![]() |
| |||||||
Log-Analyse und Auswertung: Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbarWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
| | Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar Hi, wenn ich Dateien auf einen zuvor formatierten USB-Stick kopiere, erscheinen diese dort. Wenn ich dann das Explorer-Fenster schließe und wieder öffne, werden keine Dateien auf dem Stick angezeigt. In den Eigenschaften des Sticks ist der Speicherplatz jedoch belegt. Beim Scan des Sticks mit BitDefander findet dieser die zu scannenden Dateien, zeigt aber keine Infektion an. Lasse ich Bitdefender über die Quell-Dateien laufen wird ebenfalls keine Infektion angezeigt. Ich würde ja den PC einfach formatieren, aber ich kann wichtige Daten ja nicht per USB sichern :-/ Im Anschluss die Log-Dateien aus defogger, frst und gmer: defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1)
Log created at 16:01 on 25/09/2014 (rspri_000)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
HKCU:DAEMON Tools Lite -> Removed
Checking for services/drivers...
-=E.O.F=-
Code:
ATTFilter Running from C:\Users\rspri_000\Downloads
Loaded Profile: rspri_000 (Available profiles: rspri_000)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-09-2014
Ran by rspri_000 (administrator) on RAPHAELS_PC on 25-09-2014 15:41:40
Platform: Windows 8 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) D:\Tools\ZuneLauncher.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Spotify Ltd) C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe
(sw4you) C:\Program Files (x86)\Hardcopy\hardcopy.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwtxapps.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\odscanui.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\seccenter.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Mozilla Corporation) D:\Tools\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\VISIO.EXE
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Dropbox, Inc.) C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Connectify Hotspot] => C:\Program Files (x86)\Connectify\Connectify.exe [5236512 2013-05-14] (Connectify)
HKLM\...\Run: [Connectify Dispatch] => C:\Program Files (x86)\Connectify\DispatchUI.exe [3121440 2013-05-14] (Connectify)
HKLM\...\Run: [Zune Launcher] => D:\Tools\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-28] (Synaptics Incorporated)
HKLM\...\Run: [Bdagent] => D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe [1580360 2014-08-20] (Bitdefender)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => "C:\AMD\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2013-10-10] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [PC Remote Server] => C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [884376 2013-04-07] (PC Remote)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Spotify Web Helper] => C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-20] (Spotify Ltd)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [1] => wscript.exe //B "C:\ProgramData\1.vbs"
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Facebook Update] => C:\Users\rspri_000\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-09-12] (Facebook Inc.)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Bitdefender-Geldbörse-Agent] => D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe [815088 2014-08-14] (Bitdefender)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\MountPoints2: {c22edc32-9e8e-11e2-be67-0026221d60c8} - "G:\SETUP.EXE"
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\MountPoints2: {fb3665b3-5386-11e3-be95-0026221d60c8} - "F:\Install.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK
ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs ()
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk /m /f \Device\HarddiskVolume4autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www2.elearning.rwth-aachen.de/
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\pmbxie.dll (Bitdefender)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH)
Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll (Bitdefender)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 172.31.12.11 172.31.12.12
FireFox:
========
FF ProfilePath: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
FF Homepage: https://www2.elearning.rwth-aachen.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\rspri_000\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF user.js: detected! => C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\user.js
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\avira-safesearch.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-maps.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\zonealarm.xml
FF Extension: Avira Browser Safety - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\abs@avira.com [2014-09-04]
FF Extension: Grooveshark Unlocker - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-05-15]
FF Extension: ProxTube - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11]
FF Extension: Adblock Plus - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-06]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: Bitdefender Antispam Toolbar - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext [2014-09-25]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-10-27]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2014-04-23]
FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff
FF Extension: Bitdefender Wallet - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-09-25]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\extensions\cliqz@cliqz.com
FF StartMenuInternet: FIREFOX.EXE - D:\Tools\Mozilla Firefox\firefox.exe
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BdDesktopParental; D:\Tools\Bitdefender\Bitdefender 2015\bdparentalservice.exe [77632 2014-08-08] (Bitdefender)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [156672 2013-05-14] (Connectify) [File not signed]
R2 Hamachi2Svc; C:\Tools\LogMeIn Hamachi\hamachi-2.exe [2525008 2014-09-04] (LogMeIn Inc.)
R3 hpqcxs08; C:\HP\Digital Imaging\bin\hpqcxs08.dll [254824 2011-04-29] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\HP\Digital Imaging\bin\hpqddsvc.dll [138600 2011-04-29] (Hewlett-Packard Co.)
R2 HPSLPSVC; C:\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
R2 UPDATESRV; D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-08-08] (Bitdefender)
R2 VSSERV; D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe [1513952 2014-08-11] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S3 WMZuneComm; D:\Tools\WMZuneComm.exe [306400 2011-08-05] (Microsoft Corporation)
S3 ZuneNetworkSvc; D:\Tools\ZuneNss.exe [8277728 2011-08-05] (Microsoft Corporation)
S3 ZuneWlanCfgSvc; D:\Tools\ZuneWlanCfgSvc.exe [467680 2011-08-05] (Microsoft Corporation)
S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1260120 2014-05-16] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261496 2013-07-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-05-16] (BitDefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-11-19] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-09-25] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-09-25] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-06] (DT Soft Ltd)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [419616 2014-07-02] (BitDefender S.R.L.)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 AAMWRegFilter; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter64.sys [X]
S3 ASW3Scan; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-25 15:41 - 2014-09-25 15:43 - 00023628 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:41 - 2014-09-25 15:42 - 00000000 ____D () C:\FRST
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 15:38 - 2014-09-25 15:38 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2014-05-16 13:04 - 00647752 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2014-09-25 12:11 - 2014-05-16 13:01 - 01260120 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2014-09-25 12:11 - 2013-11-19 14:44 - 00098768 _____ (BitDefender LLC) C:\Windows\system32\Drivers\bdfndisf6.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00082824 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00074512 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll
2014-09-25 12:11 - 2013-09-08 20:04 - 00023568 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys
2014-09-25 12:11 - 2013-07-17 19:31 - 00261496 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys
2014-09-25 12:11 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll
2014-09-25 12:00 - 2014-09-25 12:18 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:00 - 2014-09-25 12:12 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:00 - 2014-09-25 12:12 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:00 - 2014-09-25 12:00 - 00002247 _____ () C:\ProgramData\1411638859.4504.bin
2014-09-25 12:00 - 2014-07-04 17:49 - 49563064 ____H () C:\bdr-im01.gz
2014-09-25 12:00 - 2013-08-13 13:38 - 03271472 ____H () C:\bdr-bz01
2014-09-25 11:57 - 2014-09-25 11:59 - 00001545 _____ () C:\ProgramData\1411638859.6416.bin
2014-09-25 11:54 - 2014-09-25 13:18 - 00185845 _____ () C:\ProgramData\1411638859.5060.bin
2014-09-25 11:54 - 2014-09-25 12:18 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 11:54 - 2014-09-25 12:12 - 00213908 _____ () C:\ProgramData\1411638859.4688.bin
2014-09-25 11:54 - 2014-09-25 12:12 - 00158277 _____ () C:\ProgramData\1411638859.6264.bin
2014-09-25 11:54 - 2014-09-25 12:11 - 00050890 _____ () C:\ProgramData\1411638859.3272.bin
2014-09-25 11:54 - 2014-09-25 12:00 - 00017817 _____ () C:\ProgramData\1411638859.3748.bin
2014-09-25 11:54 - 2014-09-25 11:57 - 00001090 _____ () C:\ProgramData\1411638859.6020.bin
2014-09-25 11:54 - 2014-09-25 11:55 - 00001089 _____ () C:\ProgramData\1411638859.768.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00017948 _____ () C:\ProgramData\1411638859.2656.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00009470 _____ () C:\ProgramData\1411638859.788.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00002969 _____ () C:\ProgramData\1411638859.6660.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-07-02 17:47 - 00419616 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2014-09-25 11:54 - 2013-11-04 15:47 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUISkin.dll
2014-09-25 11:54 - 2013-11-04 15:46 - 00034384 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUH.dll
2014-09-25 11:54 - 2013-08-23 13:48 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2014-09-25 11:49 - 2014-09-25 11:54 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 11:20 - 2014-09-25 11:51 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:12 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-18 22:12 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 09:20 - 2014-08-09 10:30 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-09-18 09:20 - 2014-08-09 10:29 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2014-09-15 20:02 - 2014-09-15 20:03 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:23 - 2014-09-12 10:24 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:13 - 2014-09-12 10:19 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\RHEng
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:12 - 2014-09-12 10:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\OpenCandy
2014-09-12 10:11 - 2014-09-12 10:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:52 - 2014-09-25 12:58 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-12 09:52 - 2014-09-25 09:58 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-12 09:52 - 2014-09-12 09:53 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:52 - 2014-09-12 09:53 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 08:18 - 2014-08-21 01:40 - 00732880 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-09-12 08:18 - 2014-08-20 19:05 - 00694784 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-09-12 08:18 - 2014-08-20 19:02 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-09-12 08:18 - 2014-06-24 09:35 - 00010450 _____ () C:\Windows\system32\autoconfig.cab
2014-09-12 08:18 - 2014-06-24 08:41 - 10115584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-09-12 08:18 - 2014-06-24 08:40 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2014-09-12 08:18 - 2014-06-24 08:39 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-09-12 08:18 - 2014-06-24 06:08 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-09-12 08:18 - 2014-06-24 06:06 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-08-20 19:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-06-24 08:39 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-09-12 08:17 - 2014-06-24 06:06 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 09:24 - 2014-08-16 11:33 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 11:33 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 09:24 - 2014-08-16 11:32 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 09:35 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 09:24 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 09:24 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-09-11 09:24 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-09-11 09:24 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 09:24 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 09:24 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 09:24 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 09:24 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 09:23 - 2014-08-16 11:34 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 09:23 - 2014-08-16 11:33 - 19280384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 09:23 - 2014-08-16 11:32 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 14369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 08:49 - 2014-08-28 13:34 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-09-11 08:49 - 2014-08-28 08:05 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:01 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-09-11 08:49 - 2014-08-01 01:40 - 01287680 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00875688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00869544 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-06-05 03:12 - 00678600 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2014-09-11 08:48 - 2014-06-04 01:12 - 00536776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-05 00:44 - 2014-09-12 21:43 - 00135049 ____H () C:\ProgramData\1.vbs
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-08-29 10:31 - 2014-08-23 08:47 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 10:04 - 2014-09-09 22:35 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-25 15:43 - 2014-09-25 15:41 - 00023628 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:42 - 2014-09-25 15:41 - 00000000 ____D () C:\FRST
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 15:38 - 2014-09-25 15:38 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 15:38 - 2013-04-06 11:04 - 00000000 ____D () C:\Users\rspri_000
2014-09-25 15:22 - 2014-03-06 12:50 - 00000000 ___RD () C:\Users\rspri_000\Dropbox
2014-09-25 15:22 - 2014-03-06 12:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Dropbox
2014-09-25 15:07 - 2013-04-06 14:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-25 15:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-09-25 14:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-09-25 14:03 - 2013-06-09 14:08 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-25 14:02 - 2013-07-25 23:34 - 01391694 _____ () C:\Windows\WindowsUpdate.log
2014-09-25 13:59 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\Offline Web Pages
2014-09-25 13:55 - 2013-04-06 12:30 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4243713041-920332011-2703711254-1001
2014-09-25 13:25 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 13:23 - 2013-07-10 19:20 - 00000406 _____ () C:\Windows\Tasks\Lyrics-Pal Update.job
2014-09-25 13:23 - 2013-06-02 16:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\LogMeIn Hamachi
2014-09-25 13:22 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-25 13:21 - 2013-07-27 09:01 - 00034870 _____ () C:\Windows\PFRO.log
2014-09-25 13:21 - 2013-04-06 14:29 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-09-25 13:20 - 2012-07-26 07:26 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-09-25 13:18 - 2014-09-25 11:54 - 00185845 _____ () C:\ProgramData\1411638859.5060.bin
2014-09-25 13:04 - 2014-03-18 13:47 - 00000000 ___HD () C:\$Windows.~BT
2014-09-25 12:58 - 2014-09-12 09:52 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-25 12:55 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:18 - 2014-09-25 12:00 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:18 - 2014-09-25 11:54 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:12 - 2014-09-25 12:00 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:12 - 2014-09-25 12:00 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:12 - 2014-09-25 11:54 - 00213908 _____ () C:\ProgramData\1411638859.4688.bin
2014-09-25 12:12 - 2014-09-25 11:54 - 00158277 _____ () C:\ProgramData\1411638859.6264.bin
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2014-09-25 11:54 - 00050890 _____ () C:\ProgramData\1411638859.3272.bin
2014-09-25 12:11 - 2013-08-23 08:02 - 00018002 _____ () C:\Windows\setupact.log
2014-09-25 12:00 - 2014-09-25 12:00 - 00002247 _____ () C:\ProgramData\1411638859.4504.bin
2014-09-25 12:00 - 2014-09-25 11:54 - 00017817 _____ () C:\ProgramData\1411638859.3748.bin
2014-09-25 11:59 - 2014-09-25 11:57 - 00001545 _____ () C:\ProgramData\1411638859.6416.bin
2014-09-25 11:57 - 2014-09-25 11:54 - 00001090 _____ () C:\ProgramData\1411638859.6020.bin
2014-09-25 11:55 - 2014-09-25 11:54 - 00001089 _____ () C:\ProgramData\1411638859.768.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00017948 _____ () C:\ProgramData\1411638859.2656.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00009470 _____ () C:\ProgramData\1411638859.788.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00002969 _____ () C:\ProgramData\1411638859.6660.bin
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-09-25 11:49 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:53 - 2013-04-06 15:49 - 07196672 ___SH () C:\Users\rspri_000\Desktop\Thumbs.db
2014-09-25 11:51 - 2014-09-25 11:20 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 09:58 - 2014-09-12 09:52 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-25 09:42 - 2012-07-26 12:27 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-09-25 09:42 - 2012-07-26 12:27 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-09-25 09:42 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-25 08:55 - 2014-05-14 08:54 - 00093004 _____ () C:\Users\rspri_000\Desktop\Transferpräse Laptop-Citrix.pptx
2014-09-24 14:59 - 2014-08-19 17:38 - 00000000 ____D () C:\Users\rspri_000\Desktop\Urlaub
2014-09-24 14:16 - 2013-08-14 19:06 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Spotify
2014-09-24 12:45 - 2013-08-14 19:05 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Spotify
2014-09-24 09:10 - 2014-07-21 19:55 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung LH
2014-09-24 09:10 - 2014-04-14 11:39 - 00000000 ____D () C:\Users\rspri_000\Desktop\Dubbel 22.Auflage
2014-09-24 09:10 - 2013-04-08 11:41 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung Praktikum
2014-09-18 23:37 - 2013-06-04 22:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TS3Client
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 16:41 - 2013-04-06 13:41 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-18 15:22 - 2014-03-06 12:46 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-17 13:36 - 2013-12-15 23:39 - 00000000 ____D () C:\ProgramData\FILEminimizer
2014-09-16 13:50 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-09-15 21:50 - 2013-12-08 20:08 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\vlc
2014-09-15 20:03 - 2014-09-15 20:02 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-15 10:07 - 2013-04-10 10:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-09-15 10:07 - 2013-04-10 10:06 - 00000000 ____D () C:\HP
2014-09-15 10:07 - 2013-04-09 20:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\HpUpdate
2014-09-12 21:43 - 2014-09-05 00:44 - 00135049 ____H () C:\ProgramData\1.vbs
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-09-12 10:45 - 2014-09-12 10:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:24 - 2014-09-12 10:23 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:21 - 2013-04-06 14:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TuneUp Software
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:19 - 2014-09-12 10:13 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\RHEng
2014-09-12 10:19 - 2013-04-06 14:12 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-09-12 10:17 - 2013-04-21 20:47 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Skype
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:12 - 2014-09-12 10:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\OpenCandy
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:53 - 2014-09-12 09:52 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:53 - 2014-09-12 09:52 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 09:36 - 2013-04-21 20:47 - 00000000 ____D () C:\ProgramData\Skype
2014-09-11 20:08 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-09-11 09:30 - 2013-04-18 11:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 09:23 - 2013-07-23 21:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 09:14 - 2013-04-07 18:42 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-09 22:35 - 2014-08-26 10:04 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe
2014-09-09 22:34 - 2013-04-06 14:18 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-08 22:35 - 2013-04-09 20:10 - 00000000 ____D () C:\Tools
2014-09-07 12:28 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-06 14:48 - 2013-04-06 16:19 - 00000000 ____D () C:\Users\rspri_000\Documents\BAföG
2014-09-04 14:48 - 2014-04-23 09:23 - 00000000 ____D () C:\ProgramData\Swiss Academic Software
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-01 20:56 - 2014-07-11 08:06 - 00428056 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 13:34 - 2014-09-11 08:49 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-28 08:05 - 2014-09-11 08:49 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-28 08:02 - 2014-09-11 08:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-28 08:01 - 2014-09-11 08:49 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-08-26 16:18 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\ELAMBKUP
Files to move or delete:
====================
C:\ProgramData\1.vbs
Some content of TEMP:
====================
C:\Users\rspri_000\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5dxwm_.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-17 09:14
==================== End Of Log ============================
|
| | #2 | |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar![]() Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es:Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Zitat:
Bitte alle Tools direkt auf den Desktop downloaden bzw. dorthin verschieben und vom Desktop starten, da unsere Anleitungen daraufhin ausgelegt sind. Zudem lassen sich dann am Ende der Bereinigung alle verwendeten Tools sehr einfach entfernen. Alle Tools bis zum Ende der Bereinigung auf dem Desktop lassen, evtl. benötigen wir manche öfter. Schritt 1 Bitte lade Dir von hier Panda USB Vaccine herunter.
Schritt 2 Scan mit Combofix
|
| | #3 |
| | Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar Hier der Log-File des ComboFix:
__________________Code:
ATTFilter Combofix Logfile: |
| | #4 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar Schritt 1 Downloade Dir bitte
Schritt 2 Downloade Dir bitte
Schritt 3 Bitte deaktiviere dein Anti-Viren-Programm, da es das Ergebnis beeinflussen oder ggf. die Bereinigung stören kann. Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/ und speichere die Datei auf deinem Desktop.
Schritt 4
Bitte poste mit deiner nächsten Antwort
|
| | #5 |
| | Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar Hi M-K-D-B, Danke für die super schnelle Antwort! Hab alles gemacht wie beschrieben. die Logdatei von AdwCleaner, die Logdatei von MBAM, die Logdatei von Zoek, die beiden neuen Logdateien von FRST AdwCleaner: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.310 - Bericht erstellt am 25/09/2014 um 19:41:27
# Aktualisiert 12/09/2014 von Xplode
# Betriebssystem : Windows 8 Pro (64 bits)
# Benutzername : rspri_000 - RAPHAELS_PC
# Gestartet von : C:\Users\rspri_000\Desktop\AdwCleaner_3.310.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\rspri_000\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\rspri_000\AppData\Roaming\pdfforge
Datei Gelöscht : C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\user.js
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyricspal
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Mozilla Firefox v20.0 (en-US)
[ Datei : C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [4329 octets] - [25/09/2014 19:38:13]
AdwCleaner[R1].txt - [4389 octets] - [25/09/2014 19:40:27]
AdwCleaner[S0].txt - [4161 octets] - [25/09/2014 19:41:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4221 octets] ##########
MBAM: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 25.09.2014 Suchlauf-Zeit: 19:50:29 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.09.25.08 Rootkit Datenbank: v2014.09.19.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 8 CPU: x64 Dateisystem: NTFS Benutzer: rspri_000 Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 334588 Verstrichene Zeit: 41 Min, 39 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 2 PUP.Optional.PriceMeter.A, C:\Users\rspri_000\AppData\Roaming\RHEng\F01163AE04F142D9842DFC72E8A0EE4F\pm.exe, In Quarantäne, [08d4fff24e2d0c2a2c48ccae0ff2e917], PUP.Optional.OpenCandy, C:\Users\rspri_000\Downloads\PhotoScape_V3.6.5.exe, In Quarantäne, [31ab44ad0c6f0a2c3ec52f04ec198e72], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter
Zoek.exe v5.0.0.0 Updated 24-09-2014
Tool run by rspri_000 on 25.09.2014 at 20:43:11,63.
Microsoft Windows 8 Pro 6.2.9200 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\rspri_000\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
25.09.2014 20:44:54 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-4243713041-920332011-2703711254-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{47833539-D0C5-4125-9FA8-0819E2EAAC93} deleted successfully
HKEY_USERS\S-1-5-21-4243713041-920332011-2703711254-1001\Software\Mozilla\Firefox\Extensions\cliqz@cliqz.com deleted successfully
==== FireFox Fix ======================
Deleted from C:\Users\RSPRI_~1\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\prefs.js:
user_pref("browser.startup.homepage", "https://www2.elearning.rwth-aachen.de/");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\RSPRI_~1\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\RSPRI_~1\AppData\Roaming\Thunderbird\Profiles\lovhopj1.default\prefs.js:
Added to C:\Users\RSPRI_~1\AppData\Roaming\Thunderbird\Profiles\lovhopj1.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\RSPRI_~1\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
user.js not found
---- Lines FFPDFArchitectConverter@pdfarchitect.com removed from prefs.js ----
user_pref("extensions.FFPDFArchitectConverter@pdfarchitect.com.install-event-fired", true);
---- Lines FFPDFArchitectConverter@pdfarchitect.com modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"FFPDFArchitectConverter@pdfarchitect.com\":{\"descriptor\":\"C:\\
---- Lines cliqz@cliqz.com removed from prefs.js ----
user_pref("extensions.cliqz@cliqz.com.install-event-fired", true);
---- FireFox user.js and prefs.js backups ----
prefs__2045_.backup
ProfilePath: C:\Users\RSPRI_~1\AppData\Roaming\Thunderbird\Profiles\lovhopj1.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__2045_.backup
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"bdwteff@bitdefender.com"="D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff" [26.08.2014 16:18]
==== Firefox Extensions ======================
ProfilePath: C:\Users\RSPRI_~1\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
- PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
- Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
- Bitdefender Wallet - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff
- Avira Browser Safety - %ProfilePath%\extensions\abs@avira.com
- Grooveshark Unlocker - %ProfilePath%\extensions\groovesharkUnlocker@overlord1337.xpi
- ProxTube - Gesperrte YouTube Videos entsperren - %ProfilePath%\extensions\ich@maltegoetz.de.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\RSPRI_~1\AppData\Roaming\Thunderbird\Profiles\lovhopj1.default
- Deutsches Wrterbuch - %ProfilePath%\extensions\de-DE@dictionaries.addons.mozilla.org
==== Firefox Plugins ======================
Profilepath: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
DFC9460CC37E5C414DC4680B10C19E7A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash
3CD19649B2C3023D65E67C056457A2BC - C:\Users\rspri_000\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www2.elearning.rwth-aachen.de/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Reset Google Chrome ======================
Nothing found to reset
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyEnable"=dword:00000000
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== C:\zoek_backup content ======================
C:\zoek_backup (files=3 folders=0 269388 bytes)
==== EOF on 25.09.2014 at 20:46:19,98 ======================
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-09-2014
Ran by rspri_000 (administrator) on RAPHAELS_PC on 25-09-2014 20:56:49
Running from C:\Users\rspri_000\Desktop
Loaded Profile: rspri_000 (Available profiles: rspri_000)
Platform: Windows 8 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
(Panda Security) D:\Tools\Panda USB Vaccine\USBVaccine.exe
(LogMeIn Inc.) C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe
(LogMeIn, Inc.) C:\Tools\LogMeIn Hamachi\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Microsoft Corporation) D:\Tools\ZuneLauncher.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe
(Spotify Ltd) C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Bitdefender) D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwtxapps.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(sw4you) C:\Program Files (x86)\Hardcopy\hardcopy.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) D:\Tools\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Connectify Hotspot] => C:\Program Files (x86)\Connectify\Connectify.exe [5236512 2013-05-14] (Connectify)
HKLM\...\Run: [Connectify Dispatch] => C:\Program Files (x86)\Connectify\DispatchUI.exe [3121440 2013-05-14] (Connectify)
HKLM\...\Run: [Zune Launcher] => D:\Tools\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-28] (Synaptics Incorporated)
HKLM\...\Run: [Bdagent] => D:\Tools\Bitdefender\Bitdefender 2015\bdagent.exe [1580360 2014-08-20] (Bitdefender)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2013-10-10] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Tools\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [PC Remote Server] => C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [884376 2013-04-07] (PC Remote)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Spotify Web Helper] => C:\Users\rspri_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-20] (Spotify Ltd)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [Bitdefender-Geldbörse-Agent] => D:\Tools\Bitdefender\Bitdefender 2015\bdwtxag.exe [815088 2014-08-14] (Bitdefender)
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [1] => wscript.exe //B "C:\ProgramData\1.vbs"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK
ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs ()
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\rspri_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk /m /f \Device\HarddiskVolume4autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\pmbxie.dll (Bitdefender)
Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Tools\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll (Bitdefender)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
FireFox:
========
FF ProfilePath: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\rspri_000\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\avira-safesearch.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\searchplugins\google-maps.xml
FF Extension: Avira Browser Safety - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\abs@avira.com [2014-09-04]
FF Extension: Grooveshark Unlocker - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-05-15]
FF Extension: ProxTube - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11]
FF Extension: Adblock Plus - C:\Users\rspri_000\AppData\Roaming\Mozilla\Firefox\Profiles\us1ffeny.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-06]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: Bitdefender Antispam Toolbar - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext [2014-09-25]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-10-27]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2014-04-23]
FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff
FF Extension: Bitdefender Wallet - D:\Tools\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-09-25]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Tools\Bitdefender\Bitdefender 2015\bdtbext
FF StartMenuInternet: FIREFOX.EXE - D:\Tools\Mozilla Firefox\firefox.exe
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BdDesktopParental; D:\Tools\Bitdefender\Bitdefender 2015\bdparentalservice.exe [77632 2014-08-08] (Bitdefender)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [156672 2013-05-14] (Connectify) [File not signed]
R2 Hamachi2Svc; C:\Tools\LogMeIn Hamachi\hamachi-2.exe [2525008 2014-09-04] (LogMeIn Inc.)
R3 hpqcxs08; C:\HP\Digital Imaging\bin\hpqcxs08.dll [254824 2011-04-29] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\HP\Digital Imaging\bin\hpqddsvc.dll [138600 2011-04-29] (Hewlett-Packard Co.)
R2 HPSLPSVC; C:\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
R2 UPDATESRV; D:\Tools\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-08-08] (Bitdefender)
R2 VSSERV; D:\Tools\Bitdefender\Bitdefender 2015\vsserv.exe [1513952 2014-08-11] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S3 WMZuneComm; D:\Tools\WMZuneComm.exe [306400 2011-08-05] (Microsoft Corporation)
S3 ZuneNetworkSvc; D:\Tools\ZuneNss.exe [8277728 2011-08-05] (Microsoft Corporation)
S3 ZuneWlanCfgSvc; D:\Tools\ZuneWlanCfgSvc.exe [467680 2011-08-05] (Microsoft Corporation)
S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1260120 2014-05-16] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261496 2013-07-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-05-16] (BitDefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-11-19] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-09-25] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-09-25] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-06] (DT Soft Ltd)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [419616 2014-07-02] (BitDefender S.R.L.)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 AAMWRegFilter; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter64.sys [X]
S3 ASW3Scan; \??\D:\Tools\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-25 20:56 - 2014-09-25 20:56 - 00021856 _____ () C:\Users\rspri_000\Desktop\FRST.txt
2014-09-25 20:56 - 2014-09-25 20:56 - 00006273 _____ () C:\Users\rspri_000\Desktop\zoek-results.txt
2014-09-25 20:44 - 2014-09-25 20:46 - 00006273 _____ () C:\zoek-results.log
2014-09-25 20:43 - 2014-09-25 20:46 - 00000000 ____D () C:\zoek_backup
2014-09-25 20:41 - 2014-09-25 20:41 - 01290752 _____ () C:\Users\rspri_000\Desktop\zoek.exe
2014-09-25 20:41 - 2014-09-25 20:41 - 00001408 _____ () C:\Users\rspri_000\Desktop\mbam.txt
2014-09-25 19:49 - 2014-09-25 20:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-25 19:49 - 2014-09-25 19:49 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-09-25 19:49 - 2014-09-25 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-09-25 19:48 - 2014-09-25 19:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-09-25 19:48 - 2014-09-25 19:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\rspri_000\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-25 19:48 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-25 19:48 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-25 19:48 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-25 19:37 - 2014-09-25 19:41 - 00000000 ____D () C:\AdwCleaner
2014-09-25 19:36 - 2014-09-25 19:36 - 01373475 _____ () C:\Users\rspri_000\Desktop\AdwCleaner_3.310.exe
2014-09-25 19:10 - 2014-09-25 19:10 - 00024302 _____ () C:\ComboFix.txt
2014-09-25 18:52 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-25 18:52 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-25 18:52 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-25 18:52 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-25 18:49 - 2014-09-25 19:10 - 00000000 ____D () C:\Qoobox
2014-09-25 18:49 - 2014-09-25 19:04 - 00000000 ____D () C:\Windows\erdnt
2014-09-25 18:45 - 2014-09-25 18:46 - 05580995 ____R (Swearware) C:\Users\rspri_000\Desktop\ComboFix.exe
2014-09-25 18:43 - 2014-09-25 18:43 - 00003052 _____ () C:\Windows\System32\Tasks\PandaUSBVaccine
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Panda Security
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2014-09-25 18:40 - 2014-09-25 18:40 - 00848856 _____ (Panda Security ) C:\Users\rspri_000\Desktop\USBVaccineSetup.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 01110476 _____ () C:\Users\rspri_000\Downloads\7z920.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-09-25 16:43 - 2014-09-25 16:43 - 509766635 _____ () C:\Windows\MEMORY.DMP
2014-09-25 16:43 - 2014-09-25 16:43 - 00286896 _____ () C:\Windows\Minidump\092514-25412-01.dmp
2014-09-25 16:01 - 2014-09-25 16:01 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 16:00 - 2014-09-25 16:03 - 05176232 _____ (F-Secure Corporation) C:\Users\rspri_000\Downloads\F-SecureOnlineScanner.exe
2014-09-25 15:46 - 2014-09-25 20:56 - 00000000 ____D () C:\Users\rspri_000\Desktop\Virenjagd
2014-09-25 15:46 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Desktop\FRST64.exe
2014-09-25 15:43 - 2014-09-25 15:45 - 00051713 _____ () C:\Users\rspri_000\Downloads\Addition.txt
2014-09-25 15:41 - 2014-09-25 20:57 - 00000000 ____D () C:\FRST
2014-09-25 15:41 - 2014-09-25 15:45 - 00056212 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2014-05-16 13:04 - 00647752 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2014-09-25 12:11 - 2014-05-16 13:01 - 01260120 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2014-09-25 12:11 - 2013-11-19 14:44 - 00098768 _____ (BitDefender LLC) C:\Windows\system32\Drivers\bdfndisf6.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00082824 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys
2014-09-25 12:11 - 2013-11-04 15:47 - 00074512 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll
2014-09-25 12:11 - 2013-09-08 20:04 - 00023568 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys
2014-09-25 12:11 - 2013-07-17 19:31 - 00261496 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys
2014-09-25 12:11 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll
2014-09-25 12:00 - 2014-09-25 12:18 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:00 - 2014-09-25 12:12 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:00 - 2014-09-25 12:12 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:00 - 2014-07-04 17:49 - 49563064 ____H () C:\bdr-im01.gz
2014-09-25 12:00 - 2013-08-13 13:38 - 03271472 ____H () C:\bdr-bz01
2014-09-25 11:54 - 2014-09-25 12:18 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-07-02 17:47 - 00419616 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2014-09-25 11:54 - 2013-11-04 15:47 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUISkin.dll
2014-09-25 11:54 - 2013-11-04 15:46 - 00034384 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUH.dll
2014-09-25 11:54 - 2013-08-23 13:48 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2014-09-25 11:49 - 2014-09-25 11:54 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 11:20 - 2014-09-25 11:51 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:12 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-18 22:12 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 09:20 - 2014-08-09 10:30 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-09-18 09:20 - 2014-08-09 10:29 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2014-09-15 20:02 - 2014-09-15 20:03 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:23 - 2014-09-12 10:24 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:13 - 2014-09-12 10:19 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\RHEng
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:11 - 2014-09-12 10:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:52 - 2014-09-25 18:58 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-12 09:52 - 2014-09-25 09:58 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-12 09:52 - 2014-09-12 09:53 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:52 - 2014-09-12 09:53 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 08:18 - 2014-08-21 01:40 - 00732880 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-09-12 08:18 - 2014-08-20 19:05 - 00694784 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-09-12 08:18 - 2014-08-20 19:02 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-09-12 08:18 - 2014-06-24 09:35 - 00010450 _____ () C:\Windows\system32\autoconfig.cab
2014-09-12 08:18 - 2014-06-24 08:41 - 10115584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-09-12 08:18 - 2014-06-24 08:40 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2014-09-12 08:18 - 2014-06-24 08:39 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-09-12 08:18 - 2014-06-24 06:08 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-09-12 08:18 - 2014-06-24 06:06 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2014-09-12 08:17 - 2014-08-20 19:05 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-08-20 19:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-12 08:17 - 2014-06-24 08:39 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-09-12 08:17 - 2014-06-24 06:06 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-09-11 09:24 - 2014-08-16 11:34 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 09:24 - 2014-08-16 11:33 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 11:33 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 09:24 - 2014-08-16 11:32 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 11:32 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 09:24 - 2014-08-16 09:37 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 09:24 - 2014-08-16 09:36 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 09:24 - 2014-08-16 09:35 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 09:24 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 09:24 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-09-11 09:24 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-09-11 09:24 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 09:24 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 09:24 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 09:24 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-09-11 09:24 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 09:24 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 09:24 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 09:24 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 09:23 - 2014-08-16 11:34 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 09:23 - 2014-08-16 11:33 - 19280384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 09:23 - 2014-08-16 11:32 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 14369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 09:23 - 2014-08-16 09:36 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 08:49 - 2014-08-28 13:34 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-09-11 08:49 - 2014-08-28 08:05 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-09-11 08:49 - 2014-08-28 08:01 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-09-11 08:49 - 2014-08-28 08:01 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-09-11 08:49 - 2014-08-01 01:40 - 01287680 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00875688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-07-24 05:33 - 00869544 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2014-09-11 08:48 - 2014-06-05 03:12 - 00678600 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2014-09-11 08:48 - 2014-06-04 01:12 - 00536776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-05 00:44 - 2014-09-12 21:43 - 00135049 _____ () C:\ProgramData\1.vbs
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-08-29 10:31 - 2014-08-23 08:47 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 10:04 - 2014-09-09 22:35 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-25 20:57 - 2014-09-25 20:56 - 00021856 _____ () C:\Users\rspri_000\Desktop\FRST.txt
2014-09-25 20:57 - 2014-09-25 15:41 - 00000000 ____D () C:\FRST
2014-09-25 20:56 - 2014-09-25 20:56 - 00006273 _____ () C:\Users\rspri_000\Desktop\zoek-results.txt
2014-09-25 20:56 - 2014-09-25 15:46 - 00000000 ____D () C:\Users\rspri_000\Desktop\Virenjagd
2014-09-25 20:51 - 2013-07-25 23:34 - 01474998 _____ () C:\Windows\WindowsUpdate.log
2014-09-25 20:46 - 2014-09-25 20:44 - 00006273 _____ () C:\zoek-results.log
2014-09-25 20:46 - 2014-09-25 20:43 - 00000000 ____D () C:\zoek_backup
2014-09-25 20:41 - 2014-09-25 20:41 - 01290752 _____ () C:\Users\rspri_000\Desktop\zoek.exe
2014-09-25 20:41 - 2014-09-25 20:41 - 00001408 _____ () C:\Users\rspri_000\Desktop\mbam.txt
2014-09-25 20:39 - 2014-09-25 19:49 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-25 20:37 - 2013-06-02 16:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\LogMeIn Hamachi
2014-09-25 20:36 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-25 20:35 - 2013-07-27 09:01 - 00036706 _____ () C:\Windows\PFRO.log
2014-09-25 20:34 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\Vss
2014-09-25 20:07 - 2013-04-06 14:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-25 20:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-09-25 19:49 - 2014-09-25 19:49 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-09-25 19:49 - 2014-09-25 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-09-25 19:49 - 2014-09-25 19:48 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-09-25 19:48 - 2014-09-25 19:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\rspri_000\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-25 19:48 - 2013-07-16 23:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-25 19:41 - 2014-09-25 19:37 - 00000000 ____D () C:\AdwCleaner
2014-09-25 19:36 - 2014-09-25 19:36 - 01373475 _____ () C:\Users\rspri_000\Desktop\AdwCleaner_3.310.exe
2014-09-25 19:10 - 2014-09-25 19:10 - 00024302 _____ () C:\ComboFix.txt
2014-09-25 19:10 - 2014-09-25 18:49 - 00000000 ____D () C:\Qoobox
2014-09-25 19:10 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-09-25 19:04 - 2014-09-25 18:49 - 00000000 ____D () C:\Windows\erdnt
2014-09-25 19:03 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-09-25 18:58 - 2014-09-12 09:52 - 00000968 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA.job
2014-09-25 18:46 - 2014-09-25 18:45 - 05580995 ____R (Swearware) C:\Users\rspri_000\Desktop\ComboFix.exe
2014-09-25 18:43 - 2014-09-25 18:43 - 00003052 _____ () C:\Windows\System32\Tasks\PandaUSBVaccine
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Panda Security
2014-09-25 18:43 - 2014-09-25 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2014-09-25 18:40 - 2014-09-25 18:40 - 00848856 _____ (Panda Security ) C:\Users\rspri_000\Desktop\USBVaccineSetup.exe
2014-09-25 17:05 - 2013-04-06 15:49 - 07196672 ___SH () C:\Users\rspri_000\Desktop\Thumbs.db
2014-09-25 17:02 - 2014-09-25 17:02 - 01110476 _____ () C:\Users\rspri_000\Downloads\7z920.exe
2014-09-25 17:02 - 2014-09-25 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-09-25 16:49 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-09-25 16:43 - 2014-09-25 16:43 - 509766635 _____ () C:\Windows\MEMORY.DMP
2014-09-25 16:43 - 2014-09-25 16:43 - 00286896 _____ () C:\Windows\Minidump\092514-25412-01.dmp
2014-09-25 16:03 - 2014-09-25 16:00 - 05176232 _____ (F-Secure Corporation) C:\Users\rspri_000\Downloads\F-SecureOnlineScanner.exe
2014-09-25 16:01 - 2014-09-25 16:01 - 00000140 _____ () C:\Users\rspri_000\defogger_reenable
2014-09-25 16:01 - 2013-04-06 11:04 - 00000000 ____D () C:\Users\rspri_000
2014-09-25 15:51 - 2012-07-26 07:26 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-09-25 15:47 - 2014-03-06 12:50 - 00000000 ___RD () C:\Users\rspri_000\Dropbox
2014-09-25 15:45 - 2014-09-25 15:43 - 00051713 _____ () C:\Users\rspri_000\Downloads\Addition.txt
2014-09-25 15:45 - 2014-09-25 15:41 - 00056212 _____ () C:\Users\rspri_000\Downloads\FRST.txt
2014-09-25 15:40 - 2014-09-25 15:46 - 02108928 _____ (Farbar) C:\Users\rspri_000\Desktop\FRST64.exe
2014-09-25 15:40 - 2014-09-25 15:40 - 02108928 _____ (Farbar) C:\Users\rspri_000\Downloads\FRST64.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00050477 _____ () C:\Users\rspri_000\Downloads\Defogger.exe
2014-09-25 15:38 - 2014-09-25 15:38 - 00000550 _____ () C:\Users\rspri_000\Downloads\defogger_disable.log
2014-09-25 15:22 - 2014-03-06 12:45 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Dropbox
2014-09-25 14:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-09-25 14:03 - 2013-06-09 14:08 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-25 13:59 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\Offline Web Pages
2014-09-25 13:55 - 2013-04-06 12:30 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4243713041-920332011-2703711254-1001
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Windows\system32\user_gensett.xml
2014-09-25 13:24 - 2014-09-25 13:24 - 00000385 _____ () C:\Users\rspri_000\AppData\Roaminguser_gensett.xml
2014-09-25 13:21 - 2013-04-06 14:29 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-09-25 13:04 - 2014-03-18 13:47 - 00000000 ____D () C:\$Windows.~BT
2014-09-25 12:55 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-25 12:49 - 2014-09-25 12:49 - 00000000 ____D () C:\OETemp
2014-09-25 12:42 - 2014-09-25 12:42 - 00079192 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2014-09-25 12:42 - 2014-09-25 12:42 - 00074512 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2014-09-25 12:18 - 2014-09-25 12:00 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Bitdefender
2014-09-25 12:18 - 2014-09-25 11:54 - 00000000 ____D () C:\ProgramData\Bitdefender
2014-09-25 12:12 - 2014-09-25 12:12 - 00000684 ____H () C:\bdr-cf01
2014-09-25 12:12 - 2014-09-25 12:00 - 00253404 ____H () C:\bdr-ld01
2014-09-25 12:12 - 2014-09-25 12:00 - 00009216 ____H () C:\bdr-ld01.mbr
2014-09-25 12:11 - 2014-09-25 12:11 - 00001047 _____ () C:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2014-09-25 12:11 - 2014-09-25 12:11 - 00000000 ____D () C:\ProgramData\BDLogging
2014-09-25 12:11 - 2013-08-23 08:02 - 00018002 _____ () C:\Windows\setupact.log
2014-09-25 11:54 - 2014-09-25 11:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\QuickScan
2014-09-25 11:54 - 2014-09-25 11:49 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
2014-09-25 11:51 - 2014-09-25 11:20 - 00527072 _____ () C:\Users\rspri_000\Desktop\Flussdiagramm Methodik.pptx
2014-09-25 11:49 - 2014-09-25 11:49 - 02849160 _____ () C:\Users\rspri_000\Downloads\bitdefender_isecurity.exe
2014-09-25 09:58 - 2014-09-12 09:52 - 00000946 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core.job
2014-09-25 09:42 - 2012-07-26 12:27 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-09-25 09:42 - 2012-07-26 12:27 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-09-25 09:42 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-25 08:55 - 2014-05-14 08:54 - 00093004 _____ () C:\Users\rspri_000\Desktop\Transferpräse Laptop-Citrix.pptx
2014-09-24 14:59 - 2014-08-19 17:38 - 00000000 ____D () C:\Users\rspri_000\Desktop\Urlaub
2014-09-24 14:16 - 2013-08-14 19:06 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Spotify
2014-09-24 12:45 - 2013-08-14 19:05 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Spotify
2014-09-24 09:10 - 2014-07-21 19:55 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung LH
2014-09-24 09:10 - 2014-04-14 11:39 - 00000000 ____D () C:\Users\rspri_000\Desktop\Dubbel 22.Auflage
2014-09-24 09:10 - 2013-04-08 11:41 - 00000000 ____D () C:\Users\rspri_000\Desktop\Bewerbung Praktikum
2014-09-18 23:37 - 2013-06-04 22:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TS3Client
2014-09-18 22:13 - 2014-09-18 22:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-18 22:11 - 2014-09-18 22:11 - 01101648 _____ () C:\Users\rspri_000\Downloads\TeamSpeak 3 64 Bit - CHIP-Installer.exe
2014-09-18 16:41 - 2013-04-06 13:41 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-18 15:22 - 2014-03-06 12:46 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-17 13:36 - 2013-12-15 23:39 - 00000000 ____D () C:\ProgramData\FILEminimizer
2014-09-16 13:50 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-09-15 21:50 - 2013-12-08 20:08 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\vlc
2014-09-15 20:03 - 2014-09-15 20:02 - 200665541 _____ () C:\Users\rspri_000\Desktop\Wakeboarden_Langenfeld_12.09.2014.mp4
2014-09-15 10:07 - 2013-04-10 10:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-09-15 10:07 - 2013-04-10 10:06 - 00000000 ____D () C:\HP
2014-09-15 10:07 - 2013-04-09 20:54 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\HpUpdate
2014-09-12 21:43 - 2014-09-05 00:44 - 00135049 _____ () C:\ProgramData\1.vbs
2014-09-12 19:48 - 2014-09-12 19:48 - 00003064 _____ () C:\Windows\System32\Tasks\{C9634C7F-2737-4B78-9D1B-DEF6CB4A8FF1}
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-09-12 19:34 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-09-12 10:45 - 2014-09-12 10:11 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\DVDVideoSoft
2014-09-12 10:34 - 2014-09-12 10:34 - 06047574 _____ () C:\Users\rspri_000\Desktop\test.flv
2014-09-12 10:24 - 2014-09-12 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Screen To Video
2014-09-12 10:24 - 2014-09-12 10:23 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\FreeScreenToVideo
2014-09-12 10:22 - 2014-09-12 10:22 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\StormFall
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\TuneUp Software
2014-09-12 10:21 - 2014-09-12 10:21 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\StormFall
2014-09-12 10:21 - 2013-04-06 14:12 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\TuneUp Software
2014-09-12 10:19 - 2014-09-12 10:19 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-09-12 10:19 - 2014-09-12 10:13 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\RHEng
2014-09-12 10:19 - 2013-04-06 14:12 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-09-12 10:17 - 2013-04-21 20:47 - 00000000 ____D () C:\Users\rspri_000\AppData\Roaming\Skype
2014-09-12 10:13 - 2014-09-12 10:13 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-09-12 10:10 - 2014-09-12 10:10 - 20012976 _____ (DVDVideoSoft Ltd. ) C:\Users\rspri_000\Downloads\FreeScreenVideoRecorder2.5.37.906.exe
2014-09-12 09:53 - 2014-09-12 09:52 - 00003824 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001UA
2014-09-12 09:53 - 2014-09-12 09:52 - 00003474 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4243713041-920332011-2703711254-1001Core
2014-09-12 09:52 - 2014-09-12 09:52 - 00501248 _____ (Facebook Inc.) C:\Users\rspri_000\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2014-09-12 09:52 - 2014-09-12 09:52 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Facebook
2014-09-12 09:36 - 2013-04-21 20:47 - 00000000 ____D () C:\ProgramData\Skype
2014-09-11 20:08 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-09-11 09:30 - 2013-04-18 11:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 09:23 - 2013-07-23 21:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 09:14 - 2013-04-07 18:42 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-09 22:35 - 2014-08-26 10:04 - 00000000 ____D () C:\Users\rspri_000\AppData\Local\Adobe
2014-09-09 22:34 - 2013-04-06 14:18 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-08 22:35 - 2014-09-08 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-08 22:35 - 2013-04-09 20:10 - 00000000 ____D () C:\Tools
2014-09-07 12:28 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-06 14:48 - 2013-04-06 16:19 - 00000000 ____D () C:\Users\rspri_000\Documents\BAföG
2014-09-04 14:48 - 2014-04-23 09:23 - 00000000 ____D () C:\ProgramData\Swiss Academic Software
2014-09-04 11:44 - 2014-09-04 11:44 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys
2014-09-04 08:57 - 2014-09-04 08:57 - 00816064 _____ ( ) C:\Users\rspri_000\Downloads\Stundenplan_2.0_CB-DL-Manager.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00705480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-02 21:32 - 2014-08-16 14:25 - 00104904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-01 20:56 - 2014-07-11 08:06 - 00428056 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 13:34 - 2014-09-11 08:49 - 00059400 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-28 08:05 - 2014-09-11 08:49 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-28 08:05 - 2014-09-11 08:49 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-28 08:02 - 2014-09-11 08:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-28 08:01 - 2014-09-11 08:49 - 03285504 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 01623552 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-28 08:01 - 2014-09-11 08:49 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2014-08-26 16:18 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\ELAMBKUP
Files to move or delete:
====================
C:\ProgramData\1.vbs
Some content of TEMP:
====================
C:\Users\rspri_000\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-17 09:14
==================== End Of Log ============================
|
| | #6 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar Servus, Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start
CloseProcesses:
HKU\S-1-5-21-4243713041-920332011-2703711254-1001\...\Run: [1] => wscript.exe //B "C:\ProgramData\1.vbs"
C:\ProgramData\1.vbs
Startup: C:\Users\rspri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.vbs ()
C:\Users\rspri_000\AppData\Roaming\RHEng
EmptyTemp:
end
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2
Stecke den USB-Stick an den Rechner an. Hast du immer noch das Problem, dass du keine Dateien sehen kannst? Bitte poste mit deiner nächsten Antwort
|
![]() |
| Themen zu Windows 8: F-Secure-Fund: trojan.lnk.gen; Dateien auf USB-Stick sind vorhanden (Speicherplatz) aber nicht sichtbar |
| administrator, adobe flash player, bitdefender 2015, converter, dateien verschwinden, dvdvideosoft ltd., fehlercode 0x80000003, fehlercode 0xc0000005, fehlercode 22, fehlercode 28, fehlercode windows, flash player, homepage, hotspot, install.exe, nicht sichtbar, pup.optional.opencandy, pup.optional.pricemeter.a, services.exe, speicherplatz, spotify web helper, this device is disabled. (code 22), trojan.lnk.gen, usb-stick, win32/installcore.qh, win32/installmonetizer.aq, win32/somoto.a, win32/toolbar.conduit, windowsapps, winlogon.exe |