Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 25.09.2014, 16:06   #1
Raphael_S
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Hi,

wenn ich Dateien auf einen zuvor formatierten USB-Stick kopiere, erscheinen diese dort.
Wenn ich dann das Explorer-Fenster schließe und wieder öffne, werden keine Dateien auf dem Stick angezeigt.
In den Eigenschaften des Sticks ist der Speicherplatz jedoch belegt.
Beim Scan des Sticks mit BitDefander findet dieser die zu scannenden Dateien, zeigt aber keine Infektion an.
Lasse ich Bitdefender über die Quell-Dateien laufen wird ebenfalls keine Infektion angezeigt.

Ich würde ja den PC einfach formatieren, aber ich kann wichtige Daten ja nicht per USB sichern :-/

Im Anschluss die Log-Dateien aus defogger, frst und gmer:

defogger:
Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 16:01 on 25/09/2014 (rspri_000)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
HKCU:DAEMON Tools Lite -> Removed

Checking for services/drivers...


-=E.O.F=-
         
frst:
Code:
ATTFilter
Running from C:\Users\rspri_000\Downloads
Loaded Profile: rspri_000 (Available profiles: rspri_000)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-09-2014
Ran by rspri_000 (administrator) on RAPHAELS_PC on 25-09-2014 15:41:40
Platform: Windows 8 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) D:\Tools\ZuneLauncher.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Spotify Ltd) C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe
(sw4you) C:\Program Files (x86)\Hardcopy\hardcopy.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwtxapps.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\odscanui.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\seccenter.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Mozilla Corporation) D:\Tools\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\VISIO.EXE
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Dropbox, Inc.) C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Connectify Hotspot] => C:\Program Files (x86)\Connectify\Connectify.exe [5236512 2013-05-14] (Connectify)
HKLM\...\Run: [Connectify Dispatch] => C:\Program Files (x86)\Connectify\DispatchUI.exe [3121440 2013-05-14] (Connectify)
HKLM\...\Run: [Zune Launcher] => D:\Tools\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-28] (Synaptics Incorporated)
HKLM\...\Run: [Bdagent] => D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe [1580360 2014-08-20] (Bitdefender)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => "C:\AMD\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2013-10-10] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [PC Remote Server] => C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [884376 2013-04-07] (PC Remote)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Spotify Web Helper] => C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-20] (Spotify Ltd)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [1] => wscript.exe //B "C:\ProgramData\1.vbs"
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Facebook Update] => C:\Users\rspri_000\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-09-12] (Facebook Inc.)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Bitdefender-Geldbörse-Agent] => D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe [815088 2014-08-14] (Bitdefender)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\MountPoints2: {c22edc32-9e8e-11e2-be67-0026221d60c8} - "G:\SETUP.EXE" 
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\MountPoints2: {fb3665b3-5386-11e3-be95-0026221d60c8} - "F:\Install.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK
ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs ()
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk /m /f \Device\HarddiskVolume4autocheck autochk * 

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www2.elearning.rwth-aachen.de/
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\pmbxie.dll (Bitdefender)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH)
Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll (Bitdefender)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 172.31.12.11 172.31.12.12

FireFox:
========
FF ProfilePath: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
FF Homepage: https://www2.elearning.rwth-aachen.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\rspri_000\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF user.js: detected! => C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\user.js
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\avira-safesearch.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-maps.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\zonealarm.xml
FF Extension: Avira Browser Safety - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\abs@avira.com [2014-09-04]
FF Extension: Grooveshark Unlocker - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-05-15]
FF Extension: ProxTube - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11]
FF Extension: Adblock Plus - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-06]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: Bitdefender Antispam Toolbar - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext [2014-09-25]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-10-27]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2014-04-23]
FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff
FF Extension: Bitdefender Wallet - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-09-25]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\extensions\cliqz@cliqz.com
FF StartMenuInternet: FIREFOX.EXE - D:\Tools\Mozilla Firefox\firefox.exe

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 BdDesktopParental; D:\Tools\Bitdefender\Bitdefender 2015\bdparentalservice.exe [77632 2014-08-08] (Bitdefender)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [156672 2013-05-14] (Connectify) [File not signed]
R2 Hamachi2Svc; C:\Tools\LogMeIn Hamachi\hamachi-2.exe [2525008 2014-09-04] (LogMeIn Inc.)
R3 hpqcxs08; C:\HP\Digital Imaging\bin\hpqcxs08.dll [254824 2011-04-29] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\HP\Digital Imaging\bin\hpqddsvc.dll [138600 2011-04-29] (Hewlett-Packard Co.)
R2 HPSLPSVC; C:\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
R2 UPDATESRV; D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-08-08] (Bitdefender)
R2 VSSERV; D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe [1513952 2014-08-11] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S3 WMZuneComm; D:\Tools\WMZuneComm.exe [306400 2011-08-05] (Microsoft Corporation)
S3 ZuneNetworkSvc; D:\Tools\ZuneNss.exe [8277728 2011-08-05] (Microsoft Corporation)
S3 ZuneWlanCfgSvc; D:\Tools\ZuneWlanCfgSvc.exe [467680 2011-08-05] (Microsoft Corporation)
S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1260120 2014-05-16] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261496 2013-07-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-05-16] (BitDefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-11-19] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-09-25] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-09-25] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-06] (DT Soft Ltd)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [419616 2014-07-02] (BitDefender S.R.L.)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 AAMWRegFilter; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter64.sys [X]
S3 ASW3Scan; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-25 15:41 - 2014-09-25 15:43 - 00023628 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:41 - 2014-09-25 15:42 - 00000000 ____D () C:\FRST
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 15:38 - 2014-09-25 15:38 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2014-05-16 13:04 - 00647752 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2014-09-25 12:11 - 2014-05-16 13:01 - 01260120 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2014-09-25 12:11 - 2013-11-19 14:44 - 00098768 _____ (BitDefender LLC) C:\Windows\system32\Drivers\bdfndisf6.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00082824 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00074512 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll
2014-09-25 12:11 - 2013-09-08 20:04 - 00023568 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys
2014-09-25 12:11 - 2013-07-17 19:31 - 00261496 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys
2014-09-25 12:11 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll
2014-09-25 12:00 - 2014-09-25 12:18 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:00 - 2014-09-25 12:12 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:00 - 2014-09-25 12:12 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:00 - 2014-09-25 12:00 - 00002247 _____ () C:\ProgramData\1411638859.4504.bin
2014-09-25 12:00 - 2014-07-04 17:49 - 49563064 ____H () C:\bdr-im01.gz
2014-09-25 12:00 - 2013-08-13 13:38 - 03271472 ____H () C:\bdr-bz01
2014-09-25 11:57 - 2014-09-25 11:59 - 00001545 _____ () C:\ProgramData\1411638859.6416.bin
2014-09-25 11:54 - 2014-09-25 13:18 - 00185845 _____ () C:\ProgramData\1411638859.5060.bin
2014-09-25 11:54 - 2014-09-25 12:18 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 11:54 - 2014-09-25 12:12 - 00213908 _____ () C:\ProgramData\1411638859.4688.bin
2014-09-25 11:54 - 2014-09-25 12:12 - 00158277 _____ () C:\ProgramData\1411638859.6264.bin
2014-09-25 11:54 - 2014-09-25 12:11 - 00050890 _____ () C:\ProgramData\1411638859.3272.bin
2014-09-25 11:54 - 2014-09-25 12:00 - 00017817 _____ () C:\ProgramData\1411638859.3748.bin
2014-09-25 11:54 - 2014-09-25 11:57 - 00001090 _____ () C:\ProgramData\1411638859.6020.bin
2014-09-25 11:54 - 2014-09-25 11:55 - 00001089 _____ () C:\ProgramData\1411638859.768.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00017948 _____ () C:\ProgramData\1411638859.2656.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00009470 _____ () C:\ProgramData\1411638859.788.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00002969 _____ () C:\ProgramData\1411638859.6660.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-07-02 17:47 - 00419616 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2014-09-25 11:54 - 2013-11-04 15:47 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUISkin.dll
2014-09-25 11:54 - 2013-11-04 15:46 - 00034384 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUH.dll
2014-09-25 11:54 - 2013-08-23 13:48 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2014-09-25 11:49 - 2014-09-25 11:54 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 11:20 - 2014-09-25 11:51 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:12 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-18 22:12 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 09:20 - 2014-08-09 10:30 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-09-18 09:20 - 2014-08-09 10:29 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2014-09-15 20:02 - 2014-09-15 20:03 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:23 - 2014-09-12 10:24 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:13 - 2014-09-12 10:19 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\RHEng
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:12 - 2014-09-12 10:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\OpenCandy
2014-09-12 10:11 - 2014-09-12 10:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:52 - 2014-09-25 12:58 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-12 09:52 - 2014-09-25 09:58 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-12 09:52 - 2014-09-12 09:53 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:52 - 2014-09-12 09:53 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 08:18 - 2014-08-21 01:40 - 00732880 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-09-12 08:18 - 2014-08-20 19:05 - 00694784 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-09-12 08:18 - 2014-08-20 19:02 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-09-12 08:18 - 2014-06-24 09:35 - 00010450 _____ () C:\Windows\system32\autoconfig.cab
2014-09-12 08:18 - 2014-06-24 08:41 - 10115584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-09-12 08:18 - 2014-06-24 08:40 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2014-09-12 08:18 - 2014-06-24 08:39 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-09-12 08:18 - 2014-06-24 06:08 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-09-12 08:18 - 2014-06-24 06:06 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-08-20 19:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-06-24 08:39 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-09-12 08:17 - 2014-06-24 06:06 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 09:24 - 2014-08-16 11:33 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 11:33 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 09:24 - 2014-08-16 11:32 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 09:35 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 09:24 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 09:24 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-09-11 09:24 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-09-11 09:24 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 09:24 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 09:24 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 09:24 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 09:24 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 09:23 - 2014-08-16 11:34 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 09:23 - 2014-08-16 11:33 - 19280384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 09:23 - 2014-08-16 11:32 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 14369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 08:49 - 2014-08-28 13:34 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-09-11 08:49 - 2014-08-28 08:05 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:01 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-09-11 08:49 - 2014-08-01 01:40 - 01287680 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00875688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00869544 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-06-05 03:12 - 00678600 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2014-09-11 08:48 - 2014-06-04 01:12 - 00536776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-05 00:44 - 2014-09-12 21:43 - 00135049 ____H () C:\ProgramData\1.vbs
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-08-29 10:31 - 2014-08-23 08:47 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 10:04 - 2014-09-09 22:35 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-25 15:43 - 2014-09-25 15:41 - 00023628 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:42 - 2014-09-25 15:41 - 00000000 ____D () C:\FRST
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 15:38 - 2014-09-25 15:38 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 15:38 - 2013-04-06 11:04 - 00000000 ____D () C:\Users\rspri_000
2014-09-25 15:22 - 2014-03-06 12:50 - 00000000 ___RD () C:\Users\rspri_000\Dropbox
2014-09-25 15:22 - 2014-03-06 12:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Dropbox
2014-09-25 15:07 - 2013-04-06 14:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-25 15:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-09-25 14:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-09-25 14:03 - 2013-06-09 14:08 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-25 14:02 - 2013-07-25 23:34 - 01391694 _____ () C:\Windows\WindowsUpdate.log
2014-09-25 13:59 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\Offline Web Pages
2014-09-25 13:55 - 2013-04-06 12:30 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4243713041-920332011-2703711254-1001
2014-09-25 13:25 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 13:23 - 2013-07-10 19:20 - 00000406 _____ () C:\Windows\Tasks\Lyrics-Pal Update.job
2014-09-25 13:23 - 2013-06-02 16:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\LogMeIn Hamachi
2014-09-25 13:22 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-25 13:21 - 2013-07-27 09:01 - 00034870 _____ () C:\Windows\PFRO.log
2014-09-25 13:21 - 2013-04-06 14:29 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-09-25 13:20 - 2012-07-26 07:26 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-09-25 13:18 - 2014-09-25 11:54 - 00185845 _____ () C:\ProgramData\1411638859.5060.bin
2014-09-25 13:04 - 2014-03-18 13:47 - 00000000 ___HD () C:\$Windows.~BT
2014-09-25 12:58 - 2014-09-12 09:52 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-25 12:55 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:18 - 2014-09-25 12:00 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:18 - 2014-09-25 11:54 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:12 - 2014-09-25 12:00 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:12 - 2014-09-25 12:00 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:12 - 2014-09-25 11:54 - 00213908 _____ () C:\ProgramData\1411638859.4688.bin
2014-09-25 12:12 - 2014-09-25 11:54 - 00158277 _____ () C:\ProgramData\1411638859.6264.bin
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2014-09-25 11:54 - 00050890 _____ () C:\ProgramData\1411638859.3272.bin
2014-09-25 12:11 - 2013-08-23 08:02 - 00018002 _____ () C:\Windows\setupact.log
2014-09-25 12:00 - 2014-09-25 12:00 - 00002247 _____ () C:\ProgramData\1411638859.4504.bin
2014-09-25 12:00 - 2014-09-25 11:54 - 00017817 _____ () C:\ProgramData\1411638859.3748.bin
2014-09-25 11:59 - 2014-09-25 11:57 - 00001545 _____ () C:\ProgramData\1411638859.6416.bin
2014-09-25 11:57 - 2014-09-25 11:54 - 00001090 _____ () C:\ProgramData\1411638859.6020.bin
2014-09-25 11:55 - 2014-09-25 11:54 - 00001089 _____ () C:\ProgramData\1411638859.768.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00017948 _____ () C:\ProgramData\1411638859.2656.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00009470 _____ () C:\ProgramData\1411638859.788.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00002969 _____ () C:\ProgramData\1411638859.6660.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-09-25 11:49 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:53 - 2013-04-06 15:49 - 07196672 ___SH () C:\Users\rspri_000\Desktop\Thumbs.db
2014-09-25 11:51 - 2014-09-25 11:20 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 09:58 - 2014-09-12 09:52 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-25 09:42 - 2012-07-26 12:27 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-09-25 09:42 - 2012-07-26 12:27 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-09-25 09:42 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-25 08:55 - 2014-05-14 08:54 - 00093004 _____ () C:\Users\rspri_000\Desktop\Transferpräse Laptop-Citrix.pptx
2014-09-24 14:59 - 2014-08-19 17:38 - 00000000 ____D () C:\Users\rspri_000\Desktop\Urlaub
2014-09-24 14:16 - 2013-08-14 19:06 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Spotify
2014-09-24 12:45 - 2013-08-14 19:05 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Spotify
2014-09-24 09:10 - 2014-07-21 19:55 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung LH
2014-09-24 09:10 - 2014-04-14 11:39 - 00000000 ____D () C:\Users\rspri_000\Desktop\Dubbel 22.Auflage
2014-09-24 09:10 - 2013-04-08 11:41 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung Praktikum
2014-09-18 23:37 - 2013-06-04 22:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TS3Client
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 16:41 - 2013-04-06 13:41 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-18 15:22 - 2014-03-06 12:46 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-17 13:36 - 2013-12-15 23:39 - 00000000 ____D () C:\ProgramData\FILEminimizer
2014-09-16 13:50 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-09-15 21:50 - 2013-12-08 20:08 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\vlc
2014-09-15 20:03 - 2014-09-15 20:02 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-15 10:07 - 2013-04-10 10:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-09-15 10:07 - 2013-04-10 10:06 - 00000000 ____D () C:\HP
2014-09-15 10:07 - 2013-04-09 20:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\HpUpdate
2014-09-12 21:43 - 2014-09-05 00:44 - 00135049 ____H () C:\ProgramData\1.vbs
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-09-12 10:45 - 2014-09-12 10:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:24 - 2014-09-12 10:23 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:21 - 2013-04-06 14:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TuneUp Software
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:19 - 2014-09-12 10:13 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\RHEng
2014-09-12 10:19 - 2013-04-06 14:12 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-09-12 10:17 - 2013-04-21 20:47 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Skype
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:12 - 2014-09-12 10:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\OpenCandy
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:53 - 2014-09-12 09:52 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:53 - 2014-09-12 09:52 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 09:36 - 2013-04-21 20:47 - 00000000 ____D () C:\ProgramData\Skype
2014-09-11 20:08 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-09-11 09:30 - 2013-04-18 11:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 09:23 - 2013-07-23 21:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 09:14 - 2013-04-07 18:42 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-09 22:35 - 2014-08-26 10:04 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe
2014-09-09 22:34 - 2013-04-06 14:18 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-08 22:35 - 2013-04-09 20:10 - 00000000 ____D () C:\Tools
2014-09-07 12:28 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-06 14:48 - 2013-04-06 16:19 - 00000000 ____D () C:\Users\rspri_000\Documents\BAföG
2014-09-04 14:48 - 2014-04-23 09:23 - 00000000 ____D () C:\ProgramData\Swiss Academic Software
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-01 20:56 - 2014-07-11 08:06 - 00428056 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 13:34 - 2014-09-11 08:49 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-28 08:05 - 2014-09-11 08:49 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-28 08:02 - 2014-09-11 08:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-28 08:01 - 2014-09-11 08:49 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-08-26 16:18 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\ELAMBKUP

Files to move or delete:
====================
C:\ProgramData\1.vbs


Some content of TEMP:
====================
C:\Users\rspri_000\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5dxwm_.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-17 09:14

==================== End Of Log ============================
         
Vielen Dank für eure Hilfe!!!

Alt 25.09.2014, 16:19   #2
M-K-D-B
/// TB-Ausbilder
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar






Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen.


Bitte beachte folgende Hinweise:
  • Falls wir Hinweise auf illegal erworbene Software finden, werden wir den Support unterbrechen bis jegliche Art von illegaler Software vom Rechner entfernt wurde.
  • Lies dir die Anleitungen sorgfältig durch. Solltest du Probleme haben, stoppe mit deiner Bearbeitung und beschreibe mir dein Problem so gut es geht.
  • Solltest du mir nicht innerhalb von 3 Tagen antworten, gehe ich davon aus, dass du keine Hilfe mehr benötigst. Dann lösche ich dein Thema aus meinem Abo.
    Solltest du einmal länger abwesend sein, so gib mir bitte Bescheid!
  • Während der Bereinigung bitte nichts installieren oder deinstallieren, außer ich bitte dich darum!
  • Alle zu verwendenen Programme sind auf dem Desktop abzuspeichern und von dort zu starten!


Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags:
So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke aauf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.

Danke für deine Mitarbeit!







Zitat:
Running from C:\Users\rspri_000\Downloads
Leider hast du unsere Anleitung nicht richtig befolgt:
Bitte alle Tools direkt auf den Desktop downloaden bzw. dorthin verschieben und vom Desktop starten, da unsere Anleitungen daraufhin ausgelegt sind.
Zudem lassen sich dann am Ende der Bereinigung alle verwendeten Tools sehr einfach entfernen.
Alle Tools bis zum Ende der Bereinigung auf dem Desktop lassen, evtl. benötigen wir manche öfter.




Schritt 1
Panda USB Vaccine

Bitte lade Dir von hier Panda USB Vaccine herunter.
  • Starte und installiere es.
  • Impfe Deinen PC





Schritt 2
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________


Alt 25.09.2014, 18:13   #3
Raphael_S
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Hier der Log-File des ComboFix:
Code:
ATTFilter
Combofix Logfile:
Code:
ATTFilter
ComboFix 14-09-24.01 - rspri_000 25.09.2014  18:54:58.1.2 - x64
Microsoft Windows 8 Pro  6.2.9200.0.1252.49.1031.18.4061.1855 [GMT 2:00]
ausgeführt von:: c:\users\rspri_000\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *Disabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall *Disabled* {A23392FD-84B9-F933-2C71-81E751F6EF46}
SP: Bitdefender Spyware-Schutz *Disabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1411638859.2656.bin
c:\programdata\1411638859.3272.bin
c:\programdata\1411638859.3748.bin
c:\programdata\1411638859.4504.bin
c:\programdata\1411638859.4688.bin
c:\programdata\1411638859.5060.bin
c:\programdata\1411638859.6020.bin
c:\programdata\1411638859.6264.bin
c:\programdata\1411638859.6416.bin
c:\programdata\1411638859.6660.bin
c:\programdata\1411638859.768.bin
c:\programdata\1411638859.788.bin
c:\users\rspri_000\AppData\Local\assembly\tmp
c:\users\rspri_000\AppData\Local\Microsoft\Windows\Temporary Internet Files\icad317.ica
c:\users\rspri_000\AppData\Roaming\Microsoft\Windows\Recent\Thumbs.db
.
.
(((((((((((((((((((((((   Dateien erstellt von 2014-08-25 bis 2014-09-25  ))))))))))))))))))))))))))))))
.
.
2014-09-25 17:03 . 2014-09-25 17:03	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-09-25 16:43 . 2014-09-25 16:43	--------	d-----w-	c:\programdata\Panda Security
2014-09-25 13:41 . 2014-09-25 13:45	--------	d-----w-	C:\FRST
2014-09-25 10:49 . 2014-09-25 10:49	--------	d-----w-	C:\OETemp
2014-09-25 10:42 . 2014-09-25 10:42	79192	----a-w-	c:\windows\system32\drivers\bdvedisk.sys
2014-09-25 10:42 . 2014-09-25 10:42	74512	----a-w-	c:\windows\system32\bdsandboxuiskin32.dll
2014-09-25 10:11 . 2014-09-25 10:11	--------	d-----w-	c:\programdata\BDLogging
2014-09-25 10:11 . 2013-09-08 18:04	23568	----a-w-	c:\windows\system32\drivers\bdelam.sys
2014-09-25 10:11 . 2013-11-19 12:44	98768	----a-w-	c:\windows\system32\drivers\bdfndisf6.sys
2014-09-25 10:11 . 2013-11-04 13:47	82824	----a-w-	c:\windows\system32\drivers\bdsandbox.sys
2014-09-25 10:11 . 2013-11-04 13:47	74512	----a-w-	c:\windows\SysWow64\bdsandboxuiskin32.dll
2014-09-25 10:11 . 2007-04-11 09:11	511328	----a-w-	c:\windows\capicom.dll
2014-09-25 10:11 . 2014-05-16 11:04	647752	----a-w-	c:\windows\system32\drivers\avckf.sys
2014-09-25 10:11 . 2014-05-16 11:01	1260120	----a-w-	c:\windows\system32\drivers\avc3.sys
2014-09-25 10:11 . 2013-07-17 17:31	261496	----a-w-	c:\windows\system32\drivers\avchv.sys
2014-09-25 10:00 . 2014-09-25 10:18	--------	d-----w-	c:\users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 10:00 . 2013-08-13 11:38	3271472	---ha-w-	C:\bdr-bz01
2014-09-25 09:54 . 2014-09-25 10:18	--------	d-----w-	c:\programdata\Bitdefender
2014-09-25 09:54 . 2013-11-04 13:47	84848	----a-w-	c:\windows\system32\BDSandBoxUISkin.dll
2014-09-25 09:54 . 2013-11-04 13:46	34384	----a-w-	c:\windows\system32\BDSandBoxUH.dll
2014-09-25 09:54 . 2013-08-23 11:48	150256	----a-w-	c:\windows\system32\drivers\gzflt.sys
2014-09-25 09:54 . 2014-07-02 15:47	419616	----a-w-	c:\windows\system32\drivers\trufos.sys
2014-09-25 09:54 . 2014-09-25 09:54	--------	d-----w-	c:\users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 09:49 . 2014-09-25 09:54	--------	d-----w-	c:\program files\Common Files\Bitdefender
2014-09-25 09:49 . 2014-09-25 09:49	--------	d-----w-	c:\program files (x86)\Common Files\Bitdefender
2014-09-18 20:12 . 2011-05-13 10:16	493056	----a-w-	c:\windows\SysWow64\dhRichClient3.dll
2014-09-18 20:12 . 2011-03-25 18:42	338432	----a-w-	c:\windows\SysWow64\sqlite36_engine.dll
2014-09-18 07:20 . 2014-08-09 08:30	148480	----a-w-	c:\windows\system32\poqexec.exe
2014-09-18 07:20 . 2014-08-09 08:29	144896	----a-w-	c:\windows\system32\tssdisai.dll
2014-09-12 08:23 . 2014-09-12 08:24	--------	d-----w-	c:\users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 08:21 . 2014-09-12 08:21	--------	d-----w-	c:\users\rspri_000\AppData\Roaming\StormFall
2014-09-12 08:21 . 2014-09-12 08:21	--------	d-----w-	c:\users\rspri_000\AppData\Local\StormFall
2014-09-12 08:21 . 2014-09-12 08:21	--------	d-----w-	c:\users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 08:19 . 2014-09-12 08:19	--------	d-sh--w-	c:\programdata\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 08:13 . 2014-09-12 08:13	--------	d-----w-	c:\programdata\CheckPoint
2014-09-12 08:13 . 2014-09-12 08:19	--------	d-----w-	c:\users\rspri_000\AppData\Roaming\RHEng
2014-09-12 08:12 . 2014-09-12 08:12	--------	d-----w-	c:\users\rspri_000\AppData\Roaming\OpenCandy
2014-09-12 08:11 . 2014-09-12 08:45	--------	d-----w-	c:\users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 07:52 . 2014-09-12 07:52	--------	d-----w-	c:\users\rspri_000\AppData\Local\Facebook
2014-09-12 07:36 . 2014-09-12 07:36	--------	d-----w-	c:\program files (x86)\Common Files\Skype
2014-09-12 06:18 . 2014-06-24 06:41	10115584	----a-w-	c:\windows\system32\twinui.dll
2014-09-12 06:18 . 2014-06-24 04:08	8858624	----a-w-	c:\windows\SysWow64\twinui.dll
2014-09-12 06:18 . 2014-06-24 06:39	2307072	----a-w-	c:\windows\system32\authui.dll
2014-09-12 06:18 . 2014-06-24 04:06	2037760	----a-w-	c:\windows\SysWow64\authui.dll
2014-09-12 06:18 . 2014-08-20 23:40	732880	----a-w-	c:\windows\system32\NotificationUI.exe
2014-09-12 06:18 . 2014-08-20 17:05	694784	----a-w-	c:\windows\system32\WSShared.dll
2014-09-12 06:18 . 2014-08-20 17:02	567808	----a-w-	c:\windows\SysWow64\WSShared.dll
2014-09-12 06:18 . 2014-06-24 06:40	125952	----a-w-	c:\windows\system32\WinSetupUI.dll
2014-09-12 06:17 . 2014-08-20 17:05	198656	----a-w-	c:\windows\system32\Windows.ApplicationModel.Store.dll
2014-09-12 06:17 . 2014-08-20 17:02	124928	----a-w-	c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 06:17 . 2014-08-20 17:05	163840	----a-w-	c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 06:17 . 2014-06-24 06:39	2146304	----a-w-	c:\windows\system32\actxprxy.dll
2014-09-12 06:17 . 2014-06-24 04:06	754176	----a-w-	c:\windows\SysWow64\actxprxy.dll
2014-09-11 07:23 . 2014-08-16 09:34	2239488	----a-w-	c:\windows\system32\wininet.dll
2014-09-11 07:23 . 2014-08-16 09:32	15399424	----a-w-	c:\windows\system32\ieframe.dll
2014-09-11 07:23 . 2014-08-16 09:33	19280384	----a-w-	c:\windows\system32\mshtml.dll
2014-09-11 06:48 . 2014-07-24 03:33	869544	----a-w-	c:\windows\system32\msvcr120_clr0400.dll
2014-09-11 06:48 . 2014-07-24 03:33	875688	----a-w-	c:\windows\SysWow64\msvcr120_clr0400.dll
2014-09-11 06:48 . 2014-06-03 23:12	536776	----a-w-	c:\windows\SysWow64\msvcp120_clr0400.dll
2014-09-11 06:48 . 2014-06-05 01:12	678600	----a-w-	c:\windows\system32\msvcp120_clr0400.dll
2014-09-11 06:47 . 2014-07-26 02:19	26218496	----a-w-	c:\program files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-09-11 06:47 . 2014-07-26 01:52	25479168	----a-w-	c:\program files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2014-09-04 22:44 . 2014-09-12 19:43	135049	--sha-w-	c:\users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs
2014-09-04 22:44 . 2014-09-12 19:43	135049	----a-w-	c:\programdata\1.vbs
2014-09-04 09:44 . 2014-09-04 09:44	46136	---ha-w-	c:\windows\system32\drivers\Hamdrv.sys
2014-08-29 08:31 . 2014-08-23 06:47	4036096	----a-w-	c:\windows\system32\win32k.sys
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-11 07:14 . 2013-04-07 16:42	101694776	----a-w-	c:\windows\system32\MRT.exe
2014-09-02 19:32 . 2014-08-16 12:25	705480	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-09-02 19:32 . 2014-08-16 12:25	104904	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-08-06 07:47 . 2014-08-06 07:47	98216	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-07-15 23:03 . 2014-08-13 19:44	1300992	----a-w-	c:\windows\system32\gdi32.dll
2014-07-15 22:51 . 2014-08-14 06:30	71168	----a-w-	c:\windows\system32\drivers\hdaudbus.sys
2014-07-15 06:38 . 2012-07-26 08:13	23264	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-07-12 02:36 . 2014-08-13 19:44	1023488	----a-w-	c:\windows\SysWow64\gdi32.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04	131480	----a-w-	c:\users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04	131480	----a-w-	c:\users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04	131480	----a-w-	c:\users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Remote Server"="c:\program files (x86)\PC Remote\PC Remote\PCRemote.exe" [2013-04-06 884376]
"Spotify Web Helper"="c:\users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-09-20 1245752]
"Bitdefender-Geldbörse-Agent"="d:\tools\Bitdefender\Bitdefender 2015\bdwtxag.exe" [2014-08-14 815088]
"1"="wscript.exe" [2012-07-26 131584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2013-10-10 707984]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2013-10-01 395656]
"Redirector"="c:\program files (x86)\Citrix\ICA Client\redirector.exe" [2013-10-01 153992]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-07-25 256896]
"LogMeIn Hamachi Ui"="c:\tools\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-09-04 3802448]
"HP Software Update"="c:\hp\HP Software Update\HPWuSchd2.exe" [2013-05-30 96056]
.
c:\users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
1.vbs [2014-9-12 135049]
Dropbox.lnk - c:\users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-9-13 36414624]
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
Hardcopy.LNK - c:\program files (x86)\Hardcopy\hardcopy.exe [2014-4-30 3752416]
HP Digital Imaging Monitor.lnk - c:\hp\Digital Imaging\bin\hpqtra08.exe [2011-4-29 276328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk /m /f \Device\HarddiskVolume4\0autocheck autochk *
.
R0 bdelam;bdelam;c:\windows\system32\drivers\bdelam.sys;c:\windows\SYSNATIVE\drivers\bdelam.sys [x]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\tools\LogMeIn Hamachi\hamachi-2.exe;c:\tools\LogMeIn Hamachi\hamachi-2.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [x]
R3 AAMWRegFilter;AAMWRegFilter;d:\tools\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter64.sys;d:\tools\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter64.sys [x]
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x]
R3 ASW3Scan;ASW3Scan;d:\tools\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS64.sys;d:\tools\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS64.sys [x]
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x]
R3 BdDesktopParental;Bitdefender Desktop Parental Control;d:\tools\Bitdefender\Bitdefender 2015\bdparentalservice.exe;d:\tools\Bitdefender\Bitdefender 2015\bdparentalservice.exe [x]
R3 bdfwfpf_pc;bdfwfpf_pc;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [x]
R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys;c:\windows\SYSNATIVE\drivers\bdsandbox.sys [x]
R3 WSDScan;WSD-Scanunterstützung;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x]
S0 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x]
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [x]
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys;c:\windows\SYSNATIVE\DRIVERS\ctxusbm.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 Connectify;Connectify;c:\program files (x86)\Connectify\ConnectifyService.exe;c:\program files (x86)\Connectify\ConnectifyService.exe [x]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x]
S2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x]
S2 UPDATESRV;Bitdefender Desktop Update Service;d:\tools\Bitdefender\Bitdefender 2015\updatesrv.exe;d:\tools\Bitdefender\Bitdefender 2015\updatesrv.exe [x]
S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [x]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x]
S3 RTL8168;Realtek 8168 NT-Treiber;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2013-09-05 14:04	215416	----a-w-	c:\program files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll
.
Inhalt des "geplante Tasks" Ordners
.
2014-09-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-06 20:34]
.
2014-09-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
- c:\users\rspri_000\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-12 07:53]
.
2014-09-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
- c:\users\rspri_000\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-12 07:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04	164760	----a-w-	c:\users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04	164760	----a-w-	c:\users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04	164760	----a-w-	c:\users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04	164760	----a-w-	c:\users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Connectify Hotspot"="c:\program files (x86)\Connectify\Connectify.exe" [2013-05-14 5236512]
"Connectify Dispatch"="c:\program files (x86)\Connectify\DispatchUI.exe" [2013-05-14 3121440]
"Zune Launcher"="d:\tools\ZuneLauncher.exe" [2011-08-05 163552]
"Bdagent"="d:\tools\Bitdefender\Bitdefender 2015\bdagent.exe" [2014-08-20 1580360]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www2.elearning.rwth-aachen.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &Citavi Picker... - file://c:\program files (x86)\Internet Explorer\Citavi Picker\ShowContextMenu.html
IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1 192.168.0.2
FF - ProfilePath - c:\users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\
FF - prefs.js: browser.startup.homepage - hxxps://www2.elearning.rwth-aachen.de/
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
FF - user.js: extensions.zonealarm.hpOld0 - hxxps://www2.elearning.rwth-aachen.de/
FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?src=tb&tbid=HFA5&Lan={dfltLng}&gu=2ff5a1a506c24c218be3d20501218f64&tu=11Jiy00Ft1D13P0&sku=&tstsId=&ver=&&q=
FF - user.js: extensions.zonealarm.id - b82b68480000000000000022fa039754
FF - user.js: extensions.zonealarm.appId - {C56C48A0-DA4E-46F6-9859-1553DC865F84}
FF - user.js: extensions.zonealarm.instlDay - 16325
FF - user.js: extensions.zonealarm.vrsn - 1.8.29.17
FF - user.js: extensions.zonealarm.vrsni - 1.8.29.17
FF - user.js: extensions.zonealarm.vrsnTs - 1.8.29.1710:14
FF - user.js: extensions.zonealarm.prtnrId - checkpoint
FF - user.js: extensions.zonealarm.prdct - zonealarm
FF - user.js: extensions.zonealarm.aflt - 5066
FF - user.js: extensions.zonealarm.smplGrp - NewUSR
FF - user.js: extensions.zonealarm.tlbrId - HFA5
FF - user.js: extensions.zonealarm.instlRef - ZLN124766134818211-5066
FF - user.js: extensions.zonealarm.dfltLng - DE
FF - user.js: extensions.zonealarm.excTlbr - false
FF - user.js: extensions.zonealarm.ffxUnstlRst - false
FF - user.js: extensions.zonealarm.admin - false
FF - user.js: extensions.zonealarm.autoRvrt - false
FF - user.js: extensions.zonealarm.rvrt - false
FF - user.js: extensions.zonealarm.hmpg - true
FF - user.js: extensions.zonealarm.hmpgUrl - hxxp://search.zonealarm.com/?src=hp&tbid=HFA5&Lan=DE&gu=2ff5a1a506c24c218be3d20501218f64&tu=11Jiy00Ft1D13P0&sku=&tstsId=&ver=&
FF - user.js: extensions.zonealarm.dfltSrch - true
FF - user.js: extensions.zonealarm.srchPrvdr - Search By ZoneAlarm
FF - user.js: extensions.zonealarm.kw_url - hxxp://search.zonealarm.com/search?src=sp&tbid=HFA5&Lan=DE&gu=2ff5a1a506c24c218be3d20501218f64&tu=11Jiy00Ft1D13P0&sku=&tstsId=&ver=&&q=
FF - user.js: extensions.zonealarm.dnsErr - true
FF - user.js: extensions.zonealarm.newTab - true
FF - user.js: extensions.zonealarm.newTabUrl - hxxp://search.zonealarm.com/?src=nt&tbid=HFA5&Lan=DE&gu=2ff5a1a506c24c218be3d20501218f64&tu=11Jiy00Ft1D13P0&sku=&tstsId=&ver=&
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-StartCCC - c:\amd\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
Wow6432Node-HKLM-Run-CitrixReceiver - c:\programdata\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{8e70e4e1-06d7-470b-9f74-a51bef21088e} - c:\programdata\Package Cache\{8e70e4e1-06d7-470b-9f74-a51bef21088e}\vcredist_x86.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Zeit der Fertigstellung: 2014-09-25  19:10:46
ComboFix-quarantined-files.txt  2014-09-25 17:10
.
Vor Suchlauf: 10 Verzeichnis(se), 29.161.508.864 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 29.013.889.024 Bytes frei
.
- - End Of File - - AA43BA75FA3980627D1CB5A69DCA46B2
         
--- --- --- A36C5E4F47E84449FF07ED3517B43A31
__________________

Alt 25.09.2014, 18:32   #4
M-K-D-B
/// TB-Ausbilder
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Schritt 1
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).





Schritt 2
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.







Schritt 3
Bitte deaktiviere dein Anti-Viren-Programm, da es das Ergebnis beeinflussen oder ggf. die Bereinigung stören kann.
Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/ und speichere die Datei auf deinem Desktop.
  • Starte Zoek.exe mit einem Doppelklick.
  • Achtung: Das folgende Skript wurde nur für diesen speziellen Fall geschrieben und könnte andere Computer beschädigen.
  • Kopiere den Text der folgenden Box in das Skriptfenster von zoek:
    Code:
    ATTFilter
    iedefaults;
    resetIEproxy;
    FFdefaults;
    CHRdefaults;
    emptyclsid;
             
  • Nun klicke auf "Run script" und sei geduldig bis das Skript durchgelaufen ist.
  • Wenn das Tool fertig ist, wird sich Notepad mit der Logdatei öffnen (ggf. erst nach einem Neustart). Das Log befindet sich aber auch noch unter c:\ .
  • Bitte poste mir das ZOEK-Log (möglichst in CODE-Tags - #-Symbol im Antwortfenster klicken).





Schritt 4
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Scan.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei von AdwCleaner,
  • die Logdatei von MBAM,
  • die Logdatei von Zoek,
  • die beiden neuen Logdateien von FRST.

Alt 25.09.2014, 20:05   #5
Raphael_S
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Hi M-K-D-B,

Danke für die super schnelle Antwort!
Hab alles gemacht wie beschrieben.

die Logdatei von AdwCleaner,
die Logdatei von MBAM,
die Logdatei von Zoek,
die beiden neuen Logdateien von FRST

AdwCleaner:
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v3.310 - Bericht erstellt am 25/09/2014 um 19:41:27
# Aktualisiert 12/09/2014 von Xplode
# Betriebssystem : Windows 8 Pro  (64 bits)
# Benutzername : rspri_000 - RAPHAELS_PC
# Gestartet von : C:\Users\rspri_000\Desktop\AdwCleaner_3.310.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Users\rspri_000\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\rspri_000\AppData\Roaming\pdfforge
Datei Gelöscht : C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\user.js

***** [ Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyricspal
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller

***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16537


-\\ Mozilla Firefox v20.0 (en-US)

[ Datei : C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [4329 octets] - [25/09/2014 19:38:13]
AdwCleaner[R1].txt - [4389 octets] - [25/09/2014 19:40:27]
AdwCleaner[S0].txt - [4161 octets] - [25/09/2014 19:41:27]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4221 octets] ##########
         
--- --- ---


MBAM:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 25.09.2014
Suchlauf-Zeit: 19:50:29
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.09.25.08
Rootkit Datenbank: v2014.09.19.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: rspri_000

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 334588
Verstrichene Zeit: 41 Min, 39 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 2
PUP.Optional.PriceMeter.A, C:\Users\rspri_000\AppData\Roaming\RHEng\F01163AE04F142D9842DFC72E8A0EE4F\pm.exe, In Quarantäne, [08d4fff24e2d0c2a2c48ccae0ff2e917], 
PUP.Optional.OpenCandy, C:\Users\rspri_000\Downloads\PhotoScape_V3.6.5.exe, In Quarantäne, [31ab44ad0c6f0a2c3ec52f04ec198e72], 

Physische Sektoren: 0
(No malicious items detected)


(end)
         
Zoek:
Code:
ATTFilter
Zoek.exe v5.0.0.0 Updated 24-09-2014
Tool run by rspri_000 on 25.09.2014 at 20:43:11,63.
Microsoft Windows 8 Pro 6.2.9200  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\rspri_000\Desktop\zoek.exe    [Scan all users] [Script inserted] 

==== System Restore Info ======================

25.09.2014 20:44:54 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-4243713041-920332011-2703711254-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{47833539-D0C5-4125-9FA8-0819E2EAAC93} deleted successfully
HKEY_USERS\S-1-5-21-4243713041-920332011-2703711254-1001\Software\Mozilla\Firefox\Extensions\cliqz@cliqz.com deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\RSPRI_~1\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\prefs.js:
user_pref("browser.startup.homepage", "https://www2.elearning.rwth-aachen.de/");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\RSPRI_~1\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\RSPRI_~1\AppData\Roaming\Thunderbird\Profiles\lovhopj1.default\prefs.js:

Added to C:\Users\RSPRI_~1\AppData\Roaming\Thunderbird\Profiles\lovhopj1.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\RSPRI_~1\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default

user.js not found
---- Lines FFPDFArchitectConverter@pdfarchitect.com removed from prefs.js ----
user_pref("extensions.FFPDFArchitectConverter@pdfarchitect.com.install-event-fired", true);
---- Lines FFPDFArchitectConverter@pdfarchitect.com modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"FFPDFArchitectConverter@pdfarchitect.com\":{\"descriptor\":\"C:\\
---- Lines cliqz@cliqz.com removed from prefs.js ----
user_pref("extensions.cliqz@cliqz.com.install-event-fired", true);
---- FireFox user.js and prefs.js backups ---- 

prefs__2045_.backup

ProfilePath: C:\Users\RSPRI_~1\AppData\Roaming\Thunderbird\Profiles\lovhopj1.default

user.js not found
---- FireFox user.js and prefs.js backups ---- 

prefs__2045_.backup

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"bdwteff@bitdefender.com"="D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff" [26.08.2014 16:18]

==== Firefox Extensions ======================

ProfilePath: C:\Users\RSPRI_~1\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
- PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
- Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
- Bitdefender Wallet - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff
- Avira Browser Safety - %ProfilePath%\extensions\abs@avira.com
- Grooveshark Unlocker - %ProfilePath%\extensions\groovesharkUnlocker@overlord1337.xpi
- ProxTube - Gesperrte YouTube Videos entsperren - %ProfilePath%\extensions\ich@maltegoetz.de.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\RSPRI_~1\AppData\Roaming\Thunderbird\Profiles\lovhopj1.default
- Deutsches Wrterbuch - %ProfilePath%\extensions\de-DE@dictionaries.addons.mozilla.org

==== Firefox Plugins ======================

Profilepath: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
DFC9460CC37E5C414DC4680B10C19E7A	- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll -	Shockwave Flash
3CD19649B2C3023D65E67C056457A2BC	- C:\Users\rspri_000\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll -	Facebook Video Calling Plugin


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www2.elearning.rwth-aachen.de/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Reset Google Chrome ======================

Nothing found to reset

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyEnable"=dword:00000000

Value(s) after fix:
"ProxyEnable"=dword:00000000

==== C:\zoek_backup content ======================

C:\zoek_backup (files=3 folders=0 269388 bytes)

==== EOF on 25.09.2014 at 20:46:19,98 ======================
         
FRST

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-09-2014
Ran by rspri_000 (administrator) on RAPHAELS_PC on 25-09-2014 20:56:49
Running from C:\Users\rspri_000\Desktop
Loaded Profile: rspri_000 (Available profiles: rspri_000)
Platform: Windows 8 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
(Panda Security) D:\Tools\Panda USB Vaccine\USBVaccine.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Microsoft Corporation) D:\Tools\ZuneLauncher.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe
(Spotify Ltd) C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwtxapps.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(sw4you) C:\Program Files (x86)\Hardcopy\hardcopy.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) D:\Tools\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Connectify Hotspot] => C:\Program Files (x86)\Connectify\Connectify.exe [5236512 2013-05-14] (Connectify)
HKLM\...\Run: [Connectify Dispatch] => C:\Program Files (x86)\Connectify\DispatchUI.exe [3121440 2013-05-14] (Connectify)
HKLM\...\Run: [Zune Launcher] => D:\Tools\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-28] (Synaptics Incorporated)
HKLM\...\Run: [Bdagent] => D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe [1580360 2014-08-20] (Bitdefender)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2013-10-10] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [PC Remote Server] => C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [884376 2013-04-07] (PC Remote)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Spotify Web Helper] => C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-20] (Spotify Ltd)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Bitdefender-Geldbörse-Agent] => D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe [815088 2014-08-14] (Bitdefender)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [1] => wscript.exe //B "C:\ProgramData\1.vbs"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK
ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs ()
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk /m /f \Device\HarddiskVolume4autocheck autochk * 

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\pmbxie.dll (Bitdefender)
Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll (Bitdefender)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF ProfilePath: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\rspri_000\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\avira-safesearch.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-maps.xml
FF Extension: Avira Browser Safety - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\abs@avira.com [2014-09-04]
FF Extension: Grooveshark Unlocker - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-05-15]
FF Extension: ProxTube - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11]
FF Extension: Adblock Plus - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-06]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: Bitdefender Antispam Toolbar - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext [2014-09-25]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-10-27]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2014-04-23]
FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff
FF Extension: Bitdefender Wallet - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-09-25]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF StartMenuInternet: FIREFOX.EXE - D:\Tools\Mozilla Firefox\firefox.exe

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 BdDesktopParental; D:\Tools\Bitdefender\Bitdefender 2015\bdparentalservice.exe [77632 2014-08-08] (Bitdefender)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [156672 2013-05-14] (Connectify) [File not signed]
R2 Hamachi2Svc; C:\Tools\LogMeIn Hamachi\hamachi-2.exe [2525008 2014-09-04] (LogMeIn Inc.)
R3 hpqcxs08; C:\HP\Digital Imaging\bin\hpqcxs08.dll [254824 2011-04-29] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\HP\Digital Imaging\bin\hpqddsvc.dll [138600 2011-04-29] (Hewlett-Packard Co.)
R2 HPSLPSVC; C:\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
R2 UPDATESRV; D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-08-08] (Bitdefender)
R2 VSSERV; D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe [1513952 2014-08-11] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S3 WMZuneComm; D:\Tools\WMZuneComm.exe [306400 2011-08-05] (Microsoft Corporation)
S3 ZuneNetworkSvc; D:\Tools\ZuneNss.exe [8277728 2011-08-05] (Microsoft Corporation)
S3 ZuneWlanCfgSvc; D:\Tools\ZuneWlanCfgSvc.exe [467680 2011-08-05] (Microsoft Corporation)
S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1260120 2014-05-16] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261496 2013-07-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-05-16] (BitDefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-11-19] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-09-25] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-09-25] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-06] (DT Soft Ltd)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [419616 2014-07-02] (BitDefender S.R.L.)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 AAMWRegFilter; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter64.sys [X]
S3 ASW3Scan; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-25 20:56 - 2014-09-25 20:56 - 00021856 _____ () C:\Users\rspri_000\Desktop\FRST.txt
2014-09-25 20:56 - 2014-09-25 20:56 - 00006273 _____ () C:\Users\rspri_000\Desktop\zoek-results.txt
2014-09-25 20:44 - 2014-09-25 20:46 - 00006273 _____ () C:\zoek-results.log
2014-09-25 20:43 - 2014-09-25 20:46 - 00000000 ____D () C:\zoek_backup
2014-09-25 20:41 - 2014-09-25 20:41 - 01290752 _____ () C:\Users\rspri_000\Desktop\zoek.exe
2014-09-25 20:41 - 2014-09-25 20:41 - 00001408 _____ () C:\Users\rspri_000\Desktop\mbam.txt
2014-09-25 19:49 - 2014-09-25 20:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-25 19:49 - 2014-09-25 19:49 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-09-25 19:49 - 2014-09-25 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-09-25 19:48 - 2014-09-25 19:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-09-25 19:48 - 2014-09-25 19:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\rspri_000\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-25 19:48 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-25 19:48 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-25 19:48 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-25 19:37 - 2014-09-25 19:41 - 00000000 ____D () C:\AdwCleaner
2014-09-25 19:36 - 2014-09-25 19:36 - 01373475 _____ () C:\Users\rspri_000\Desktop\AdwCleaner_3.310.exe
2014-09-25 19:10 - 2014-09-25 19:10 - 00024302 _____ () C:\ComboFix.txt
2014-09-25 18:52 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-25 18:52 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-25 18:52 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-25 18:49 - 2014-09-25 19:10 - 00000000 ____D () C:\Qoobox
2014-09-25 18:49 - 2014-09-25 19:04 - 00000000 ____D () C:\Windows\erdnt
2014-09-25 18:45 - 2014-09-25 18:46 - 05580995 ____R (Swearware) C:\Users\rspri_000\Desktop\ComboFix.exe
2014-09-25 18:43 - 2014-09-25 18:43 - 00003052 _____ () C:\Windows\System32\Tasks\PandaUSBVaccine
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Panda Security
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2014-09-25 18:40 - 2014-09-25 18:40 - 00848856 _____ (Panda Security ) C:\Users\rspri_000\Desktop\USBVaccineSetup.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 01110476 _____ () C:\Users\rspri_000\Downloads\7z920.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-09-25 16:43 - 2014-09-25 16:43 - 509766635 _____ () C:\Windows\MEMORY.DMP
2014-09-25 16:43 - 2014-09-25 16:43 - 00286896 _____ () C:\Windows\Minidump\092514-25412-01.dmp
2014-09-25 16:01 - 2014-09-25 16:01 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 16:00 - 2014-09-25 16:03 - 05176232 _____ (F-Secure Corporation) C:\Users\rspri_000\Downloads\F-SecureOnlineScanner.exe
2014-09-25 15:46 - 2014-09-25 20:56 - 00000000 ____D () C:\Users\rspri_000\Desktop\Virenjagd
2014-09-25 15:46 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Desktop\FRST64.exe
2014-09-25 15:43 - 2014-09-25 15:45 - 00051713 _____ () C:\Users\rspri_000\Downloads\Addition.txt
2014-09-25 15:41 - 2014-09-25 20:57 - 00000000 ____D () C:\FRST
2014-09-25 15:41 - 2014-09-25 15:45 - 00056212 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2014-05-16 13:04 - 00647752 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2014-09-25 12:11 - 2014-05-16 13:01 - 01260120 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2014-09-25 12:11 - 2013-11-19 14:44 - 00098768 _____ (BitDefender LLC) C:\Windows\system32\Drivers\bdfndisf6.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00082824 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00074512 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll
2014-09-25 12:11 - 2013-09-08 20:04 - 00023568 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys
2014-09-25 12:11 - 2013-07-17 19:31 - 00261496 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys
2014-09-25 12:11 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll
2014-09-25 12:00 - 2014-09-25 12:18 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:00 - 2014-09-25 12:12 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:00 - 2014-09-25 12:12 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:00 - 2014-07-04 17:49 - 49563064 ____H () C:\bdr-im01.gz
2014-09-25 12:00 - 2013-08-13 13:38 - 03271472 ____H () C:\bdr-bz01
2014-09-25 11:54 - 2014-09-25 12:18 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-07-02 17:47 - 00419616 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2014-09-25 11:54 - 2013-11-04 15:47 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUISkin.dll
2014-09-25 11:54 - 2013-11-04 15:46 - 00034384 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUH.dll
2014-09-25 11:54 - 2013-08-23 13:48 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2014-09-25 11:49 - 2014-09-25 11:54 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 11:20 - 2014-09-25 11:51 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:12 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-18 22:12 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 09:20 - 2014-08-09 10:30 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-09-18 09:20 - 2014-08-09 10:29 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2014-09-15 20:02 - 2014-09-15 20:03 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:23 - 2014-09-12 10:24 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:13 - 2014-09-12 10:19 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\RHEng
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:11 - 2014-09-12 10:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:52 - 2014-09-25 18:58 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-12 09:52 - 2014-09-25 09:58 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-12 09:52 - 2014-09-12 09:53 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:52 - 2014-09-12 09:53 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 08:18 - 2014-08-21 01:40 - 00732880 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-09-12 08:18 - 2014-08-20 19:05 - 00694784 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-09-12 08:18 - 2014-08-20 19:02 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-09-12 08:18 - 2014-06-24 09:35 - 00010450 _____ () C:\Windows\system32\autoconfig.cab
2014-09-12 08:18 - 2014-06-24 08:41 - 10115584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-09-12 08:18 - 2014-06-24 08:40 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2014-09-12 08:18 - 2014-06-24 08:39 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-09-12 08:18 - 2014-06-24 06:08 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-09-12 08:18 - 2014-06-24 06:06 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-08-20 19:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-06-24 08:39 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-09-12 08:17 - 2014-06-24 06:06 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 09:24 - 2014-08-16 11:33 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 11:33 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 09:24 - 2014-08-16 11:32 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 09:35 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 09:24 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 09:24 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-09-11 09:24 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-09-11 09:24 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 09:24 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 09:24 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 09:24 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 09:24 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 09:23 - 2014-08-16 11:34 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 09:23 - 2014-08-16 11:33 - 19280384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 09:23 - 2014-08-16 11:32 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 14369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 08:49 - 2014-08-28 13:34 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-09-11 08:49 - 2014-08-28 08:05 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:01 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-09-11 08:49 - 2014-08-01 01:40 - 01287680 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00875688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00869544 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-06-05 03:12 - 00678600 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2014-09-11 08:48 - 2014-06-04 01:12 - 00536776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-05 00:44 - 2014-09-12 21:43 - 00135049 _____ () C:\ProgramData\1.vbs
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-08-29 10:31 - 2014-08-23 08:47 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 10:04 - 2014-09-09 22:35 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-25 20:57 - 2014-09-25 20:56 - 00021856 _____ () C:\Users\rspri_000\Desktop\FRST.txt
2014-09-25 20:57 - 2014-09-25 15:41 - 00000000 ____D () C:\FRST
2014-09-25 20:56 - 2014-09-25 20:56 - 00006273 _____ () C:\Users\rspri_000\Desktop\zoek-results.txt
2014-09-25 20:56 - 2014-09-25 15:46 - 00000000 ____D () C:\Users\rspri_000\Desktop\Virenjagd
2014-09-25 20:51 - 2013-07-25 23:34 - 01474998 _____ () C:\Windows\WindowsUpdate.log
2014-09-25 20:46 - 2014-09-25 20:44 - 00006273 _____ () C:\zoek-results.log
2014-09-25 20:46 - 2014-09-25 20:43 - 00000000 ____D () C:\zoek_backup
2014-09-25 20:41 - 2014-09-25 20:41 - 01290752 _____ () C:\Users\rspri_000\Desktop\zoek.exe
2014-09-25 20:41 - 2014-09-25 20:41 - 00001408 _____ () C:\Users\rspri_000\Desktop\mbam.txt
2014-09-25 20:39 - 2014-09-25 19:49 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-25 20:37 - 2013-06-02 16:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\LogMeIn Hamachi
2014-09-25 20:36 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-25 20:35 - 2013-07-27 09:01 - 00036706 _____ () C:\Windows\PFRO.log
2014-09-25 20:34 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\Vss
2014-09-25 20:07 - 2013-04-06 14:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-25 20:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-09-25 19:49 - 2014-09-25 19:49 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-09-25 19:49 - 2014-09-25 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-09-25 19:49 - 2014-09-25 19:48 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-09-25 19:48 - 2014-09-25 19:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\rspri_000\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-25 19:48 - 2013-07-16 23:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-25 19:41 - 2014-09-25 19:37 - 00000000 ____D () C:\AdwCleaner
2014-09-25 19:36 - 2014-09-25 19:36 - 01373475 _____ () C:\Users\rspri_000\Desktop\AdwCleaner_3.310.exe
2014-09-25 19:10 - 2014-09-25 19:10 - 00024302 _____ () C:\ComboFix.txt
2014-09-25 19:10 - 2014-09-25 18:49 - 00000000 ____D () C:\Qoobox
2014-09-25 19:10 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-09-25 19:04 - 2014-09-25 18:49 - 00000000 ____D () C:\Windows\erdnt
2014-09-25 19:03 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-09-25 18:58 - 2014-09-12 09:52 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-25 18:46 - 2014-09-25 18:45 - 05580995 ____R (Swearware) C:\Users\rspri_000\Desktop\ComboFix.exe
2014-09-25 18:43 - 2014-09-25 18:43 - 00003052 _____ () C:\Windows\System32\Tasks\PandaUSBVaccine
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Panda Security
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2014-09-25 18:40 - 2014-09-25 18:40 - 00848856 _____ (Panda Security ) C:\Users\rspri_000\Desktop\USBVaccineSetup.exe
2014-09-25 17:05 - 2013-04-06 15:49 - 07196672 ___SH () C:\Users\rspri_000\Desktop\Thumbs.db
2014-09-25 17:02 - 2014-09-25 17:02 - 01110476 _____ () C:\Users\rspri_000\Downloads\7z920.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-09-25 16:49 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-09-25 16:43 - 2014-09-25 16:43 - 509766635 _____ () C:\Windows\MEMORY.DMP
2014-09-25 16:43 - 2014-09-25 16:43 - 00286896 _____ () C:\Windows\Minidump\092514-25412-01.dmp
2014-09-25 16:03 - 2014-09-25 16:00 - 05176232 _____ (F-Secure Corporation) C:\Users\rspri_000\Downloads\F-SecureOnlineScanner.exe
2014-09-25 16:01 - 2014-09-25 16:01 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 16:01 - 2013-04-06 11:04 - 00000000 ____D () C:\Users\rspri_000
2014-09-25 15:51 - 2012-07-26 07:26 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-09-25 15:47 - 2014-03-06 12:50 - 00000000 ___RD () C:\Users\rspri_000\Dropbox
2014-09-25 15:45 - 2014-09-25 15:43 - 00051713 _____ () C:\Users\rspri_000\Downloads\Addition.txt
2014-09-25 15:45 - 2014-09-25 15:41 - 00056212 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:40 - 2014-09-25 15:46 - 02108928 _____ (Farbar) C:\Users\rspri_000\Desktop\FRST64.exe
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 15:22 - 2014-03-06 12:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Dropbox
2014-09-25 14:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-09-25 14:03 - 2013-06-09 14:08 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-25 13:59 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\Offline Web Pages
2014-09-25 13:55 - 2013-04-06 12:30 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4243713041-920332011-2703711254-1001
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 13:21 - 2013-04-06 14:29 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-09-25 13:04 - 2014-03-18 13:47 - 00000000 ____D () C:\$Windows.~BT
2014-09-25 12:55 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:18 - 2014-09-25 12:00 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:18 - 2014-09-25 11:54 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:12 - 2014-09-25 12:00 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:12 - 2014-09-25 12:00 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2013-08-23 08:02 - 00018002 _____ () C:\Windows\setupact.log
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-09-25 11:49 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:51 - 2014-09-25 11:20 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 09:58 - 2014-09-12 09:52 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-25 09:42 - 2012-07-26 12:27 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-09-25 09:42 - 2012-07-26 12:27 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-09-25 09:42 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-25 08:55 - 2014-05-14 08:54 - 00093004 _____ () C:\Users\rspri_000\Desktop\Transferpräse Laptop-Citrix.pptx
2014-09-24 14:59 - 2014-08-19 17:38 - 00000000 ____D () C:\Users\rspri_000\Desktop\Urlaub
2014-09-24 14:16 - 2013-08-14 19:06 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Spotify
2014-09-24 12:45 - 2013-08-14 19:05 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Spotify
2014-09-24 09:10 - 2014-07-21 19:55 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung LH
2014-09-24 09:10 - 2014-04-14 11:39 - 00000000 ____D () C:\Users\rspri_000\Desktop\Dubbel 22.Auflage
2014-09-24 09:10 - 2013-04-08 11:41 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung Praktikum
2014-09-18 23:37 - 2013-06-04 22:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TS3Client
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 16:41 - 2013-04-06 13:41 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-18 15:22 - 2014-03-06 12:46 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-17 13:36 - 2013-12-15 23:39 - 00000000 ____D () C:\ProgramData\FILEminimizer
2014-09-16 13:50 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-09-15 21:50 - 2013-12-08 20:08 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\vlc
2014-09-15 20:03 - 2014-09-15 20:02 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-15 10:07 - 2013-04-10 10:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-09-15 10:07 - 2013-04-10 10:06 - 00000000 ____D () C:\HP
2014-09-15 10:07 - 2013-04-09 20:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\HpUpdate
2014-09-12 21:43 - 2014-09-05 00:44 - 00135049 _____ () C:\ProgramData\1.vbs
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-09-12 10:45 - 2014-09-12 10:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:24 - 2014-09-12 10:23 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:21 - 2013-04-06 14:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TuneUp Software
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:19 - 2014-09-12 10:13 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\RHEng
2014-09-12 10:19 - 2013-04-06 14:12 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-09-12 10:17 - 2013-04-21 20:47 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Skype
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:53 - 2014-09-12 09:52 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:53 - 2014-09-12 09:52 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 09:36 - 2013-04-21 20:47 - 00000000 ____D () C:\ProgramData\Skype
2014-09-11 20:08 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-09-11 09:30 - 2013-04-18 11:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 09:23 - 2013-07-23 21:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 09:14 - 2013-04-07 18:42 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-09 22:35 - 2014-08-26 10:04 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe
2014-09-09 22:34 - 2013-04-06 14:18 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-08 22:35 - 2013-04-09 20:10 - 00000000 ____D () C:\Tools
2014-09-07 12:28 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-06 14:48 - 2013-04-06 16:19 - 00000000 ____D () C:\Users\rspri_000\Documents\BAföG
2014-09-04 14:48 - 2014-04-23 09:23 - 00000000 ____D () C:\ProgramData\Swiss Academic Software
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-01 20:56 - 2014-07-11 08:06 - 00428056 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 13:34 - 2014-09-11 08:49 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-28 08:05 - 2014-09-11 08:49 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-28 08:02 - 2014-09-11 08:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-28 08:01 - 2014-09-11 08:49 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-08-26 16:18 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\ELAMBKUP

Files to move or delete:
====================
C:\ProgramData\1.vbs


Some content of TEMP:
====================
C:\Users\rspri_000\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-17 09:14

==================== End Of Log ============================
         
--- --- ---


Alt 26.09.2014, 12:22   #6
M-K-D-B
/// TB-Ausbilder
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Servus,







Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:
ATTFilter
start
CloseProcesses:
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [1] => wscript.exe //B "C:\ProgramData\1.vbs"
C:\ProgramData\1.vbs
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs ()
C:\Users\rspri_000\AppData\Roaming\RHEng
EmptyTemp:
end
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.







Schritt 2
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Scan.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.





Stecke den USB-Stick an den Rechner an. Hast du immer noch das Problem, dass du keine Dateien sehen kannst?





Bitte poste mit deiner nächsten Antwort
  • die Logdatei des FRST-Fix,
  • die beiden neuen Logdateien von FRST,
  • die Beantwortung der gestellten Fragen.

Alt 27.09.2014, 07:12   #7
Raphael_S
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Hi,

ich habe am Wochenende wenig Zeit. Daher werde ich wsl erst Montag antworten.

Schönes Wochenende ;-)

Alt 27.09.2014, 07:44   #8
M-K-D-B
/// TB-Ausbilder
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Servus,


alles klar, dann bis nächste Woche.

Alt 29.09.2014, 15:01   #9
Raphael_S
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Hi,

hab probiert Dateien auf nen neuen USB-Stick zu laden und das klappt.


Nich eine Frage: Ich habe eine extere Festplatte mit wichtigen Daten, die ich in letzter Zeit auch an dem PC benutzt habe. Kann sich der Virus auch au diese kopiert haben?

Zuletzt noch die Log-Files:

Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-09-2014
Ran by rspri_000 at 2014-09-26 13:43:23 Run:1
Running from C:\Users\rspri_000\Desktop
Loaded Profile: rspri_000 (Available profiles: rspri_000)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [1] => wscript.exe //B "C:\ProgramData\1.vbs"
C:\ProgramData\1.vbs
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs ()
C:\Users\rspri_000\AppData\Roaming\RHEng
EmptyTemp:
end
*****************

Processes closed successfully.
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\Software\Microsoft\Windows\CurrentVersion\Run\\1 => value deleted successfully.
C:\ProgramData\1.vbs => Moved successfully.
C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs => Moved successfully.
C:\Users\rspri_000\AppData\Roaming\RHEng => Moved successfully.
EmptyTemp: => Removed 500.6 MB temporary data.


The system needed a reboot. 

==== End of Fixlog ====
         
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-09-2014
Ran by rspri_000 at 2014-09-26 13:52:33
Running from C:\Users\rspri_000\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Spyware-Schutz (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - )
8000A809 (x32 Version: 140.0.001.000 - Hewlett-Packard) Hidden
8000A809_eDocs (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden
8000A809_Help (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 13.0.0.111 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 13.0.0.111 - Adobe Systems Incorporated) Hidden
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated)
Adobe Download Assistant (x32 Version: 1.2.6 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Amazon Kindle (HKCU\...\Amazon Kindle) (Version:  - Amazon)
AMD Accelerated Video Transcoding (Version: 12.5.100.21116 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.937.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{FAF03106-1653-15E1-3C0C-E7AE4FAE6EBF}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Media Foundation Decoders (Version: 1.0.71116.1554 - Advanced Micro Devices, Inc.) Hidden
B110 (x32 Version: 140.0.353.000 - Hewlett-Packard) Hidden
Bitdefender Internet Security 2015 (HKLM\...\Bitdefender) (Version: 18.14.0.1088 - Bitdefender)
BPDSoftware (x32 Version: 140.0.001.000 - Hewlett-Packard) Hidden
BPDSoftware_Ini (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1116.1515.27190 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.1116.1515.27190 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.1116.1515.27190 - Advanced Micro Devices, Inc.) Hidden
Catalyst Pro Control Center (x32 Version: 2012.1116.1515.27190 - Ihr Firmenname) Hidden
CCC Help Chinese Standard (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.1116.1514.27190 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.1116.1515.27190 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.04 - Piriform)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.04072 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.04072 - Cisco Systems, Inc.) Hidden
Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.3.0.15 - Swiss Academic Software)
Citrix Authentication Manager (x32 Version: 5.1.0.62606 - Citrix Systems, Inc.) Hidden
Citrix Receiver (DV) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver (HDX Flash-Umleitung) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.1.0.0 - Citrix Systems, Inc.)
Citrix Receiver (USB) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver Inside (x32 Version: 4.1.0.56471 - Citrix Systems, Inc.) Hidden
Citrix Receiver Updater (x32 Version: 4.1.0.56461 - Citrix Systems, Inc.) Hidden
Citrix Receiver(Aero) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Connectify (HKLM\...\Connectify) (Version: 5.0.1.27651 - Connectify)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{650DE870-ECA3-4E63-8D77-778512BE5D4C}) (Version:  - Microsoft)
Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FILEminimizer Suite (HKLM-x32\...\FILEminimizer Suite_is1) (Version:  - balesio AG)
Free Screen To Video V 2.0 (HKLM-x32\...\Free Screen To Video_is1) (Version: 2.0.0.0 - Koyote Soft)
gnuplot 4.6.5 (HKLM-x32\...\{AB419AC3-9BC1-4EC5-A75B-4D8870DD651F}_is1) (Version: 4.6.5 - gnuplot development team)
GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Hardcopy (HKLM-x32\...\Hardcopy) (Version: 2014.01.27 - www.hardcopy.de)
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Officejet Pro 8000 A809 Series 14.0 Rel. 6 (HKLM\...\{8649FF29-FF6F-47D8-B9DF-4389C99DA458}) (Version: 14.0 - HP)
HP Photosmart Wireless B110 All-In-One Driver Software 14.0 Rel. 6 (HKLM\...\{C63184F3-8343-408F-A948-DDB0AC969A99}) (Version: 14.0 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPAppStudio (x32 Version: 140.0.95.000 - Hewlett-Packard) Hidden
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
inSSIDer Home (HKLM-x32\...\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.236 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.236 - LogMeIn, Inc.) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Visio 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Visio MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visio Professional 2010 (HKLM-x32\...\Office14.VISIOR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Mozilla Firefox 20.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 20.0 (x86 en-US)) (Version: 20.0 - Mozilla)
Mozilla Firefox 32.0.3 (x86 en-US) (HKCU\...\Mozilla Firefox 32.0.3 (x86 en-US)) (Version: 32.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 17.0.5 - Mozilla)
Mozilla Thunderbird 17.0.5 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 17.0.5 (x86 de)) (Version: 17.0.5 - Mozilla)
Mozilla Thunderbird 24.5.0 (x86 de) (HKCU\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
myPrintMileage (Officejet Pro 8000 A809) (HKLM-x32\...\{366584A4-1D35-49B2-97B3-C803DDFCC543}) (Version: 1.00.0000 - Hewlett-Packard)
Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden
Nice PDF Compressor 2.0 (HKLM-x32\...\Nice PDF Compressor_is1) (Version:  - NicePDF Software, Inc.)
Nokia Connectivity Cable Driver (HKLM\...\{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}) (Version: 7.1.32.69 - )
Online Plug-in (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Panda USB Vaccine 1.0.1.4 (HKLM-x32\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version:  - Panda Security)
PC Remote (HKLM-x32\...\{B44AF2D8-9A5D-4653-AF10-F1697C98019F}) (Version: 3.38 - PC Remote)
PDF Architect (HKLM-x32\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH)
PDF Split And Merge Basic (HKLM\...\{C91B24F6-1629-11E2-B696-21676188709B}) (Version: 2.2.2 - Andrea Vacondio)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.1 - pdfforge)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
ProductContext (x32 Version: 140.0.001.000 - Hewlett-Packard) Hidden
PS_AIO_07_B110_SW_Min (x32 Version: 140.0.365.000 - Hewlett-Packard) Hidden
QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
Self-Service Plug-in (x32 Version: 4.1.0.41738 - Citrix Systems, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{359ADBEC-068A-4CC9-9174-77AB8EDB867A}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)
Skypeâ„¢ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Spotify (HKCU\...\Spotify) (Version: 0.9.13.24.g5dbb3103 - Spotify AB)
Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.8.21 - Synaptics Incorporated)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.3020.2 - TuneUp Software) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIOR_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.VISIOR_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.VISIOR_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2889914) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{F3F83933-75FC-4B60-84F2-3F8FA63D042E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{90140000-0054-0407-0000-0000000FF1CE}_Office14.VISIOR_{43C22E89-E170-4764-8E7E-7386E34F94E0}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VLC media player 2.1.1 (HKLM-x32\...\VLC media player) (Version: 2.1.1 - VideoLAN)
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden
Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
XnView 2.22 (HKLM-x32\...\XnView_is1) (Version: 2.22 - Gougelet Pierre-e)
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4243713041-920332011-2703711254-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================

25-09-2014 09:39:41 Removed PDF Architect

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-07-26 07:26 - 2014-09-25 19:03 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {1DB31D8C-5B28-419B-8D56-7071A393D155} - System32\Tasks\CCleanerSkipUAC => D:\Tools\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd)
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2601E706-4995-42C5-9826-660DA88632A9} - System32\Tasks\hcdll2_ex_x64 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe [2012-11-08] ()
Task: {28A96790-4BD4-46F0-BAD4-AD9EAB875916} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21] (Adobe Systems Incorporated)
Task: {3965868B-A952-4350-947C-ECFD7CB84555} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09] (Adobe Systems Incorporated)
Task: {5304E77F-3AD7-4061-BDF9-B31D836CFFC1} - System32\Tasks\PandaUSBVaccine => D:\Tools\Panda USB Vaccine\RunInteractiveWin.exe [2009-09-23] ()
Task: {57A0F150-FFC4-4DB1-805C-869C79332598} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core => C:\Users\rspri_000\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-12] (Facebook Inc.)
Task: {65EA9421-F9BA-46D9-A488-8D85C4708695} - System32\Tasks\hcdll2_ex_Win32 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe [2013-07-17] ()
Task: {8550A796-D1F3-45B3-951F-E622B8815121} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\HP\HP Software Update\HPWuSchd2.exe [2013-05-30] (Hewlett-Packard)
Task: {8763BF6A-2CAA-4C54-B7ED-80207F7ACE81} - System32\Tasks\Microsoft\Windows\Setup\8.1 auto install => C:\Windows\system32\NotificationUI.exe [2014-08-21] (Microsoft Corporation)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {B43ACD4D-BA62-489A-8DE7-6994B36C9F06} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-09-11] (Microsoft Corporation)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {DDCB73CE-E120-4783-B15F-2DD98CD5F56E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA => C:\Users\rspri_000\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-12] (Facebook Inc.)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job => C:\Users\rspri_000\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job => C:\Users\rspri_000\AppData\Local\Facebook\Update\FacebookUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-09-25 12:11 - 2014-08-08 13:30 - 00265080 _____ () D:\Tools\Bitdefender\Bitdefender 2015\txmlutil.dll
2014-09-25 12:11 - 2014-08-26 16:14 - 00003072 _____ () D:\Tools\Bitdefender\Bitdefender 2015\UI\accessl.ui
2014-09-25 12:11 - 2012-10-29 14:22 - 00152816 _____ () D:\Tools\Bitdefender\Bitdefender 2015\bdfwcore.dll
2014-09-25 12:11 - 2014-07-24 09:44 - 00780592 _____ () D:\Tools\Bitdefender\Bitdefender 2015\otengines_001_001\ashttpbr.mdl
2014-09-25 12:11 - 2014-07-24 09:44 - 00568400 _____ () D:\Tools\Bitdefender\Bitdefender 2015\otengines_001_001\ashttpdsp.mdl
2014-09-25 12:11 - 2014-07-24 09:44 - 02602680 _____ () D:\Tools\Bitdefender\Bitdefender 2015\otengines_001_001\ashttpph.mdl
2014-09-25 12:11 - 2014-07-24 09:44 - 01323408 _____ () D:\Tools\Bitdefender\Bitdefender 2015\otengines_001_001\ashttprbl.mdl
2014-04-30 08:49 - 2013-10-30 11:49 - 00126968 _____ () C:\Program Files (x86)\Hardcopy\HcDLL2_43_x64.dll
2014-04-30 08:49 - 2012-11-08 08:38 - 00044608 _____ () C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe
2014-04-30 08:49 - 2013-07-17 17:03 - 00037880 _____ () C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe
2014-03-12 10:55 - 2014-03-12 10:56 - 00176048 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2013-10-10 23:48 - 2013-10-10 23:48 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2013-06-09 14:09 - 2013-05-14 15:29 - 00036128 _____ () C:\Program Files (x86)\Connectify\NativeLibrary.dll
2013-06-09 14:09 - 2013-05-14 15:29 - 00950560 _____ () C:\Program Files (x86)\Connectify\ConnectifyNAT.dll
2013-06-09 14:09 - 2013-05-14 15:29 - 00378144 _____ () C:\Program Files (x86)\Connectify\log4cplus.dll
2013-06-09 14:09 - 2013-05-14 15:29 - 00060704 _____ () C:\Program Files (x86)\Connectify\LibDispatch.dll
2014-04-30 08:49 - 2012-07-05 15:56 - 00052800 _____ () C:\Program Files (x86)\Hardcopy\hardcopy_05.dll
2014-04-30 08:49 - 2013-10-30 11:49 - 00117752 _____ () C:\Program Files (x86)\Hardcopy\HcDLL2_43_Win32.dll
2014-04-30 08:49 - 2014-01-10 18:57 - 03647456 _____ () C:\Program Files (x86)\Hardcopy\HcDllS.dll
2014-09-24 22:52 - 2014-09-24 22:52 - 03715184 _____ () D:\Tools\Mozilla Firefox\mozjs.dll
2014-04-23 09:23 - 2014-01-28 07:47 - 00430080 _____ () C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox\components\FirefoxPickerCommunication.dll
2014-09-25 12:11 - 2014-08-08 13:29 - 00204280 _____ () D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff\components\txmlutil.dll
2014-09-25 12:11 - 2014-08-08 13:39 - 00070392 _____ () D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff\components\bdwtxff.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\rspri_000\Desktop\ComboFix.exe:BDU
AlternateDataStreams: C:\Users\rspri_000\Desktop\FRST64.exe:BDU
AlternateDataStreams: C:\Users\rspri_000\Desktop\mbam-setup-2.0.2.1012.exe:BDU
AlternateDataStreams: C:\Users\rspri_000\Desktop\USBVaccineSetup.exe:BDU
AlternateDataStreams: C:\Users\rspri_000\Desktop\zoek.exe:BDU
AlternateDataStreams: C:\Users\rspri_000\Downloads\7z920.exe:BDU
AlternateDataStreams: C:\Users\rspri_000\Downloads\Defogger.exe:BDU
AlternateDataStreams: C:\Users\rspri_000\Downloads\F-SecureOnlineScanner.exe:BDU
AlternateDataStreams: C:\Users\rspri_000\Downloads\FRST64.exe:BDU

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk"
HKLM\...\StartupApproved\Run: => "Connectify Hotspot"
HKLM\...\StartupApproved\Run: => "Connectify Dispatch"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKLM\...\StartupApproved\Run32: => "HP Software Update"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKLM\...\StartupApproved\Run32: => "Cisco AnyConnect Secure Mobility Agent for Windows"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "ConnectionCenter"
HKLM\...\StartupApproved\Run32: => "Redirector"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKCU\...\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKCU\...\StartupApproved\StartupFolder: => "OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk"
HKCU\...\StartupApproved\Run: => "Pando Media Booster"
HKCU\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKCU\...\StartupApproved\Run: => "PC Remote Server"

========================= Accounts: ==========================

Administrator (S-1-5-21-4243713041-920332011-2703711254-500 - Disabled - Status: Degraded)
Gast (S-1-5-21-4243713041-920332011-2703711254-501 - Disabled - Status: Degraded)
HomeGroupUser$ (S-1-5-21-4243713041-920332011-2703711254-1003 - Enabled - Status: OK)
rspri_000 (S-1-5-21-4243713041-920332011-2703711254-1001 - Enabled - Status: OK) => C:\Users\rspri_000

==================== Faulty Device Manager Devices =============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Photosmart B110 series
Description: Photosmart B110 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: FingerPrinter Reader
Description: FingerPrinter Reader
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Photosmart B110 series
Description: Photosmart B110 series
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: HP
Service: StillCam
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Basissystemgerät
Description: Basissystemgerät
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Basissystemgerät
Description: Basissystemgerät
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/26/2014 11:18:47 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm OUTLOOK.EXE, Version 12.0.6691.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1e98

Startzeit: 01cfd9558f66d4f1

Endzeit: 4294967295

Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE

Berichts-ID: 1c695257-455e-11e4-bec2-0026221d60c8

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/26/2014 10:31:24 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RAPHAELS_PC)
Description: Bei der Aktivierung der App „microsoft.microsoftskydrive_8wekyb3d8bbwe!Microsoft.MicrosoftSkyDrive“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (09/26/2014 10:31:24 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1ab8

Startzeit: 01cfd963cc7f5002

Endzeit: 4294967295

Anwendungspfad: C:\Windows\system32\wwahost.exe

Berichts-ID: 1592387a-4557-11e4-bec2-0026221d60c8

Vollständiger Name des fehlerhaften Pakets: microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe

Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Microsoft.MicrosoftSkyDrive

Error: (09/26/2014 10:28:21 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: RAPHAELS_PC)
Description: Die App „microsoft.microsoftskydrive_8wekyb3d8bbwe!Microsoft.MicrosoftSkyDrive“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.

Error: (09/26/2014 08:53:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LiveComm.exe, Version: 17.0.1119.516, Zeitstempel: 0x519504e1
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16912, Zeitstempel: 0x536464ba
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000007b58
ID des fehlerhaften Prozesses: 0x149c
Startzeit der fehlerhaften Anwendung: 0xLiveComm.exe0
Pfad der fehlerhaften Anwendung: LiveComm.exe1
Pfad des fehlerhaften Moduls: LiveComm.exe2
Berichtskennung: LiveComm.exe3
Vollständiger Name des fehlerhaften Pakets: LiveComm.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: LiveComm.exe5

Error: (09/25/2014 11:17:15 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm USBVaccine.exe, Version 1.0.1.4 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: c3c

Startzeit: 01cfd8efbcfd1a8b

Endzeit: 4

Anwendungspfad: D:\Tools\Panda USB Vaccine\USBVaccine.exe

Berichts-ID: 4e56deb6-44f9-11e4-bec2-0026221d60c8

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/25/2014 04:05:58 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Gmer-19357.exe, Version 2.1.19357.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: b84

Startzeit: 01cfd8c9caf59126

Endzeit: 16

Anwendungspfad: C:\Users\rspri_000\Desktop\Virenjagd\Gmer-19357.exe

Berichts-ID: 1089724c-44bd-11e4-bebf-0026221d60c8

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/25/2014 04:03:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Gmer-19357.exe, Version 2.1.19357.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1478

Startzeit: 01cfd8c96f149e7d

Endzeit: 9

Anwendungspfad: C:\Users\rspri_000\Downloads\Gmer-19357.exe

Berichts-ID: b1b9595c-44bc-11e4-bebf-0026221d60c8

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/25/2014 11:36:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 32.0.3.5379, Zeitstempel: 0x54224e6b
Name des fehlerhaften Moduls: mozalloc.dll, Version: 32.0.3.5379, Zeitstempel: 0x54221b67
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0x3f8
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Vollständiger Name des fehlerhaften Pakets: plugin-container.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: plugin-container.exe5

Error: (09/25/2014 11:36:25 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 32.0.3.5379 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 164

Startzeit: 01cfd88846864c38

Endzeit: 16

Anwendungspfad: D:\Tools\Mozilla Firefox\firefox.exe

Berichts-ID: 6414a6a0-4497-11e4-bebd-0026221d60c8

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:


System errors:
=============
Error: (09/26/2014 01:47:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "ZoneAlarm Privacy Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (09/26/2014 01:47:08 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "PDF Architect Service" wurde mit folgendem Fehler beendet: 
%%2147500037

Error: (09/26/2014 01:46:29 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Bitdefender Virus Shield" wurde nicht richtig gestartet.

Error: (09/26/2014 01:44:39 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst Gruppenrichtlinienclient konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.

Error: (09/26/2014 01:43:54 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: 
%%1056

Error: (09/26/2014 01:43:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Office Software Protection Platform" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (09/26/2014 01:43:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (09/26/2014 01:43:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (09/26/2014 01:43:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (09/26/2014 01:43:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "LogMeIn Hamachi Tunneling Engine" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


Microsoft Office Sessions:
=========================
Error: (08/29/2014 05:07:07 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6700.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 6872 seconds with 3180 seconds of active time.  This session ended with a crash.

Error: (08/26/2014 04:33:21 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 25468 seconds with 4260 seconds of active time.  This session ended with a crash.

Error: (08/20/2014 04:21:16 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 28650 seconds with 2340 seconds of active time.  This session ended with a crash.

Error: (05/19/2014 09:20:48 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2014-09-25 19:02:46.863
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

Processor: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
Percentage of memory in use: 46%
Total physical RAM: 4060.79 MB
Available physical RAM: 2156.66 MB
Total Pagefile: 5020.79 MB
Available Pagefile: 2792.74 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:68.02 GB) (Free:25.41 GB) NTFS
Drive d: (Programme) (Fixed) (Total:164.52 GB) (Free:97.15 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: F7B36CEB)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=68 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=164.5 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-09-2014
Ran by rspri_000 (administrator) on RAPHAELS_PC on 26-09-2014 13:49:57
Running from C:\Users\rspri_000\Desktop
Loaded Profile: rspri_000 (Available profiles: rspri_000)
Platform: Windows 8 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe
(Panda Security) D:\Tools\Panda USB Vaccine\USBVaccine.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
(Microsoft Corporation) D:\Tools\ZuneLauncher.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe
(Spotify Ltd) C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwtxapps.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(sw4you) C:\Program Files (x86)\Hardcopy\hardcopy.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) D:\Tools\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Connectify Hotspot] => C:\Program Files (x86)\Connectify\Connectify.exe [5236512 2013-05-14] (Connectify)
HKLM\...\Run: [Connectify Dispatch] => C:\Program Files (x86)\Connectify\DispatchUI.exe [3121440 2013-05-14] (Connectify)
HKLM\...\Run: [Zune Launcher] => D:\Tools\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-28] (Synaptics Incorporated)
HKLM\...\Run: [Bdagent] => D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe [1580360 2014-08-20] (Bitdefender)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2013-10-10] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [PC Remote Server] => C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [884376 2013-04-07] (PC Remote)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Spotify Web Helper] => C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-20] (Spotify Ltd)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Bitdefender-Geldbörse-Agent] => D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe [815088 2014-08-14] (Bitdefender)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK
ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk /m /f \Device\HarddiskVolume4autocheck autochk * 

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\pmbxie.dll (Bitdefender)
Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll (Bitdefender)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 172.31.12.11 172.31.12.12

FireFox:
========
FF ProfilePath: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\rspri_000\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\avira-safesearch.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-maps.xml
FF Extension: Avira Browser Safety - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\abs@avira.com [2014-09-04]
FF Extension: Grooveshark Unlocker - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-05-15]
FF Extension: ProxTube - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11]
FF Extension: Adblock Plus - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-06]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: Bitdefender Antispam Toolbar - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext [2014-09-25]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-10-27]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2014-04-23]
FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff
FF Extension: Bitdefender Wallet - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-09-25]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF StartMenuInternet: FIREFOX.EXE - D:\Tools\Mozilla Firefox\firefox.exe

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 BdDesktopParental; D:\Tools\Bitdefender\Bitdefender 2015\bdparentalservice.exe [77632 2014-08-08] (Bitdefender)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [156672 2013-05-14] (Connectify) [File not signed]
R2 Hamachi2Svc; C:\Tools\LogMeIn Hamachi\hamachi-2.exe [2525008 2014-09-04] (LogMeIn Inc.)
R3 hpqcxs08; C:\HP\Digital Imaging\bin\hpqcxs08.dll [254824 2011-04-29] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\HP\Digital Imaging\bin\hpqddsvc.dll [138600 2011-04-29] (Hewlett-Packard Co.)
R2 HPSLPSVC; C:\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
S2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
R2 UPDATESRV; D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-08-08] (Bitdefender)
R2 VSSERV; D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe [1513952 2014-08-11] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S3 WMZuneComm; D:\Tools\WMZuneComm.exe [306400 2011-08-05] (Microsoft Corporation)
S3 ZuneNetworkSvc; D:\Tools\ZuneNss.exe [8277728 2011-08-05] (Microsoft Corporation)
S3 ZuneWlanCfgSvc; D:\Tools\ZuneWlanCfgSvc.exe [467680 2011-08-05] (Microsoft Corporation)
S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1260120 2014-05-16] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261496 2013-07-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-05-16] (BitDefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-11-19] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-09-25] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-09-25] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-06] (DT Soft Ltd)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [419616 2014-07-02] (BitDefender S.R.L.)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 AAMWRegFilter; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter64.sys [X]
S3 ASW3Scan; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-26 10:25 - 2014-09-26 10:41 - 659610001 _____ () C:\Users\rspri_000\Documents.rar
2014-09-25 21:04 - 2014-09-25 21:04 - 00001408 _____ () C:\Users\rspri_000\Desktop\mbam.txt
2014-09-25 20:56 - 2014-09-26 13:51 - 00021527 _____ () C:\Users\rspri_000\Desktop\FRST.txt
2014-09-25 20:56 - 2014-09-25 20:56 - 00006273 _____ () C:\Users\rspri_000\Desktop\zoek-results.txt
2014-09-25 20:44 - 2014-09-25 20:46 - 00006273 _____ () C:\zoek-results.log
2014-09-25 20:43 - 2014-09-25 20:46 - 00000000 ____D () C:\zoek_backup
2014-09-25 20:41 - 2014-09-25 20:41 - 01290752 _____ () C:\Users\rspri_000\Desktop\zoek.exe
2014-09-25 19:49 - 2014-09-25 20:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-25 19:49 - 2014-09-25 19:49 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-09-25 19:49 - 2014-09-25 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-09-25 19:48 - 2014-09-25 19:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-09-25 19:48 - 2014-09-25 19:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\rspri_000\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-25 19:48 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-25 19:48 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-25 19:48 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-25 19:37 - 2014-09-25 19:41 - 00000000 ____D () C:\AdwCleaner
2014-09-25 19:36 - 2014-09-25 19:36 - 01373475 _____ () C:\Users\rspri_000\Desktop\AdwCleaner_3.310.exe
2014-09-25 19:10 - 2014-09-25 19:10 - 00024302 _____ () C:\ComboFix.txt
2014-09-25 18:52 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-25 18:52 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-25 18:52 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-25 18:49 - 2014-09-25 19:10 - 00000000 ____D () C:\Qoobox
2014-09-25 18:49 - 2014-09-25 19:04 - 00000000 ____D () C:\Windows\erdnt
2014-09-25 18:45 - 2014-09-25 18:46 - 05580995 ____R (Swearware) C:\Users\rspri_000\Desktop\ComboFix.exe
2014-09-25 18:43 - 2014-09-25 18:43 - 00003052 _____ () C:\Windows\System32\Tasks\PandaUSBVaccine
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Panda Security
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2014-09-25 18:40 - 2014-09-25 18:40 - 00848856 _____ (Panda Security ) C:\Users\rspri_000\Desktop\USBVaccineSetup.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 01110476 _____ () C:\Users\rspri_000\Downloads\7z920.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-09-25 16:43 - 2014-09-25 16:43 - 509766635 _____ () C:\Windows\MEMORY.DMP
2014-09-25 16:43 - 2014-09-25 16:43 - 00286896 _____ () C:\Windows\Minidump\092514-25412-01.dmp
2014-09-25 16:01 - 2014-09-25 16:01 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 16:00 - 2014-09-25 16:03 - 05176232 _____ (F-Secure Corporation) C:\Users\rspri_000\Downloads\F-SecureOnlineScanner.exe
2014-09-25 15:46 - 2014-09-26 07:12 - 00000000 ____D () C:\Users\rspri_000\Desktop\Virenjagd
2014-09-25 15:46 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Desktop\FRST64.exe
2014-09-25 15:43 - 2014-09-25 15:45 - 00051713 _____ () C:\Users\rspri_000\Downloads\Addition.txt
2014-09-25 15:41 - 2014-09-26 13:50 - 00000000 ____D () C:\FRST
2014-09-25 15:41 - 2014-09-25 15:45 - 00056212 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2014-05-16 13:04 - 00647752 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2014-09-25 12:11 - 2014-05-16 13:01 - 01260120 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2014-09-25 12:11 - 2013-11-19 14:44 - 00098768 _____ (BitDefender LLC) C:\Windows\system32\Drivers\bdfndisf6.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00082824 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00074512 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll
2014-09-25 12:11 - 2013-09-08 20:04 - 00023568 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys
2014-09-25 12:11 - 2013-07-17 19:31 - 00261496 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys
2014-09-25 12:11 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll
2014-09-25 12:00 - 2014-09-25 12:18 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:00 - 2014-09-25 12:12 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:00 - 2014-09-25 12:12 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:00 - 2014-07-04 17:49 - 49563064 ____H () C:\bdr-im01.gz
2014-09-25 12:00 - 2013-08-13 13:38 - 03271472 ____H () C:\bdr-bz01
2014-09-25 11:54 - 2014-09-25 12:18 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-07-02 17:47 - 00419616 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2014-09-25 11:54 - 2013-11-04 15:47 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUISkin.dll
2014-09-25 11:54 - 2013-11-04 15:46 - 00034384 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUH.dll
2014-09-25 11:54 - 2013-08-23 13:48 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2014-09-25 11:49 - 2014-09-25 11:54 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 11:20 - 2014-09-25 11:51 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:12 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-18 22:12 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 09:20 - 2014-08-09 10:30 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-09-18 09:20 - 2014-08-09 10:29 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2014-09-15 20:02 - 2014-09-15 20:03 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:23 - 2014-09-12 10:24 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:11 - 2014-09-12 10:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:52 - 2014-09-26 00:58 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-12 09:52 - 2014-09-25 09:58 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-12 09:52 - 2014-09-12 09:53 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:52 - 2014-09-12 09:53 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 08:18 - 2014-08-21 01:40 - 00732880 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-09-12 08:18 - 2014-08-20 19:05 - 00694784 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-09-12 08:18 - 2014-08-20 19:02 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-09-12 08:18 - 2014-06-24 09:35 - 00010450 _____ () C:\Windows\system32\autoconfig.cab
2014-09-12 08:18 - 2014-06-24 08:41 - 10115584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-09-12 08:18 - 2014-06-24 08:40 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2014-09-12 08:18 - 2014-06-24 08:39 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-09-12 08:18 - 2014-06-24 06:08 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-09-12 08:18 - 2014-06-24 06:06 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-08-20 19:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-06-24 08:39 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-09-12 08:17 - 2014-06-24 06:06 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 09:24 - 2014-08-16 11:33 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 11:33 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 09:24 - 2014-08-16 11:32 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 09:35 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 09:24 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 09:24 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-09-11 09:24 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-09-11 09:24 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 09:24 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 09:24 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 09:24 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 09:24 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 09:23 - 2014-08-16 11:34 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 09:23 - 2014-08-16 11:33 - 19280384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 09:23 - 2014-08-16 11:32 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 14369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 08:49 - 2014-08-28 13:34 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-09-11 08:49 - 2014-08-28 08:05 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:01 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-09-11 08:49 - 2014-08-01 01:40 - 01287680 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00875688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00869544 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-06-05 03:12 - 00678600 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2014-09-11 08:48 - 2014-06-04 01:12 - 00536776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-08-29 10:31 - 2014-08-23 08:47 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-26 13:51 - 2014-09-25 20:56 - 00021527 _____ () C:\Users\rspri_000\Desktop\FRST.txt
2014-09-26 13:50 - 2014-09-25 15:41 - 00000000 ____D () C:\FRST
2014-09-26 13:50 - 2013-07-25 23:34 - 01497477 _____ () C:\Windows\WindowsUpdate.log
2014-09-26 13:48 - 2013-04-06 15:49 - 07196672 ___SH () C:\Users\rspri_000\Desktop\Thumbs.db
2014-09-26 13:47 - 2013-06-02 16:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\LogMeIn Hamachi
2014-09-26 13:47 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-26 13:45 - 2013-07-27 09:01 - 00038446 _____ () C:\Windows\PFRO.log
2014-09-26 13:44 - 2012-07-26 07:26 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-09-26 13:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-09-26 11:11 - 2013-12-15 23:39 - 00000000 ____D () C:\ProgramData\FILEminimizer
2014-09-26 10:41 - 2014-09-26 10:25 - 659610001 _____ () C:\Users\rspri_000\Documents.rar
2014-09-26 10:25 - 2013-04-06 11:04 - 00000000 ____D () C:\Users\rspri_000
2014-09-26 10:13 - 2014-03-06 12:50 - 00000000 ___RD () C:\Users\rspri_000\Dropbox
2014-09-26 09:45 - 2014-03-06 12:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Dropbox
2014-09-26 07:12 - 2014-09-25 15:46 - 00000000 ____D () C:\Users\rspri_000\Desktop\Virenjagd
2014-09-26 01:07 - 2013-04-06 14:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-26 00:58 - 2014-09-12 09:52 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-25 21:04 - 2014-09-25 21:04 - 00001408 _____ () C:\Users\rspri_000\Desktop\mbam.txt
2014-09-25 20:56 - 2014-09-25 20:56 - 00006273 _____ () C:\Users\rspri_000\Desktop\zoek-results.txt
2014-09-25 20:46 - 2014-09-25 20:44 - 00006273 _____ () C:\zoek-results.log
2014-09-25 20:46 - 2014-09-25 20:43 - 00000000 ____D () C:\zoek_backup
2014-09-25 20:41 - 2014-09-25 20:41 - 01290752 _____ () C:\Users\rspri_000\Desktop\zoek.exe
2014-09-25 20:39 - 2014-09-25 19:49 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-25 20:35 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\Vss
2014-09-25 19:49 - 2014-09-25 19:49 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-09-25 19:49 - 2014-09-25 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-09-25 19:49 - 2014-09-25 19:48 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-09-25 19:48 - 2014-09-25 19:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\rspri_000\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-25 19:48 - 2013-07-16 23:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-25 19:41 - 2014-09-25 19:37 - 00000000 ____D () C:\AdwCleaner
2014-09-25 19:36 - 2014-09-25 19:36 - 01373475 _____ () C:\Users\rspri_000\Desktop\AdwCleaner_3.310.exe
2014-09-25 19:10 - 2014-09-25 19:10 - 00024302 _____ () C:\ComboFix.txt
2014-09-25 19:10 - 2014-09-25 18:49 - 00000000 ____D () C:\Qoobox
2014-09-25 19:10 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-09-25 19:04 - 2014-09-25 18:49 - 00000000 ____D () C:\Windows\erdnt
2014-09-25 19:03 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-09-25 18:46 - 2014-09-25 18:45 - 05580995 ____R (Swearware) C:\Users\rspri_000\Desktop\ComboFix.exe
2014-09-25 18:43 - 2014-09-25 18:43 - 00003052 _____ () C:\Windows\System32\Tasks\PandaUSBVaccine
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Panda Security
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2014-09-25 18:40 - 2014-09-25 18:40 - 00848856 _____ (Panda Security ) C:\Users\rspri_000\Desktop\USBVaccineSetup.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 01110476 _____ () C:\Users\rspri_000\Downloads\7z920.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-09-25 16:49 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-09-25 16:43 - 2014-09-25 16:43 - 509766635 _____ () C:\Windows\MEMORY.DMP
2014-09-25 16:43 - 2014-09-25 16:43 - 00286896 _____ () C:\Windows\Minidump\092514-25412-01.dmp
2014-09-25 16:03 - 2014-09-25 16:00 - 05176232 _____ (F-Secure Corporation) C:\Users\rspri_000\Downloads\F-SecureOnlineScanner.exe
2014-09-25 16:01 - 2014-09-25 16:01 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 15:45 - 2014-09-25 15:43 - 00051713 _____ () C:\Users\rspri_000\Downloads\Addition.txt
2014-09-25 15:45 - 2014-09-25 15:41 - 00056212 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:40 - 2014-09-25 15:46 - 02108928 _____ (Farbar) C:\Users\rspri_000\Desktop\FRST64.exe
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 14:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-09-25 14:03 - 2013-06-09 14:08 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-25 13:59 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\Offline Web Pages
2014-09-25 13:55 - 2013-04-06 12:30 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4243713041-920332011-2703711254-1001
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 13:21 - 2013-04-06 14:29 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-09-25 13:04 - 2014-03-18 13:47 - 00000000 ____D () C:\$Windows.~BT
2014-09-25 12:55 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:18 - 2014-09-25 12:00 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:18 - 2014-09-25 11:54 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:12 - 2014-09-25 12:00 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:12 - 2014-09-25 12:00 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2013-08-23 08:02 - 00018002 _____ () C:\Windows\setupact.log
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-09-25 11:49 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:51 - 2014-09-25 11:20 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 09:58 - 2014-09-12 09:52 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-25 09:42 - 2012-07-26 12:27 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-09-25 09:42 - 2012-07-26 12:27 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-09-25 09:42 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-25 08:55 - 2014-05-14 08:54 - 00093004 _____ () C:\Users\rspri_000\Desktop\Transferpräse Laptop-Citrix.pptx
2014-09-24 14:59 - 2014-08-19 17:38 - 00000000 ____D () C:\Users\rspri_000\Desktop\Urlaub
2014-09-24 14:16 - 2013-08-14 19:06 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Spotify
2014-09-24 12:45 - 2013-08-14 19:05 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Spotify
2014-09-24 09:10 - 2014-07-21 19:55 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung LH
2014-09-24 09:10 - 2014-04-14 11:39 - 00000000 ____D () C:\Users\rspri_000\Desktop\Dubbel 22.Auflage
2014-09-24 09:10 - 2013-04-08 11:41 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung Praktikum
2014-09-18 23:37 - 2013-06-04 22:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TS3Client
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 16:41 - 2013-04-06 13:41 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-18 15:22 - 2014-03-06 12:46 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-16 13:50 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-09-15 21:50 - 2013-12-08 20:08 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\vlc
2014-09-15 20:03 - 2014-09-15 20:02 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-15 10:07 - 2013-04-10 10:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-09-15 10:07 - 2013-04-10 10:06 - 00000000 ____D () C:\HP
2014-09-15 10:07 - 2013-04-09 20:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\HpUpdate
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-09-12 10:45 - 2014-09-12 10:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:24 - 2014-09-12 10:23 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:21 - 2013-04-06 14:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TuneUp Software
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:19 - 2013-04-06 14:12 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-09-12 10:17 - 2013-04-21 20:47 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Skype
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:53 - 2014-09-12 09:52 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:53 - 2014-09-12 09:52 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 09:36 - 2013-04-21 20:47 - 00000000 ____D () C:\ProgramData\Skype
2014-09-11 20:08 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-09-11 09:30 - 2013-04-18 11:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 09:23 - 2013-07-23 21:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 09:14 - 2013-04-07 18:42 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-09 22:35 - 2014-08-26 10:04 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe
2014-09-09 22:34 - 2013-04-06 14:18 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-08 22:35 - 2013-04-09 20:10 - 00000000 ____D () C:\Tools
2014-09-07 12:28 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-06 14:48 - 2013-04-06 16:19 - 00000000 ____D () C:\Users\rspri_000\Documents\BAföG
2014-09-04 14:48 - 2014-04-23 09:23 - 00000000 ____D () C:\ProgramData\Swiss Academic Software
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-01 20:56 - 2014-07-11 08:06 - 00428056 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 13:34 - 2014-09-11 08:49 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-28 08:05 - 2014-09-11 08:49 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-28 08:02 - 2014-09-11 08:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-28 08:01 - 2014-09-11 08:49 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-17 09:14

==================== End Of Log ============================
         
--- --- ---

Alt 29.09.2014, 15:27   #10
M-K-D-B
/// TB-Ausbilder
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Zitat:
Zitat von Raphael_S Beitrag anzeigen
Ich habe eine extere Festplatte mit wichtigen Daten, die ich in letzter Zeit auch an dem PC benutzt habe. Kann sich der Virus auch au diese kopiert haben?
Ja, kann sein. Sobald die externe Festplatte angeschlossen wird, sollte das Laufwerk aber von Panda Vaccine automatisch geimpft werden.

Wir verwenden noch ESET, das schaut noch auf der externen Festplatte nach.



Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 3 h) dauern.
Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg.




Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:
ATTFilter
start
CloseProcesses:
EmptyTemp:
end
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.






Schritt 2

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset







Schritt 3
Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei des FRST-Fix,
  • die Logdatei von ESET,
  • die Logdatei von SecurityCheck.

Alt 30.09.2014, 15:58   #11
Raphael_S
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Hi,

Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-09-2014
Ran by rspri_000 at 2014-09-30 12:52:45 Run:2
Running from C:\Users\rspri_000\Desktop
Loaded Profile: rspri_000 (Available profiles: rspri_000)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
EmptyTemp:
end
*****************

Processes closed successfully.
EmptyTemp: => Removed 387.9 MB temporary data.


The system needed a reboot. 

==== End of Fixlog ====
         
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=a768df7aab99294ba94d184e26d30798
# engine=20367
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-09-30 02:39:13
# local_time=2014-09-30 04:39:13 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT 
# compatibility_mode_1='Bitdefender Antivirus'
# compatibility_mode=2066 16777213 100 100 12721 115936862 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 11745633 20446673 0 0
# scanned=274133
# found=4
# cleaned=0
# scan_time=12508
sh=98FCF260C8C676E33DA77173AB222BA6B0142116 ft=1 fh=e0b1efaf129489ac vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\rspri_000\AppData\Roaming\RHEng\C71AAAB9C9C34F278CC3EB901F141CEE\zafwSetupWeb_131_211_000.exe"
sh=9434866971DD357600C9F2B1E31B7893C3A070F0 ft=1 fh=4f14aeb246e47811 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\rspri_000\Downloads\PDFCreator-1_7_1_setup.exe"
sh=DC2A589D4932CB212AA461265C923A6E0BF7D210 ft=1 fh=7dcb11e90d56dfe3 vn="Variante von Win32/InstallCore.QH evtl. unerwünschte Anwendung" ac=I fn="C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe"
sh=C24089D407E6280B79BEC86532E9DE0118E4DE71 ft=1 fh=c71c0011cedfdcb5 vn="Win32/Somoto.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\rspri_000\Local Settings\Application Data\Bundled software uninstaller\biclient.exe"
         
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.87  
   x64 (UAC is enabled)  
 Internet Explorer 10 Out of date! 
``````````````Antivirus/Firewall Check:`````````````` 
Bitdefender Antivirus   
Windows Defender        
 Antivirus out of date!  
`````````Anti-malware/Other Utilities Check:````````` 
 TuneUp Utilities Language Pack (de-DE) 
 Java 7 Update 67  
 Adobe Flash Player 	15.0.0.152  
 Adobe Reader XI  
 Mozilla Firefox 20.0 Firefox out of Date!  
 Mozilla Thunderbird (17.0.5) 
````````Process Check: objlist.exe by Laurent````````  
 ESET ESET Online Scanner OnlineScannerApp.exe  
 Bitdefender Bitdefender 2015 vsserv.exe  
 Bitdefender Bitdefender 2015 updatesrv.exe  
 Bitdefender Bitdefender 2015 bdagent.exe  
 Bitdefender Bitdefender 2015 bdwtxag.exe  
 Bitdefender Bitdefender 2015 Antispam32 bdwtxapps.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log``````````````````````
         

Alt 30.09.2014, 16:30   #12
M-K-D-B
/// TB-Ausbilder
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Reste entfernen
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:
ATTFilter
start
CloseProcesses:
C:\Users\rspri_000\Downloads\PDFCreator-1_7_1_setup.exe
C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
C:\Users\rspri_000\Local Settings\Application Data\Bundled software uninstaller
end
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Die Fixlog von FRST gleich posten, da diese sonst mit DelFix (siehe weiter unten) automatisch entfernt wird!






Wenn du keine Probleme mehr mit Malware hast, dann sind wir hier fertig. Deine Logdateien sind sauber.
Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern.





Ändere regelmäßig alle deine Passwörter, jetzt nach der Bereinigung ist ein idealer Zeitpunkt dafür!
  • Verwende für jede Anwendung und jeden Account ein anderes Passwort.
  • Ändere regelmäßig dein Passwort, vor allem bei Onlinebanking oder deinem Emailpostfach ist das sehr wichtig.
  • Speichere keine Passwörter auf deinem PC, gib diese nicht an Dritte weiter.
  • Ein sicheres Passwort besteht aus mindestens 8 Zeichen und beinhaltet Groß- und Kleinbuchstaben, Zahlen und Sonderzeichen.
  • Benutze keine Zahlen- oder Buchstabenkombinationen, ( zB 12345678, qwertzui) auch keine Zahlen oder Buchstabenmuster.
  • Verwende keine Passwörter die einen Bezug zu dir, deinem Wohnort, Familienmitglied oder Haustier (Geburtsdatum, Postleitzahl, Adresse, Name) haben.






Schritt 1
Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.







Schritt 2
Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems.


Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti-Viren-Programm und zusätzlicher Schutz
  • Gehe sicher, dass du immer nur eine Anti-Viren Software installiert hast und dass diese auch up to date ist! Ein kostenloses Anti-Viren Programm, das wir empfehlen, wäre z. B. Avast! Free Antivirus oder Microsoft Security Essentials.
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt. Du kannst es zusätzlich zu deinem Anti-Viren Programm verwenden.
    Update das Tool und lasse es einmal in der Woche laufen. Die Kaufversion bietet zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • AdwCleaner
    Dieses Tool erkennt eine Vielzahl von Werbeprogrammen (Adware) und unerwünschten Programmen (PUPs).
    Starte das Tool einmal die Woche und lass es laufen. Sollte eine neue Version verfügbar sein, so wird dies angezeigt und du kannst dir die neueste Version direkt von der Herstellerseite auf den Desktop herunterladen. Auch dieses Programm kann parallel zu deinem Anti-Viren Programm verwendet werden.
  • SpywareBlaster
    Eine kurze Einführung findest du Hier


Alternative Browser
Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Mozilla Firefox
  • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
  • NoScript
    Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt, wenn Du es bestätigst.
  • AdblockPlus
    Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzuzufügen reicht und dieser wird nicht mehr geladen.
    Es spart außerdem Downloadkapazität.


Performance
  • Halte dich fern von Registry Cleanern.
    Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link:
    Miekemoes Blogspot ( MVP )


Was du vermeiden solltest:
  • Klicke nicht auf alles, nur weil es dich dazu auffordert und schön bunt ist.
  • Verwende keine P2P oder Filesharing Software (Emule, uTorrent,..).
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie z.B. deinFoto.jpg.exe.
  • Lade keine Software von Softonic oder Chip herunter, da diese Installer oft mit Adware oder unerünschter Software versehen sind!



Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen?

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

Alt 30.09.2014, 17:15   #13
Raphael_S
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-09-2014
Ran by rspri_000 at 2014-09-30 18:03:02 Run:3
Running from C:\Users\rspri_000\Desktop
Loaded Profile: rspri_000 (Available profiles: rspri_000)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
C:\Users\rspri_000\Downloads\PDFCreator-1_7_1_setup.exe
C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
C:\Users\rspri_000\Local Settings\Application Data\Bundled software uninstaller
end
*****************

Processes closed successfully.
C:\Users\rspri_000\Downloads\PDFCreator-1_7_1_setup.exe => Moved successfully.
C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe => Moved successfully.
C:\Users\rspri_000\Local Settings\Application Data\Bundled software uninstaller => Moved successfully.


The system needed a reboot. 

==== End of Fixlog ====
         

Alt 01.10.2014, 15:21   #14
M-K-D-B
/// TB-Ausbilder
 
Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Standard

Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar



Ich bin froh, dass wir helfen konnten

In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest:
Lob, Kritik und Wünsche
Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank!

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen.

Antwort

Themen zu Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar
administrator, adobe flash player, bitdefender 2015, converter, dateien verschwinden, dvdvideosoft ltd., fehlercode 0x80000003, fehlercode 0xc0000005, fehlercode 22, fehlercode 28, fehlercode windows, flash player, homepage, hotspot, install.exe, nicht sichtbar, pup.optional.opencandy, pup.optional.pricemeter.a, services.exe, speicherplatz, spotify web helper, this device is disabled. (code 22), trojan.lnk.gen, usb-stick, win32/installcore.qh, win32/installmonetizer.aq, win32/somoto.a, win32/toolbar.conduit, windowsapps, winlogon.exe




Ähnliche Themen: Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar


  1. USB-Stick Dateien sind nur noch Verknüpfungen
    Log-Analyse und Auswertung - 17.08.2015 (44)
  2. auf meinem Stick kopierte Dateien werden sofort Verknüpfungen, die nicht mehr löschbar sind ?
    Log-Analyse und Auswertung - 25.09.2014 (25)
  3. Windows 8: Schwarzer Bildschirm bei Anmeldung, aber Cursor sichtbar und Anmeldemaske sichtbar
    Log-Analyse und Auswertung - 17.07.2014 (23)
  4. Win 7 : Kein Speicherplatz mehr auf C und nach Loeschen von Dateien wird C schnell gefuellt - aber wovon?
    Plagegeister aller Art und deren Bekämpfung - 09.03.2014 (38)
  5. Auf USB Stick nur noch Verknüpfungen (Dateien sind versteckt)
    Log-Analyse und Auswertung - 27.02.2014 (19)
  6. Windows Verschlüsselungs Trojaner entfernt aber die Dateien sind verschlüsselt!
    Plagegeister aller Art und deren Bekämpfung - 09.08.2012 (25)
  7. Dateien sind verschlüsselt, aber nicht umbenannt.
    Plagegeister aller Art und deren Bekämpfung - 04.07.2012 (1)
  8. habe GEMA Trojaner aber finde die dateien nicht die in diversen anleitungen aufgelistet sind
    Plagegeister aller Art und deren Bekämpfung - 11.06.2012 (9)
  9. Lizenz-Trojaner entfernt, Scareuncrypt entschlüsselt auch aber Dateien sind trotzdem nicht lesbar
    Plagegeister aller Art und deren Bekämpfung - 16.05.2012 (0)
  10. Dateien die da sind aber dann doch nicht
    Plagegeister aller Art und deren Bekämpfung - 27.04.2012 (1)
  11. Windows findet keinen Speicherplatz,Festplatten nicht sichtbar,Trojaner,Malware
    Log-Analyse und Auswertung - 06.01.2012 (8)
  12. Dateien auf dem USB stick sind nur noch als Verknüpfungen vorhanden
    Log-Analyse und Auswertung - 22.11.2011 (18)
  13. PDM.Trojan.generic - Einige Ordner und Dateien sowie nicht sichtbar
    Log-Analyse und Auswertung - 02.06.2011 (6)
  14. Windows Fix Disk und einige Dateien nicht sichtbar
    Log-Analyse und Auswertung - 30.05.2011 (19)
  15. windows recovery entfernt nun dateien versteckt und nicht sichtbar
    Log-Analyse und Auswertung - 19.05.2011 (5)
  16. Windows Fix Disk - Dateien nicht mehr sichtbar! Desktop mit schwarzem Hintergrund!
    Log-Analyse und Auswertung - 30.04.2011 (18)
  17. Festplatte C sind keine Daten mehr sichtbar - Windows7 läuft aber?
    Plagegeister aller Art und deren Bekämpfung - 17.04.2011 (18)

Zum Thema Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar - Hi, wenn ich Dateien auf einen zuvor formatierten USB-Stick kopiere, erscheinen diese dort. Wenn ich dann das Explorer-Fenster schließe und wieder öffne, werden keine Dateien auf dem Stick angezeigt. In - Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar...
Archiv
Du betrachtest: Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.