Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 31.08.2015, 23:38   #1
daniel1989
 
Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild - Standard

Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild



Hallo an das Forum! Ich hoffe, ihr könnt mir helfen!
Auf meinem PC mit Windows 7 ist beim "arbeiten" auf einmal alles total langsam geworden bis ich einen blauen Bildschirm zu sehen bekommen habe mit irgendeiner Fehlermeldung, PC aus wieder an - er war weiterhin total langsam ich bekam Pop up Fehlermeldungen ohne Ende am meisten allerdings das der Microsoft Explorer nicht geht und ich warten oder ihn beenden muesse...der Pc ist nur noch im abgesicherten modus wirklich bedienbar Wenn ich im normalen Modus bin warte ich gut und gerne 10 minuten bis mir ein ordner geoeffnet wird... manchmal geht aber wieder alles fix wie vorher !? und dann kommt auch gerne immer wieder ein schwarzer Bildschirm fuer ein paar minuten bis er verschwindet manchmal bleibt er aber auch ewig...Malewarebytes, adw cleaner, brachten mir nichts mit meinem kaspersky internet security virenprogramm konnte ich keinen fullscan machen habe somit keine log datei davon.. ich habe den pc gebraucht gekauft vor ca. einem monat viel maleware von geloescht und dannach lief er wie eine 1 ...naja .. ich komme nicht mehr weiter und brauche dringend hilfe Ich hoffe ich habe mich an alle Regeln und Normen gehalten Und bedanke mich schon mal vortraeglich bei meinem zukuenftigem Helfer/in!!! hier meine logs die ich im abgesicherten modus machen musste :

Defogger_Disable.log:


Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 03:07 on 31/08/2015 (xxx)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         
FRST.txt:

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:30-08-2015
durchgeführt von xxx (Administrator) auf XXX (31-08-2015 03:54:20)
Gestartet von C:\Users\xxx\Desktop
Geladene Profile: xxx (Verfügbare Profile: xxx)
Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 10 (Standard-Browser: FF)
Start-Modus: Safe Mode (with Networking)
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2867984 2011-12-22] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (Der Dateneintrag hat 36 mehr Zeichen).
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2012-01-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [bdruninstaller] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setuplauncher.exe" /run:"setupdownloader.exe" /args:"/token:64b /after_restart"
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\...\Run: [uTorrent] => C:\Users\xxx\AppData\Roaming\uTorrent\uTorrent.exe [1696096 2015-08-29] (BitTorrent Inc.)
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
GroupPolicyScripts: Gruppenrichtline erkannt <======= ACHTUNG
CHR HKLM\SOFTWARE\Policies\Google: Richtlinienbeschränkung <======= ACHTUNG

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)

ProxyEnable: [.DEFAULT] => Proxy ist aktiviert.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49737;https=127.0.0.1:49737
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{6EF27CF9-2594-4B68-8B80-9276E723E19E}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{8541C6AF-41FF-4C87-A65C-38721CCEE50C}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{FD42EE94-C8AB-4635-97A2-B585F803CAB0}: [DhcpNameServer] 193.189.244.206 193.189.244.225

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Richtlinienbeschränkung <======= ACHTUNG
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Richtlinienbeschränkung <======= ACHTUNG
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2015-08-08] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2015-08-08] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-29] (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-29] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-08-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-04-28] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-08-10] ()
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [Keine Datei]
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [Keine Datei]
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-29] (Oracle Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\content_blocker@kaspersky.com [2015-08-08] ()
FF Plugin-x32: @kaspersky.com/online_banking -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\online_banking@kaspersky.com [2015-08-30] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2015-08-08] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-12-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-12-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-12-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-12-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-12-18] (Apple Inc.)
FF Extension: YouTube Unblocker - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\youtubeunblocker@unblocker.yt [2015-08-06]
FF Extension: Flashblock - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2015-08-05]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\adblockpopups@jessehakanen.net.xpi [2015-08-19]
FF Extension: Ghostery - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\firefox@ghostery.com.xpi [2015-08-08]
FF Extension: Stop YouTube Autoplay - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\jid0-Pm0nbsggUvL00CBoW6YwCaqv8bk@jetpack.xpi [2015-08-17]
FF Extension: NoScript - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-08-08]
FF Extension: Adblock Plus - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-06-24]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\content_blocker@kaspersky.com [2015-08-08]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2015-08-08]
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\url_advisor@kaspersky.com [2015-08-08]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\anti_banner@kaspersky.com [2015-08-08]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\online_banking@kaspersky.com [2015-08-08]

Chrome: 
=======
CHR dev: Chrome dev build erkannt! <======= ACHTUNG
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S2 AVP15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\avp.exe [233552 2014-04-20] (Kaspersky Lab ZAO)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation)
S2 CPUCooLServer; C:\Program Files (x86)\CPUCooL\CooLSrv.exe [743936 2011-12-01] () [Datei ist nicht signiert]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation) [Datei ist nicht signiert]
S2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-08-30] (SurfRight B.V.)
S2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [1823952 2015-08-05] (AnchorFree Inc.)
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [96600 2015-08-05] ()
S2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [846544 2015-08-05] ()
S2 i2p; C:\Program Files (x86)\i2p\I2Psvc.exe [389632 2015-08-11] (Tanuki Software, Ltd.) [Datei ist nicht signiert]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert]
S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [38200 2015-08-04] (The OpenVPN Project)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-06-20] ()
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [Datei ist nicht signiert]
S2 Themes; C:\Windows\system32\themeservice.dll [44544 2015-08-13] (Microsoft Corporation) [Datei ist nicht signiert]
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44648 2015-06-04] (AnchorFree Inc.)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [457824 2014-02-20] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [141320 2015-08-08] (Kaspersky Lab ZAO)
S1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [243808 2014-04-10] (Kaspersky Lab ZAO)
S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [793800 2015-08-08] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO)
S3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO)
S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO)
S1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2014-03-25] (Kaspersky Lab ZAO)
S1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179296 2014-03-26] (Kaspersky Lab ZAO)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-31] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [23040 2013-07-25] (Apple Inc.) [Datei ist nicht signiert]
S2 npf; C:\Windows\System32\drivers\npf.sys [36600 2015-06-01] (Riverbed Technology, Inc.)
S1 ntiopnp; C:\Windows\System32\Drivers\ntiopnp.sys [19544 2010-11-11] ()
R3 SmbDrv; C:\Windows\System32\DRIVERS\Smb_driver.sys [21264 2011-12-22] (Synaptics Incorporated)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42088 2015-06-04] (Anchorfree Inc.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-06-10] (Apple, Inc.) [Datei ist nicht signiert]
S1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [117768 2015-07-09] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [146072 2015-07-09] (Oracle Corporation)
S2 uxstyle; \??\C:\Windows\system32\Drivers\uxstyle.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-31 03:22 - 2015-08-31 03:22 - 00021289 _____ C:\Users\xxx\Desktop\Addition.txt
2015-08-31 03:21 - 2015-08-31 03:54 - 00007819 _____ C:\Users\xxx\Desktop\FRST.txt
2015-08-31 03:21 - 2015-08-31 03:54 - 00000000 ____D C:\FRST
2015-08-31 03:07 - 2015-08-31 03:07 - 00000468 _____ C:\Users\xxx\Desktop\defogger_disable.log
2015-08-31 03:07 - 2015-08-31 03:07 - 00000000 _____ C:\Users\xxx\defogger_reenable
2015-08-31 02:44 - 2015-08-31 02:44 - 00003818 _____ C:\Users\xxx\Desktop\eset.txt
2015-08-31 02:25 - 2015-08-31 02:25 - 00380416 _____ C:\Users\xxx\Desktop\9ie9fcez.exe
2015-08-31 02:22 - 2015-08-31 02:22 - 02188288 _____ (Farbar) C:\Users\xxx\Desktop\FRST64.exe
2015-08-31 02:15 - 2015-08-31 02:15 - 00050477 _____ C:\Users\xxx\Desktop\Defogger.exe
2015-08-31 00:17 - 2015-08-31 00:17 - 00003360 ____N C:\bootsqm.dat
2015-08-30 23:20 - 2015-08-30 23:20 - 00008754 _____ C:\HitmanPro_20150830_2320.log
2015-08-30 21:55 - 2015-08-30 23:19 - 00000640 _____ C:\Windows\system32\.crusader
2015-08-30 21:44 - 2015-08-30 21:44 - 00001905 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2015-08-30 21:44 - 2015-08-30 21:44 - 00000000 ____D C:\Program Files\HitmanPro
2015-08-30 21:41 - 2015-08-30 21:43 - 11352032 _____ (SurfRight B.V.) C:\Users\xxx\Downloads\HitmanPro_x64.exe
2015-08-30 21:40 - 2015-08-30 21:56 - 00000000 ____D C:\ProgramData\HitmanPro
2015-08-30 19:22 - 2015-08-30 19:22 - 00299544 _____ C:\Windows\Minidump\083015-20280-01.dmp
2015-08-29 01:34 - 2015-08-29 01:34 - 00332344 _____ C:\Windows\Minidump\082915-32900-01.dmp
2015-08-29 01:33 - 2015-08-30 19:22 - 487727759 _____ C:\Windows\MEMORY.DMP
2015-08-28 23:21 - 2015-08-29 00:38 - 00000000 ____D C:\Users\xxx\Downloads\MW3 ChromatiX
2015-08-27 23:12 - 2015-08-27 23:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\2B0C5369.sys
2015-08-26 02:33 - 2015-08-31 01:09 - 00000000 ____D C:\Users\xxx\Desktop\xbab[mp3freex.com]
2015-08-25 23:16 - 2015-08-25 23:16 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\61973A00.sys
2015-08-20 01:32 - 2015-08-20 01:33 - 00000000 ____D C:\Users\xxx\Desktop\Games
2015-08-19 22:03 - 2015-08-19 22:03 - 00000218 _____ C:\Users\xxx\AppData\Local\recently-used.xbel
2015-08-19 18:04 - 2015-08-19 18:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aspyr
2015-08-19 18:02 - 2015-08-19 18:02 - 00000000 ____D C:\Program Files (x86)\Aspyr
2015-08-19 11:52 - 2015-08-19 17:24 - 00000328 _____ C:\Windows\Tasks\LoudProof.job
2015-08-19 11:52 - 2015-08-19 17:20 - 00000000 ____D C:\ProgramData\{976ab3cf-d8d2-3e4a-976a-ab3cfd8dcf3f}
2015-08-19 11:52 - 2015-08-19 11:52 - 00003236 _____ C:\Windows\System32\Tasks\LoudProof
2015-08-19 11:22 - 2015-08-26 23:07 - 00000000 ____D C:\Users\xxx\AppData\Local\NFS Underground 2
2015-08-19 11:17 - 2015-08-19 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2015-08-19 11:15 - 2015-08-19 11:15 - 00000000 ____D C:\Program Files (x86)\EA GAMES
2015-08-19 11:07 - 2015-08-31 01:05 - 00000000 ____D C:\Users\xxx\Downloads\nfsu2
2015-08-19 02:14 - 2015-08-19 02:14 - 00000000 ____D C:\Program Files (x86)\GameSpy Arcade
2015-08-19 01:53 - 2015-08-19 11:22 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-19 01:49 - 2015-08-19 01:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
2015-08-19 01:49 - 2015-08-19 01:49 - 00000000 ____D C:\Program Files (x86)\Activision
2015-08-19 01:44 - 2015-08-19 01:44 - 00000000 ____D C:\ProgramData\Steam
2015-08-19 01:39 - 2015-08-19 17:50 - 00000000 ____D C:\Program Files (x86)\Age of Empires II HD The Forgotten
2015-08-18 19:46 - 2015-08-18 19:47 - 65444688 _____ (Microsoft Corporation) C:\Users\xxx\Downloads\NDP46-KB3045557-x86-x64-AllOS-ENU.exe
2015-08-18 19:43 - 2015-08-18 20:01 - 00037993 _____ C:\Users\xxx\Documents\Unbenannt1.cpp
2015-08-18 16:31 - 2015-08-18 16:31 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Dev-Cpp
2015-08-18 13:17 - 2015-08-18 13:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodshed Dev-C++
2015-08-18 13:16 - 2015-08-18 13:16 - 00000000 ____D C:\Users\xxx\Desktop\Dev-Cpp
2015-08-18 01:00 - 2015-08-18 09:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-13 10:08 - 2015-08-13 22:35 - 00003234 _____ C:\Windows\System32\Tasks\SidebarExecute
2015-08-13 06:11 - 2015-08-13 06:11 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\0CCB001E.sys
2015-08-13 05:59 - 2015-08-13 05:59 - 00000000 ____D C:\Users\xxx\Downloads\7tsp_Vs_se7en_Pack
2015-08-13 05:46 - 2015-08-13 06:06 - 00000000 ____D C:\Windows\system32\Taskman
2015-08-13 04:36 - 2015-08-13 04:36 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Windows SideBar
2015-08-13 04:31 - 2015-08-13 05:07 - 00000000 ____D C:\Gadgets
2015-08-13 03:55 - 2015-08-19 10:50 - 00003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8E1BA6FC-3CD5-40FE-A806-F7D9A8078D70}
2015-08-13 00:04 - 2015-08-13 03:34 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\22116713.sys
2015-08-12 17:02 - 2015-08-12 17:02 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\7ED024B6.sys
2015-08-12 17:00 - 2015-08-12 17:00 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1B282295.sys
2015-08-12 16:13 - 2015-08-12 16:13 - 00000000 ____D C:\Windows\SysWOW64\Hotspot Shield
2015-08-12 16:10 - 2015-08-12 16:10 - 00262144 _____ C:\Windows\system32\config\elam
2015-08-11 10:28 - 2015-08-31 03:42 - 00002914 _____ C:\Windows\setupact.log
2015-08-11 10:28 - 2015-08-11 10:28 - 00000000 _____ C:\Windows\setuperr.log
2015-08-11 10:27 - 2015-08-29 01:33 - 00064998 _____ C:\Windows\PFRO.log
2015-08-11 03:22 - 2015-08-11 03:22 - 00032178 _____ C:\Users\xxx\Documents\cc_20150811_032249.reg
2015-08-11 03:05 - 2015-08-11 03:05 - 00000000 ____D C:\Users\xxx\AppData\Local\CrashRpt
2015-08-11 02:55 - 2015-08-11 03:04 - 00000000 ____D C:\ProgramData\Hotspot Shield
2015-08-11 02:55 - 2015-08-11 02:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
2015-08-11 02:54 - 2015-08-20 01:37 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
2015-08-11 02:54 - 2015-08-11 02:54 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Hotspot Shield
2015-08-11 02:54 - 2015-06-04 01:02 - 00044648 _____ (AnchorFree Inc.) C:\Windows\system32\Drivers\hssdrv6.sys
2015-08-11 02:34 - 2015-08-11 02:34 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\I2P
2015-08-11 01:30 - 2015-08-31 03:42 - 00000000 ____D C:\ProgramData\i2p
2015-08-11 01:20 - 2015-08-19 17:11 - 00000000 ____D C:\Users\xxx\AppData\Roaming\I2P
2015-08-11 01:18 - 2015-08-30 19:26 - 00000000 ____D C:\Program Files (x86)\i2p
2015-08-11 01:18 - 2015-08-11 01:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I2P
2015-08-10 23:03 - 2015-08-11 03:18 - 00000000 ____D C:\Program Files (x86)\Tor Browser
2015-08-10 22:40 - 2015-08-10 22:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
2015-08-10 22:40 - 2015-08-10 22:41 - 00000000 ____D C:\Program Files\OpenVPN
2015-08-10 15:21 - 2015-08-10 15:21 - 04072200 _____ C:\Users\xxx\Downloads\TeknoMW3_ServerTool_1.5.8_ServerMonitor_1.1.exe
2015-08-10 12:21 - 2015-08-10 12:21 - 00000000 ____D C:\Users\xxx\AppData\Local\IsolatedStorage
2015-08-09 02:01 - 2015-08-11 04:54 - 00000000 ____D C:\Users\xxx\.zenmap
2015-08-09 02:00 - 2015-08-09 02:00 - 00000000 ____D C:\Program Files\WinPcap
2015-08-09 01:59 - 2015-08-09 02:01 - 00000000 ____D C:\Program Files (x86)\Nmap
2015-08-09 01:58 - 2015-08-19 01:37 - 00000000 ____D C:\Users\xxx\AppData\Roaming\inkscape
2015-08-08 23:13 - 2015-08-08 23:13 - 00001051 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape.lnk
2015-08-08 23:09 - 2015-08-08 23:13 - 00000000 ____D C:\Program Files (x86)\Inkscape
2015-08-08 17:57 - 2015-08-08 17:57 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6A4515E8.sys
2015-08-08 16:42 - 2015-08-08 16:42 - 00000000 ____D C:\Program Files (x86)\Stardock
2015-08-08 16:15 - 2015-08-08 16:15 - 00000000 ____D C:\ProgramData\Stardock
2015-08-08 16:02 - 2015-08-08 16:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2015-08-08 16:02 - 2015-08-08 16:02 - 00000000 ____D C:\Users\xxx\AppData\Local\Stardock
2015-08-08 16:02 - 2015-08-08 16:02 - 00000000 ____D C:\Users\Public\Documents\Stardock
2015-08-08 15:43 - 2015-08-08 15:43 - 00000000 ___HD C:\Program Files (x86)\InstallJammer Registry
2015-08-08 15:33 - 2015-08-12 16:10 - 00000000 ____D C:\ProgramData\{430548d0-bab8-9b04-4305-548d0bab2342}
2015-08-08 15:33 - 2015-08-08 16:53 - 00000338 _____ C:\Windows\Tasks\AlcoProof.job
2015-08-08 15:33 - 2015-08-08 15:33 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Purposeful Advice
2015-08-08 15:21 - 2015-08-08 15:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2015-08-08 15:20 - 2015-08-31 03:43 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-08-08 15:20 - 2015-08-08 15:20 - 00000000 ____D C:\Windows\ELAMBKUP
2015-08-08 15:20 - 2015-08-08 15:20 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2015-08-08 15:20 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2015-08-08 15:19 - 2015-08-08 15:55 - 00793800 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2015-08-08 15:19 - 2015-08-08 15:55 - 00141320 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2015-08-08 15:19 - 2014-04-10 17:25 - 00243808 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys
2015-08-08 15:14 - 2015-08-08 15:14 - 00270632 _____ C:\ProgramData\1439035440.bdinstall.bin
2015-08-07 12:49 - 2015-08-07 13:35 - 00000000 ____D C:\Users\xxx\Documents\VirtualDJ
2015-08-07 12:49 - 2015-08-07 12:49 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2015-08-07 12:49 - 2015-08-07 12:49 - 00000000 ____D C:\Program Files (x86)\VirtualDJ
2015-08-04 17:16 - 2015-08-04 17:16 - 00000000 ____D C:\Users\xxx\AppData\Roaming\IrfanView

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-08-31 03:49 - 2015-06-20 11:53 - 00000000 ____D C:\Users\xxx\AppData\Roaming\vlc
2015-08-31 03:49 - 2009-07-14 06:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-31 03:49 - 2009-07-14 06:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-31 03:48 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-31 03:45 - 2013-02-27 00:40 - 01478942 _____ C:\Windows\WindowsUpdate.log
2015-08-31 03:42 - 2015-07-15 02:52 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-31 03:42 - 2015-07-13 02:40 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Skype
2015-08-31 03:42 - 2015-06-20 01:20 - 00000000 ____D C:\Users\xxx\AppData\Roaming\uTorrent
2015-08-31 03:42 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-31 03:10 - 2015-04-19 14:20 - 00000554 _____ C:\Users\xxx\AppData\Roaming\a55CxS51lp6oDbN
2015-08-31 03:07 - 2015-06-19 01:57 - 00000000 ____D C:\Users\xxx
2015-08-31 02:53 - 2015-06-21 18:51 - 00000000 ____D C:\AdwCleaner
2015-08-31 01:14 - 2015-06-19 21:46 - 00000000 ___RD C:\Users\xxx\Desktop\Stuff
2015-08-31 01:07 - 2015-06-20 16:40 - 00000000 ____D C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^
2015-08-30 19:22 - 2015-07-18 20:02 - 00000000 ____D C:\Windows\Minidump
2015-08-30 13:54 - 2015-07-14 20:56 - 00000000 ____D C:\Users\xxx\.VirtualBox
2015-08-29 06:08 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2015-08-29 03:56 - 2015-07-15 03:42 - 00000000 ____D C:\Program Files (x86)\7tsp
2015-08-29 03:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Cursors
2015-08-29 03:12 - 2013-04-25 20:08 - 00000000 ____D C:\ProgramData\Skype
2015-08-26 20:40 - 2015-06-20 00:55 - 00000000 ____D C:\Users\xxx\AppData\Local\TeknoGods
2015-08-26 02:56 - 2011-04-12 09:43 - 00699666 _____ C:\Windows\system32\perfh007.dat
2015-08-26 02:56 - 2011-04-12 09:43 - 00149774 _____ C:\Windows\system32\perfc007.dat
2015-08-26 02:56 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-20 12:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2015-08-19 17:21 - 2015-06-19 01:58 - 00001421 _____ C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-18 19:57 - 2014-01-04 12:35 - 01594892 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-08-18 19:47 - 2015-07-13 18:34 - 00000000 ____D C:\Users\xxx\Documents\Visual Studio 2013
2015-08-18 09:13 - 2013-03-15 16:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-13 22:33 - 2009-07-14 06:45 - 04875472 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-13 05:37 - 2010-11-21 05:23 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2015-08-13 05:37 - 2009-07-14 01:55 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2015-08-13 05:37 - 2009-07-14 01:54 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\themeservice.dll
2015-08-13 04:47 - 2015-06-21 05:23 - 00000020 ____H C:\ProgramData\PKP_DLet.DAT
2015-08-10 23:21 - 2015-06-19 01:57 - 00000000 ____D C:\Users\xxx\AppData\Local\VirtualStore
2015-08-10 01:41 - 2015-06-20 07:22 - 00000000 ____D C:\Users\xxx\AppData\Local\Adobe
2015-08-10 01:41 - 2013-04-25 19:58 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-10 01:41 - 2013-04-25 19:58 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-08 14:06 - 2015-07-14 00:48 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2015-08-07 12:57 - 2015-06-20 23:34 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CPUCooL

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-04-19 14:20 - 2015-08-31 03:10 - 0000554 _____ () C:\Users\xxx\AppData\Roaming\a55CxS51lp6oDbN
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\Users\xxx\AppData\Roaming\Sci-Fi
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\Users\xxx\AppData\Roaming\Screen Saver
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\Users\xxx\AppData\Roaming\Screen Savers
2015-08-19 22:03 - 2015-08-19 22:03 - 0000218 _____ () C:\Users\xxx\AppData\Local\recently-used.xbel
2015-06-21 13:09 - 2015-06-21 13:09 - 0007605 _____ () C:\Users\xxx\AppData\Local\Resmon.ResmonCfg
2015-08-08 15:14 - 2015-08-08 15:14 - 0270632 _____ () C:\ProgramData\1439035440.bdinstall.bin
2015-06-21 05:23 - 2015-06-21 05:23 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2015-06-21 05:23 - 2015-08-13 04:47 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2015-06-21 05:23 - 2015-06-21 05:23 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\ProgramData\Services
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\ProgramData\SingleFiles
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\ProgramData\Smooth Strings

Einige Dateien in TEMP:
====================
C:\Users\xxx\AppData\Local\Temp\11d590cff4f84ae384ade7c1d0afc4f3.dll
C:\Users\xxx\AppData\Local\Temp\12cd0626caa34310af61e370f35eb6db.dll
C:\Users\xxx\AppData\Local\Temp\14dafad713ac494b816443bdc836f37f.dll
C:\Users\xxx\AppData\Local\Temp\14e508d49cd442158cd9d52b98b3d506.dll
C:\Users\xxx\AppData\Local\Temp\2dfa3d5861f74101bc780dda0bcfd1fa.dll
C:\Users\xxx\AppData\Local\Temp\31a6cee590ac4043b656da8e0595e1d8.dll
C:\Users\xxx\AppData\Local\Temp\35eceddb983b4a2cac8b76ed7429d294.dll
C:\Users\xxx\AppData\Local\Temp\3a4be230186f43f19f0b4016d189c85f.dll
C:\Users\xxx\AppData\Local\Temp\3eeb51b3723447498a49b9a74a3e9adf.dll
C:\Users\xxx\AppData\Local\Temp\44e5563ff2c34e7db3a8f2ed82480111.dll
C:\Users\xxx\AppData\Local\Temp\47167afdb6d946aebcb91474d3a89139.dll
C:\Users\xxx\AppData\Local\Temp\475f88b715d2492ca77f54e52b96587e.dll
C:\Users\xxx\AppData\Local\Temp\49c0473ed2bd414e9ec857fabd644ed7.dll
C:\Users\xxx\AppData\Local\Temp\51b34e2700484fa3b83272cfdfeea9ce.dll
C:\Users\xxx\AppData\Local\Temp\529a1aea68314b199102a761ea15d255.dll
C:\Users\xxx\AppData\Local\Temp\5f703dc7af4a458485133e098842329d.dll
C:\Users\xxx\AppData\Local\Temp\650fbc9470004a02bafee4cf79051683.dll
C:\Users\xxx\AppData\Local\Temp\68fc1c1ba1cd4507a5d442a5b9181fa3.dll
C:\Users\xxx\AppData\Local\Temp\6d45f5c516be423da169b3061c2a63d4.dll
C:\Users\xxx\AppData\Local\Temp\6db1824c4e214a5eb1f1104b44b947a1.dll
C:\Users\xxx\AppData\Local\Temp\8fc6335c749b4299a2fd33d13923d75d.dll
C:\Users\xxx\AppData\Local\Temp\920fba4d59a14eb4bcbbe40b25a308c4.dll
C:\Users\xxx\AppData\Local\Temp\940903881ace4980b949ad919dd362d5.dll
C:\Users\xxx\AppData\Local\Temp\96c23eec399e42c4a30cbf969a463455.dll
C:\Users\xxx\AppData\Local\Temp\96c68ba6661b4700810c8a9059e93cf8.dll
C:\Users\xxx\AppData\Local\Temp\99653f456d51477a8f82d52c2ed1d6bd.dll
C:\Users\xxx\AppData\Local\Temp\9b9cea71eb83436288cb42dafde6ab74.dll
C:\Users\xxx\AppData\Local\Temp\9cc4e736dd9b4c67b44a451609c98fad.dll
C:\Users\xxx\AppData\Local\Temp\a381e3fdfafc4e3db26f3b3a8ad06ba0.dll
C:\Users\xxx\AppData\Local\Temp\ad9e0686a724437c870c2c32704f936b.dll
C:\Users\xxx\AppData\Local\Temp\AutoRun.exe
C:\Users\xxx\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\xxx\AppData\Local\Temp\b36d970cdfe94a8b9520239351190ebf.dll
C:\Users\xxx\AppData\Local\Temp\b7f94411c5ed48f6939a0be97b876565.dll
C:\Users\xxx\AppData\Local\Temp\b89ae9f245d9474184d33dc5549575f9.dll
C:\Users\xxx\AppData\Local\Temp\bass.dll
C:\Users\xxx\AppData\Local\Temp\c17f53c590f54eddb8be2f94fe3e30c6.dll
C:\Users\xxx\AppData\Local\Temp\c6adfdf6d5a94aafa9dab851e1870300.dll
C:\Users\xxx\AppData\Local\Temp\c9dc9a049a554cf6b724f9cedf7fe0ab.dll
C:\Users\xxx\AppData\Local\Temp\cb4682c969aa4afd812fbbeb67afb6cc.dll
C:\Users\xxx\AppData\Local\Temp\cdabcc656d75485fa72d9870964fe2d5.dll
C:\Users\xxx\AppData\Local\Temp\ce5b1916dc9e4a349f58da1cd92fd1d1.dll
C:\Users\xxx\AppData\Local\Temp\d72ad769917a4da580b53eb4dca24fe5.dll
C:\Users\xxx\AppData\Local\Temp\d87d405cecbb4879a135fdbb265ef560.dll
C:\Users\xxx\AppData\Local\Temp\d9c5bf8700d745bda95935d86a1f9f9d.dll
C:\Users\xxx\AppData\Local\Temp\e4f4c40b55214200bdc7915838a24611.dll
C:\Users\xxx\AppData\Local\Temp\eauninstall.exe
C:\Users\xxx\AppData\Local\Temp\f05571a057bd47b1bb0d2cbf135a27c3.dll
C:\Users\xxx\AppData\Local\Temp\f9a74a53082d4fbf92257c06667146f6.dll
C:\Users\xxx\AppData\Local\Temp\fc0e5d9358c445019ad28db22080f4e7.dll
C:\Users\xxx\AppData\Local\Temp\fd75ddd6aca14f6a97ea94e42e36220f.dll
C:\Users\xxx\AppData\Local\Temp\hss_update.exe


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-08-04 02:09

==================== Ende von FRST.txt ============================
         

Addition.txt:

Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:30-08-2015
durchgeführt von xxx (2015-08-31 03:22:37)
Gestartet von C:\Users\xxx\Desktop
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3674743092-987190976-2435912599-500 - Administrator - Disabled)
Gast (S-1-5-21-3674743092-987190976-2435912599-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3674743092-987190976-2435912599-1004 - Limited - Enabled)
xxx (S-1-5-21-3674743092-987190976-2435912599-1003 - Administrator - Enabled) => C:\Users\xxx

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

µTorrent (HKU\S-1-5-21-3674743092-987190976-2435912599-1003\...\uTorrent) (Version: 3.4.4.40911 - BitTorrent Inc.)
µTorrent (HKU\S-1-5-21-3674743092-987190976-2435912599-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\uTorrent) (Version: 3.4.4.40911 - BitTorrent Inc.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Reader XI - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Age of Empires II HD The Forgotten (HKLM-x32\...\QWdlb2ZFbXBpcmVzSUlIRFRoZUZvcmdvdHRlbg==_is1) (Version: 1 - )
AMD Catalyst Install Manager (HKLM\...\{F856881A-D370-B1A7-2AFF-128F4AA93558}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.12.13 - Atheros Communications Inc.)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
AzureTools.Notifications (x32 Version: 2.1.10731.1602 - Microsoft Corporation) Hidden
Behaviors SDK (XAML) for Visual Studio (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden
Blend for Visual Studio 2013 (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden
Blend for Visual Studio 2013 ENU resources (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Build Tools - amd64 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools - x86 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools Language Resources - amd64 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools Language Resources - x86 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
CPUCooL (remove only) (HKLM-x32\...\CPUCooL) (Version:  - )
Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.11 - Bloodshed Software)
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4954.46574 - PreEmptive Solutions) Hidden
Entity Framework Tools for Visual Studio 2013 (HKLM-x32\...\{08AEF86A-1956-4846-B906-B01350E96E30}) (Version: 12.0.20912.0 - Microsoft Corporation)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.245 - SurfRight B.V.)
Hotspot Shield 4.20.5 (HKLM-x32\...\HotspotShield) (Version: 4.20.5 - AnchorFree Inc.)
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Inkscape 0.91 (HKLM-x32\...\Inkscape) (Version: 0.91 - )
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
IsoBuster 3.6 (HKLM-x32\...\IsoBuster_is1) (Version: 3.6 - Smart Projects)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
JavaScript Tooling (Version: 12.0.21005 - Microsoft Corporation) Hidden
Kaspersky Internet Security Technical Preview (HKLM-x32\...\InstallWIX_{653C1B5A-3287-47B1-8613-0745D4E771C4}) (Version: 15.0.0.463 - Kaspersky Lab)
Kaspersky Internet Security Technical Preview (x32 Version: 15.0.0.463 - Kaspersky Lab) Hidden
LocalESPC Dev12 (x32 Version: 8.100.25984 - Microsoft Corporation) Hidden
LocalESPCui for en-us Dev12 (x32 Version: 8.100.25984 - Microsoft) Hidden
Mac OS X Cursors (HKLM-x32\...\48AEB547-6B1C-4CFC-957B-E11C22C8A25F) (Version: 1.1 - www.46palermo.com)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.6 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{58FED865-4F13-408D-A5BF-996019C4B936}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{1B876496-B3A2-4D22-9B12-B608A3FD4B8B}) (Version: 11.1.2902.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (x64) (HKLM\...\{A6BA243E-85A3-4635-A269-32949C98AC7F}) (Version: 11.1.2902.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{6C026A91-640F-4A23-8B68-05D589CC6F18}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{2F7DBBE6-8EBC-495C-9041-46A772F4E311}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{D411E9C9-CE62-4DBF-9D92-4CB22B750ED5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{54C5041B-0E91-4E92-8417-AAA12493C790}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{04DD7AF4-A6D3-4E30-9BB9-3B3670719234}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (12.0.30919.1) (HKLM-x32\...\{0D7FCBFB-F478-4D32-901C-83F0BF5A3501}) (Version: 12.0.30919.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1) (HKLM-x32\...\{6781FF9B-E87D-4A03-9373-A55A288B83FA}) (Version: 12.0.30919.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{070C38AC-05CE-43DF-9A20-141332F6AB2B}) (Version: 11.1.3366.16 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{05FF8209-C4F1-4C77-BC28-791653156D20}) (Version: 11.1.3366.16 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{b341426f-8543-4e0d-96c3-e976f8ec5ab6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{4fd02573-5f12-4ae4-8027-c63f8e1115af}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.40820 - Microsoft Corporation)
Microsoft Visual Studio Professional 2013 (HKLM-x32\...\{6dff50d0-3bc3-4a92-b724-bf6d6a99de4f}) (Version: 12.0.21005.13 - Microsoft Corporation)
Microsoft Web Deploy 3.5 (HKLM\...\{3674F088-9B90-473A-AAC3-20A00D8D810C}) (Version: 3.1237.1762 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minimal ADB and Fastboot version 1.1.3 (HKLM-x32\...\{DE46417A-9E9E-4BCD-BBDD-DA21943193BB}_is1) (Version: 1.1.3 - )
Mozilla Firefox 40.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 40.0.2 (x86 de)) (Version: 40.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.2.5702 - Mozilla)
Need for Speed Underground 2 (HKLM-x32\...\{909F8EBC-EC7F-48FF-0085-475D818F0F31}) (Version:  - )
Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.0.1 - Nikon)
Nmap 6.49BETA4 (HKLM-x32\...\Nmap) (Version:  - )
Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
OpenVPN 2.3.8-I601  (HKLM\...\OpenVPN) (Version: 2.3.8-I601 - )
Oracle VM VirtualBox 5.0.0 (HKLM\...\{FCD0B365-2189-45F3-9AF2-2BCED86C121A}) (Version: 5.0.0 - Oracle Corporation)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Picture Control Utility (HKLM-x32\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.2.2 - Nikon)
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.3197.1 - PreEmptive Solutions) Hidden
Premium Sound HD (HKLM\...\{439A73C2-8CFA-4630-8484-36BCA2AEBB0A}) (Version: 1.12.0300 - SRS Labs, Inc.)
Prerequisites for SSDT  (HKLM-x32\...\{35C1D9D6-87C0-46A3-B1B4-EDBCC063221C}) (Version: 11.1.3000.0 - Microsoft Corporation)
Python Tools Redirection Template (x32 Version: 1.1 - Microsoft Corporation) Hidden
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RawTherapee Version 4.1 (HKLM\...\{128459AB-59A7-430A-8BD0-3D8803D50400}_is1) (Version: 4.1 - rawtherapee.com)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7601.39013 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SharePoint Client Components (Version: 15.0.4481.1505 - Microsoft Corporation) Hidden
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.103 - Skype Technologies S.A.)
Stardock CursorFX (HKLM-x32\...\CursorFX) (Version: 2.16 - Stardock Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.39.0 - Synaptics Incorporated)
Team Explorer for Microsoft Visual Studio 2013 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Technitium MAC Address Changer v6.0 (HKLM-x32\...\TMACv6.0) (Version: 6.0 - Technitium)
Tony Hawk's Pro Skater 2 (HKLM-x32\...\Activision_THPS2UninstallKey) (Version:  - )
Tony Hawks Pro Skater 4 (HKLM-x32\...\{E0F07676-2C60-4465-A727-20DE3BFCABAC}) (Version: 1.00.0000 - Aspyr Media)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.2.3.0 - TOSHIBA CORPORATION)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.11 for x64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{97965331-BC5D-4D9F-B6DF-5C0A123E4AE0}) (Version: 2.1.0.8 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\...\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 2.0.3.33 - TOSHIBA Corporation)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.2 - TrueCrypt Foundation)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
ViewNX 2 (HKLM-x32\...\{DDD62492-32A7-412B-8AF1-2CF032AD42E3}) (Version: 2.1.2 - Nikon)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes)
VirtualDJ 8 (HKLM-x32\...\{F7A68F9D-BBF0-48FF-B138-2EFB5165638C}) (Version: 8.0.2048.0 - Atomix Productions)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WCF Data Services 5.6.0 Runtime (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2013 (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation)
Windows-Treiberpaket - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (08/28/2014 11.0.0000.00000) (HKLM\...\092555911492C6959D2596D612F52DCA71881CA2) (Version: 08/28/2014 11.0.0000.00000 - Google, Inc.)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - CACE Technologies)
WinRAR (HKLM-x32\...\WinRAR archiver) (Version:  - )
Workflow Manager Client 1.0 (Version: 2.0.30813.2 - Microsoft Corporation) Hidden
Workflow Manager Tools 1.0 for Visual Studio (Version: 2.0.30725.1 - Microsoft Corporation) Hidden

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Wiederherstellungspunkte =========================


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ___RA C:\Windows\system32\Drivers\etc\hosts

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {0BE85537-5689-4DEC-A3DC-38D5103862F5} - System32\Tasks\LoudProof => c:\programdata\{976ab3cf-d8d2-3e4a-976a-ab3cfd8dcf3f}\gamesetup.exe <==== ACHTUNG
Task: {1866A771-138D-42A2-A49E-75E52E7A73E2} - \Winsta Update -> Keine Datei <==== ACHTUNG
Task: {1EFEA92F-7139-4B35-90E8-A70F424EE846} - \avabvbavad -> Keine Datei <==== ACHTUNG
Task: {22479C06-B56A-465A-85A8-2023774CA229} - \AdobeAAMUpdater-1.0-Toshiba-xxx -> Keine Datei <==== ACHTUNG
Task: {3A062199-CB44-413C-8C4D-3B2D460E9169} - \DFOZSNJILP -> Keine Datei <==== ACHTUNG
Task: {43CDEEEB-2B15-4B93-A047-D0E04BEFB0D2} - \SmartWeb Upgrade Trigger Task -> Keine Datei <==== ACHTUNG
Task: {54A49564-469B-42CD-A0B6-D40B54CA3262} - \{F05C6774-D1E3-400A-BF54-41B6C72D18A2} -> Keine Datei <==== ACHTUNG
Task: {6B4F8AD2-B802-4DD1-B75C-64B14A7F8AA3} - \{FE848F92-98FB-4AE7-8ACF-723F8C49ACFA} -> Keine Datei <==== ACHTUNG
Task: {80B64C67-A468-4821-9528-DBCA0ED3D8E9} - \AlcoProof -> Keine Datei <==== ACHTUNG
Task: {92C91CDB-6A66-4AB3-A6C0-7469F499F2A5} - \{4F923200-1F8D-4530-B555-4126DD1B7551} -> Keine Datei <==== ACHTUNG
Task: {A252F268-C7A4-4D31-A02A-01313845B979} - \{6654E48F-0F72-403A-A2D3-22F84DE6DC43} -> Keine Datei <==== ACHTUNG
Task: {AAE6A730-1FD5-49F5-B490-24D0FB6DF6B9} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender 2015\bdproductdata.exe
Task: {BD523089-A475-47B5-868E-191D7A91078C} - \Convertor -> Keine Datei <==== ACHTUNG
Task: {BF4E57C6-DED3-4243-BE72-8BC467A5D265} - \ProPCCleaner_Start -> Keine Datei <==== ACHTUNG
Task: {CAD68D5D-6CFD-45D5-94DC-BB00116DF5AB} - \{25059126-90E9-4B17-9F87-45C87C21A8BF} -> Keine Datei <==== ACHTUNG
Task: {CE157836-4F37-44AF-A43C-C1BA6D1B3BE9} - \CCleanerSkipUAC -> Keine Datei <==== ACHTUNG
Task: {F65255A3-6739-4815-B76A-B14C22706714} - \ProPCCleaner_Popup -> Keine Datei <==== ACHTUNG
Task: {F9E8E8DD-1416-49B9-A373-234659E52054} - \WinKit -> Keine Datei <==== ACHTUNG

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\AlcoProof.job => c:\programdata\{430548d0-bab8-9b04-4305-548d0bab2342}\kis-2015 patch.exe <==== ACHTUNG
Task: C:\Windows\Tasks\LoudProof.job => c:\programdata\{976ab3cf-d8d2-3e4a-976a-ab3cfd8dcf3f}\gamesetup.exe <==== ACHTUNG

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
         

Gmer.txt:

Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-08-31 08:58:47
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MQ01ABD100 rev.AX002M 931,51GB
Running: 9ie9fcez.exe; Driver: C:\Users\xxx\AppData\Local\Temp\pxldipow.sys


---- Registry - GMER 2.1 ----

Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\446d57d52051 (not active ControlSet)  
Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\446d57d52051                      
Reg  HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\446d57d52051 (not active ControlSet)  

---- EOF - GMER 2.1 ----
         
Hitman Pro log:

Code:
ATTFilter
HitmanPro 3.7.9.245
www.hitmanpro.com

   Computer name . . . . : XXX
   Windows . . . . . . . : 6.1.1.7601.X64/8
   Safe Mode Boot  . . . : NETWORK
   User name . . . . . . : XXX\xxx
   UAC . . . . . . . . . : Disabled
   License . . . . . . . : Trial (29 days left)

   Scan date . . . . . . : 2015-08-31 23:34:16
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 8m 57s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 3
   Traces  . . . . . . . : 9

   Objects scanned . . . : 2.066.943
   Files scanned . . . . : 115.049
   Remnants scanned  . . : 675.782 files / 1.276.112 keys

Malware _____________________________________________________________________

   C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\multi-player.exe
      Size . . . . . . . : 8.045.588 bytes
      Age  . . . . . . . : 21.4 days (2015-08-10 14:40:18)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : 19BF61F477F8A0653ECB6EE3EA87F78DC297E31136E69FB670B166BC9DBDEC62
    > Bitdefender  . . . : Trojan.Generic.12373416
      Fuzzy  . . . . . . : 109.0
      References
         HKU\S-1-5-21-3674743092-987190976-2435912599-1003\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\multi-player.exe
      Forensic Cluster
         -1.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\exposed.dll
         -0.9s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\gener.dll
         -0.9s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\generico.dll
         -0.9s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\How-to-play-after-update.txt
          0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\multi-player.exe
          0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\MW3 Launcher Update.exe
          0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\single-player.exe
          0.9s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\steam_appid.txt
          1.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\VMProtectSDK32.dll
          1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\dw\Favorities.slist
          1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\0.sdm
          1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\42695.sdm
          1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\42696.sdm
          1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\42697.sdm
          1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\42698.sdm

   C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\TeknoMW3.dll
      Size . . . . . . . : 1.158.144 bytes
      Age  . . . . . . . : 21.4 days (2015-08-10 14:51:03)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : E743B6B2EC8F49ACF8CCDE78445D0CC023147CE8ECBE0E4F0CEF281AF2FAAC62
    > Bitdefender  . . . : Trojan.Generic.12373416
      Fuzzy  . . . . . . : 114.0
      Forensic Cluster
         -0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\
         -0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\main\
         -0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\main\iw_23.iwd
         -0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\main\iw_24.iwd
         -0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\
         -0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\
         -0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\code_post_gfx.ff
         -0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\code_post_gfx_mp.ff
         -0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\code_pre_gfx.ff
         -0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\code_pre_gfx_mp.ff
         -0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\localized_code_post_gfx_mp.ff
         -0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\localized_code_pre_gfx_mp.ff
         -0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\localized_ui_mp.ff
         -0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch.ff
         -0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_hamburg.ff
         -0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_hijack.ff
         -0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_innocent.ff
         -0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_london.ff
         -0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_aground_ss.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_burn_ss.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_cement.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_courtyard_ss.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_crosswalk_ss.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_dome.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_exchange.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_hillside_ss.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_lambeth.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_morningwood.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_paris.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_park.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_qadeem.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_radar.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_restrepo_ss.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_six_ss.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_underground.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_village.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_paris_ac130.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_prague_escape.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_escape_hamburg.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_ied_berlin.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_littlebird_payback.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_bootleg.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_cement.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_dome.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_morningwood.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_park.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_village.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_zodiac2_ny_harbor.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_specialops.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_berlin.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_intro.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_ny_harbor.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_ny_manhattan.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_warlord.ff
         -0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_survival.ff
         -0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\ui.ff
         -0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\ui_mp.ff
         -0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\client.wyc
         -0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\steam_api.dll
          0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\TeknoMW3.dll
          0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\TeknoMW3.exe
          0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\TeknoMW3_Update.exe
         18.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\TeknoMW3_Update.exe
         21.5s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\iw_24.iwd

   C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\client_2.7.3.7\TeknoMW3.dll
      Size . . . . . . . : 1.158.144 bytes
      Age  . . . . . . . : 41.6 days (2015-07-21 10:08:53)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : E743B6B2EC8F49ACF8CCDE78445D0CC023147CE8ECBE0E4F0CEF281AF2FAAC62
    > Bitdefender  . . . : Trojan.Generic.12373416
      Fuzzy  . . . . . . : 114.0


Suspicious files ____________________________________________________________

   C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-shm
      Size . . . . . . . : 32.768 bytes
      Age  . . . . . . . : 0.0 days (2015-08-31 22:53:56)
      Entropy  . . . . . : 5.6
      SHA-256  . . . . . : 321E810FB5ACDC59E5A2F24B380C82E187ED15F5F1FB3762AE2B99B15A1DDC55
      Product  . . . . . : Microsoft® Windows® Operating System
      Publisher  . . . . : Microsoft Corporation
      Description  . . . : Remote Desktop Generic USB Driver
      Version  . . . . . : 6.1.7601.17514
      Copyright  . . . . : © Microsoft Corporation. All rights reserved.
      LanguageID . . . . : 1033
      Fuzzy  . . . . . . : 48.0
         The file is hidden from Windows API. This is typical for malware.
         The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
         The file name extension of this program is not common.
         Time indicates that the file appeared recently on this computer.
         The file is in use by one or more active processes.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
      Forensic Cluster
         -16.6s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\revocations.txt
         -15.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-wal
         -15.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-shm
         -15.5s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webapps\webapps.json
         -15.4s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\sessionCheckpoints.json
         -15.1s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cookies.sqlite-wal
         -15.1s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cookies.sqlite-shm
         -11.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\08390A20B59A7060A1C2F75B0F327F62A023CEE6
         -11.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\39FF5907CAB2DAA38CA0327D3206B962B3B3E745
         -10.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\36569E711477EE052773D7D72F738A4719B48377
         -9.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webappsstore.sqlite-wal
         -9.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webappsstore.sqlite-shm
         -9.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\directoryLinks.json
         -6.8s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\sessionstore-backups\recovery.bak
         -6.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EB748F82B405287A0C467E1289B4A25ED0A363A1
         -5.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3ADCE44D1AEDA7677FC3F83EC20BBF2B1ADCB7B7
         -5.0s C:\Users\xxx\AppData\Local\Temp\etilqs_bRrFuFtgj5ocWxi
         -5.0s C:\Users\xxx\AppData\Local\Temp\etilqs_FLv6uQezXbd9Mzs
         -4.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\4F53355D5A7A33C43A579E6A37E7ADC48F13CEC9
         -4.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E0CDEFC7594B66588A783144A2DFCFBDDC604C36
         -3.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D103B4C13B80196FD20D11F5EF2A76B61CC8D7F8
         -0.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1686520AE5A04A249C5F4B73063B1ED2861894E5
         -0.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\B8A5D55A6A1E5E8FDAC2D0C6356CBCF99157B9D4
         -0.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-wal
          0.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-shm
          0.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C760A8FDDB87F07F0B76CC26655736C1BFB32978
          0.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\8608C899AE5A354371E1055D50A6DC9325A4FC17
          1.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A128FF81D21259C26E770DBEDD7168C1CFDB25E1
          1.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\679DBEBB015A009317946FB791A8797ACEF0BDBD
          2.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\694C24F8BAB03DE803E25A18F3EE2A2594997E68
          4.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\56CBC047DCBB5AB07CFCBA84ABF338CB2F1FC6DC
          5.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3AA08DA7102A7B37A81ED99732EF2F240A626469
          5.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DDA136C8BDCC5D6A89E403D0F0861969783DB5A4
          6.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31F63A3D6DC081D114C22FEB4D917AAE29152C43
          6.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E4C7FF3F2A85A6A0BB8F74ACA7DA48A57376E338
          7.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\CC3FA6DA28A4CBC6E00744F0AECB2800A7E4E632
          9.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\9BA79DEE79C3F2261B9E4042657756B35FB38B27
          9.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DFFDC978BEE11579705ED27DD479C3E471F22E59
         10.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\AE6CEF5AC399403C340F019E30042F3B09528E2C
         13.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\352ADD13304A8EA6BCEACDE948E85EE15A5536DF
         17.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F4EF60D2DD717CC8C7167E9AFEDF685A19F657B4
         18.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\05A38ABF159077A9B86B8CD447AE9DFA713822AF
         18.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\630967E047618112554D86B317740983B7EA941B
         18.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D3233DC1A750F0BCBD0E30B3EF74CF09FBAFCCC0
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\01CE926D1AF998DFB14DC38ECB660437C799E1D9
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A77CA4B03778D91B9A1E8C3F819265AE851E805B
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\72F27A73F60E232FE099C70D7E3460D01B68D059
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\27EBBD4959998E6DC866C944712C87638615D449
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\59C73A640FAEF18D5E915E71F540A3DA6CE66941
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0BE107C9106736426E1C782BD276CFFAE6E31254
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A76272BAD977F006EEFDDC6A91550FA32792473B
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\8415235A64BC3B87475D6BB8845381A03461ADAE
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0CA7A5A4F8226D22B92E85A5E18AB1742214BEC0
         18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C6934EFB0F32BA60EB8B572D8D272D1650A39446
         18.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F73521CA494258FCC3B2A0A09DFA5093B1AEE612
         18.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0957C95B0A19F22426127910130B6CD4B3FF987A
         18.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F1343EBFA146EF7382E54FEBCC57FD22B731673A
         18.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D0409148DFB2CB6A488A462DA4E89E1E22E5AAE2
         18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\7D9BA45C7451E5EC64D8D5906322EDCFF659E16A
         18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\9AE52A91C9DE51D341DD41E6390AC5E0EDED17A4
         18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\667793EFF3A274291541CD256CB070593EB79B19
         18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F56260859FFF9F054B435363CE122CBA06DCFC9F
         18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\27A453963E993390A5CD9CCD1868B11D44A81EDA
         18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DAC7F766D262263CE7BCA551CA0A3C1975D87A10
         18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\4AE6E3AA65D9D60916361725268EAEC2CA34B6AF
         18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31196827406DA57C90881A88195B8849C8BF0BEA
         18.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\6818565905DCF3E6663570F8DF800AD4F6527DE7
         19.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\75B4A8CBFA98A3884D8115A47DB099989AA14FB5
         22.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D91B00DDD7EC21BDD5D0ABD4FEF1F2E7690F73F1
         41.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\crashes\store.json.mozlz4
         43.4s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\adblockplus\patterns.ini
         44.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\84B06F9721F0BBD5FFB2BDED44BA98CE8FF03F66
         44.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1B64EB7463DB9D7DC9745EA37AA263B739E35C14
         48.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\adblockplus\elemhide.css
         48.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0783065335759578BEAD953BDB648B309F5A0A12
         48.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\CEA2DD6F31D9D48A6BAE06940A28D7D9ABE10DDC
         48.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\43D0A329B2F370975E0562603A8E0D63151C453B
         48.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3583C39E2DC1D70D1A9FA4F66F92D0985CBB8DE8
         61.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C8280EA2FFA428364EE23F31758CF31810005E1E
         61.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A454585B024CBD141D85594968B33288DAADD713
         61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C30EFFDBB49AE0B20BD4ED3903E9486A78B03284
         61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EB9F7E6523DF30ED3C4F21C342211C4DAA0599E6
         61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31C13251D2BDF7641D6134057AB64B2D2D1BCD1F
         61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\794C8766DA5A87E4DFA72D6684F07ADF1E5589A9
         61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D9694BA649B822C154EF7CDC694DBA3BE42FABAB
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F05C999A73F203853BEC696830B6A73F615641FE
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\ECE118C79EF305336862F896E8E43307D79C10F9
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\B1570C6EBCA59F8100614FC8C30A8C9E6FB41AEA
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E0C2FA7DC37DA3F98E7448323522FFCC81AD461A
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0773B826DD1C2064375C255B7AF9035367CDBA8A
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E62CC7CB72EB558F6DA3C625AECA1A6F2450655A
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\290CAEC5E0A8A078A4738F1D0367B947525100BF
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1994A21070F0BE056ED2AF54D8C9CD946B029452
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EBF32C8EE33B785EBB787522EC7460D6EA01A964
         61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\711A8797FEF201C319196FF97A58A08D93557998
         62.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\97F9495FAE777BDDA5EEAF8CB6FA2BA5FBCE3CEA
         62.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\025E754E03664FA82C72BD5C010D4149A7C14B63
         69.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A2D141634F2EF4238440EECD0D155B4ECDED7D98
         70.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D8B7F5F0A7403645D443D2E804EEC41AE0726301
         70.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\FB59CA83515EBB883B60A4A595D0C1F286FF5D6A
         70.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\346A94DA1FC4D458E00BB346625FAB0C6D346F6B
         70.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\430FABFBDDAF5B10292D83A6012C8ABEE4AA0247
         70.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\42691B662FE5595D2EA40D22D213DD5B8F1D4C17

   C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-shm
      Size . . . . . . . : 32.768 bytes
      Age  . . . . . . . : 0.0 days (2015-08-31 22:53:40)
      Entropy  . . . . . : 5.4
      SHA-256  . . . . . : FE1947F538EE41FFFAF2D805C99FBD7C78F0C48CC5DB70CEDFED108F7A7085DE
      Product  . . . . . : Microsoft® Windows® Operating System
      Publisher  . . . . : Microsoft Corporation
      Description  . . . : VGA/Super VGA Video Driver
      Version  . . . . . : 6.1.7600.16385
      LanguageID . . . . : 0
      Fuzzy  . . . . . . : 48.0
         The file is hidden from Windows API. This is typical for malware.
         The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
         The file name extension of this program is not common.
         Time indicates that the file appeared recently on this computer.
         The file is in use by one or more active processes.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
      Forensic Cluster
         -0.7s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\revocations.txt
          0.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-wal
          0.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-shm
          0.4s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webapps\webapps.json
          0.4s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\sessionCheckpoints.json
          0.7s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cookies.sqlite-wal
          0.7s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cookies.sqlite-shm
          4.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\08390A20B59A7060A1C2F75B0F327F62A023CEE6
          4.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\39FF5907CAB2DAA38CA0327D3206B962B3B3E745
          5.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\36569E711477EE052773D7D72F738A4719B48377
          6.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webappsstore.sqlite-wal
          6.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webappsstore.sqlite-shm
          6.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\directoryLinks.json
          9.1s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\sessionstore-backups\recovery.bak
          9.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EB748F82B405287A0C467E1289B4A25ED0A363A1
         10.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3ADCE44D1AEDA7677FC3F83EC20BBF2B1ADCB7B7
         10.9s C:\Users\xxx\AppData\Local\Temp\etilqs_bRrFuFtgj5ocWxi
         10.9s C:\Users\xxx\AppData\Local\Temp\etilqs_FLv6uQezXbd9Mzs
         11.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\4F53355D5A7A33C43A579E6A37E7ADC48F13CEC9
         11.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E0CDEFC7594B66588A783144A2DFCFBDDC604C36
         12.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D103B4C13B80196FD20D11F5EF2A76B61CC8D7F8
         15.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1686520AE5A04A249C5F4B73063B1ED2861894E5
         15.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\B8A5D55A6A1E5E8FDAC2D0C6356CBCF99157B9D4
         15.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-wal
         15.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-shm
         16.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C760A8FDDB87F07F0B76CC26655736C1BFB32978
         16.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\8608C899AE5A354371E1055D50A6DC9325A4FC17
         17.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A128FF81D21259C26E770DBEDD7168C1CFDB25E1
         17.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\679DBEBB015A009317946FB791A8797ACEF0BDBD
         17.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\694C24F8BAB03DE803E25A18F3EE2A2594997E68
         20.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\56CBC047DCBB5AB07CFCBA84ABF338CB2F1FC6DC
         20.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3AA08DA7102A7B37A81ED99732EF2F240A626469
         21.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DDA136C8BDCC5D6A89E403D0F0861969783DB5A4
         22.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31F63A3D6DC081D114C22FEB4D917AAE29152C43
         22.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E4C7FF3F2A85A6A0BB8F74ACA7DA48A57376E338
         23.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\CC3FA6DA28A4CBC6E00744F0AECB2800A7E4E632
         25.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\9BA79DEE79C3F2261B9E4042657756B35FB38B27
         25.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DFFDC978BEE11579705ED27DD479C3E471F22E59
         26.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\AE6CEF5AC399403C340F019E30042F3B09528E2C
         29.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\352ADD13304A8EA6BCEACDE948E85EE15A5536DF
         33.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F4EF60D2DD717CC8C7167E9AFEDF685A19F657B4
         34.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\05A38ABF159077A9B86B8CD447AE9DFA713822AF
         34.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\630967E047618112554D86B317740983B7EA941B
         34.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D3233DC1A750F0BCBD0E30B3EF74CF09FBAFCCC0
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\01CE926D1AF998DFB14DC38ECB660437C799E1D9
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A77CA4B03778D91B9A1E8C3F819265AE851E805B
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\72F27A73F60E232FE099C70D7E3460D01B68D059
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\27EBBD4959998E6DC866C944712C87638615D449
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\59C73A640FAEF18D5E915E71F540A3DA6CE66941
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0BE107C9106736426E1C782BD276CFFAE6E31254
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A76272BAD977F006EEFDDC6A91550FA32792473B
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\8415235A64BC3B87475D6BB8845381A03461ADAE
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0CA7A5A4F8226D22B92E85A5E18AB1742214BEC0
         34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C6934EFB0F32BA60EB8B572D8D272D1650A39446
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F73521CA494258FCC3B2A0A09DFA5093B1AEE612
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0957C95B0A19F22426127910130B6CD4B3FF987A
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F1343EBFA146EF7382E54FEBCC57FD22B731673A
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D0409148DFB2CB6A488A462DA4E89E1E22E5AAE2
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\7D9BA45C7451E5EC64D8D5906322EDCFF659E16A
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\9AE52A91C9DE51D341DD41E6390AC5E0EDED17A4
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\667793EFF3A274291541CD256CB070593EB79B19
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F56260859FFF9F054B435363CE122CBA06DCFC9F
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\27A453963E993390A5CD9CCD1868B11D44A81EDA
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DAC7F766D262263CE7BCA551CA0A3C1975D87A10
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\4AE6E3AA65D9D60916361725268EAEC2CA34B6AF
         34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31196827406DA57C90881A88195B8849C8BF0BEA
         34.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\6818565905DCF3E6663570F8DF800AD4F6527DE7
         35.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\75B4A8CBFA98A3884D8115A47DB099989AA14FB5
         38.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D91B00DDD7EC21BDD5D0ABD4FEF1F2E7690F73F1
         56.8s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\crashes\store.json.mozlz4
         59.3s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\adblockplus\patterns.ini
         60.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\84B06F9721F0BBD5FFB2BDED44BA98CE8FF03F66
         60.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1B64EB7463DB9D7DC9745EA37AA263B739E35C14
         63.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\adblockplus\elemhide.css
         64.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0783065335759578BEAD953BDB648B309F5A0A12
         64.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\CEA2DD6F31D9D48A6BAE06940A28D7D9ABE10DDC
         64.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\43D0A329B2F370975E0562603A8E0D63151C453B
         64.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3583C39E2DC1D70D1A9FA4F66F92D0985CBB8DE8
         77.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C8280EA2FFA428364EE23F31758CF31810005E1E
         77.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A454585B024CBD141D85594968B33288DAADD713
         77.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C30EFFDBB49AE0B20BD4ED3903E9486A78B03284
         77.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EB9F7E6523DF30ED3C4F21C342211C4DAA0599E6
         77.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31C13251D2BDF7641D6134057AB64B2D2D1BCD1F
         77.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\794C8766DA5A87E4DFA72D6684F07ADF1E5589A9
         77.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D9694BA649B822C154EF7CDC694DBA3BE42FABAB
         77.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F05C999A73F203853BEC696830B6A73F615641FE
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\ECE118C79EF305336862F896E8E43307D79C10F9
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\B1570C6EBCA59F8100614FC8C30A8C9E6FB41AEA
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E0C2FA7DC37DA3F98E7448323522FFCC81AD461A
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0773B826DD1C2064375C255B7AF9035367CDBA8A
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E62CC7CB72EB558F6DA3C625AECA1A6F2450655A
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\290CAEC5E0A8A078A4738F1D0367B947525100BF
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1994A21070F0BE056ED2AF54D8C9CD946B029452
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EBF32C8EE33B785EBB787522EC7460D6EA01A964
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\711A8797FEF201C319196FF97A58A08D93557998
         77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\97F9495FAE777BDDA5EEAF8CB6FA2BA5FBCE3CEA
         77.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\025E754E03664FA82C72BD5C010D4149A7C14B63
         85.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A2D141634F2EF4238440EECD0D155B4ECDED7D98
         85.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D8B7F5F0A7403645D443D2E804EEC41AE0726301
         86.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\FB59CA83515EBB883B60A4A595D0C1F286FF5D6A
         86.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\346A94DA1FC4D458E00BB346625FAB0C6D346F6B
         86.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\430FABFBDDAF5B10292D83A6012C8ABEE4AA0247
         86.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\42691B662FE5595D2EA40D22D213DD5B8F1D4C17

   C:\Users\xxx\Desktop\FRST64.exe
      Size . . . . . . . : 2.188.288 bytes
      Age  . . . . . . . : 0.9 days (2015-08-31 02:22:34)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : 06B2C8DEAA568DD38CB8451EA21AE7BAECFAFB8F7FA674D8C3EA035493FBA8FD
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      Forensic Cluster
         -398.9s C:\Users\xxx\Desktop\9ie9fcez.exe
         -388.8s C:\Users\xxx\Desktop\FRST64.exe
         
Malewarebytes Anti maleware :

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 31.08.2015
Suchlaufzeit: 23:56
Protokolldatei: 
Administrator: Ja

Version: 2.1.8.1057
Malware-Datenbank: v2015.08.31.04
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Premium-Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: xxx

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 432242
Abgelaufene Zeit: 28 Min., 13 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Warnen

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
         
Adwcleaner:

Code:
ATTFilter
# AdwCleaner v3.001 - Report created 01/09/2015 at 00:32:18
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : xxx - XXX
# Running from : C:\Users\xxx\Desktop\Stuff\tools\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\jetpack

***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16750


-\\ Mozilla Firefox v40.0.2 (x86 de)

[ File : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\prefs.js ]


*************************

AdwCleaner[R0].txt - [4071 octets] - [21/06/2015 18:51:12]
AdwCleaner[R10].txt - [4613 octets] - [19/08/2015 12:13:22]
AdwCleaner[R11].txt - [2114 octets] - [19/08/2015 17:34:28]
AdwCleaner[R12].txt - [2343 octets] - [29/08/2015 03:40:58]
AdwCleaner[R13].txt - [2466 octets] - [30/08/2015 14:39:39]
AdwCleaner[R14].txt - [2588 octets] - [31/08/2015 02:52:00]
AdwCleaner[R15].txt - [1123 octets] - [01/09/2015 00:32:18]
AdwCleaner[R1].txt - [1835 octets] - [22/06/2015 01:17:53]
AdwCleaner[R2].txt - [1223 octets] - [22/06/2015 03:20:17]
AdwCleaner[R3].txt - [1115 octets] - [22/06/2015 03:42:19]
AdwCleaner[R4].txt - [1345 octets] - [22/06/2015 12:20:06]
AdwCleaner[R5].txt - [3009 octets] - [23/06/2015 23:18:29]
AdwCleaner[R6].txt - [1501 octets] - [23/06/2015 23:23:44]
AdwCleaner[R7].txt - [1703 octets] - [27/06/2015 01:12:09]
AdwCleaner[R8].txt - [1755 octets] - [27/06/2015 01:16:14]
AdwCleaner[R9].txt - [2329 octets] - [14/08/2015 20:52:41]
AdwCleaner[S0].txt - [3171 octets] - [21/06/2015 18:52:02]
AdwCleaner[S10].txt - [3160 octets] - [19/08/2015 17:21:36]
AdwCleaner[S11].txt - [2177 octets] - [19/08/2015 17:35:20]
AdwCleaner[S12].txt - [2410 octets] - [29/08/2015 03:41:49]
AdwCleaner[S13].txt - [2532 octets] - [30/08/2015 14:40:43]
AdwCleaner[S1].txt - [1741 octets] - [22/06/2015 01:18:40]
AdwCleaner[S2].txt - [1293 octets] - [22/06/2015 03:21:13]
AdwCleaner[S3].txt - [1177 octets] - [22/06/2015 03:42:56]
AdwCleaner[S4].txt - [1411 octets] - [22/06/2015 12:21:39]
AdwCleaner[S5].txt - [2858 octets] - [23/06/2015 23:19:37]
AdwCleaner[S6].txt - [1562 octets] - [23/06/2015 23:24:23]
AdwCleaner[S7].txt - [1729 octets] - [27/06/2015 01:13:07]
AdwCleaner[S8].txt - [1816 octets] - [27/06/2015 01:17:13]
AdwCleaner[S9].txt - [2371 octets] - [14/08/2015 20:57:06]

########## EOF - C:\AdwCleaner\AdwCleaner[R15].txt - [2568 octets] ##########
         
Junkware Removal Tool:


Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 7 Professional x64
Ran by xxx on 01.09.2015 at  1:00:05,80
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update thirteen degrees
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util thirteen degrees



~~~ Files

Failed to delete: [File] C:\Windows\SysWOW64\number of results
Successfully deleted: [File] C:\ProgramData\1439035440.bdinstall.bin
Successfully deleted: [File] C:\Users\xxx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\hotspot shield.lnk



~~~ Folders

Successfully deleted: [Folder] C:\Program Files (x86)\predm
Successfully deleted: [Folder] C:\ProgramData\abc
Successfully deleted: [Folder] C:\Users\xxx\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\ProgramData\0f3b5471928b4fd3834dad205fba7597
Successfully deleted: [Folder] C:\ProgramData\28341ff220e0446c9fff27c4493d622e



~~~ FireFox

Successfully deleted the following from C:\Users\xxx\AppData\Roaming\mozilla\firefox\profiles\ks5t7hh7.default-1435098893833\prefs.js

user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine);
user_pref(browser.search.searchengine.ptid, wpc);
user_pref(browser.search.searchengine.uid, TOSHIBAXMQ01ABD100_523IS39ISXX523IS39IS);
user_pref(extensions.quick_start.enable_search1, false);
user_pref(extensions.quick_start.sd.closeWindowWithLastTab_prev_state, false);
Emptied folder: C:\Users\xxx\AppData\Roaming\mozilla\firefox\profiles\ks5t7hh7.default-1435098893833\minidumps [6 files]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.09.2015 at  1:01:20,33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

Geändert von daniel1989 (01.09.2015 um 00:03 Uhr) Grund: JRT log vergessen...

 

Themen zu Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild
antivirus, askbar, avp, bildschirm, computer, device driver, dnsapi.dll, downloader, dringend, ebanking, explorer reagiert nicht, flash player, gebraucht, google, helper, homepage, hotspot, iexplore.exe, installation, internet, kaspersky, langsam, lightning, mozilla, programm, registry, schwarzer bildschim, schwarzer bildschirm, security, software, svchost.exe, system, virus, windows, windows7




Ähnliche Themen: Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild


  1. Windows 7: Programme lassen sich nicht mehr über Verknüpfung öffnen
    Plagegeister aller Art und deren Bekämpfung - 05.12.2015 (36)
  2. Windows 7: .exe Programme lassen sich nicht öffnen
    Plagegeister aller Art und deren Bekämpfung - 27.07.2015 (4)
  3. Win7- Systemstart und programme brauchen ewig beim laden
    Log-Analyse und Auswertung - 08.05.2015 (27)
  4. Avira Antivir lässt sich nicht mehr installieren/ Programme lassen sich nicht öffnen
    Antiviren-, Firewall- und andere Schutzprogramme - 23.03.2015 (10)
  5. Windows 8.1 Programme, Systemsteuerung, etc. lassen sich nicht mehr öffnen
    Alles rund um Windows - 15.03.2015 (3)
  6. Win Vista: Virus oder Registry durcheinander? Gruppenrichtilien blockieren / Programme lassen sich nicht installieren
    Plagegeister aller Art und deren Bekämpfung - 09.09.2014 (38)
  7. Windows 7 braucht ewig bis es reagiert, ordner lassen sich nicht öffnen.
    Log-Analyse und Auswertung - 05.08.2014 (12)
  8. Windows 7: Grafikoptionen lassen sich nicht auswählen / verschwommenes Bild
    Log-Analyse und Auswertung - 11.07.2014 (11)
  9. Windows 7 Internet Explorer langsam Internet Explorer reagiert lahm oder gar nicht
    Log-Analyse und Auswertung - 28.05.2014 (15)
  10. Windows XP: Fragmente verschiedener Programme lassen sich nicht deinstallieren, Desktophintergrund verändert sich
    Log-Analyse und Auswertung - 18.02.2014 (12)
  11. Windows Update + FIX-IT + Microsoft £Anwendunge lassen sich nicht mehr installieren
    Log-Analyse und Auswertung - 25.07.2013 (1)
  12. Programmdateien im Explorer verschwunden, Programme lassen sich nicht mehr starten
    Log-Analyse und Auswertung - 05.06.2012 (10)
  13. Pc lässt sich nicht hochfahren nur schwarzes bild mit blau weißen Streifen!
    Netzwerk und Hardware - 03.01.2011 (1)
  14. Windows Xp spinnt total. Programme lassen sich nicht ordentlich ausführen
    Alles rund um Windows - 09.11.2009 (10)
  15. Rechner startet sehr langsam und Programme brauchen ewig zum öffnen
    Log-Analyse und Auswertung - 09.03.2009 (1)
  16. Internetseiten lassen sich nicht mehr oeffnen/hiJackThis Logfile
    Log-Analyse und Auswertung - 04.05.2008 (11)
  17. Probleme mit meinem Rechner/Seiten lassen sich nicht oeffnen/Hijackthis Log
    Log-Analyse und Auswertung - 26.09.2004 (10)

Zum Thema Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild - Hallo an das Forum! Ich hoffe, ihr könnt mir helfen! Auf meinem PC mit Windows 7 ist beim "arbeiten" auf einmal alles total langsam geworden bis ich einen blauen Bildschirm - Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild...
Archiv
Du betrachtest: Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.