E69E8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{6FE39E42-A9DE-41A6-9C11-67C8545F7445}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{560CFA07-1F50-4FC3-B7B5-8D342EF9C556}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{0A8DFF77-6F90-428B-94F1-0AD6CB03E64E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{939E0F63-0DCD-417A-B271-8A32740EE73C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{51B1AE16-8E82-48D9-A12B-458A23A66B46}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{2FCFAA31-5F2E-4EE9-97F6-10EDF33A2D2E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{DD411DF8-5638-4E1B-955B-A143E18D1E75}] => (Allow) LPort=1900
FirewallRules: [{E5927AC1-9F11-402F-8D8D-15DC242D4743}] => (Allow) LPort=2869
FirewallRules: [{C18D1F24-3C12-467C-BC95-1FF7786E3A43}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{69CEFCF5-250A-4CD8-89A3-FC635E843F0D}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{F86EB3E8-CEAA-41E1-9FB1-B1986FD52190}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/23/2015 11:45:31 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/22/2015 05:44:42 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/22/2015 12:12:41 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/21/2015 06:46:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: thunderbird.exe, Version: 38.0.1.5637, Zeitstempel: 0x5575e6c2
Name des fehlerhaften Moduls: xul.dll, Version: 38.0.1.5637, Zeitstempel: 0x5575e79d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0008749b
ID des fehlerhaften Prozesses: 0xe44
Startzeit der fehlerhaften Anwendung: 0xthunderbird.exe0
Pfad der fehlerhaften Anwendung: thunderbird.exe1
Pfad des fehlerhaften Moduls: thunderbird.exe2
Berichtskennung: thunderbird.exe3
Vollständiger Name des fehlerhaften Pakets: thunderbird.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: thunderbird.exe5
Error: (07/21/2015 02:59:50 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/20/2015 12:36:00 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/19/2015 03:29:43 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/18/2015 07:22:38 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/18/2015 12:58:05 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/17/2015 05:02:02 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Der Index kann nicht initialisiert werden.
Details:
Das angegebene Objekt wurde nicht gefunden. Geben Sie den Namen eines vorhandenen Objekts an. (HRESULT : 0x80040d06) (0x80040d06)
System errors:
=============
Error: (07/23/2015 04:43:56 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT-AUTORITÄT)
Description: Für den Miniport "HUAWEI Mobile Connect - Network Adapter, {911A0AC8-7281-402E-B978-1C522B971556}" ist das Ereignis "74" aufgetreten.
Error: (07/23/2015 11:20:59 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT-AUTORITÄT)
Description: Für den Miniport "HUAWEI Mobile Connect - Network Adapter, {911A0AC8-7281-402E-B978-1C522B971556}" ist das Ereignis "74" aufgetreten.
Error: (07/22/2015 06:17:00 PM) (Source: DCOM) (EventID: 10010) (User: Liabsladele)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (07/22/2015 06:16:30 PM) (Source: DCOM) (EventID: 10010) (User: Liabsladele)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (07/22/2015 05:19:44 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT-AUTORITÄT)
Description: Für den Miniport "HUAWEI Mobile Connect - Network Adapter, {911A0AC8-7281-402E-B978-1C522B971556}" ist das Ereignis "74" aufgetreten.
Error: (07/22/2015 11:34:49 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde nicht richtig gestartet.
Error: (07/22/2015 11:32:20 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Intel(R) Rapid Storage Technology" wurde nicht richtig gestartet.
Error: (07/22/2015 11:29:40 AM) (Source: DCOM) (EventID: 10010) (User: Liabsladele)
Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793}
Error: (07/22/2015 11:29:10 AM) (Source: DCOM) (EventID: 10010) (User: Liabsladele)
Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793}
Error: (07/22/2015 11:27:42 AM) (Source: BTHUSB) (EventID: 30) (User: )
Description: Der lokale Adapter bietet keine Unterstützung für einen wichtigen Controllerstatus für energiearme Geräte. Die mindestens erforderliche unterstützte Statusmaske ist "0x1f7fffff", vorhanden ist jedoch "0x1f3fffff". Die Funktionalität für energiearme Geräte wird deaktiviert.
Microsoft Office:
=========================
Error: (07/23/2015 11:45:31 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/22/2015 05:44:42 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/22/2015 12:12:41 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/21/2015 06:46:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: thunderbird.exe38.0.1.56375575e6c2xul.dll38.0.1.56375575e79dc00000050008749be4401d0c3c966f13de8C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exeC:\Program Files (x86)\Mozilla Thunderbird\xul.dllfe33257e-2fc7-11e5-800d-6036dd23ec53
Error: (07/21/2015 02:59:50 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/20/2015 12:36:00 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/19/2015 03:29:43 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/18/2015 07:22:38 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/18/2015 12:58:05 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/17/2015 05:02:02 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description:
Details:
Das angegebene Objekt wurde nicht gefunden. Geben Sie den Namen eines vorhandenen Objekts an. (HRESULT : 0x80040d06) (0x80040d06)
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-3110M CPU @ 2.40GHz
Percentage of memory in use: 24%
Total physical RAM: 8070.57 MB
Available physical RAM: 6132.48 MB
Total Virtual: 9350.57 MB
Available Virtual: 7187.09 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:869.36 GB) (Free:806.15 GB) NTFS
Drive d: (Recover) (Fixed) (Total:60 GB) (Free:40.8 GB) NTFS
Drive e: (3DataManager) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 462A80D0)
Partition: GPT Partition Type.
==================== End of log ============================ --- --- ---
--- --- --- Code:
Additional
FRST Logfile:
Code:
scan result of Farbar Recovery Scan Tool (x64) Version:20-07-2015
Ran by Alexandra at 2015-07-23 16:53:44
Running from C:\Users\Alexandra\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2422082488-33307941-859794934-500 - Administrator - Disabled)
Alexandra (S-1-5-21-2422082488-33307941-859794934-1002 - Administrator - Enabled) => C:\Users\Alexandra
Gast (S-1-5-21-2422082488-33307941-859794934-501 - Limited - Disabled)
UpdatusUser (S-1-5-21-2422082488-33307941-859794934-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
3DataManager (HKLM-x32\...\3DataManager) (Version: 3.5 - 3DataManager)
4500_G510gm_Help (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
4500G510gm (x32 Version: 140.0.001.000 - Hewlett-Packard) Hidden
4500G510gm_Software_Min (x32 Version: 140.0.001.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.05 - Piriform)
CHIP Best Deal (HKLM-x32\...\{7553EA3C-F8DA-4188-B7BC-956894EA54F5}) (Version: 1.4.21 - Ciuvo GmbH)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 140.0.185.000 - Hewlett-Packard) Hidden
Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) Hidden
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.)
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Officejet 4500 G510g-m 14.0 Rel. 6 (HKLM\...\{C55BF64E-60E1-494C-B1EB-97A008141A55}) (Version: 14.0 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)
HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
IT9130 Driver v12.2.3.1 (HKLM-x32\...\IT9130 DriverInstaller_12.2.3.1) (Version: - )
MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Mediathek (HKLM-x32\...\{EFFED0C0-5299-422E-AFE6-8B8066D18A2A}) (Version: 1.4.0 - Medion)
Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4675.1003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla)
Mozilla Thunderbird 38.0.1 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 38.0.1 (x86 de)) (Version: 38.0.1 - Mozilla)
MyFreeCodec (HKU\S-1-5-21-2422082488-33307941-859794934-1002\...\MyFreeCodec) (Version: - )
Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden
NVIDIA 3D Vision Treiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
PHotkey (HKLM-x32\...\{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}) (Version: 1.00.0081 - Pegatron Corporation)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6722 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Smart Switch v1.4.7 (HKLM-x32\...\Smart Switch) (Version: v1.4.7 - GIGABYTE TECHNOLOGY CO.,LTD.)
SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip Malware Protector (HKLM-x32\...\WinZip Malware Protector_is1) (Version: 2.1.1000.14260 - WinZip International LLC)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2422082488-33307941-859794934-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
==================== Restore Points =========================
17-07-2015 15:15:16 Uniblue PC Mechanic installation
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {026E154A-52C6-4815-92D4-6072D677E1C0} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {0438F22F-32A1-4FF4-AA2C-1FD6D396A466} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe [2015-03-13] (Nico Mak Computing)
Task: {08BE7C4C-4FE2-4BBD-8C0A-AF0F145F0F45} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {39D0F636-137E-48E1-A754-84AB3DD7A79B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
Task: {5DE4DF0D-A73B-42B4-92FB-230BA846D24E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {6C101D18-DAA6-4799-8928-978661752FB2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated)
Task: {8703140F-CB23-400D-B984-9D0DB88C0ADB} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {951DCF2F-0A04-40A5-8B36-6152848BB900} - System32\Tasks\chipSWU => Cscript.exe "C:\Program Files (x86)\chip\Internet Explorer\swu.vbs"
Task: {A8894C2C-511B-4DF0-A580-3CF0D6057CFD} - System32\Tasks\Installer for avg_safeguard => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\thirdpartyinstaller.exe <==== ATTENTION
Task: {ACA00654-4D80-465B-B5B9-0E62712D5865} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {CCCB1A73-B348-48A3-98EA-0DAB644BAA6B} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {DA08D4DF-9078-40B6-910F-4DF57D471E2F} - System32\Tasks\{67AA193C-B398-40E7-B3AF-48489F8A5BCE} => pcalua.exe -a "C:\Program Files (x86)\3DataManager\Uninstaller.exe"
Task: {DC136A3D-DDEF-4AD7-B72A-C9B70D663120} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-25] (Avast Software s.r.o.)
Task: {ED3D0FFD-C9B7-4CF2-B8DF-A5C9544514B2} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {F8EB148D-41AD-4A29-A282-5350C47E51AF} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-06-11] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Installer for avg_safeguard.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\thirdpartyinstaller.exe C:\Users\ALEXAN~1\AppData\Local\Temp\Uniblue\Offers\AVG_Safeguard.exe --stat-prefix sp --installer-type web --offer-name avg_safeguard --params /PASSWORD=TB38GF9P66 /DISTRIBUTIONSOURCE=ub011 /FINISHURL=http:/toolbar.avg.com <==== ATTENTION
==================== Loaded Modules (Whitelisted) ==============
2013-10-27 09:03 - 2013-10-27 09:03 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2015-06-23 19:18 - 2013-10-23 10:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-11-29 15:32 - 2012-11-29 15:53 - 00805888 _____ () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2014-04-20 19:08 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2013-09-26 09:18 - 2012-07-05 06:03 - 00343024 ____N () C:\Program Files (x86)\3DataManager\WTGService.exe
2012-11-29 15:32 - 2012-11-27 17:18 - 02215424 _____ () C:\Program Files (x86)\PHotkey\PHotkey.exe
2013-09-26 09:18 - 2012-07-10 15:38 - 00506864 ____N () C:\Program Files (x86)\3DataManager\3DataManager_Launcher.exe
2012-11-29 15:32 - 2010-01-12 19:36 - 00117256 _____ () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2012-11-29 15:32 - 2010-01-12 19:36 - 00121864 _____ () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2012-11-29 15:32 - 2010-12-17 16:04 - 00449032 _____ () C:\Program Files (x86)\PHotkey\ATouch64.exe
2012-11-29 15:32 - 2012-10-23 20:07 - 03471872 _____ () C:\Program Files (x86)\PHotkey\POSD.exe
2012-11-29 15:32 - 2012-08-08 20:10 - 07536128 _____ () C:\Program Files (x86)\PHotkey\GPMTray.exe
2015-05-09 11:35 - 2015-05-09 11:35 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-05-09 11:34 - 2015-05-09 11:34 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-07-21 14:17 - 2015-07-21 14:17 - 02957312 _____ () C:\Program Files\AVAST Software\Avast\defs\15072100\algo.dll
2015-07-23 12:56 - 2015-07-23 12:56 - 02957312 _____ () C:\Program Files\AVAST Software\Avast\defs\15072300\algo.dll
2013-10-27 09:03 - 2013-10-27 09:03 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2015-07-18 14:10 - 2013-02-28 16:53 - 00886272 _____ () C:\Program Files (x86)\WinZip Malware Protector\System.Data.SQLite.dll
2015-07-18 14:10 - 2015-03-13 14:34 - 01717936 _____ () C:\Program Files (x86)\WinZip Malware Protector\aspsys.dll
2015-07-18 14:10 - 2013-02-28 16:53 - 00168448 _____ () C:\Program Files (x86)\WinZip Malware Protector\UNRAR.DLL
2012-11-29 15:32 - 2009-12-18 17:36 - 00973432 _____ () C:\Program Files (x86)\PHotkey\acAuth.dll
2012-11-29 15:32 - 2009-12-18 17:41 - 00129544 _____ () C:\Program Files (x86)\PHotkey\GFNEX.dll
2015-05-09 11:35 - 2015-05-09 11:35 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-07-02 17:11 - 2015-07-02 17:11 - 00016384 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\f95a84be655dce46534e2570f3b8bef6\PSIClient.ni.dll
2012-11-14 10:20 - 2012-06-25 11:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-09-26 09:18 - 2012-07-13 14:19 - 00073728 ____N () C:\Program Files (x86)\3DataManager\WtgDriverInstall.dll
2013-09-26 09:18 - 2012-07-13 14:21 - 00745472 ____N () C:\Program Files (x86)\3DataManager\WtgCore.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00110592 ____N () C:\Program Files (x86)\3DataManager\WtgDatabase.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00208896 ____N () C:\Program Files (x86)\3DataManager\WtgDetection.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00086016 ____N () C:\Program Files (x86)\3DataManager\WtgDialup.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00098304 ____N () C:\Program Files (x86)\3DataManager\WtgPorts.dll
2013-09-26 09:18 - 2012-07-13 14:19 - 00098304 ____N () C:\Program Files (x86)\3DataManager\WtgUtil.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00139264 ____N () C:\Program Files (x86)\3DataManager\WtgBluetooth.dll
2013-09-26 09:18 - 2012-07-13 14:19 - 00012288 ____N () C:\Program Files (x86)\3DataManager\WTGDebugs.dll
2013-09-26 09:18 - 2011-11-10 09:48 - 01105920 ____N () C:\Program Files (x86)\3DataManager\NDISAPI.dll
2013-09-26 09:19 - 2011-06-09 10:44 - 00602112 ____N () C:\Program Files (x86)\3DataManager\WTGXMLUtil.dll
2013-09-26 09:18 - 2012-07-13 14:20 - 00274432 ____N () C:\Program Files (x86)\3DataManager\WTGSMSPCClient.Dll
2013-09-26 09:18 - 2012-07-13 14:21 - 00012800 ____N () C:\Program Files (x86)\3DataManager\WTGDriverInstallX.Dll
2013-09-26 09:18 - 2012-06-12 10:02 - 00249856 ____N () C:\Program Files (x86)\3DataManager\WtgMobileBroadband7.dll
2015-04-04 14:55 - 2015-06-08 21:23 - 00153712 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2015-04-04 14:55 - 2015-06-08 21:23 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:373E1720
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2422082488-33307941-859794934-1001\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-2422082488-33307941-859794934-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme2\img8.jpg
DNS Servers: 213.94.78.16 - 213.94.78.17
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk"
HKLM\...\StartupApproved\Run32: => "HP Software Update"
HKLM\...\StartupApproved\Run32: => "SaferSurf Tray"
HKLM\...\StartupApproved\Run32: => "BingDesktop"
HKU\S-1-5-21-2422082488-33307941-859794934-1002\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-2422082488-33307941-859794934-1002\...\StartupApproved\Run: => "iMesh"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{43B91403-4632-40CE-B2E0-4B153C50B59A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{EC5FA963-0DDE-4CF8-8848-0334902805B4}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [UDP Query User{70784348-A80B-434C-818A-ACB9E460DD93}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{83893365-AAFB-4F4E-8893-D33E9367C725}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{937F8D4B-DA1F-4B32-A386-CB433FB07ABB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F873DA5C-D77D-4729-99A3-8A9B353B9CD5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{87086A43-1DEE-46F3-8D71-B57884A97A61}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{D4A39ACA-F147-4674-ADD8-40E3625667C9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{928AE05C-65F3-474B-9850-F92563006BDE}] => (Allow) C:\Users\Alexandra\AppData\Local\Torch\Application\torch.exe
FirewallRules: [{EE45D7EA-FEFC-4F45-AE39-B21EA50040D1}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{525A74F7-2291-458D-84F6-AC7F612072A8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{C841C1C6-3D67-4199-94EA-C2AFFA1C59E5}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{C337F121-6331-44E4-B154-F923E1C4DFC1}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{F96C6669-290F-4370-B3E8-26FFBFDAEF7D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{4D5BF7EF-EEF6-4910-8DFD-FB1E1307BBC4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{A483BAE6-6F91-4FD6-9EF3-14A69F5D08FB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{CBE20616-B267-4F02-8B71-827F85C5C957}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{0E36A7E9-1D0A-4D55-BFD4-C21EEDE1FD62}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{1AFE496F-2A21-46D5-A3C2-01FD001E8665}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{715171B6-D864-4B74-9749-85BF3052A34A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{8FA09228-E7B1-42FF-8F29-31D2D8744AEF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{DF5773C0-A2F2-4C0A-A01E-7F27CA58377E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{1B8A3DD5-FA4B-42EC-A0D8-0BFA9398A0EA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{C8CDF691-BAC5-4A27-B9BB-6BF5DA16FF35}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{F15C6FBF-FBD7-49DF-9A26-E9EB431E69E8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{6FE39E42-A9DE-41A6-9C11-67C8545F7445}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{560CFA07-1F50-4FC3-B7B5-8D342EF9C556}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{0A8DFF77-6F90-428B-94F1-0AD6CB03E64E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{939E0F63-0DCD-417A-B271-8A32740EE73C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{51B1AE16-8E82-48D9-A12B-458A23A66B46}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{2FCFAA31-5F2E-4EE9-97F6-10EDF33A2D2E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{DD411DF8-5638-4E1B-955B-A143E18D1E75}] => (Allow) LPort=1900
FirewallRules: [{E5927AC1-9F11-402F-8D8D-15DC242D4743}] => (Allow) LPort=2869
FirewallRules: [{C18D1F24-3C12-467C-BC95-1FF7786E3A43}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{69CEFCF5-250A-4CD8-89A3-FC635E843F0D}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{F86EB3E8-CEAA-41E1-9FB1-B1986FD52190}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/23/2015 11:45:31 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/22/2015 05:44:42 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/22/2015 12:12:41 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/21/2015 06:46:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: thunderbird.exe, Version: 38.0.1.5637, Zeitstempel: 0x5575e6c2
Name des fehlerhaften Moduls: xul.dll, Version: 38.0.1.5637, Zeitstempel: 0x5575e79d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0008749b
ID des fehlerhaften Prozesses: 0xe44
Startzeit der fehlerhaften Anwendung: 0xthunderbird.exe0
Pfad der fehlerhaften Anwendung: thunderbird.exe1
Pfad des fehlerhaften Moduls: thunderbird.exe2
Berichtskennung: thunderbird.exe3
Vollständiger Name des fehlerhaften Pakets: thunderbird.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: thunderbird.exe5
Error: (07/21/2015 02:59:50 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/20/2015 12:36:00 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/19/2015 03:29:43 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/18/2015 07:22:38 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/18/2015 12:58:05 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/17/2015 05:02:02 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Der Index kann nicht initialisiert werden.
Details:
Das angegebene Objekt wurde nicht gefunden. Geben Sie den Namen eines vorhandenen Objekts an. (HRESULT : 0x80040d06) (0x80040d06)
System errors:
=============
Error: (07/23/2015 04:43:56 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT-AUTORITÄT)
Description: Für den Miniport "HUAWEI Mobile Connect - Network Adapter, {911A0AC8-7281-402E-B978-1C522B971556}" ist das Ereignis "74" aufgetreten.
Error: (07/23/2015 11:20:59 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT-AUTORITÄT)
Description: Für den Miniport "HUAWEI Mobile Connect - Network Adapter, {911A0AC8-7281-402E-B978-1C522B971556}" ist das Ereignis "74" aufgetreten.
Error: (07/22/2015 06:17:00 PM) (Source: DCOM) (EventID: 10010) (User: Liabsladele)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (07/22/2015 06:16:30 PM) (Source: DCOM) (EventID: 10010) (User: Liabsladele)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (07/22/2015 05:19:44 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT-AUTORITÄT)
Description: Für den Miniport "HUAWEI Mobile Connect - Network Adapter, {911A0AC8-7281-402E-B978-1C522B971556}" ist das Ereignis "74" aufgetreten.
Error: (07/22/2015 11:34:49 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde nicht richtig gestartet.
Error: (07/22/2015 11:32:20 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Intel(R) Rapid Storage Technology" wurde nicht richtig gestartet.
Error: (07/22/2015 11:29:40 AM) (Source: DCOM) (EventID: 10010) (User: Liabsladele)
Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793}
Error: (07/22/2015 11:29:10 AM) (Source: DCOM) (EventID: 10010) (User: Liabsladele)
Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793}
Error: (07/22/2015 11:27:42 AM) (Source: BTHUSB) (EventID: 30) (User: )
Description: Der lokale Adapter bietet keine Unterstützung für einen wichtigen Controllerstatus für energiearme Geräte. Die mindestens erforderliche unterstützte Statusmaske ist "0x1f7fffff", vorhanden ist jedoch "0x1f3fffff". Die Funktionalität für energiearme Geräte wird deaktiviert.
Microsoft Office:
=========================
Error: (07/23/2015 11:45:31 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/22/2015 05:44:42 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/22/2015 12:12:41 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/21/2015 06:46:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: thunderbird.exe38.0.1.56375575e6c2xul.dll38.0.1.56375575e79dc00000050008749be4401d0c3c966f13de8C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exeC:\Program Files (x86)\Mozilla Thunderbird\xul.dllfe33257e-2fc7-11e5-800d-6036dd23ec53
Error: (07/21/2015 02:59:50 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/20/2015 12:36:00 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/19/2015 03:29:43 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/18/2015 07:22:38 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/18/2015 12:58:05 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (07/17/2015 05:02:02 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description:
Details:
Das angegebene Objekt wurde nicht gefunden. Geben Sie den Namen eines vorhandenen Objekts an. (HRESULT : 0x80040d06) (0x80040d06)
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-3110M CPU @ 2.40GHz
Percentage of memory in use: 24%
Total physical RAM: 8070.57 MB
Available physical RAM: 6132.48 MB
Total Virtual: 9350.57 MB
Available Virtual: 7187.09 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:869.36 GB) (Free:806.15 GB) NTFS
Drive d: (Recover) (Fixed) (Total:60 GB) (Free:40.8 GB) NTFS
Drive e: (3DataManager) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 462A80D0)
Partition: GPT Partition Type.
==================== End of log ============================ --- --- --- |