Alt 31.10.2013, 20:11   #1
Whilokii-Virus


Das Problem ist hier scheinbar bekannt. Anbei die beiden Dateien, die für die nächsten Schritte benötigt werden.


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013
Ran by Fadi (administrator) on FADI on 31-10-2013 19:59:08
Running from C:\Users\Fadi\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\windows\system32\atiesrxx.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\AllShareFrameworkManagerDMS.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\AllShareFrameworkDMS.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Microsoft Corporation) C:\windows\system32\dashost.exe
(Hi-Rez Studios) C:\Games\Smite\HiPatchService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Copyright 2013 SAMSUNG) C:\Users\Fadi\Desktop\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Users\Fadi\Desktop\Samsung Link\Samsung Link.exe
(TeamViewer GmbH) C:\Meine Programme\TeamViewer\TeamViewer_Service.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(AMD) C:\windows\system32\atieclxx.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe
(Intel Corporation) C:\windows\system32\igfxext.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Facebook Inc.) C:\Users\Fadi\AppData\Local\Facebook\Update\FacebookUpdate.exe
(BitTorrent Inc.) C:\Meine Programme\uTorrent\uTorrent.exe
(Dropbox, Inc.) C:\Users\Fadi\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(www.IslamicFinder.org) C:\Meine Programme\Athan\Athan.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Microsoft Corporation) C:\windows\system32\wwahost.exe
(Microsoft Corporation) C:\windows\System32\LogonUI.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Mozilla Corporation) C:\Meine Programme\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Meine Programme\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Microsoft Corporation) C:\windows\system32\msiexec.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Samsung Link] - C:\Users\Fadi\Desktop\Samsung Link\Samsung Link Tray Agent.exe [597576 2013-10-17] (Copyright 2013 SAMSUNG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [HP Officejet 6500 E710n-z (NET)] - C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKCU\...\Run: [Facebook Update] - C:\Users\Fadi\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-10-10] (Facebook Inc.)
HKCU\...\Run: [uTorrent] - C:\Meine Programme\uTorrent\uTorrent.exe [1045072 2013-05-30] (BitTorrent Inc.)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe [40312 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4908592 2013-10-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Athan] - C:\Meine Programme\Athan\Athan.exe [1208320 2013-02-03] (www.IslamicFinder.org)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Startup: C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Fadi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6500 E710n-z (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6500 E710n-z (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 6500 E710n-z\bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
SearchScopes: HKLM - DefaultScope {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - DefaultScope {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKCU - DefaultScope {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = 
SearchScopes: HKCU - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = 
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Fadi\AppData\Roaming\Mozilla\Firefox\Profiles\72bgqvbf.default
FF user.js: detected! => C:\Users\Fadi\AppData\Roaming\Mozilla\Firefox\Profiles\72bgqvbf.default\user.js
FF Homepage: hxxp://www.google.at/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Meine Programme\VLC Player\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Meine Programme\VLC Player\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: samsung.com/SamsungLinkPCPlugin - C:\Users\Fadi\Desktop\Samsung Link\utils\npSamsungLinkPCPlugin.dll (Samsung)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Fadi\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Extension: firefox - C:\Users\Fadi\AppData\Roaming\Mozilla\Firefox\Profiles\72bgqvbf.default\Extensions\firefox@whilokii.net.xpi
FF StartMenuInternet: FIREFOX.EXE - C:\Meine Programme\Mozilla Firefox\firefox.exe

==================== Services (Whitelisted) =================

R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171664 2012-11-05] (Adobe Systems Incorporated)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\AllShareFrameworkManagerDMS.exe [404360 2013-10-01] (Samsung)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3538480 2013-10-03] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [301152 2013-09-25] (AVG Technologies CZ, s.r.o.)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1591176 2012-11-30] (Samsung Electronics CO., LTD.)
R2 HiPatchService; C:\Games\Smite\HiPatchService.exe [9216 2013-10-25] (Hi-Rez Studios)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-09-06] (Microsoft Corporation)
R2 Samsung Link Service; C:\Users\Fadi\Desktop\Samsung Link\Samsung Link.exe [605768 2013-10-17] (Copyright 2013 SAMSUNG)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)
R2 TeamViewer8; C:\Meine Programme\TeamViewer\TeamViewer_Service.exe [3574624 2013-04-23] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros)

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [35496 2012-07-09] (Advanced Micro Devices, Inc.)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [148792 2013-09-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [241464 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [192824 2013-09-02] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-08-20] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-08] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [252728 2013-07-30] (AVG Technologies CZ, s.r.o.)
R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-09] (Corel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-10-31 19:58 - 2013-10-31 19:58 - 00000000 ____D C:\FRST
2013-10-31 19:57 - 2013-10-31 19:57 - 01957098 _____ (Farbar) C:\Users\Fadi\Downloads\FRST64.exe
2013-10-30 10:38 - 2013-10-30 10:38 - 00000000 ___RD C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2013-10-29 14:36 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-29 14:36 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-10-29 14:36 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-10-29 14:36 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-10-29 14:34 - 2013-10-29 14:36 - 00004897 _____ C:\windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-28 23:07 - 2013-10-28 23:07 - 00003126 _____ C:\windows\System32\Tasks\advRecovery
2013-10-28 23:07 - 2013-10-28 23:07 - 00000709 _____ C:\Users\Public\Desktop\Recovery.lnk
2013-10-28 22:58 - 2013-10-28 22:58 - 00000000 ____D C:\Program Files (x86)\UEFI WinFlash
2013-10-28 22:47 - 2013-10-28 22:47 - 00000003 _____ C:\windows\system32\HRUPPROG.TXT
2013-10-27 12:08 - 2013-10-27 12:08 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\WinRAR
2013-10-27 12:08 - 2013-10-27 12:08 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-10-27 12:06 - 2013-10-27 12:06 - 02074056 _____ C:\Users\Fadi\Downloads\winrar-x64-500d.exe.part
2013-10-27 12:06 - 2013-10-27 12:06 - 02074056 _____ C:\Users\Fadi\Downloads\winrar-x64-500d.exe
2013-10-27 12:06 - 2013-10-27 12:06 - 01970848 _____ C:\Users\Fadi\Downloads\winrar-x64-500.exe.part
2013-10-26 22:49 - 2013-10-26 22:49 - 00000000 ____D C:\Users\Fadi\Desktop\Dredd 3D
2013-10-26 22:40 - 2013-10-26 22:40 - 00000000 ____D C:\Users\Fadi\Desktop\Star Trek Into Darkness ger
2013-10-26 21:59 - 2013-10-28 08:55 - 00000000 ____D C:\Users\Fadi\Desktop\Tai Chi Zero
2013-10-26 21:34 - 2013-10-26 21:34 - 00000000 ____D C:\Users\Fadi\Desktop\Monsters vs Aliens
2013-10-26 21:14 - 2013-10-26 21:14 - 00000000 ____D C:\Users\Fadi\Desktop\Egypt 3D
2013-10-26 20:51 - 2013-10-26 20:51 - 00000000 ____D C:\Users\Fadi\Desktop\Meet the Robinsons
2013-10-26 20:46 - 2013-10-26 20:46 - 00000000 ____D C:\Users\Fadi\Desktop\Dredd
2013-10-26 20:44 - 2013-10-26 20:44 - 00000000 ____D C:\Users\Fadi\Desktop\Escape from Planet Earth
2013-10-26 20:41 - 2013-10-26 20:41 - 00000000 ____D C:\Users\Fadi\Desktop\Star Trek Into Darkness
2013-10-23 21:26 - 2013-10-23 21:26 - 00000777 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-10-23 20:17 - 2013-10-23 20:18 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2013-10-23 20:17 - 2013-10-23 20:17 - 00000000 ____D C:\Users\Fadi\Samsung Link
2013-10-23 20:05 - 2013-10-23 20:05 - 00000000 ____D C:\Upload
2013-10-23 20:04 - 2013-10-23 20:04 - 00000000 ____D C:\Users\Fadi\.swt
2013-10-23 20:03 - 2013-10-23 20:03 - 00000000 ____D C:\Users\Fadi\Desktop\Samsung Link
2013-10-23 10:06 - 2013-10-23 10:06 - 00001956 _____ C:\Users\Public\Desktop\SW Update.lnk
2013-10-20 22:39 - 2013-10-20 22:39 - 01376768 _____ C:\Users\Fadi\Downloads\7z920-x64.msi
2013-10-19 10:53 - 2013-10-19 10:54 - 62411022 _____ C:\Users\Fadi\Desktop\powerpoint  piaget.pptx
2013-10-18 21:21 - 2013-10-18 23:10 - 00020220 _____ C:\Users\Fadi\Desktop\BM6 Experiment.odt
2013-10-18 17:52 - 2013-10-25 13:31 - 02350982 _____ C:\Users\Fadi\Desktop\powerpoint  piaget.odp
2013-10-18 17:52 - 2013-10-18 17:52 - 00000000 ____D C:\Users\Fadi\Documents\Benutzerdefinierte Office-Vorlagen
2013-10-17 17:58 - 2013-10-25 14:27 - 00029223 _____ C:\Users\Fadi\Desktop\Referat Piaget BM6.odt
2013-10-17 17:40 - 2013-10-26 21:02 - 00000000 ____D C:\Users\Fadi\Desktop\[www.top-hitz.com]Shark.Night.3D.R5.MD.German.XviD.derp
2013-10-17 15:31 - 2013-10-30 20:19 - 00000000 ____D C:\Users\Fadi\Desktop\experiment
2013-10-17 15:21 - 2013-10-30 20:20 - 00000000 ____D C:\Users\Fadi\Desktop\handy sheyma
2013-10-16 13:13 - 2013-10-31 16:44 - 00005116 _____ C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Fadi-Fadi Fadi
2013-10-16 11:45 - 2013-10-16 11:46 - 00000000 ____D C:\Users\Fadi\Desktop\Teamspeak
2013-10-16 11:23 - 2013-10-16 12:19 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\TS3Client
2013-10-16 11:22 - 2013-10-16 11:22 - 00000598 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2013-10-16 07:18 - 2013-10-27 12:30 - 00000000 ____D C:\Users\Fadi\Desktop\www.byte.to...Hotel.Transsilvanien.3D.German.DL.720p.BluRay.x264-ETM
2013-10-16 07:12 - 2013-10-16 07:12 - 03459168 _____ C:\windows\system32\FNTCACHE.DAT
2013-10-15 21:14 - 2013-10-30 20:20 - 00000000 ____D C:\Users\Fadi\Desktop\Monsters University (2013) [3D] [HSBS]
2013-10-15 21:10 - 2013-10-30 20:19 - 00000000 ____D C:\Users\Fadi\Desktop\Cinderella3D
2013-10-15 21:07 - 2013-10-30 20:14 - 00000000 ____D C:\Users\Fadi\Desktop\Abenteuer Bahamas 3D
2013-10-15 20:42 - 2013-10-15 20:51 - 204472320 _____ C:\Users\Fadi\Downloads\The.Fire.Dragon.Chronicles.3D.2008.German.H-SBS.German.DTS.DL.1080p.BluRay.x264-LeetHD.part01.rar
2013-10-15 20:35 - 2013-10-15 20:35 - 00077236 _____ (AppWork UG (haftungsbeschränkt)) C:\Users\Fadi\Downloads\jDownloaderWebInstaller09581.exe
2013-10-15 20:34 - 2013-10-15 20:34 - 00002912 _____ C:\Users\Fadi\Downloads\uobzwm4m4912ov4.ccf
2013-10-14 16:57 - 2013-08-10 06:21 - 00448512 _____ (Microsoft Corporation) C:\windows\system32\SettingSync.dll
2013-10-14 16:57 - 2013-08-10 06:21 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\SettingSyncInfo.dll
2013-10-14 16:57 - 2013-08-10 04:58 - 00356352 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSync.dll
2013-10-14 16:57 - 2013-08-03 07:40 - 01374208 _____ (Microsoft Corporation) C:\windows\system32\wdc.dll
2013-10-14 16:57 - 2013-08-03 07:40 - 00566784 _____ (Microsoft Corporation) C:\windows\system32\wvc.dll
2013-10-14 16:57 - 2013-08-03 07:40 - 00462336 _____ (Microsoft Corporation) C:\windows\system32\sysmon.ocx
2013-10-14 16:57 - 2013-08-03 06:14 - 00399360 _____ (Microsoft Corporation) C:\windows\SysWOW64\sysmon.ocx
2013-10-14 16:57 - 2013-08-03 06:13 - 01245696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdc.dll
2013-10-14 16:57 - 2013-08-03 06:13 - 00437248 _____ (Microsoft Corporation) C:\windows\SysWOW64\wvc.dll
2013-10-14 16:57 - 2013-08-02 07:28 - 19758080 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2013-10-14 16:57 - 2013-08-02 07:28 - 10116608 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2013-10-14 16:57 - 2013-08-02 07:28 - 00222208 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2013-10-14 16:57 - 2013-08-02 07:26 - 02304512 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2013-10-14 16:57 - 2013-08-02 06:08 - 17561088 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2013-10-14 16:57 - 2013-08-02 06:08 - 08858112 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2013-10-14 16:57 - 2013-08-02 06:08 - 00199168 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
2013-10-14 16:57 - 2013-08-02 06:06 - 02035712 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2013-10-14 16:57 - 2013-08-01 11:41 - 02233688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-10-14 16:57 - 2013-07-31 00:30 - 00386923 _____ C:\windows\system32\ApnDatabase.xml
2013-10-14 16:57 - 2013-07-25 00:10 - 00158208 _____ (Microsoft Corporation) C:\windows\SysWOW64\mbsmsapi.dll
2013-10-14 16:57 - 2013-07-25 00:06 - 00225280 _____ (Microsoft Corporation) C:\windows\system32\mbsmsapi.dll
2013-10-14 16:57 - 2013-04-10 00:17 - 01125888 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2013-10-14 16:57 - 2013-04-09 23:29 - 00893952 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2013-10-13 17:30 - 2013-10-30 10:39 - 00000000 ___RD C:\Users\Fadi\Dropbox
2013-10-13 17:30 - 2013-10-13 17:30 - 00001000 _____ C:\Users\Fadi\Desktop\Dropbox.lnk
2013-10-13 17:28 - 2013-10-13 17:28 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-13 17:27 - 2013-10-30 23:50 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Dropbox
2013-10-10 19:11 - 2013-10-10 19:11 - 00000912 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2669165515-361187302-876288576-1001Core.job
2013-10-10 19:11 - 2013-10-10 19:11 - 00000000 ____D C:\Users\Fadi\AppData\Local\Facebook
2013-10-10 19:11 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-10-10 19:11 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-10-10 19:11 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-10-10 19:11 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-10-10 19:11 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-10-10 19:11 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-10-10 19:11 - 2013-07-06 01:15 - 00652288 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2013-10-10 19:11 - 2013-07-04 03:13 - 00541696 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2013-10-10 19:11 - 2013-05-15 23:37 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
2013-10-10 19:11 - 2013-05-14 14:14 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-10-10 19:11 - 2013-05-14 10:23 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-10-10 19:11 - 2013-02-21 11:29 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-10-10 19:11 - 2013-02-21 11:29 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-10-10 19:11 - 2013-02-21 11:29 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-10-10 19:11 - 2013-02-21 11:29 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-10-10 19:11 - 2013-02-21 11:14 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-10-10 19:11 - 2013-02-21 11:14 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-10-10 19:11 - 2012-11-08 05:20 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-10-10 19:11 - 2012-11-08 05:20 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-10-10 19:10 - 2013-08-23 06:11 - 04040192 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-10-10 19:10 - 2013-07-05 23:02 - 00099328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2013-10-10 19:10 - 2013-07-05 23:01 - 00210560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2013-10-10 19:10 - 2013-07-01 23:14 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbprint.sys
2013-10-10 19:10 - 2013-06-29 04:08 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2013-10-10 19:10 - 2013-06-29 04:07 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2013-10-10 19:10 - 2013-06-22 06:45 - 00785624 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2013-10-10 19:10 - 2013-06-22 06:45 - 00054488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2013-10-10 19:10 - 2013-05-27 00:17 - 00035328 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2013-10-10 19:10 - 2013-05-26 23:59 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2013-10-10 19:10 - 2013-05-25 04:15 - 00362496 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2013-10-10 19:10 - 2013-05-25 03:32 - 00300032 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2013-10-10 17:49 - 2013-10-02 02:38 - 00694232 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-10-10 17:49 - 2013-10-02 02:38 - 00078296 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-10 11:44 - 2013-07-19 23:13 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 11:44 - 2013-07-19 23:13 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 11:44 - 2013-07-02 02:41 - 00447320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2013-10-10 11:44 - 2013-07-02 02:41 - 00337752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBXHCI.SYS
2013-10-10 11:44 - 2013-07-02 02:41 - 00213336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\UCX01000.SYS
2013-10-10 11:44 - 2013-07-01 02:42 - 00623448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2013-10-10 11:44 - 2013-07-01 02:42 - 00498008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2013-10-10 11:44 - 2013-07-01 02:42 - 00079192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2013-10-10 11:44 - 2013-07-01 02:42 - 00021848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2013-10-10 11:44 - 2013-06-29 04:07 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2013-10-10 11:44 - 2013-06-29 04:06 - 00120832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2013-10-07 22:29 - 2013-10-07 22:29 - 00002245 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00002245 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00002236 _____ C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ___RD C:\Users\Fadi\SkyDrive
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ____D C:\ProgramData\Microsoft SkyDrive
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2013-10-07 22:18 - 2013-10-10 10:06 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-10-07 22:18 - 2013-10-07 22:18 - 00575168 _____ (Microsoft Corporation) C:\Users\Fadi\Downloads\Setup.X86.de-DE_O365HomePremRetail_cc7b04f3-ea18-45eb-b5b1-8f60fa5fbe90_TX_DB_.exe
2013-10-01 09:09 - 2013-10-01 09:09 - 00908800 _____ C:\windows\system32\ContentDirectoryPresenter64.dll
2013-10-01 09:09 - 2013-10-01 09:09 - 00030720 _____ C:\windows\system32\MediaDB64.dll
2013-10-01 08:46 - 2013-10-01 08:46 - 00025600 _____ C:\windows\SysWOW64\MediaDB.dll
2013-10-01 08:11 - 2013-10-01 08:11 - 00706560 _____ C:\windows\SysWOW64\ContentDirectoryPresenter.dll

==================== One Month Modified Files and Folders =======

2013-10-31 20:00 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\sru
2013-10-31 19:58 - 2013-10-31 19:58 - 00000000 ____D C:\FRST
2013-10-31 19:58 - 2013-05-30 18:13 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\uTorrent
2013-10-31 19:57 - 2013-10-31 19:57 - 01957098 _____ (Farbar) C:\Users\Fadi\Downloads\FRST64.exe
2013-10-31 19:44 - 2013-06-08 15:49 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-10-31 19:15 - 2013-01-25 04:10 - 00000360 _____ C:\windows\Tasks\Xerox PhotoCafe Communicator.job
2013-10-31 18:50 - 2013-05-30 03:00 - 00000000 ____D C:\ProgramData\MFAData
2013-10-31 16:44 - 2013-10-16 13:13 - 00005116 _____ C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Fadi-Fadi Fadi
2013-10-31 13:22 - 2013-01-25 02:52 - 01496092 _____ C:\windows\WindowsUpdate.log
2013-10-31 06:59 - 2012-07-26 09:12 - 00000000 ____D C:\windows\AUInstallAgent
2013-10-31 06:55 - 2013-01-25 20:05 - 00791060 _____ C:\windows\system32\perfh00C.dat
2013-10-31 06:55 - 2013-01-25 20:05 - 00155620 _____ C:\windows\system32\perfc00C.dat
2013-10-31 06:55 - 2013-01-25 19:59 - 00782014 _____ C:\windows\system32\perfh010.dat
2013-10-31 06:55 - 2013-01-25 19:59 - 00153144 _____ C:\windows\system32\perfc010.dat
2013-10-31 06:55 - 2013-01-25 19:54 - 00754172 _____ C:\windows\system32\perfh007.dat
2013-10-31 06:55 - 2013-01-25 19:54 - 00156362 _____ C:\windows\system32\perfc007.dat
2013-10-31 06:55 - 2012-07-26 08:28 - 03630792 _____ C:\windows\system32\PerfStringBackup.INI
2013-10-30 23:50 - 2013-10-13 17:27 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Dropbox
2013-10-30 20:20 - 2013-10-17 15:21 - 00000000 ____D C:\Users\Fadi\Desktop\handy sheyma
2013-10-30 20:20 - 2013-10-15 21:14 - 00000000 ____D C:\Users\Fadi\Desktop\Monsters University (2013) [3D] [HSBS]
2013-10-30 20:19 - 2013-10-17 15:31 - 00000000 ____D C:\Users\Fadi\Desktop\experiment
2013-10-30 20:19 - 2013-10-15 21:10 - 00000000 ____D C:\Users\Fadi\Desktop\Cinderella3D
2013-10-30 20:16 - 2013-09-30 10:35 - 00000000 ____D C:\Users\Fadi\AppData\Local\Avg2014
2013-10-30 20:14 - 2013-10-15 21:07 - 00000000 ____D C:\Users\Fadi\Desktop\Abenteuer Bahamas 3D
2013-10-30 19:17 - 2013-05-30 03:16 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\vlc
2013-10-30 19:16 - 2013-05-30 01:41 - 00000000 ____D C:\Users\Fadi\AppData\Local\CrashDumps
2013-10-30 11:35 - 2013-05-30 18:16 - 00000000 ____D C:\Users\Fadi\Desktop\Kochbuch
2013-10-30 10:52 - 2013-05-30 00:01 - 00003596 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2669165515-361187302-876288576-1001
2013-10-30 10:44 - 2013-01-25 03:58 - 00000000 ____D C:\ProgramData\WinClon
2013-10-30 10:42 - 2012-07-26 06:26 - 00262144 ___SH C:\windows\system32\config\ELAM
2013-10-30 10:39 - 2013-10-13 17:30 - 00000000 ___RD C:\Users\Fadi\Dropbox
2013-10-30 10:38 - 2013-10-30 10:38 - 00000000 ___RD C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2013-10-30 10:38 - 2013-01-25 03:48 - 00000868 _____ C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-10-29 18:50 - 2012-07-26 08:22 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-10-29 18:49 - 2012-08-05 22:07 - 00967498 _____ C:\windows\PFRO.log
2013-10-29 14:36 - 2013-10-29 14:34 - 00004897 _____ C:\windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-29 14:36 - 2013-06-29 13:50 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-29 10:00 - 2013-01-25 03:48 - 00000870 _____ C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-10-28 23:07 - 2013-10-28 23:07 - 00003126 _____ C:\windows\System32\Tasks\advRecovery
2013-10-28 23:07 - 2013-10-28 23:07 - 00000709 _____ C:\Users\Public\Desktop\Recovery.lnk
2013-10-28 23:07 - 2013-01-25 02:52 - 00000000 ____D C:\Program Files\Samsung
2013-10-28 23:07 - 2013-01-25 02:51 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-28 22:58 - 2013-10-28 22:58 - 00000000 ____D C:\Program Files (x86)\UEFI WinFlash
2013-10-28 22:47 - 2013-10-28 22:47 - 00000003 _____ C:\windows\system32\HRUPPROG.TXT
2013-10-28 08:55 - 2013-10-26 21:59 - 00000000 ____D C:\Users\Fadi\Desktop\Tai Chi Zero
2013-10-27 12:30 - 2013-10-16 07:18 - 00000000 ____D C:\Users\Fadi\Desktop\www.byte.to...Hotel.Transsilvanien.3D.German.DL.720p.BluRay.x264-ETM
2013-10-27 12:08 - 2013-10-27 12:08 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\WinRAR
2013-10-27 12:08 - 2013-10-27 12:08 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-10-27 12:07 - 2013-05-30 02:43 - 00000000 ____D C:\Meine Programme
2013-10-27 12:06 - 2013-10-27 12:06 - 02074056 _____ C:\Users\Fadi\Downloads\winrar-x64-500d.exe.part
2013-10-27 12:06 - 2013-10-27 12:06 - 02074056 _____ C:\Users\Fadi\Downloads\winrar-x64-500d.exe
2013-10-27 12:06 - 2013-10-27 12:06 - 01970848 _____ C:\Users\Fadi\Downloads\winrar-x64-500.exe.part
2013-10-26 22:49 - 2013-10-26 22:49 - 00000000 ____D C:\Users\Fadi\Desktop\Dredd 3D
2013-10-26 22:40 - 2013-10-26 22:40 - 00000000 ____D C:\Users\Fadi\Desktop\Star Trek Into Darkness ger
2013-10-26 21:34 - 2013-10-26 21:34 - 00000000 ____D C:\Users\Fadi\Desktop\Monsters vs Aliens
2013-10-26 21:14 - 2013-10-26 21:14 - 00000000 ____D C:\Users\Fadi\Desktop\Egypt 3D
2013-10-26 21:02 - 2013-10-17 17:40 - 00000000 ____D C:\Users\Fadi\Desktop\[www.top-hitz.com]Shark.Night.3D.R5.MD.German.XviD.derp
2013-10-26 20:51 - 2013-10-26 20:51 - 00000000 ____D C:\Users\Fadi\Desktop\Meet the Robinsons
2013-10-26 20:46 - 2013-10-26 20:46 - 00000000 ____D C:\Users\Fadi\Desktop\Dredd
2013-10-26 20:44 - 2013-10-26 20:44 - 00000000 ____D C:\Users\Fadi\Desktop\Escape from Planet Earth
2013-10-26 20:41 - 2013-10-26 20:41 - 00000000 ____D C:\Users\Fadi\Desktop\Star Trek Into Darkness
2013-10-26 07:53 - 2013-05-30 18:16 - 00000000 ____D C:\Users\Fadi\Desktop\Sheyma zeug
2013-10-25 14:27 - 2013-10-17 17:58 - 00029223 _____ C:\Users\Fadi\Desktop\Referat Piaget BM6.odt
2013-10-25 13:31 - 2013-10-18 17:52 - 02350982 _____ C:\Users\Fadi\Desktop\powerpoint  piaget.odp
2013-10-23 21:26 - 2013-10-23 21:26 - 00000777 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-10-23 20:18 - 2013-10-23 20:17 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2013-10-23 20:17 - 2013-10-23 20:17 - 00000000 ____D C:\Users\Fadi\Samsung Link
2013-10-23 20:17 - 2013-05-29 23:52 - 00000000 ____D C:\Users\Fadi
2013-10-23 20:05 - 2013-10-23 20:05 - 00000000 ____D C:\Upload
2013-10-23 20:04 - 2013-10-23 20:04 - 00000000 ____D C:\Users\Fadi\.swt
2013-10-23 20:04 - 2013-05-29 23:54 - 00000000 ____D C:\Users\Fadi\AppData\Local\Samsung
2013-10-23 20:04 - 2013-01-25 04:00 - 00000000 ____D C:\ProgramData\Samsung
2013-10-23 20:03 - 2013-10-23 20:03 - 00000000 ____D C:\Users\Fadi\Desktop\Samsung Link
2013-10-23 10:06 - 2013-10-23 10:06 - 00001956 _____ C:\Users\Public\Desktop\SW Update.lnk
2013-10-20 22:39 - 2013-10-20 22:39 - 01376768 _____ C:\Users\Fadi\Downloads\7z920-x64.msi
2013-10-19 10:58 - 2013-05-29 23:52 - 00000000 ____D C:\Users\Fadi\AppData\Local\Packages
2013-10-19 10:54 - 2013-10-19 10:53 - 62411022 _____ C:\Users\Fadi\Desktop\powerpoint  piaget.pptx
2013-10-18 23:10 - 2013-10-18 21:21 - 00020220 _____ C:\Users\Fadi\Desktop\BM6 Experiment.odt
2013-10-18 22:46 - 2012-07-26 06:26 - 00262144 ___SH C:\windows\system32\config\BBI
2013-10-18 17:52 - 2013-10-18 17:52 - 00000000 ____D C:\Users\Fadi\Documents\Benutzerdefinierte Office-Vorlagen
2013-10-16 12:19 - 2013-10-16 11:23 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\TS3Client
2013-10-16 11:46 - 2013-10-16 11:45 - 00000000 ____D C:\Users\Fadi\Desktop\Teamspeak
2013-10-16 11:22 - 2013-10-16 11:22 - 00000598 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2013-10-16 09:01 - 2012-07-26 09:12 - 00000000 ____D C:\windows\rescache
2013-10-16 07:14 - 2013-05-29 23:55 - 00000000 ___RD C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-16 07:14 - 2013-05-29 23:55 - 00000000 ___RD C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-16 07:12 - 2013-10-16 07:12 - 03459168 _____ C:\windows\system32\FNTCACHE.DAT
2013-10-15 22:55 - 2012-07-26 09:12 - 00000000 ___RD C:\windows\ToastData
2013-10-15 20:51 - 2013-10-15 20:42 - 204472320 _____ C:\Users\Fadi\Downloads\The.Fire.Dragon.Chronicles.3D.2008.German.H-SBS.German.DTS.DL.1080p.BluRay.x264-LeetHD.part01.rar
2013-10-15 20:35 - 2013-10-15 20:35 - 00077236 _____ (AppWork UG (haftungsbeschränkt)) C:\Users\Fadi\Downloads\jDownloaderWebInstaller09581.exe
2013-10-15 20:34 - 2013-10-15 20:34 - 00002912 _____ C:\Users\Fadi\Downloads\uobzwm4m4912ov4.ccf
2013-10-13 17:30 - 2013-10-13 17:30 - 00001000 _____ C:\Users\Fadi\Desktop\Dropbox.lnk
2013-10-13 17:28 - 2013-10-13 17:28 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-11 09:38 - 2013-05-30 03:03 - 00000000 ___HD C:\$AVG
2013-10-11 09:38 - 2012-07-26 09:12 - 00000000 ___HD C:\windows\ELAMBKUP
2013-10-10 19:11 - 2013-10-10 19:11 - 00000912 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2669165515-361187302-876288576-1001Core.job
2013-10-10 19:11 - 2013-10-10 19:11 - 00000000 ____D C:\Users\Fadi\AppData\Local\Facebook
2013-10-10 17:51 - 2013-07-29 09:17 - 00000000 ____D C:\windows\system32\MRT
2013-10-10 17:50 - 2013-05-30 01:02 - 80541720 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-10-10 10:06 - 2013-10-07 22:18 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-10-09 11:44 - 2013-06-08 15:49 - 00003772 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-10-08 20:34 - 2013-07-29 21:40 - 00000000 ____D C:\Users\Fadi\Desktop\aria arbeit
2013-10-08 07:50 - 2013-10-29 14:36 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 07:46 - 2013-10-29 14:36 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-10-08 07:46 - 2013-10-29 14:36 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-10-08 07:46 - 2013-10-29 14:36 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-10-07 22:29 - 2013-10-07 22:29 - 00002245 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00002245 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00002236 _____ C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ___RD C:\Users\Fadi\SkyDrive
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ____D C:\ProgramData\Microsoft SkyDrive
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2013-10-07 22:29 - 2013-01-25 04:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-10-07 22:19 - 2013-05-29 23:53 - 00000000 ____D C:\Users\Fadi\AppData\Local\VirtualStore
2013-10-07 22:18 - 2013-10-07 22:18 - 00575168 _____ (Microsoft Corporation) C:\Users\Fadi\Downloads\Setup.X86.de-DE_O365HomePremRetail_cc7b04f3-ea18-45eb-b5b1-8f60fa5fbe90_TX_DB_.exe
2013-10-05 01:19 - 2013-05-30 18:16 - 00000000 ____D C:\Users\Fadi\Desktop\UNI
2013-10-02 02:38 - 2013-10-10 17:49 - 00694232 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-10-02 02:38 - 2013-10-10 17:49 - 00078296 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-01 09:09 - 2013-10-01 09:09 - 00908800 _____ C:\windows\system32\ContentDirectoryPresenter64.dll
2013-10-01 09:09 - 2013-10-01 09:09 - 00030720 _____ C:\windows\system32\MediaDB64.dll
2013-10-01 08:46 - 2013-10-01 08:46 - 00025600 _____ C:\windows\SysWOW64\MediaDB.dll
2013-10-01 08:11 - 2013-10-01 08:11 - 00706560 _____ C:\windows\SysWOW64\ContentDirectoryPresenter.dll

Files to move or delete:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-10-30 10:55

==================== End Of Log ============================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-10-2013
Ran by Fadi at 2013-10-31 20:00:44
Running from C:\Users\Fadi\Downloads
Boot Mode: Normal

==================== Security Center ========================

AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

µTorrent (x32 Version:
7-Zip 9.20 (x64 edition) (Version:
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Photoshop Elements 11 (x32 Version: 11.0)
Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8)
AllShare Framework DMS (Version: 1.3.20)
AMD APP SDK Runtime (Version: 10.0.938.2)
AMD Catalyst Install Manager (Version: 8.0.881.0)
Athan Basic 4.4 (x32)
AVG 2014 (Version: 14.0.3615)
AVG 2014 (Version: 14.0.4158)
AVG 2014 (Version: 2014.0.4158)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center InstallProxy (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center Localization All (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center Profiles Mobile (x32 Version: 2012.0806.1156.19437)
CCC Help Chinese Standard (x32 Version: 2012.0806.1155.19437)
CCC Help Chinese Traditional (x32 Version: 2012.0806.1155.19437)
CCC Help Czech (x32 Version: 2012.0806.1155.19437)
CCC Help Danish (x32 Version: 2012.0806.1155.19437)
CCC Help Dutch (x32 Version: 2012.0806.1155.19437)
CCC Help English (x32 Version: 2012.0806.1155.19437)
CCC Help Finnish (x32 Version: 2012.0806.1155.19437)
CCC Help French (x32 Version: 2012.0806.1155.19437)
CCC Help German (x32 Version: 2012.0806.1155.19437)
CCC Help Greek (x32 Version: 2012.0806.1155.19437)
CCC Help Hungarian (x32 Version: 2012.0806.1155.19437)
CCC Help Italian (x32 Version: 2012.0806.1155.19437)
CCC Help Japanese (x32 Version: 2012.0806.1155.19437)
CCC Help Korean (x32 Version: 2012.0806.1155.19437)
CCC Help Norwegian (x32 Version: 2012.0806.1155.19437)
CCC Help Polish (x32 Version: 2012.0806.1155.19437)
CCC Help Portuguese (x32 Version: 2012.0806.1155.19437)
CCC Help Russian (x32 Version: 2012.0806.1155.19437)
CCC Help Spanish (x32 Version: 2012.0806.1155.19437)
CCC Help Swedish (x32 Version: 2012.0806.1155.19437)
CCC Help Thai (x32 Version: 2012.0806.1155.19437)
CCC Help Turkish (x32 Version: 2012.0806.1155.19437)
ccc-utility64 (Version: 2012.0806.1156.19437)
CyberLink PowerDVD 10 (x32 Version: 10.0.4421.02)
D3DX10 (x32 Version: 15.4.2368.0902)
Dropbox (HKCU Version: 2.4.2)
Easy File Share (x32 Version: 1.3.6)
Elements 11 Organizer (x32 Version: 11.0)
E-POP (x32 Version: 1.0.1)
Facebook Video Calling (x32 Version: 1.2.287)
Fotogalerie (x32 Version: 16.4.3505.0912)
Galerie de photos (x32 Version: 16.4.3505.0912)
Help Desk (Version: 1.0.96)
Hi-Rez Studios Authenticate and Update Service (x32 Version:
HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät (Version: 28.0.1315.0)
HP Officejet 6500 E710n-z Hilfe (x32 Version:
HP Update (x32 Version:
HPDiagnosticAlert (x32 Version: 1.00.0000)
I.R.I.S. OCR (x32 Version:
Intel AppUp(SM) center (x32 Version:
Intel(R) Control Center (x32 Version:
Intel(R) Display Audio Driver (x32 Version:
Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version:
Intel(R) Management Engine Components (x32 Version:
Intel(R) Rapid Storage Technology (x32 Version:
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version:
K-Lite Codec Pack 9.3.0 (Basic) (x32 Version: 9.3.0)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 365 Home Premium - de-de (Version: 15.0.4535.1511)
Microsoft SkyDrive (HKCU Version: 17.0.2003.1112)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft-Maus- und Tastatur-Center (Version:
Movie Maker (x32 Version: 16.4.3505.0912)
Mozilla Firefox 21.0 (x86 de) (x32 Version: 21.0)
Mozilla Firefox 24.0 (x86 de) (HKCU Version: 24.0)
Mozilla Maintenance Service (x32 Version: 21.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4535.1511)
Office 15 Click-to-Run Licensing Component (Version: 15.0.4535.1511)
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4535.1511)
OpenOffice.org 3.4.1 (x32 Version: 3.41.9593)
Opera 12.16 (Version: 12.16.1860)
Photo Common (x32 Version: 16.4.3505.0912)
Photo Gallery (x32 Version: 16.4.3505.0912)
PSE11 STI Installer (x32 Version: 11.0)
PX Profile Update (x32 Version: 1.00.1.)
Qualcomm Atheros Bluetooth Suite (64) (Version:
Qualcomm Atheros Client Installation Program (x32 Version: 10.0)
Raccolta foto (x32 Version: 16.4.3505.0912)
Realtek Ethernet Controller Driver (x32 Version: 8.3.730.2012)
Realtek High Definition Audio Driver (x32 Version:
Realtek USB 2.0 Card Reader (x32 Version: 6.1.8400.39030)
Recovery (x32 Version:
S Agent (Version: 1.1.45)
Samsung Link (Version:
Settings (x32 Version: 2.0.1)
Smite (x32 Version: 0.1.1807.0)
Sudoku Assistenten 2.0.1 (x32)
Support Center (Version: 2.1.1106)
Support Center FAQ (x32 Version: 1.0.11)
SW Update (x32 Version: 2.1.21)
Synaptics Pointing Device Driver (Version:
TeamSpeak 3 Client (x32 Version: 3.0.13)
TeamViewer 8 (x32 Version: 8.0.18051)
User Guide (x32 Version: 1.4.00)
Visual Studio 2010 x64 Redistributables (Version:
Visual Studio 2012 x64 Redistributables (Version:
Visual Studio 2012 x86 Redistributables (x32 Version:
VLC media player 2.0.8 (Version: 2.0.8)
Windows Live (x32 Version: 16.4.3505.0912)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912)
Windows Live Essentials (x32 Version: 16.4.3505.0912)
Windows Live Installer (x32 Version: 16.4.3505.0912)
Windows Live Photo Common (x32 Version: 16.4.3505.0912)
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912)
Windows Live SOXE (x32 Version: 16.4.3505.0912)
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912)
Windows Live UX Platform (x32 Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912)
WinRAR 5.00 (64-Bit) (Version: 5.00.0)
Xerox PhotoCafe (x32 Version:

==================== Restore Points  =========================

31-10-2013 15:00:58 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {06A4AD44-E164-481C-97E7-4FD0C13BE49F} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2012-11-30] (Samsung Electronics CO., LTD.)
Task: {19E7604D-5F98-4CF1-9297-0ECF24D8C9CF} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation)
Task: {1DE9AF10-1F5F-42AF-9C44-9718B6DC62A9} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {36057DFE-E13F-4025-90F1-D5CF7BA5C0E4} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation)
Task: {3D9246B4-6002-438B-841A-4F641357D102} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {3EFB56B1-D717-495F-B2BC-A11BEF438F8D} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-06] (Microsoft Corporation)
Task: {4AA7E9A4-D73C-4C6B-B81F-A2852332C3C1} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-10-16] (Synaptics Incorporated)
Task: {4F762654-AC6D-4C69-8302-4DF74916DADA} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2013-10-10] (Microsoft Corporation)
Task: {59ED68AC-CE6F-4B61-BE58-F596EDEDC4DE} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2013-10-16] (Samsung Electronics CO., LTD.)
Task: {6E48F844-22D1-44F3-8857-7D0452415727} - System32\Tasks\Xerox PhotoCafe Communicator => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe [2011-10-26] ()
Task: {A1A9B5C8-2253-4F53-ADF8-4BC8EDA7A9B5} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Fadi-Fadi Fadi => C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE [2013-10-10] (Microsoft Corporation)
Task: {C4DF8FF0-0F9D-4DC1-BCF3-F23B64AA7197} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation)
Task: {C669F688-311C-42D4-A350-0BE6884E441E} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {CAF0BF99-B602-47E9-A709-73C7A7D60C39} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {CE7CCF83-90EC-4B94-A25D-C340444D53FD} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\MouseKeyboardCenter.exe [2013-05-13] (Microsoft)
Task: {EAEA5B77-F924-4CD1-BA87-3E7ECAE56490} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {FFD11D67-9040-406D-9138-407D3BF221FC} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2013-08-23] (SEC)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2669165515-361187302-876288576-1001Core.job => C:\Users\Fadi\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\windows\Tasks\Xerox PhotoCafe Communicator.job => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe

==================== Loaded Modules (whitelisted) =============

2013-05-30 01:04 - 2013-05-30 01:04 - 00176024 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2012-12-05 12:44 - 2012-12-05 12:44 - 00384128 _____ () C:\Program Files (x86)\Bluetooth Suite\ContactsApi.dll
2012-12-05 12:39 - 2012-12-05 12:39 - 00020992 _____ () C:\Program Files (x86)\Bluetooth Suite\L10n\de-DE\BtTray.de-DE.dll
2012-12-05 12:41 - 2012-12-05 12:41 - 00011264 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2013-10-16 18:15 - 2013-10-16 18:15 - 00088624 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll
2013-10-01 08:47 - 2013-10-01 08:47 - 01112576 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\DMSManager.dll
2013-07-23 18:18 - 2013-07-23 18:18 - 00227840 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\boost_serialization-vc90-mt-1_47.dll
2013-07-23 18:18 - 2013-07-23 18:18 - 00038912 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\boost_date_time-vc90-mt-1_47.dll
2013-07-23 18:18 - 2013-07-23 18:18 - 00012800 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\boost_system-vc90-mt-1_47.dll
2013-07-23 18:18 - 2013-07-23 18:18 - 00046592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\boost_thread-vc90-mt-1_47.dll
2013-10-01 08:11 - 2013-10-01 08:11 - 00706560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\ContentDirectoryPresenter.dll
2013-10-01 08:46 - 2013-10-01 08:46 - 00107008 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\DCMCDP.dll
2013-10-01 08:11 - 2013-10-01 08:11 - 00102400 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\FolderCDP.dll
2013-10-01 08:47 - 2013-10-01 08:47 - 00032768 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\Autobackup.dll
2013-04-19 15:38 - 2013-04-19 15:38 - 00055808 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\RosettaAllShare.dll
2013-10-01 08:10 - 2013-10-01 08:10 - 00077312 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\MetadataFramework.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00520234 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\sqlite3.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00450560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\MoodExtractor.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 05717504 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\DCMImgExtractor.dll
2013-08-12 18:27 - 2013-08-12 18:27 - 00028672 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\AutoChaptering.dll
2013-08-09 16:07 - 2013-08-09 16:07 - 00028160 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\AudioExtractor.dll
2013-08-23 09:51 - 2013-08-23 09:51 - 00017920 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\VideoExtractor.dll
2013-08-23 09:51 - 2013-08-23 09:51 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\ImageExtractor.dll
2013-08-09 16:07 - 2013-08-09 16:07 - 00013824 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\TextExtractor.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00147456 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\libexpat.dll
2013-08-12 18:27 - 2013-08-12 18:27 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\VideoThumb.dll
2013-08-09 16:07 - 2013-08-09 16:07 - 00064000 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\ID3Driver.dll
2013-08-09 16:07 - 2013-08-09 16:07 - 00023040 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\RichInfoDriver.dll
2013-08-23 09:51 - 2013-08-23 09:51 - 00117248 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\ThumbnailMaker.dll
2013-08-22 17:17 - 2013-08-22 17:17 - 00134144 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\VideoMetadataDriver.dll
2013-08-09 16:07 - 2013-08-09 16:07 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\SECMetaDriver.dll
2013-04-12 07:58 - 2013-04-12 07:58 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\photoDriver.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 04671488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\avcodec-52.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00686080 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\avformat-52.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00070656 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\avutil-50.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00152064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\swscale-0.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00366592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\tag.dll
2013-04-12 07:58 - 2013-04-12 07:58 - 00289792 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\libThumbnail.dll
2013-08-23 09:51 - 2013-08-23 09:51 - 01033216 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\ImageMagickWrapper.dll
2013-08-09 16:07 - 2013-08-09 16:07 - 00290816 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\libKeyFrame.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00399826 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\libexif-12.dll.dll
2013-02-14 18:42 - 2013-02-14 18:42 - 00044032 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\us.dll
2013-08-17 16:02 - 2013-08-17 16:02 - 00017920 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\PSIClient\26def6ab53d268e53635f2a61a1b2ed3\PSIClient.ni.dll
2013-01-25 03:47 - 2012-06-25 18:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 00028792 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 01068664 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 00026744 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 00060536 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2012-11-30 08:26 - 2012-11-30 08:26 - 00103032 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Fadi\AppData\Roaming\Dropbox\bin\libcef.dll
2004-12-25 11:37 - 2004-12-25 11:37 - 00258121 _____ () C:\Meine Programme\Athan\vbh.dll
2010-03-08 20:08 - 2010-03-08 20:08 - 00282697 _____ () C:\Meine Programme\Athan\vbp.dll
2004-03-20 12:49 - 2004-03-20 12:49 - 00229444 _____ () C:\Meine Programme\Athan\vbq.dll
2013-09-17 18:40 - 2013-09-17 18:40 - 03279768 _____ () C:\Meine Programme\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

==================== Safe Mode (whitelisted) ===================

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (10/30/2013 08:48:25 PM) (Source: Application Hang) (User: )
Description: Programm IEXPLORE.EXE, Version 10.0.9200.16537 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 6260

Startzeit: 01ced56fece9d02f

Endzeit: 401

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID: 3726ed36-419c-11e3-bec0-1867b05f6451

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (10/30/2013 07:16:22 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: soffice.bin, Version: 3.4.9593.500, Zeitstempel: 0x5028bfc0
Name des fehlerhaften Moduls: RPCRT4.dll, Version: 6.2.9200.16622, Zeitstempel: 0x519e974e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001f035
ID des fehlerhaften Prozesses: 0x73d8
Startzeit der fehlerhaften Anwendung: 0xsoffice.bin0
Pfad der fehlerhaften Anwendung: soffice.bin1
Pfad des fehlerhaften Moduls: soffice.bin2
Berichtskennung: soffice.bin3
Vollständiger Name des fehlerhaften Pakets: soffice.bin4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: soffice.bin5

Error: (10/29/2013 08:20:12 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: soffice.bin, Version: 3.4.9593.500, Zeitstempel: 0x5028bfc0
Name des fehlerhaften Moduls: RPCRT4.dll, Version: 6.2.9200.16622, Zeitstempel: 0x519e974e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001f035
ID des fehlerhaften Prozesses: 0x2cb0
Startzeit der fehlerhaften Anwendung: 0xsoffice.bin0
Pfad der fehlerhaften Anwendung: soffice.bin1
Pfad des fehlerhaften Moduls: soffice.bin2
Berichtskennung: soffice.bin3
Vollständiger Name des fehlerhaften Pakets: soffice.bin4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: soffice.bin5

Error: (10/29/2013 06:53:45 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: MetaExtractor.exe, Version:, Zeitstempel: 0x52117fee
Name des fehlerhaften Moduls: MetaExtractorDLL.dll, Version:, Zeitstempel: 0x52117fe9
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00003bf6
ID des fehlerhaften Prozesses: 0x1b78
Startzeit der fehlerhaften Anwendung: 0xMetaExtractor.exe0
Pfad der fehlerhaften Anwendung: MetaExtractor.exe1
Pfad des fehlerhaften Moduls: MetaExtractor.exe2
Berichtskennung: MetaExtractor.exe3
Vollständiger Name des fehlerhaften Pakets: MetaExtractor.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MetaExtractor.exe5

Error: (10/28/2013 11:09:01 PM) (Source: MsiInstaller) (User: Fadi)
Description: Product: S Agent -- Unable to install because a newer version of this product is already installed.

Error: (10/28/2013 11:07:10 PM) (Source: MsiInstaller) (User: Fadi)
Description: Product: S Agent -- Unable to install because a newer version of this product is already installed.

Error: (10/28/2013 09:38:36 AM) (Source: Application Hang) (User: )
Description: Programm IEXPLORE.EXE, Version 10.0.9200.16537 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1ab00

Startzeit: 01ced3b30523eb64

Endzeit: 31

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID: 5328c16d-3fac-11e3-bebf-1867b05f6451

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (10/28/2013 08:50:24 AM) (Source: Desktop Window Manager) (User: )
Description: Der Desktopfenster-Manager hat einen schwerwiegenden Fehler (0x8898008d) festgestellt.

Error: (10/27/2013 03:04:52 PM) (Source: Application Hang) (User: )
Description: Programm IEXPLORE.EXE, Version 10.0.9200.16537 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 189ec

Startzeit: 01ced318e805854d

Endzeit: 31

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID: bc7eea90-3f10-11e3-bebf-1867b05f6451

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (10/27/2013 00:36:37 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: vlc.exe, Version:, Zeitstempel: 0x520e8be6
Name des fehlerhaften Moduls: vlc.exe, Version:, Zeitstempel: 0x520e8be6
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000001aaa
ID des fehlerhaften Prozesses: 0x10684
Startzeit der fehlerhaften Anwendung: 0xvlc.exe0
Pfad der fehlerhaften Anwendung: vlc.exe1
Pfad des fehlerhaften Moduls: vlc.exe2
Berichtskennung: vlc.exe3
Vollständiger Name des fehlerhaften Pakets: vlc.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: vlc.exe5

System errors:
Error: (10/31/2013 07:07:38 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070570 fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB2779768)

Error: (10/31/2013 00:19:30 AM) (Source: DCOM) (User: Fadi)
Description: {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C}

Error: (10/30/2013 10:55:55 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070570 fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB2779768)

Error: (10/29/2013 07:11:38 PM) (Source: DCOM) (User: Fadi)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}FadiFadiS-1-5-21-2669165515-361187302-876288576-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar

Error: (10/29/2013 06:50:25 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎29.‎10.‎2013 um 18:39:18 unerwartet heruntergefahren.

Error: (10/29/2013 04:16:52 PM) (Source: DCOM) (User: Fadi)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}FadiFadiS-1-5-21-2669165515-361187302-876288576-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar

Error: (10/29/2013 04:16:52 PM) (Source: DCOM) (User: Fadi)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}FadiFadiS-1-5-21-2669165515-361187302-876288576-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar

Error: (10/29/2013 09:53:36 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070570 fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB2779768)

Error: (10/28/2013 11:18:13 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070570 fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB2779768)

Error: (10/27/2013 03:02:05 PM) (Source: DCOM) (User: Fadi)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}FadiFadiS-1-5-21-2669165515-361187302-876288576-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar

Microsoft Office Sessions:
Error: (10/30/2013 08:48:25 PM) (Source: Application Hang)(User: )
Description: IEXPLORE.EXE10.0.9200.16537626001ced56fece9d02f401C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE3726ed36-419c-11e3-bec0-1867b05f6451

Error: (10/30/2013 07:16:22 PM) (Source: Application Error)(User: )
Description: soffice.bin3.4.9593.5005028bfc0RPCRT4.dll6.2.9200.16622519e974ec00000050001f03573d801ced553cb7112e2C:\Program Files (x86)\OpenOffice.org 3\program\soffice.binC:\windows\SYSTEM32\RPCRT4.dll60d0cb89-418f-11e3-bec0-1867b05f6451

Error: (10/29/2013 08:20:12 PM) (Source: Application Error)(User: )
Description: soffice.bin3.4.9593.5005028bfc0RPCRT4.dll6.2.9200.16622519e974ec00000050001f0352cb001ced4d06b8ca1beC:\Program Files (x86)\OpenOffice.org 3\program\soffice.binC:\windows\SYSTEM32\RPCRT4.dll214d1fee-40cf-11e3-bec0-1867b05f6451

Error: (10/29/2013 06:53:45 PM) (Source: Application Error)(User: )
Description: MetaExtractor.exe1.8.0.052117feeMetaExtractorDLL.dll0.0.0.052117fe9c000000500003bf61b7801ced4cfccbc0748C:\Users\Fadi\Desktop\Samsung Link\utils\MetaExtractor.exeC:\Users\Fadi\Desktop\Samsung Link\utils\MetaExtractorDLL.dll0e034d21-40c3-11e3-bec0-1867b05f6451

Error: (10/28/2013 11:09:01 PM) (Source: MsiInstaller)(User: Fadi)
Description: Product: S Agent -- Unable to install because a newer version of this product is already installed.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (10/28/2013 11:07:10 PM) (Source: MsiInstaller)(User: Fadi)
Description: Product: S Agent -- Unable to install because a newer version of this product is already installed.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (10/28/2013 09:38:36 AM) (Source: Application Hang)(User: )
Description: IEXPLORE.EXE10.0.9200.165371ab0001ced3b30523eb6431C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE5328c16d-3fac-11e3-bebf-1867b05f6451

Error: (10/28/2013 08:50:24 AM) (Source: Desktop Window Manager)(User: )
Description: 0x8898008d

Error: (10/27/2013 03:04:52 PM) (Source: Application Hang)(User: )
Description: IEXPLORE.EXE10.0.9200.16537189ec01ced318e805854d31C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEbc7eea90-3f10-11e3-bebf-1867b05f6451

Error: (10/27/2013 00:36:37 PM) (Source: Application Error)(User: )
Description: vlc.exe2.0.8.0520e8be6vlc.exe2.0.8.0520e8be6c00000050000000000001aaa1068401ced308ca17bd5cC:\Meine Programme\VLC Player\vlc.exeC:\Meine Programme\VLC Player\vlc.exe09703718-3efc-11e3-bebf-1867b05f6451

==================== Memory info =========================== 

Percentage of memory in use: 44%
Total physical RAM: 8083.41 MB
Available physical RAM: 4516.61 MB
Total Pagefile: 9299.42 MB
Available Pagefile: 5178.41 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:436.5 GB) (Free:286.38 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (Size: 466 GB) (Disk ID: C774ED6C)

Partition: GPT Partition Type
==================== End Of Log ============================
Herzlichen Dank im voraus für Eure Hilfe.

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

und ein frisches FRST log bitte.


Whilokii-Virus


Malwarebytes Anti-Malware

Malwarebytes Anti-Malware

Datenbank Version: v2013.10.31.07

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16721
Fadi :: FADI [Administrator]

31.10.2013 20:45:00
mbam-log-2013-10-31 (20-45-00).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 210047
Laufzeit: 8 Minute(n), 58 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 2
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 1
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 1W1G1U1K1O1H -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\PROGRAMDATA\REF\REF.01 (Trojan.Monder) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\PROGRAMDATA\REF\REF.02 (PUP.Ardamax) -> Erfolgreich gelöscht und in Quarantäne gestellt.


# AdwCleaner v3.010 - Bericht erstellt am 31/10/2013 um 21:48:43
# Updated 20/10/2013 von Xplode
# Betriebssystem : Windows 8  (64 bits)
# Benutzername : Fadi - FADI
# Gestartet von : C:\Users\Fadi\Downloads\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\boost_interprocess
Datei Gelöscht : C:\Users\Fadi\AppData\Roaming\Mozilla\Firefox\Profiles\72bgqvbf.default\user.js

***** [ Verknüpfungen ] *****

***** [ Registrierungsdatenbank ] *****

***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16537

-\\ Mozilla Firefox v21.0 (de)

[ Datei : C:\Users\Fadi\AppData\Roaming\Mozilla\Firefox\Profiles\72bgqvbf.default\prefs.js ]


AdwCleaner[R0].txt - [915 octets] - [31/10/2013 21:46:39]
AdwCleaner[S0].txt - [839 octets] - [31/10/2013 21:48:43]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [898 octets] ##########

Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.7 (10.15.2013:3)
OS: Windows 8 x64
Ran by Fadi on 31.10.2013 at 21:58:02,14

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ Event Viewer Logs were cleared

Scan was completed on 31.10.2013 at 22:07:40,21
End of JRT log

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013
Ran by Fadi (administrator) on FADI on 31-10-2013 22:13:19
Running from C:\Users\Fadi\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\windows\system32\atiesrxx.exe
(AMD) C:\windows\system32\atieclxx.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\AllShareFrameworkManagerDMS.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\AllShareFrameworkDMS.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Microsoft Corporation) C:\windows\system32\dashost.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Copyright 2013 SAMSUNG) C:\Users\Fadi\Desktop\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Users\Fadi\Desktop\Samsung Link\Samsung Link.exe
(TeamViewer GmbH) C:\Meine Programme\TeamViewer\TeamViewer_Service.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Copyright 2013 SAMSUNG) C:\Users\Fadi\Desktop\Samsung Link\Samsung Link Tray Agent.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe
(Facebook Inc.) C:\Users\Fadi\AppData\Local\Facebook\Update\FacebookUpdate.exe
(BitTorrent Inc.) C:\Meine Programme\uTorrent\uTorrent.exe
(Dropbox, Inc.) C:\Users\Fadi\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(www.IslamicFinder.org) C:\Meine Programme\Athan\Athan.exe
(Intel Corporation) C:\windows\system32\igfxext.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcfgex.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Meine Programme\Mozilla Firefox\firefox.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Meine Programme\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Farbar) C:\Users\Fadi\Downloads\FRST64(1).exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Samsung Link] - C:\Users\Fadi\Desktop\Samsung Link\Samsung Link Tray Agent.exe [597576 2013-10-17] (Copyright 2013 SAMSUNG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [HP Officejet 6500 E710n-z (NET)] - C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKCU\...\Run: [Facebook Update] - C:\Users\Fadi\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-10-10] (Facebook Inc.)
HKCU\...\Run: [uTorrent] - C:\Meine Programme\uTorrent\uTorrent.exe [1045072 2013-05-30] (BitTorrent Inc.)
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe [40312 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4908592 2013-10-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Athan] - C:\Meine Programme\Athan\Athan.exe [1208320 2013-02-03] (www.IslamicFinder.org)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Startup: C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Fadi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6500 E710n-z (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6500 E710n-z (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 6500 E710n-z\bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
SearchScopes: HKLM - DefaultScope {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKCU - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = 
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Fadi\AppData\Roaming\Mozilla\Firefox\Profiles\72bgqvbf.default
FF Homepage: hxxp://www.google.at/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Meine Programme\VLC Player\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Meine Programme\VLC Player\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: samsung.com/SamsungLinkPCPlugin - C:\Users\Fadi\Desktop\Samsung Link\utils\npSamsungLinkPCPlugin.dll (Samsung)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Fadi\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF StartMenuInternet: FIREFOX.EXE - C:\Meine Programme\Mozilla Firefox\firefox.exe

==================== Services (Whitelisted) =================

R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171664 2012-11-05] (Adobe Systems Incorporated)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.20\AllShareFrameworkManagerDMS.exe [404360 2013-10-01] (Samsung)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3538480 2013-10-03] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [301152 2013-09-25] (AVG Technologies CZ, s.r.o.)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1591176 2012-11-30] (Samsung Electronics CO., LTD.)
S2 HiPatchService; C:\Games\Smite\HiPatchService.exe [9216 2013-10-25] (Hi-Rez Studios)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-09-06] (Microsoft Corporation)
R2 Samsung Link Service; C:\Users\Fadi\Desktop\Samsung Link\Samsung Link.exe [605768 2013-10-17] (Copyright 2013 SAMSUNG)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)
R2 TeamViewer8; C:\Meine Programme\TeamViewer\TeamViewer_Service.exe [3574624 2013-04-23] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros)

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [35496 2012-07-09] (Advanced Micro Devices, Inc.)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [148792 2013-09-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [241464 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [192824 2013-09-02] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-08-20] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-08] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [252728 2013-07-30] (AVG Technologies CZ, s.r.o.)
R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-09] (Corel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-10-31 22:12 - 2013-10-31 22:12 - 01957098 _____ (Farbar) C:\Users\Fadi\Downloads\FRST64(1).exe
2013-10-31 22:07 - 2013-10-31 22:07 - 00000611 _____ C:\Users\Fadi\Desktop\JRT.txt
2013-10-31 21:57 - 2013-10-31 21:57 - 01033335 _____ (Thisisu) C:\Users\Fadi\Downloads\JRT.exe
2013-10-31 21:57 - 2013-10-31 21:57 - 00000000 ____D C:\windows\ERUNT
2013-10-31 21:53 - 2013-10-31 21:53 - 00000977 _____ C:\Users\Fadi\Desktop\AdwCleaner[S0].txt
2013-10-31 21:52 - 2013-10-31 21:52 - 00000000 ___RD C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2013-10-31 20:49 - 2013-10-31 21:48 - 00000000 ____D C:\AdwCleaner
2013-10-31 20:49 - 2013-10-31 20:49 - 01060070 _____ C:\Users\Fadi\Downloads\adwcleaner.exe
2013-10-31 20:42 - 2013-10-31 20:42 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Malwarebytes
2013-10-31 20:41 - 2013-10-31 20:41 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Fadi\Downloads\mbam-setup-
2013-10-31 20:41 - 2013-10-31 20:41 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-10-31 20:41 - 2013-10-31 20:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-31 20:41 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-10-31 20:03 - 2013-10-31 20:03 - 00045962 _____ C:\Users\Fadi\Desktop\FRST.txt
2013-10-31 20:02 - 2013-10-31 20:02 - 00030996 _____ C:\Users\Fadi\Desktop\Addition.txt
2013-10-31 20:00 - 2013-10-31 20:02 - 00030996 _____ C:\Users\Fadi\Downloads\Addition.txt
2013-10-31 19:58 - 2013-10-31 19:58 - 00000000 ____D C:\FRST
2013-10-31 19:57 - 2013-10-31 19:57 - 01957098 _____ (Farbar) C:\Users\Fadi\Downloads\FRST64.exe
2013-10-29 14:36 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-29 14:36 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-10-29 14:36 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-10-29 14:36 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-10-29 14:34 - 2013-10-29 14:36 - 00004897 _____ C:\windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-28 23:07 - 2013-10-28 23:07 - 00003126 _____ C:\windows\System32\Tasks\advRecovery
2013-10-28 23:07 - 2013-10-28 23:07 - 00000709 _____ C:\Users\Public\Desktop\Recovery.lnk
2013-10-28 22:58 - 2013-10-28 22:58 - 00000000 ____D C:\Program Files (x86)\UEFI WinFlash
2013-10-28 22:47 - 2013-10-28 22:47 - 00000003 _____ C:\windows\system32\HRUPPROG.TXT
2013-10-27 12:08 - 2013-10-27 12:08 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\WinRAR
2013-10-27 12:08 - 2013-10-27 12:08 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-10-27 12:06 - 2013-10-27 12:06 - 02074056 _____ C:\Users\Fadi\Downloads\winrar-x64-500d.exe.part
2013-10-27 12:06 - 2013-10-27 12:06 - 02074056 _____ C:\Users\Fadi\Downloads\winrar-x64-500d.exe
2013-10-27 12:06 - 2013-10-27 12:06 - 01970848 _____ C:\Users\Fadi\Downloads\winrar-x64-500.exe.part
2013-10-26 22:49 - 2013-10-26 22:49 - 00000000 ____D C:\Users\Fadi\Desktop\Dredd 3D
2013-10-26 22:40 - 2013-10-26 22:40 - 00000000 ____D C:\Users\Fadi\Desktop\Star Trek Into Darkness ger
2013-10-26 21:59 - 2013-10-28 08:55 - 00000000 ____D C:\Users\Fadi\Desktop\Tai Chi Zero
2013-10-26 21:34 - 2013-10-26 21:34 - 00000000 ____D C:\Users\Fadi\Desktop\Monsters vs Aliens
2013-10-26 21:14 - 2013-10-26 21:14 - 00000000 ____D C:\Users\Fadi\Desktop\Egypt 3D
2013-10-26 20:51 - 2013-10-26 20:51 - 00000000 ____D C:\Users\Fadi\Desktop\Meet the Robinsons
2013-10-26 20:46 - 2013-10-26 20:46 - 00000000 ____D C:\Users\Fadi\Desktop\Dredd
2013-10-26 20:44 - 2013-10-26 20:44 - 00000000 ____D C:\Users\Fadi\Desktop\Escape from Planet Earth
2013-10-26 20:41 - 2013-10-26 20:41 - 00000000 ____D C:\Users\Fadi\Desktop\Star Trek Into Darkness
2013-10-23 21:26 - 2013-10-23 21:26 - 00000777 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-10-23 20:17 - 2013-10-23 20:18 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2013-10-23 20:17 - 2013-10-23 20:17 - 00000000 ____D C:\Users\Fadi\Samsung Link
2013-10-23 20:05 - 2013-10-23 20:05 - 00000000 ____D C:\Upload
2013-10-23 20:04 - 2013-10-23 20:04 - 00000000 ____D C:\Users\Fadi\.swt
2013-10-23 20:03 - 2013-10-23 20:03 - 00000000 ____D C:\Users\Fadi\Desktop\Samsung Link
2013-10-23 10:06 - 2013-10-23 10:06 - 00001956 _____ C:\Users\Public\Desktop\SW Update.lnk
2013-10-20 22:39 - 2013-10-20 22:39 - 01376768 _____ C:\Users\Fadi\Downloads\7z920-x64.msi
2013-10-19 10:53 - 2013-10-19 10:54 - 62411022 _____ C:\Users\Fadi\Desktop\powerpoint  piaget.pptx
2013-10-18 21:21 - 2013-10-18 23:10 - 00020220 _____ C:\Users\Fadi\Desktop\BM6 Experiment.odt
2013-10-18 17:52 - 2013-10-25 13:31 - 02350982 _____ C:\Users\Fadi\Desktop\powerpoint  piaget.odp
2013-10-18 17:52 - 2013-10-18 17:52 - 00000000 ____D C:\Users\Fadi\Documents\Benutzerdefinierte Office-Vorlagen
2013-10-17 17:58 - 2013-10-25 14:27 - 00029223 _____ C:\Users\Fadi\Desktop\Referat Piaget BM6.odt
2013-10-17 17:40 - 2013-10-26 21:02 - 00000000 ____D C:\Users\Fadi\Desktop\[www.top-hitz.com]Shark.Night.3D.R5.MD.German.XviD.derp
2013-10-17 15:31 - 2013-10-30 20:19 - 00000000 ____D C:\Users\Fadi\Desktop\experiment
2013-10-17 15:21 - 2013-10-30 20:20 - 00000000 ____D C:\Users\Fadi\Desktop\handy sheyma
2013-10-16 13:13 - 2013-10-31 22:08 - 00005116 _____ C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Fadi-Fadi Fadi
2013-10-16 11:45 - 2013-10-16 11:46 - 00000000 ____D C:\Users\Fadi\Desktop\Teamspeak
2013-10-16 11:23 - 2013-10-16 12:19 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\TS3Client
2013-10-16 11:22 - 2013-10-16 11:22 - 00000598 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2013-10-16 07:18 - 2013-10-27 12:30 - 00000000 ____D C:\Users\Fadi\Desktop\www.byte.to...Hotel.Transsilvanien.3D.German.DL.720p.BluRay.x264-ETM
2013-10-16 07:12 - 2013-10-16 07:12 - 03459168 _____ C:\windows\system32\FNTCACHE.DAT
2013-10-15 21:14 - 2013-10-30 20:20 - 00000000 ____D C:\Users\Fadi\Desktop\Monsters University (2013) [3D] [HSBS]
2013-10-15 21:10 - 2013-10-30 20:19 - 00000000 ____D C:\Users\Fadi\Desktop\Cinderella3D
2013-10-15 21:07 - 2013-10-30 20:14 - 00000000 ____D C:\Users\Fadi\Desktop\Abenteuer Bahamas 3D
2013-10-15 20:42 - 2013-10-15 20:51 - 204472320 _____ C:\Users\Fadi\Downloads\The.Fire.Dragon.Chronicles.3D.2008.German.H-SBS.German.DTS.DL.1080p.BluRay.x264-LeetHD.part01.rar
2013-10-15 20:35 - 2013-10-15 20:35 - 00077236 _____ (AppWork UG (haftungsbeschränkt)) C:\Users\Fadi\Downloads\jDownloaderWebInstaller09581.exe
2013-10-15 20:34 - 2013-10-15 20:34 - 00002912 _____ C:\Users\Fadi\Downloads\uobzwm4m4912ov4.ccf
2013-10-14 16:57 - 2013-08-10 06:21 - 00448512 _____ (Microsoft Corporation) C:\windows\system32\SettingSync.dll
2013-10-14 16:57 - 2013-08-10 06:21 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\SettingSyncInfo.dll
2013-10-14 16:57 - 2013-08-10 04:58 - 00356352 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSync.dll
2013-10-14 16:57 - 2013-08-03 07:40 - 01374208 _____ (Microsoft Corporation) C:\windows\system32\wdc.dll
2013-10-14 16:57 - 2013-08-03 07:40 - 00566784 _____ (Microsoft Corporation) C:\windows\system32\wvc.dll
2013-10-14 16:57 - 2013-08-03 07:40 - 00462336 _____ (Microsoft Corporation) C:\windows\system32\sysmon.ocx
2013-10-14 16:57 - 2013-08-03 06:14 - 00399360 _____ (Microsoft Corporation) C:\windows\SysWOW64\sysmon.ocx
2013-10-14 16:57 - 2013-08-03 06:13 - 01245696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdc.dll
2013-10-14 16:57 - 2013-08-03 06:13 - 00437248 _____ (Microsoft Corporation) C:\windows\SysWOW64\wvc.dll
2013-10-14 16:57 - 2013-08-02 07:28 - 19758080 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2013-10-14 16:57 - 2013-08-02 07:28 - 10116608 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2013-10-14 16:57 - 2013-08-02 07:28 - 00222208 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2013-10-14 16:57 - 2013-08-02 07:26 - 02304512 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2013-10-14 16:57 - 2013-08-02 06:08 - 17561088 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2013-10-14 16:57 - 2013-08-02 06:08 - 08858112 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2013-10-14 16:57 - 2013-08-02 06:08 - 00199168 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
2013-10-14 16:57 - 2013-08-02 06:06 - 02035712 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2013-10-14 16:57 - 2013-08-01 11:41 - 02233688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-10-14 16:57 - 2013-07-31 00:30 - 00386923 _____ C:\windows\system32\ApnDatabase.xml
2013-10-14 16:57 - 2013-07-25 00:10 - 00158208 _____ (Microsoft Corporation) C:\windows\SysWOW64\mbsmsapi.dll
2013-10-14 16:57 - 2013-07-25 00:06 - 00225280 _____ (Microsoft Corporation) C:\windows\system32\mbsmsapi.dll
2013-10-14 16:57 - 2013-04-10 00:17 - 01125888 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2013-10-14 16:57 - 2013-04-09 23:29 - 00893952 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2013-10-13 17:30 - 2013-10-31 21:53 - 00000000 ___RD C:\Users\Fadi\Dropbox
2013-10-13 17:30 - 2013-10-13 17:30 - 00001000 _____ C:\Users\Fadi\Desktop\Dropbox.lnk
2013-10-13 17:28 - 2013-10-13 17:28 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-13 17:27 - 2013-10-31 21:54 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Dropbox
2013-10-10 19:11 - 2013-10-10 19:11 - 00000912 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2669165515-361187302-876288576-1001Core.job
2013-10-10 19:11 - 2013-10-10 19:11 - 00000000 ____D C:\Users\Fadi\AppData\Local\Facebook
2013-10-10 19:11 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-10-10 19:11 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-10-10 19:11 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-10-10 19:11 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-10-10 19:11 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-10-10 19:11 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-10-10 19:11 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-10-10 19:11 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-10-10 19:11 - 2013-07-06 01:15 - 00652288 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2013-10-10 19:11 - 2013-07-04 03:13 - 00541696 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2013-10-10 19:11 - 2013-05-15 23:37 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
2013-10-10 19:11 - 2013-05-14 14:14 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-10-10 19:11 - 2013-05-14 10:23 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-10-10 19:11 - 2013-02-21 11:29 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-10-10 19:11 - 2013-02-21 11:29 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-10-10 19:11 - 2013-02-21 11:29 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-10-10 19:11 - 2013-02-21 11:29 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-10-10 19:11 - 2013-02-21 11:14 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-10-10 19:11 - 2013-02-21 11:14 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-10-10 19:11 - 2012-11-08 05:20 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-10-10 19:11 - 2012-11-08 05:20 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-10-10 19:10 - 2013-08-23 06:11 - 04040192 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-10-10 19:10 - 2013-07-05 23:02 - 00099328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2013-10-10 19:10 - 2013-07-05 23:01 - 00210560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2013-10-10 19:10 - 2013-07-01 23:14 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbprint.sys
2013-10-10 19:10 - 2013-06-29 04:08 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2013-10-10 19:10 - 2013-06-29 04:07 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2013-10-10 19:10 - 2013-06-22 06:45 - 00785624 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2013-10-10 19:10 - 2013-06-22 06:45 - 00054488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2013-10-10 19:10 - 2013-05-27 00:17 - 00035328 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2013-10-10 19:10 - 2013-05-26 23:59 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2013-10-10 19:10 - 2013-05-25 04:15 - 00362496 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2013-10-10 19:10 - 2013-05-25 03:32 - 00300032 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2013-10-10 17:49 - 2013-10-02 02:38 - 00694232 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-10-10 17:49 - 2013-10-02 02:38 - 00078296 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-10 11:44 - 2013-07-19 23:13 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 11:44 - 2013-07-19 23:13 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 11:44 - 2013-07-02 02:41 - 00447320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2013-10-10 11:44 - 2013-07-02 02:41 - 00337752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBXHCI.SYS
2013-10-10 11:44 - 2013-07-02 02:41 - 00213336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\UCX01000.SYS
2013-10-10 11:44 - 2013-07-01 02:42 - 00623448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2013-10-10 11:44 - 2013-07-01 02:42 - 00498008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2013-10-10 11:44 - 2013-07-01 02:42 - 00079192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2013-10-10 11:44 - 2013-07-01 02:42 - 00021848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2013-10-10 11:44 - 2013-06-29 04:07 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2013-10-10 11:44 - 2013-06-29 04:06 - 00120832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2013-10-07 22:29 - 2013-10-07 22:29 - 00002245 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00002245 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00002236 _____ C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ___RD C:\Users\Fadi\SkyDrive
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ____D C:\ProgramData\Microsoft SkyDrive
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2013-10-07 22:18 - 2013-10-10 10:06 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-10-07 22:18 - 2013-10-07 22:18 - 00575168 _____ (Microsoft Corporation) C:\Users\Fadi\Downloads\Setup.X86.de-DE_O365HomePremRetail_cc7b04f3-ea18-45eb-b5b1-8f60fa5fbe90_TX_DB_.exe
2013-10-01 09:09 - 2013-10-01 09:09 - 00908800 _____ C:\windows\system32\ContentDirectoryPresenter64.dll
2013-10-01 09:09 - 2013-10-01 09:09 - 00030720 _____ C:\windows\system32\MediaDB64.dll
2013-10-01 08:46 - 2013-10-01 08:46 - 00025600 _____ C:\windows\SysWOW64\MediaDB.dll
2013-10-01 08:11 - 2013-10-01 08:11 - 00706560 _____ C:\windows\SysWOW64\ContentDirectoryPresenter.dll

==================== One Month Modified Files and Folders =======

2013-10-31 22:12 - 2013-10-31 22:12 - 01957098 _____ (Farbar) C:\Users\Fadi\Downloads\FRST64(1).exe
2013-10-31 22:12 - 2013-05-30 18:13 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\uTorrent
2013-10-31 22:08 - 2013-10-16 13:13 - 00005116 _____ C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Fadi-Fadi Fadi
2013-10-31 22:07 - 2013-10-31 22:07 - 00000611 _____ C:\Users\Fadi\Desktop\JRT.txt
2013-10-31 22:06 - 2013-05-30 00:01 - 00003594 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2669165515-361187302-876288576-1001
2013-10-31 22:00 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\sru
2013-10-31 21:58 - 2013-01-25 03:58 - 00000000 ____D C:\ProgramData\WinClon
2013-10-31 21:57 - 2013-10-31 21:57 - 01033335 _____ (Thisisu) C:\Users\Fadi\Downloads\JRT.exe
2013-10-31 21:57 - 2013-10-31 21:57 - 00000000 ____D C:\windows\ERUNT
2013-10-31 21:54 - 2013-10-13 17:27 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Dropbox
2013-10-31 21:53 - 2013-10-31 21:53 - 00000977 _____ C:\Users\Fadi\Desktop\AdwCleaner[S0].txt
2013-10-31 21:53 - 2013-10-13 17:30 - 00000000 ___RD C:\Users\Fadi\Dropbox
2013-10-31 21:52 - 2013-10-31 21:52 - 00000000 ___RD C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2013-10-31 21:51 - 2013-01-25 03:48 - 00000868 _____ C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-10-31 21:50 - 2012-07-26 08:22 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-10-31 21:49 - 2012-07-26 06:26 - 00262144 ___SH C:\windows\system32\config\BBI
2013-10-31 21:48 - 2013-10-31 20:49 - 00000000 ____D C:\AdwCleaner
2013-10-31 21:44 - 2013-06-08 15:49 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-10-31 21:14 - 2013-01-25 04:10 - 00000360 _____ C:\windows\Tasks\Xerox PhotoCafe Communicator.job
2013-10-31 21:06 - 2013-01-25 20:05 - 00791060 _____ C:\windows\system32\perfh00C.dat
2013-10-31 21:06 - 2013-01-25 20:05 - 00155620 _____ C:\windows\system32\perfc00C.dat
2013-10-31 21:06 - 2013-01-25 19:59 - 00782014 _____ C:\windows\system32\perfh010.dat
2013-10-31 21:06 - 2013-01-25 19:59 - 00153144 _____ C:\windows\system32\perfc010.dat
2013-10-31 21:06 - 2013-01-25 19:54 - 00754172 _____ C:\windows\system32\perfh007.dat
2013-10-31 21:06 - 2013-01-25 19:54 - 00156362 _____ C:\windows\system32\perfc007.dat
2013-10-31 21:06 - 2012-07-26 08:28 - 03630792 _____ C:\windows\system32\PerfStringBackup.INI
2013-10-31 20:58 - 2012-08-05 22:07 - 00968924 _____ C:\windows\PFRO.log
2013-10-31 20:55 - 2013-06-20 11:11 - 00000000 __SHD C:\ProgramData\REF
2013-10-31 20:49 - 2013-10-31 20:49 - 01060070 _____ C:\Users\Fadi\Downloads\adwcleaner.exe
2013-10-31 20:42 - 2013-10-31 20:42 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Malwarebytes
2013-10-31 20:41 - 2013-10-31 20:41 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Fadi\Downloads\mbam-setup-
2013-10-31 20:41 - 2013-10-31 20:41 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-10-31 20:41 - 2013-10-31 20:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-31 20:41 - 2013-05-30 02:43 - 00000000 ____D C:\Meine Programme
2013-10-31 20:03 - 2013-10-31 20:03 - 00045962 _____ C:\Users\Fadi\Desktop\FRST.txt
2013-10-31 20:02 - 2013-10-31 20:02 - 00030996 _____ C:\Users\Fadi\Desktop\Addition.txt
2013-10-31 20:02 - 2013-10-31 20:00 - 00030996 _____ C:\Users\Fadi\Downloads\Addition.txt
2013-10-31 19:58 - 2013-10-31 19:58 - 00000000 ____D C:\FRST
2013-10-31 19:57 - 2013-10-31 19:57 - 01957098 _____ (Farbar) C:\Users\Fadi\Downloads\FRST64.exe
2013-10-31 18:50 - 2013-05-30 03:00 - 00000000 ____D C:\ProgramData\MFAData
2013-10-31 13:22 - 2013-01-25 02:52 - 01496092 _____ C:\windows\WindowsUpdate.log
2013-10-31 06:59 - 2012-07-26 09:12 - 00000000 ____D C:\windows\AUInstallAgent
2013-10-30 20:20 - 2013-10-17 15:21 - 00000000 ____D C:\Users\Fadi\Desktop\handy sheyma
2013-10-30 20:20 - 2013-10-15 21:14 - 00000000 ____D C:\Users\Fadi\Desktop\Monsters University (2013) [3D] [HSBS]
2013-10-30 20:19 - 2013-10-17 15:31 - 00000000 ____D C:\Users\Fadi\Desktop\experiment
2013-10-30 20:19 - 2013-10-15 21:10 - 00000000 ____D C:\Users\Fadi\Desktop\Cinderella3D
2013-10-30 20:16 - 2013-09-30 10:35 - 00000000 ____D C:\Users\Fadi\AppData\Local\Avg2014
2013-10-30 20:14 - 2013-10-15 21:07 - 00000000 ____D C:\Users\Fadi\Desktop\Abenteuer Bahamas 3D
2013-10-30 19:17 - 2013-05-30 03:16 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\vlc
2013-10-30 19:16 - 2013-05-30 01:41 - 00000000 ____D C:\Users\Fadi\AppData\Local\CrashDumps
2013-10-30 11:35 - 2013-05-30 18:16 - 00000000 ____D C:\Users\Fadi\Desktop\Kochbuch
2013-10-30 10:42 - 2012-07-26 06:26 - 00262144 ___SH C:\windows\system32\config\ELAM
2013-10-29 14:36 - 2013-10-29 14:34 - 00004897 _____ C:\windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-29 14:36 - 2013-06-29 13:50 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-29 10:00 - 2013-01-25 03:48 - 00000870 _____ C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-10-28 23:07 - 2013-10-28 23:07 - 00003126 _____ C:\windows\System32\Tasks\advRecovery
2013-10-28 23:07 - 2013-10-28 23:07 - 00000709 _____ C:\Users\Public\Desktop\Recovery.lnk
2013-10-28 23:07 - 2013-01-25 02:52 - 00000000 ____D C:\Program Files\Samsung
2013-10-28 23:07 - 2013-01-25 02:51 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-28 22:58 - 2013-10-28 22:58 - 00000000 ____D C:\Program Files (x86)\UEFI WinFlash
2013-10-28 22:47 - 2013-10-28 22:47 - 00000003 _____ C:\windows\system32\HRUPPROG.TXT
2013-10-28 08:55 - 2013-10-26 21:59 - 00000000 ____D C:\Users\Fadi\Desktop\Tai Chi Zero
2013-10-27 12:30 - 2013-10-16 07:18 - 00000000 ____D C:\Users\Fadi\Desktop\www.byte.to...Hotel.Transsilvanien.3D.German.DL.720p.BluRay.x264-ETM
2013-10-27 12:08 - 2013-10-27 12:08 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\WinRAR
2013-10-27 12:08 - 2013-10-27 12:08 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-10-27 12:06 - 2013-10-27 12:06 - 02074056 _____ C:\Users\Fadi\Downloads\winrar-x64-500d.exe.part
2013-10-27 12:06 - 2013-10-27 12:06 - 02074056 _____ C:\Users\Fadi\Downloads\winrar-x64-500d.exe
2013-10-27 12:06 - 2013-10-27 12:06 - 01970848 _____ C:\Users\Fadi\Downloads\winrar-x64-500.exe.part
2013-10-26 22:49 - 2013-10-26 22:49 - 00000000 ____D C:\Users\Fadi\Desktop\Dredd 3D
2013-10-26 22:40 - 2013-10-26 22:40 - 00000000 ____D C:\Users\Fadi\Desktop\Star Trek Into Darkness ger
2013-10-26 21:34 - 2013-10-26 21:34 - 00000000 ____D C:\Users\Fadi\Desktop\Monsters vs Aliens
2013-10-26 21:14 - 2013-10-26 21:14 - 00000000 ____D C:\Users\Fadi\Desktop\Egypt 3D
2013-10-26 21:02 - 2013-10-17 17:40 - 00000000 ____D C:\Users\Fadi\Desktop\[www.top-hitz.com]Shark.Night.3D.R5.MD.German.XviD.derp
2013-10-26 20:51 - 2013-10-26 20:51 - 00000000 ____D C:\Users\Fadi\Desktop\Meet the Robinsons
2013-10-26 20:46 - 2013-10-26 20:46 - 00000000 ____D C:\Users\Fadi\Desktop\Dredd
2013-10-26 20:44 - 2013-10-26 20:44 - 00000000 ____D C:\Users\Fadi\Desktop\Escape from Planet Earth
2013-10-26 20:41 - 2013-10-26 20:41 - 00000000 ____D C:\Users\Fadi\Desktop\Star Trek Into Darkness
2013-10-26 07:53 - 2013-05-30 18:16 - 00000000 ____D C:\Users\Fadi\Desktop\Sheyma zeug
2013-10-25 14:27 - 2013-10-17 17:58 - 00029223 _____ C:\Users\Fadi\Desktop\Referat Piaget BM6.odt
2013-10-25 13:31 - 2013-10-18 17:52 - 02350982 _____ C:\Users\Fadi\Desktop\powerpoint  piaget.odp
2013-10-23 21:26 - 2013-10-23 21:26 - 00000777 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-10-23 20:18 - 2013-10-23 20:17 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2013-10-23 20:17 - 2013-10-23 20:17 - 00000000 ____D C:\Users\Fadi\Samsung Link
2013-10-23 20:17 - 2013-05-29 23:52 - 00000000 ____D C:\Users\Fadi
2013-10-23 20:05 - 2013-10-23 20:05 - 00000000 ____D C:\Upload
2013-10-23 20:04 - 2013-10-23 20:04 - 00000000 ____D C:\Users\Fadi\.swt
2013-10-23 20:04 - 2013-05-29 23:54 - 00000000 ____D C:\Users\Fadi\AppData\Local\Samsung
2013-10-23 20:04 - 2013-01-25 04:00 - 00000000 ____D C:\ProgramData\Samsung
2013-10-23 20:03 - 2013-10-23 20:03 - 00000000 ____D C:\Users\Fadi\Desktop\Samsung Link
2013-10-23 10:06 - 2013-10-23 10:06 - 00001956 _____ C:\Users\Public\Desktop\SW Update.lnk
2013-10-20 22:39 - 2013-10-20 22:39 - 01376768 _____ C:\Users\Fadi\Downloads\7z920-x64.msi
2013-10-19 10:58 - 2013-05-29 23:52 - 00000000 ____D C:\Users\Fadi\AppData\Local\Packages
2013-10-19 10:54 - 2013-10-19 10:53 - 62411022 _____ C:\Users\Fadi\Desktop\powerpoint  piaget.pptx
2013-10-18 23:10 - 2013-10-18 21:21 - 00020220 _____ C:\Users\Fadi\Desktop\BM6 Experiment.odt
2013-10-18 17:52 - 2013-10-18 17:52 - 00000000 ____D C:\Users\Fadi\Documents\Benutzerdefinierte Office-Vorlagen
2013-10-16 12:19 - 2013-10-16 11:23 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\TS3Client
2013-10-16 11:46 - 2013-10-16 11:45 - 00000000 ____D C:\Users\Fadi\Desktop\Teamspeak
2013-10-16 11:22 - 2013-10-16 11:22 - 00000598 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2013-10-16 09:01 - 2012-07-26 09:12 - 00000000 ____D C:\windows\rescache
2013-10-16 07:14 - 2013-05-29 23:55 - 00000000 ___RD C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-16 07:14 - 2013-05-29 23:55 - 00000000 ___RD C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-16 07:12 - 2013-10-16 07:12 - 03459168 _____ C:\windows\system32\FNTCACHE.DAT
2013-10-15 22:55 - 2012-07-26 09:12 - 00000000 ___RD C:\windows\ToastData
2013-10-15 20:51 - 2013-10-15 20:42 - 204472320 _____ C:\Users\Fadi\Downloads\The.Fire.Dragon.Chronicles.3D.2008.German.H-SBS.German.DTS.DL.1080p.BluRay.x264-LeetHD.part01.rar
2013-10-15 20:35 - 2013-10-15 20:35 - 00077236 _____ (AppWork UG (haftungsbeschränkt)) C:\Users\Fadi\Downloads\jDownloaderWebInstaller09581.exe
2013-10-15 20:34 - 2013-10-15 20:34 - 00002912 _____ C:\Users\Fadi\Downloads\uobzwm4m4912ov4.ccf
2013-10-13 17:30 - 2013-10-13 17:30 - 00001000 _____ C:\Users\Fadi\Desktop\Dropbox.lnk
2013-10-13 17:28 - 2013-10-13 17:28 - 00000000 ____D C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-10-11 09:38 - 2013-05-30 03:03 - 00000000 ___HD C:\$AVG
2013-10-11 09:38 - 2012-07-26 09:12 - 00000000 ___HD C:\windows\ELAMBKUP
2013-10-10 19:11 - 2013-10-10 19:11 - 00000912 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2669165515-361187302-876288576-1001Core.job
2013-10-10 19:11 - 2013-10-10 19:11 - 00000000 ____D C:\Users\Fadi\AppData\Local\Facebook
2013-10-10 17:51 - 2013-07-29 09:17 - 00000000 ____D C:\windows\system32\MRT
2013-10-10 17:50 - 2013-05-30 01:02 - 80541720 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-10-10 10:06 - 2013-10-07 22:18 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-10-09 11:44 - 2013-06-08 15:49 - 00003772 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-10-08 20:34 - 2013-07-29 21:40 - 00000000 ____D C:\Users\Fadi\Desktop\aria arbeit
2013-10-08 07:50 - 2013-10-29 14:36 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 07:46 - 2013-10-29 14:36 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-10-08 07:46 - 2013-10-29 14:36 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-10-08 07:46 - 2013-10-29 14:36 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-10-07 22:29 - 2013-10-07 22:29 - 00002245 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00002245 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00002236 _____ C:\Users\Fadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ___RD C:\Users\Fadi\SkyDrive
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ____D C:\ProgramData\Microsoft SkyDrive
2013-10-07 22:29 - 2013-10-07 22:29 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2013-10-07 22:29 - 2013-01-25 04:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-10-07 22:19 - 2013-05-29 23:53 - 00000000 ____D C:\Users\Fadi\AppData\Local\VirtualStore
2013-10-07 22:18 - 2013-10-07 22:18 - 00575168 _____ (Microsoft Corporation) C:\Users\Fadi\Downloads\Setup.X86.de-DE_O365HomePremRetail_cc7b04f3-ea18-45eb-b5b1-8f60fa5fbe90_TX_DB_.exe
2013-10-05 01:19 - 2013-05-30 18:16 - 00000000 ____D C:\Users\Fadi\Desktop\UNI
2013-10-02 02:38 - 2013-10-10 17:49 - 00694232 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-10-02 02:38 - 2013-10-10 17:49 - 00078296 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-01 09:09 - 2013-10-01 09:09 - 00908800 _____ C:\windows\system32\ContentDirectoryPresenter64.dll
2013-10-01 09:09 - 2013-10-01 09:09 - 00030720 _____ C:\windows\system32\MediaDB64.dll
2013-10-01 08:46 - 2013-10-01 08:46 - 00025600 _____ C:\windows\SysWOW64\MediaDB.dll
2013-10-01 08:11 - 2013-10-01 08:11 - 00706560 _____ C:\windows\SysWOW64\ContentDirectoryPresenter.dll

Files to move or delete:

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-10-30 10:55

==================== End Of Log ============================
--- --- ---

Danke für deine Hilfe.

Alt 01.11.2013, 12:17   #4
/// the machine
/// TB-Ausbilder

Whilokii-Virus - Standard


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

Alt 03.11.2013, 13:34   #5
Whilokii-Virus - Standard


Herzlichen Dank.

Alles in Ordnung


Alt 04.11.2013, 09:01   #6
/// the machine
/// TB-Ausbilder

Whilokii-Virus - Standard


--> Whilokii-Virus

Alt 05.11.2013, 21:54   #7
Whilokii-Virus - Standard


Hab leider bereits alles wieder gelöscht. Habe aber alle Schritte durchgezogen.

Danke nochmal.

Alt 06.11.2013, 13:40   #8
/// the machine
/// TB-Ausbilder

Whilokii-Virus - Standard



