![]() |
| |||||||
Log-Analyse und Auswertung: Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes BildWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #1 |
![]() | Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild Hallo an das Forum! Ich hoffe, ihr könnt mir helfen! Auf meinem PC mit Windows 7 ist beim "arbeiten" auf einmal alles total langsam geworden bis ich einen blauen Bildschirm zu sehen bekommen habe mit irgendeiner Fehlermeldung, PC aus wieder an - er war weiterhin total langsam ich bekam Pop up Fehlermeldungen ohne Ende am meisten allerdings das der Microsoft Explorer nicht geht und ich warten oder ihn beenden muesse...der Pc ist nur noch im abgesicherten modus wirklich bedienbar Wenn ich im normalen Modus bin warte ich gut und gerne 10 minuten bis mir ein ordner geoeffnet wird... manchmal geht aber wieder alles fix wie vorher !? und dann kommt auch gerne immer wieder ein schwarzer Bildschirm fuer ein paar minuten bis er verschwindet manchmal bleibt er aber auch ewig...Malewarebytes, adw cleaner, brachten mir nichts mit meinem kaspersky internet security virenprogramm konnte ich keinen fullscan machen habe somit keine log datei davon .. ich habe den pc gebraucht gekauft vor ca. einem monat viel maleware von geloescht und dannach lief er wie eine 1 ...naja .. ich komme nicht mehr weiter und brauche dringend hilfe Ich hoffe ich habe mich an alle Regeln und Normen gehalten Und bedanke mich schon mal vortraeglich bei meinem zukuenftigem Helfer/in!!! hier meine logs die ich im abgesicherten modus machen musste :Defogger_Disable.log: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1)
Log created at 03:07 on 31/08/2015 (xxx)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:30-08-2015
durchgeführt von xxx (Administrator) auf XXX (31-08-2015 03:54:20)
Gestartet von C:\Users\xxx\Desktop
Geladene Profile: xxx (Verfügbare Profile: xxx)
Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 10 (Standard-Browser: FF)
Start-Modus: Safe Mode (with Networking)
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2867984 2011-12-22] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (Der Dateneintrag hat 36 mehr Zeichen).
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2012-01-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [bdruninstaller] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setuplauncher.exe" /run:"setupdownloader.exe" /args:"/token:64b /after_restart"
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\...\Run: [uTorrent] => C:\Users\xxx\AppData\Roaming\uTorrent\uTorrent.exe [1696096 2015-08-29] (BitTorrent Inc.)
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
GroupPolicyScripts: Gruppenrichtline erkannt <======= ACHTUNG
CHR HKLM\SOFTWARE\Policies\Google: Richtlinienbeschränkung <======= ACHTUNG
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)
ProxyEnable: [.DEFAULT] => Proxy ist aktiviert.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49737;https=127.0.0.1:49737
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{6EF27CF9-2594-4B68-8B80-9276E723E19E}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{8541C6AF-41FF-4C87-A65C-38721CCEE50C}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{FD42EE94-C8AB-4635-97A2-B585F803CAB0}: [DhcpNameServer] 193.189.244.206 193.189.244.225
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Richtlinienbeschränkung <======= ACHTUNG
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Richtlinienbeschränkung <======= ACHTUNG
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2015-08-08] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2015-08-08] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-29] (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-29] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-08-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-04-28] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-08-10] ()
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [Keine Datei]
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [Keine Datei]
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-29] (Oracle Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\content_blocker@kaspersky.com [2015-08-08] ()
FF Plugin-x32: @kaspersky.com/online_banking -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\online_banking@kaspersky.com [2015-08-30] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2015-08-08] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-12-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-12-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-12-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-12-18] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-12-18] (Apple Inc.)
FF Extension: YouTube Unblocker - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\youtubeunblocker@unblocker.yt [2015-08-06]
FF Extension: Flashblock - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2015-08-05]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\adblockpopups@jessehakanen.net.xpi [2015-08-19]
FF Extension: Ghostery - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\firefox@ghostery.com.xpi [2015-08-08]
FF Extension: Stop YouTube Autoplay - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\jid0-Pm0nbsggUvL00CBoW6YwCaqv8bk@jetpack.xpi [2015-08-17]
FF Extension: NoScript - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-08-08]
FF Extension: Adblock Plus - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-06-24]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\content_blocker@kaspersky.com [2015-08-08]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2015-08-08]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\url_advisor@kaspersky.com [2015-08-08]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\anti_banner@kaspersky.com [2015-08-08]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\FFExt\online_banking@kaspersky.com [2015-08-08]
Chrome:
=======
CHR dev: Chrome dev build erkannt! <======= ACHTUNG
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AVP15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security Technical Preview 15.0.0\avp.exe [233552 2014-04-20] (Kaspersky Lab ZAO)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation)
S2 CPUCooLServer; C:\Program Files (x86)\CPUCooL\CooLSrv.exe [743936 2011-12-01] () [Datei ist nicht signiert]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation) [Datei ist nicht signiert]
S2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-08-30] (SurfRight B.V.)
S2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [1823952 2015-08-05] (AnchorFree Inc.)
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [96600 2015-08-05] ()
S2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [846544 2015-08-05] ()
S2 i2p; C:\Program Files (x86)\i2p\I2Psvc.exe [389632 2015-08-11] (Tanuki Software, Ltd.) [Datei ist nicht signiert]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert]
S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [38200 2015-08-04] (The OpenVPN Project)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-06-20] ()
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [Datei ist nicht signiert]
S2 Themes; C:\Windows\system32\themeservice.dll [44544 2015-08-13] (Microsoft Corporation) [Datei ist nicht signiert]
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44648 2015-06-04] (AnchorFree Inc.)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [457824 2014-02-20] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [141320 2015-08-08] (Kaspersky Lab ZAO)
S1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [243808 2014-04-10] (Kaspersky Lab ZAO)
S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [793800 2015-08-08] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO)
S3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO)
S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO)
S1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2014-03-25] (Kaspersky Lab ZAO)
S1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179296 2014-03-26] (Kaspersky Lab ZAO)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-31] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [23040 2013-07-25] (Apple Inc.) [Datei ist nicht signiert]
S2 npf; C:\Windows\System32\drivers\npf.sys [36600 2015-06-01] (Riverbed Technology, Inc.)
S1 ntiopnp; C:\Windows\System32\Drivers\ntiopnp.sys [19544 2010-11-11] ()
R3 SmbDrv; C:\Windows\System32\DRIVERS\Smb_driver.sys [21264 2011-12-22] (Synaptics Incorporated)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42088 2015-06-04] (Anchorfree Inc.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-06-10] (Apple, Inc.) [Datei ist nicht signiert]
S1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [117768 2015-07-09] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [146072 2015-07-09] (Oracle Corporation)
S2 uxstyle; \??\C:\Windows\system32\Drivers\uxstyle.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-08-31 03:22 - 2015-08-31 03:22 - 00021289 _____ C:\Users\xxx\Desktop\Addition.txt
2015-08-31 03:21 - 2015-08-31 03:54 - 00007819 _____ C:\Users\xxx\Desktop\FRST.txt
2015-08-31 03:21 - 2015-08-31 03:54 - 00000000 ____D C:\FRST
2015-08-31 03:07 - 2015-08-31 03:07 - 00000468 _____ C:\Users\xxx\Desktop\defogger_disable.log
2015-08-31 03:07 - 2015-08-31 03:07 - 00000000 _____ C:\Users\xxx\defogger_reenable
2015-08-31 02:44 - 2015-08-31 02:44 - 00003818 _____ C:\Users\xxx\Desktop\eset.txt
2015-08-31 02:25 - 2015-08-31 02:25 - 00380416 _____ C:\Users\xxx\Desktop\9ie9fcez.exe
2015-08-31 02:22 - 2015-08-31 02:22 - 02188288 _____ (Farbar) C:\Users\xxx\Desktop\FRST64.exe
2015-08-31 02:15 - 2015-08-31 02:15 - 00050477 _____ C:\Users\xxx\Desktop\Defogger.exe
2015-08-31 00:17 - 2015-08-31 00:17 - 00003360 ____N C:\bootsqm.dat
2015-08-30 23:20 - 2015-08-30 23:20 - 00008754 _____ C:\HitmanPro_20150830_2320.log
2015-08-30 21:55 - 2015-08-30 23:19 - 00000640 _____ C:\Windows\system32\.crusader
2015-08-30 21:44 - 2015-08-30 21:44 - 00001905 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2015-08-30 21:44 - 2015-08-30 21:44 - 00000000 ____D C:\Program Files\HitmanPro
2015-08-30 21:41 - 2015-08-30 21:43 - 11352032 _____ (SurfRight B.V.) C:\Users\xxx\Downloads\HitmanPro_x64.exe
2015-08-30 21:40 - 2015-08-30 21:56 - 00000000 ____D C:\ProgramData\HitmanPro
2015-08-30 19:22 - 2015-08-30 19:22 - 00299544 _____ C:\Windows\Minidump\083015-20280-01.dmp
2015-08-29 01:34 - 2015-08-29 01:34 - 00332344 _____ C:\Windows\Minidump\082915-32900-01.dmp
2015-08-29 01:33 - 2015-08-30 19:22 - 487727759 _____ C:\Windows\MEMORY.DMP
2015-08-28 23:21 - 2015-08-29 00:38 - 00000000 ____D C:\Users\xxx\Downloads\MW3 ChromatiX
2015-08-27 23:12 - 2015-08-27 23:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\2B0C5369.sys
2015-08-26 02:33 - 2015-08-31 01:09 - 00000000 ____D C:\Users\xxx\Desktop\xbab[mp3freex.com]
2015-08-25 23:16 - 2015-08-25 23:16 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\61973A00.sys
2015-08-20 01:32 - 2015-08-20 01:33 - 00000000 ____D C:\Users\xxx\Desktop\Games
2015-08-19 22:03 - 2015-08-19 22:03 - 00000218 _____ C:\Users\xxx\AppData\Local\recently-used.xbel
2015-08-19 18:04 - 2015-08-19 18:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aspyr
2015-08-19 18:02 - 2015-08-19 18:02 - 00000000 ____D C:\Program Files (x86)\Aspyr
2015-08-19 11:52 - 2015-08-19 17:24 - 00000328 _____ C:\Windows\Tasks\LoudProof.job
2015-08-19 11:52 - 2015-08-19 17:20 - 00000000 ____D C:\ProgramData\{976ab3cf-d8d2-3e4a-976a-ab3cfd8dcf3f}
2015-08-19 11:52 - 2015-08-19 11:52 - 00003236 _____ C:\Windows\System32\Tasks\LoudProof
2015-08-19 11:22 - 2015-08-26 23:07 - 00000000 ____D C:\Users\xxx\AppData\Local\NFS Underground 2
2015-08-19 11:17 - 2015-08-19 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2015-08-19 11:15 - 2015-08-19 11:15 - 00000000 ____D C:\Program Files (x86)\EA GAMES
2015-08-19 11:07 - 2015-08-31 01:05 - 00000000 ____D C:\Users\xxx\Downloads\nfsu2
2015-08-19 02:14 - 2015-08-19 02:14 - 00000000 ____D C:\Program Files (x86)\GameSpy Arcade
2015-08-19 01:53 - 2015-08-19 11:22 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-19 01:49 - 2015-08-19 01:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
2015-08-19 01:49 - 2015-08-19 01:49 - 00000000 ____D C:\Program Files (x86)\Activision
2015-08-19 01:44 - 2015-08-19 01:44 - 00000000 ____D C:\ProgramData\Steam
2015-08-19 01:39 - 2015-08-19 17:50 - 00000000 ____D C:\Program Files (x86)\Age of Empires II HD The Forgotten
2015-08-18 19:46 - 2015-08-18 19:47 - 65444688 _____ (Microsoft Corporation) C:\Users\xxx\Downloads\NDP46-KB3045557-x86-x64-AllOS-ENU.exe
2015-08-18 19:43 - 2015-08-18 20:01 - 00037993 _____ C:\Users\xxx\Documents\Unbenannt1.cpp
2015-08-18 16:31 - 2015-08-18 16:31 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Dev-Cpp
2015-08-18 13:17 - 2015-08-18 13:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodshed Dev-C++
2015-08-18 13:16 - 2015-08-18 13:16 - 00000000 ____D C:\Users\xxx\Desktop\Dev-Cpp
2015-08-18 01:00 - 2015-08-18 09:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-13 10:08 - 2015-08-13 22:35 - 00003234 _____ C:\Windows\System32\Tasks\SidebarExecute
2015-08-13 06:11 - 2015-08-13 06:11 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\0CCB001E.sys
2015-08-13 05:59 - 2015-08-13 05:59 - 00000000 ____D C:\Users\xxx\Downloads\7tsp_Vs_se7en_Pack
2015-08-13 05:46 - 2015-08-13 06:06 - 00000000 ____D C:\Windows\system32\Taskman
2015-08-13 04:36 - 2015-08-13 04:36 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Windows SideBar
2015-08-13 04:31 - 2015-08-13 05:07 - 00000000 ____D C:\Gadgets
2015-08-13 03:55 - 2015-08-19 10:50 - 00003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{8E1BA6FC-3CD5-40FE-A806-F7D9A8078D70}
2015-08-13 00:04 - 2015-08-13 03:34 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\22116713.sys
2015-08-12 17:02 - 2015-08-12 17:02 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\7ED024B6.sys
2015-08-12 17:00 - 2015-08-12 17:00 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1B282295.sys
2015-08-12 16:13 - 2015-08-12 16:13 - 00000000 ____D C:\Windows\SysWOW64\Hotspot Shield
2015-08-12 16:10 - 2015-08-12 16:10 - 00262144 _____ C:\Windows\system32\config\elam
2015-08-11 10:28 - 2015-08-31 03:42 - 00002914 _____ C:\Windows\setupact.log
2015-08-11 10:28 - 2015-08-11 10:28 - 00000000 _____ C:\Windows\setuperr.log
2015-08-11 10:27 - 2015-08-29 01:33 - 00064998 _____ C:\Windows\PFRO.log
2015-08-11 03:22 - 2015-08-11 03:22 - 00032178 _____ C:\Users\xxx\Documents\cc_20150811_032249.reg
2015-08-11 03:05 - 2015-08-11 03:05 - 00000000 ____D C:\Users\xxx\AppData\Local\CrashRpt
2015-08-11 02:55 - 2015-08-11 03:04 - 00000000 ____D C:\ProgramData\Hotspot Shield
2015-08-11 02:55 - 2015-08-11 02:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
2015-08-11 02:54 - 2015-08-20 01:37 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
2015-08-11 02:54 - 2015-08-11 02:54 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Hotspot Shield
2015-08-11 02:54 - 2015-06-04 01:02 - 00044648 _____ (AnchorFree Inc.) C:\Windows\system32\Drivers\hssdrv6.sys
2015-08-11 02:34 - 2015-08-11 02:34 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\I2P
2015-08-11 01:30 - 2015-08-31 03:42 - 00000000 ____D C:\ProgramData\i2p
2015-08-11 01:20 - 2015-08-19 17:11 - 00000000 ____D C:\Users\xxx\AppData\Roaming\I2P
2015-08-11 01:18 - 2015-08-30 19:26 - 00000000 ____D C:\Program Files (x86)\i2p
2015-08-11 01:18 - 2015-08-11 01:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I2P
2015-08-10 23:03 - 2015-08-11 03:18 - 00000000 ____D C:\Program Files (x86)\Tor Browser
2015-08-10 22:40 - 2015-08-10 22:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
2015-08-10 22:40 - 2015-08-10 22:41 - 00000000 ____D C:\Program Files\OpenVPN
2015-08-10 15:21 - 2015-08-10 15:21 - 04072200 _____ C:\Users\xxx\Downloads\TeknoMW3_ServerTool_1.5.8_ServerMonitor_1.1.exe
2015-08-10 12:21 - 2015-08-10 12:21 - 00000000 ____D C:\Users\xxx\AppData\Local\IsolatedStorage
2015-08-09 02:01 - 2015-08-11 04:54 - 00000000 ____D C:\Users\xxx\.zenmap
2015-08-09 02:00 - 2015-08-09 02:00 - 00000000 ____D C:\Program Files\WinPcap
2015-08-09 01:59 - 2015-08-09 02:01 - 00000000 ____D C:\Program Files (x86)\Nmap
2015-08-09 01:58 - 2015-08-19 01:37 - 00000000 ____D C:\Users\xxx\AppData\Roaming\inkscape
2015-08-08 23:13 - 2015-08-08 23:13 - 00001051 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape.lnk
2015-08-08 23:09 - 2015-08-08 23:13 - 00000000 ____D C:\Program Files (x86)\Inkscape
2015-08-08 17:57 - 2015-08-08 17:57 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6A4515E8.sys
2015-08-08 16:42 - 2015-08-08 16:42 - 00000000 ____D C:\Program Files (x86)\Stardock
2015-08-08 16:15 - 2015-08-08 16:15 - 00000000 ____D C:\ProgramData\Stardock
2015-08-08 16:02 - 2015-08-08 16:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2015-08-08 16:02 - 2015-08-08 16:02 - 00000000 ____D C:\Users\xxx\AppData\Local\Stardock
2015-08-08 16:02 - 2015-08-08 16:02 - 00000000 ____D C:\Users\Public\Documents\Stardock
2015-08-08 15:43 - 2015-08-08 15:43 - 00000000 ___HD C:\Program Files (x86)\InstallJammer Registry
2015-08-08 15:33 - 2015-08-12 16:10 - 00000000 ____D C:\ProgramData\{430548d0-bab8-9b04-4305-548d0bab2342}
2015-08-08 15:33 - 2015-08-08 16:53 - 00000338 _____ C:\Windows\Tasks\AlcoProof.job
2015-08-08 15:33 - 2015-08-08 15:33 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Purposeful Advice
2015-08-08 15:21 - 2015-08-08 15:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2015-08-08 15:20 - 2015-08-31 03:43 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-08-08 15:20 - 2015-08-08 15:20 - 00000000 ____D C:\Windows\ELAMBKUP
2015-08-08 15:20 - 2015-08-08 15:20 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2015-08-08 15:20 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2015-08-08 15:19 - 2015-08-08 15:55 - 00793800 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2015-08-08 15:19 - 2015-08-08 15:55 - 00141320 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2015-08-08 15:19 - 2014-04-10 17:25 - 00243808 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys
2015-08-08 15:14 - 2015-08-08 15:14 - 00270632 _____ C:\ProgramData\1439035440.bdinstall.bin
2015-08-07 12:49 - 2015-08-07 13:35 - 00000000 ____D C:\Users\xxx\Documents\VirtualDJ
2015-08-07 12:49 - 2015-08-07 12:49 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2015-08-07 12:49 - 2015-08-07 12:49 - 00000000 ____D C:\Program Files (x86)\VirtualDJ
2015-08-04 17:16 - 2015-08-04 17:16 - 00000000 ____D C:\Users\xxx\AppData\Roaming\IrfanView
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-08-31 03:49 - 2015-06-20 11:53 - 00000000 ____D C:\Users\xxx\AppData\Roaming\vlc
2015-08-31 03:49 - 2009-07-14 06:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-31 03:49 - 2009-07-14 06:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-31 03:48 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-31 03:45 - 2013-02-27 00:40 - 01478942 _____ C:\Windows\WindowsUpdate.log
2015-08-31 03:42 - 2015-07-15 02:52 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-31 03:42 - 2015-07-13 02:40 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Skype
2015-08-31 03:42 - 2015-06-20 01:20 - 00000000 ____D C:\Users\xxx\AppData\Roaming\uTorrent
2015-08-31 03:42 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-31 03:10 - 2015-04-19 14:20 - 00000554 _____ C:\Users\xxx\AppData\Roaming\a55CxS51lp6oDbN
2015-08-31 03:07 - 2015-06-19 01:57 - 00000000 ____D C:\Users\xxx
2015-08-31 02:53 - 2015-06-21 18:51 - 00000000 ____D C:\AdwCleaner
2015-08-31 01:14 - 2015-06-19 21:46 - 00000000 ___RD C:\Users\xxx\Desktop\Stuff
2015-08-31 01:07 - 2015-06-20 16:40 - 00000000 ____D C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^
2015-08-30 19:22 - 2015-07-18 20:02 - 00000000 ____D C:\Windows\Minidump
2015-08-30 13:54 - 2015-07-14 20:56 - 00000000 ____D C:\Users\xxx\.VirtualBox
2015-08-29 06:08 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2015-08-29 03:56 - 2015-07-15 03:42 - 00000000 ____D C:\Program Files (x86)\7tsp
2015-08-29 03:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Cursors
2015-08-29 03:12 - 2013-04-25 20:08 - 00000000 ____D C:\ProgramData\Skype
2015-08-26 20:40 - 2015-06-20 00:55 - 00000000 ____D C:\Users\xxx\AppData\Local\TeknoGods
2015-08-26 02:56 - 2011-04-12 09:43 - 00699666 _____ C:\Windows\system32\perfh007.dat
2015-08-26 02:56 - 2011-04-12 09:43 - 00149774 _____ C:\Windows\system32\perfc007.dat
2015-08-26 02:56 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-20 12:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2015-08-19 17:21 - 2015-06-19 01:58 - 00001421 _____ C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-18 19:57 - 2014-01-04 12:35 - 01594892 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-08-18 19:47 - 2015-07-13 18:34 - 00000000 ____D C:\Users\xxx\Documents\Visual Studio 2013
2015-08-18 09:13 - 2013-03-15 16:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-13 22:33 - 2009-07-14 06:45 - 04875472 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-13 05:37 - 2010-11-21 05:23 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2015-08-13 05:37 - 2009-07-14 01:55 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2015-08-13 05:37 - 2009-07-14 01:54 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\themeservice.dll
2015-08-13 04:47 - 2015-06-21 05:23 - 00000020 ____H C:\ProgramData\PKP_DLet.DAT
2015-08-10 23:21 - 2015-06-19 01:57 - 00000000 ____D C:\Users\xxx\AppData\Local\VirtualStore
2015-08-10 01:41 - 2015-06-20 07:22 - 00000000 ____D C:\Users\xxx\AppData\Local\Adobe
2015-08-10 01:41 - 2013-04-25 19:58 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-10 01:41 - 2013-04-25 19:58 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-08 14:06 - 2015-07-14 00:48 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2015-08-07 12:57 - 2015-06-20 23:34 - 00000000 ____D C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CPUCooL
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-04-19 14:20 - 2015-08-31 03:10 - 0000554 _____ () C:\Users\xxx\AppData\Roaming\a55CxS51lp6oDbN
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\Users\xxx\AppData\Roaming\Sci-Fi
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\Users\xxx\AppData\Roaming\Screen Saver
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\Users\xxx\AppData\Roaming\Screen Savers
2015-08-19 22:03 - 2015-08-19 22:03 - 0000218 _____ () C:\Users\xxx\AppData\Local\recently-used.xbel
2015-06-21 13:09 - 2015-06-21 13:09 - 0007605 _____ () C:\Users\xxx\AppData\Local\Resmon.ResmonCfg
2015-08-08 15:14 - 2015-08-08 15:14 - 0270632 _____ () C:\ProgramData\1439035440.bdinstall.bin
2015-06-21 05:23 - 2015-06-21 05:23 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2015-06-21 05:23 - 2015-08-13 04:47 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2015-06-21 05:23 - 2015-06-21 05:23 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\ProgramData\Services
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\ProgramData\SingleFiles
2015-06-21 05:23 - 2015-06-21 05:23 - 0000268 ___RH () C:\ProgramData\Smooth Strings
Einige Dateien in TEMP:
====================
C:\Users\xxx\AppData\Local\Temp\11d590cff4f84ae384ade7c1d0afc4f3.dll
C:\Users\xxx\AppData\Local\Temp\12cd0626caa34310af61e370f35eb6db.dll
C:\Users\xxx\AppData\Local\Temp\14dafad713ac494b816443bdc836f37f.dll
C:\Users\xxx\AppData\Local\Temp\14e508d49cd442158cd9d52b98b3d506.dll
C:\Users\xxx\AppData\Local\Temp\2dfa3d5861f74101bc780dda0bcfd1fa.dll
C:\Users\xxx\AppData\Local\Temp\31a6cee590ac4043b656da8e0595e1d8.dll
C:\Users\xxx\AppData\Local\Temp\35eceddb983b4a2cac8b76ed7429d294.dll
C:\Users\xxx\AppData\Local\Temp\3a4be230186f43f19f0b4016d189c85f.dll
C:\Users\xxx\AppData\Local\Temp\3eeb51b3723447498a49b9a74a3e9adf.dll
C:\Users\xxx\AppData\Local\Temp\44e5563ff2c34e7db3a8f2ed82480111.dll
C:\Users\xxx\AppData\Local\Temp\47167afdb6d946aebcb91474d3a89139.dll
C:\Users\xxx\AppData\Local\Temp\475f88b715d2492ca77f54e52b96587e.dll
C:\Users\xxx\AppData\Local\Temp\49c0473ed2bd414e9ec857fabd644ed7.dll
C:\Users\xxx\AppData\Local\Temp\51b34e2700484fa3b83272cfdfeea9ce.dll
C:\Users\xxx\AppData\Local\Temp\529a1aea68314b199102a761ea15d255.dll
C:\Users\xxx\AppData\Local\Temp\5f703dc7af4a458485133e098842329d.dll
C:\Users\xxx\AppData\Local\Temp\650fbc9470004a02bafee4cf79051683.dll
C:\Users\xxx\AppData\Local\Temp\68fc1c1ba1cd4507a5d442a5b9181fa3.dll
C:\Users\xxx\AppData\Local\Temp\6d45f5c516be423da169b3061c2a63d4.dll
C:\Users\xxx\AppData\Local\Temp\6db1824c4e214a5eb1f1104b44b947a1.dll
C:\Users\xxx\AppData\Local\Temp\8fc6335c749b4299a2fd33d13923d75d.dll
C:\Users\xxx\AppData\Local\Temp\920fba4d59a14eb4bcbbe40b25a308c4.dll
C:\Users\xxx\AppData\Local\Temp\940903881ace4980b949ad919dd362d5.dll
C:\Users\xxx\AppData\Local\Temp\96c23eec399e42c4a30cbf969a463455.dll
C:\Users\xxx\AppData\Local\Temp\96c68ba6661b4700810c8a9059e93cf8.dll
C:\Users\xxx\AppData\Local\Temp\99653f456d51477a8f82d52c2ed1d6bd.dll
C:\Users\xxx\AppData\Local\Temp\9b9cea71eb83436288cb42dafde6ab74.dll
C:\Users\xxx\AppData\Local\Temp\9cc4e736dd9b4c67b44a451609c98fad.dll
C:\Users\xxx\AppData\Local\Temp\a381e3fdfafc4e3db26f3b3a8ad06ba0.dll
C:\Users\xxx\AppData\Local\Temp\ad9e0686a724437c870c2c32704f936b.dll
C:\Users\xxx\AppData\Local\Temp\AutoRun.exe
C:\Users\xxx\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\xxx\AppData\Local\Temp\b36d970cdfe94a8b9520239351190ebf.dll
C:\Users\xxx\AppData\Local\Temp\b7f94411c5ed48f6939a0be97b876565.dll
C:\Users\xxx\AppData\Local\Temp\b89ae9f245d9474184d33dc5549575f9.dll
C:\Users\xxx\AppData\Local\Temp\bass.dll
C:\Users\xxx\AppData\Local\Temp\c17f53c590f54eddb8be2f94fe3e30c6.dll
C:\Users\xxx\AppData\Local\Temp\c6adfdf6d5a94aafa9dab851e1870300.dll
C:\Users\xxx\AppData\Local\Temp\c9dc9a049a554cf6b724f9cedf7fe0ab.dll
C:\Users\xxx\AppData\Local\Temp\cb4682c969aa4afd812fbbeb67afb6cc.dll
C:\Users\xxx\AppData\Local\Temp\cdabcc656d75485fa72d9870964fe2d5.dll
C:\Users\xxx\AppData\Local\Temp\ce5b1916dc9e4a349f58da1cd92fd1d1.dll
C:\Users\xxx\AppData\Local\Temp\d72ad769917a4da580b53eb4dca24fe5.dll
C:\Users\xxx\AppData\Local\Temp\d87d405cecbb4879a135fdbb265ef560.dll
C:\Users\xxx\AppData\Local\Temp\d9c5bf8700d745bda95935d86a1f9f9d.dll
C:\Users\xxx\AppData\Local\Temp\e4f4c40b55214200bdc7915838a24611.dll
C:\Users\xxx\AppData\Local\Temp\eauninstall.exe
C:\Users\xxx\AppData\Local\Temp\f05571a057bd47b1bb0d2cbf135a27c3.dll
C:\Users\xxx\AppData\Local\Temp\f9a74a53082d4fbf92257c06667146f6.dll
C:\Users\xxx\AppData\Local\Temp\fc0e5d9358c445019ad28db22080f4e7.dll
C:\Users\xxx\AppData\Local\Temp\fd75ddd6aca14f6a97ea94e42e36220f.dll
C:\Users\xxx\AppData\Local\Temp\hss_update.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-08-04 02:09
==================== Ende von FRST.txt ============================
Addition.txt: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:30-08-2015
durchgeführt von xxx (2015-08-31 03:22:37)
Gestartet von C:\Users\xxx\Desktop
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-3674743092-987190976-2435912599-500 - Administrator - Disabled)
Gast (S-1-5-21-3674743092-987190976-2435912599-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3674743092-987190976-2435912599-1004 - Limited - Enabled)
xxx (S-1-5-21-3674743092-987190976-2435912599-1003 - Administrator - Enabled) => C:\Users\xxx
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
µTorrent (HKU\S-1-5-21-3674743092-987190976-2435912599-1003\...\uTorrent) (Version: 3.4.4.40911 - BitTorrent Inc.)
µTorrent (HKU\S-1-5-21-3674743092-987190976-2435912599-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\uTorrent) (Version: 3.4.4.40911 - BitTorrent Inc.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Reader XI - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Age of Empires II HD The Forgotten (HKLM-x32\...\QWdlb2ZFbXBpcmVzSUlIRFRoZUZvcmdvdHRlbg==_is1) (Version: 1 - )
AMD Catalyst Install Manager (HKLM\...\{F856881A-D370-B1A7-2AFF-128F4AA93558}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.12.13 - Atheros Communications Inc.)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
AzureTools.Notifications (x32 Version: 2.1.10731.1602 - Microsoft Corporation) Hidden
Behaviors SDK (XAML) for Visual Studio (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden
Blend for Visual Studio 2013 (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden
Blend for Visual Studio 2013 ENU resources (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Build Tools - amd64 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools - x86 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools Language Resources - amd64 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Build Tools Language Resources - x86 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
CPUCooL (remove only) (HKLM-x32\...\CPUCooL) (Version: - )
Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.11 - Bloodshed Software)
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4954.46574 - PreEmptive Solutions) Hidden
Entity Framework Tools for Visual Studio 2013 (HKLM-x32\...\{08AEF86A-1956-4846-B906-B01350E96E30}) (Version: 12.0.20912.0 - Microsoft Corporation)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.245 - SurfRight B.V.)
Hotspot Shield 4.20.5 (HKLM-x32\...\HotspotShield) (Version: 4.20.5 - AnchorFree Inc.)
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version: - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version: - )
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Inkscape 0.91 (HKLM-x32\...\Inkscape) (Version: 0.91 - )
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
IsoBuster 3.6 (HKLM-x32\...\IsoBuster_is1) (Version: 3.6 - Smart Projects)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
JavaScript Tooling (Version: 12.0.21005 - Microsoft Corporation) Hidden
Kaspersky Internet Security Technical Preview (HKLM-x32\...\InstallWIX_{653C1B5A-3287-47B1-8613-0745D4E771C4}) (Version: 15.0.0.463 - Kaspersky Lab)
Kaspersky Internet Security Technical Preview (x32 Version: 15.0.0.463 - Kaspersky Lab) Hidden
LocalESPC Dev12 (x32 Version: 8.100.25984 - Microsoft Corporation) Hidden
LocalESPCui for en-us Dev12 (x32 Version: 8.100.25984 - Microsoft) Hidden
Mac OS X Cursors (HKLM-x32\...\48AEB547-6B1C-4CFC-957B-E11C22C8A25F) (Version: 1.1 - www.46palermo.com)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.6 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{58FED865-4F13-408D-A5BF-996019C4B936}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework (HKLM-x32\...\{1B876496-B3A2-4D22-9B12-B608A3FD4B8B}) (Version: 11.1.2902.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework (x64) (HKLM\...\{A6BA243E-85A3-4635-A269-32949C98AC7F}) (Version: 11.1.2902.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{6C026A91-640F-4A23-8B68-05D589CC6F18}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects (HKLM-x32\...\{2F7DBBE6-8EBC-495C-9041-46A772F4E311}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects (x64) (HKLM\...\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client (HKLM\...\{D411E9C9-CE62-4DBF-9D92-4CB22B750ED5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{54C5041B-0E91-4E92-8417-AAA12493C790}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service (HKLM-x32\...\{04DD7AF4-A6D3-4E30-9BB9-3B3670719234}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (12.0.30919.1) (HKLM-x32\...\{0D7FCBFB-F478-4D32-901C-83F0BF5A3501}) (Version: 12.0.30919.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1) (HKLM-x32\...\{6781FF9B-E87D-4A03-9373-A55A288B83FA}) (Version: 12.0.30919.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{070C38AC-05CE-43DF-9A20-141332F6AB2B}) (Version: 11.1.3366.16 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{05FF8209-C4F1-4C77-BC28-791653156D20}) (Version: 11.1.3366.16 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{b341426f-8543-4e0d-96c3-e976f8ec5ab6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{4fd02573-5f12-4ae4-8027-c63f8e1115af}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.40820 - Microsoft Corporation)
Microsoft Visual Studio Professional 2013 (HKLM-x32\...\{6dff50d0-3bc3-4a92-b724-bf6d6a99de4f}) (Version: 12.0.21005.13 - Microsoft Corporation)
Microsoft Web Deploy 3.5 (HKLM\...\{3674F088-9B90-473A-AAC3-20A00D8D810C}) (Version: 3.1237.1762 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minimal ADB and Fastboot version 1.1.3 (HKLM-x32\...\{DE46417A-9E9E-4BCD-BBDD-DA21943193BB}_is1) (Version: 1.1.3 - )
Mozilla Firefox 40.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 40.0.2 (x86 de)) (Version: 40.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.2.5702 - Mozilla)
Need for Speed Underground 2 (HKLM-x32\...\{909F8EBC-EC7F-48FF-0085-475D818F0F31}) (Version: - )
Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.0.1 - Nikon)
Nmap 6.49BETA4 (HKLM-x32\...\Nmap) (Version: - )
Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
OpenVPN 2.3.8-I601 (HKLM\...\OpenVPN) (Version: 2.3.8-I601 - )
Oracle VM VirtualBox 5.0.0 (HKLM\...\{FCD0B365-2189-45F3-9AF2-2BCED86C121A}) (Version: 5.0.0 - Oracle Corporation)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Picture Control Utility (HKLM-x32\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.2.2 - Nikon)
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.3197.1 - PreEmptive Solutions) Hidden
Premium Sound HD (HKLM\...\{439A73C2-8CFA-4630-8484-36BCA2AEBB0A}) (Version: 1.12.0300 - SRS Labs, Inc.)
Prerequisites for SSDT (HKLM-x32\...\{35C1D9D6-87C0-46A3-B1B4-EDBCC063221C}) (Version: 11.1.3000.0 - Microsoft Corporation)
Python Tools Redirection Template (x32 Version: 1.1 - Microsoft Corporation) Hidden
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RawTherapee Version 4.1 (HKLM\...\{128459AB-59A7-430A-8BD0-3D8803D50400}_is1) (Version: 4.1 - rawtherapee.com)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7601.39013 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SharePoint Client Components (Version: 15.0.4481.1505 - Microsoft Corporation) Hidden
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.103 - Skype Technologies S.A.)
Stardock CursorFX (HKLM-x32\...\CursorFX) (Version: 2.16 - Stardock Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.39.0 - Synaptics Incorporated)
Team Explorer for Microsoft Visual Studio 2013 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Technitium MAC Address Changer v6.0 (HKLM-x32\...\TMACv6.0) (Version: 6.0 - Technitium)
Tony Hawk's Pro Skater 2 (HKLM-x32\...\Activision_THPS2UninstallKey) (Version: - )
Tony Hawks Pro Skater 4 (HKLM-x32\...\{E0F07676-2C60-4465-A727-20DE3BFCABAC}) (Version: 1.00.0000 - Aspyr Media)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.2.3.0 - TOSHIBA CORPORATION)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.11 for x64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{97965331-BC5D-4D9F-B6DF-5C0A123E4AE0}) (Version: 2.1.0.8 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\...\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 2.0.3.33 - TOSHIBA Corporation)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.2 - TrueCrypt Foundation)
Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
ViewNX 2 (HKLM-x32\...\{DDD62492-32A7-412B-8AF1-2CF032AD42E3}) (Version: 2.1.2 - Nikon)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes)
VirtualDJ 8 (HKLM-x32\...\{F7A68F9D-BBF0-48FF-B138-2EFB5165638C}) (Version: 8.0.2048.0 - Atomix Productions)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WCF Data Services 5.6.0 Runtime (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2013 (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation)
Windows-Treiberpaket - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/28/2014 11.0.0000.00000) (HKLM\...\092555911492C6959D2596D612F52DCA71881CA2) (Version: 08/28/2014 11.0.0000.00000 - Google, Inc.)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - CACE Technologies)
WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - )
Workflow Manager Client 1.0 (Version: 2.0.30813.2 - Microsoft Corporation) Hidden
Workflow Manager Tools 1.0 for Visual Studio (Version: 2.0.30725.1 - Microsoft Corporation) Hidden
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Wiederherstellungspunkte =========================
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ___RA C:\Windows\system32\Drivers\etc\hosts
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0BE85537-5689-4DEC-A3DC-38D5103862F5} - System32\Tasks\LoudProof => c:\programdata\{976ab3cf-d8d2-3e4a-976a-ab3cfd8dcf3f}\gamesetup.exe <==== ACHTUNG
Task: {1866A771-138D-42A2-A49E-75E52E7A73E2} - \Winsta Update -> Keine Datei <==== ACHTUNG
Task: {1EFEA92F-7139-4B35-90E8-A70F424EE846} - \avabvbavad -> Keine Datei <==== ACHTUNG
Task: {22479C06-B56A-465A-85A8-2023774CA229} - \AdobeAAMUpdater-1.0-Toshiba-xxx -> Keine Datei <==== ACHTUNG
Task: {3A062199-CB44-413C-8C4D-3B2D460E9169} - \DFOZSNJILP -> Keine Datei <==== ACHTUNG
Task: {43CDEEEB-2B15-4B93-A047-D0E04BEFB0D2} - \SmartWeb Upgrade Trigger Task -> Keine Datei <==== ACHTUNG
Task: {54A49564-469B-42CD-A0B6-D40B54CA3262} - \{F05C6774-D1E3-400A-BF54-41B6C72D18A2} -> Keine Datei <==== ACHTUNG
Task: {6B4F8AD2-B802-4DD1-B75C-64B14A7F8AA3} - \{FE848F92-98FB-4AE7-8ACF-723F8C49ACFA} -> Keine Datei <==== ACHTUNG
Task: {80B64C67-A468-4821-9528-DBCA0ED3D8E9} - \AlcoProof -> Keine Datei <==== ACHTUNG
Task: {92C91CDB-6A66-4AB3-A6C0-7469F499F2A5} - \{4F923200-1F8D-4530-B555-4126DD1B7551} -> Keine Datei <==== ACHTUNG
Task: {A252F268-C7A4-4D31-A02A-01313845B979} - \{6654E48F-0F72-403A-A2D3-22F84DE6DC43} -> Keine Datei <==== ACHTUNG
Task: {AAE6A730-1FD5-49F5-B490-24D0FB6DF6B9} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender 2015\bdproductdata.exe
Task: {BD523089-A475-47B5-868E-191D7A91078C} - \Convertor -> Keine Datei <==== ACHTUNG
Task: {BF4E57C6-DED3-4243-BE72-8BC467A5D265} - \ProPCCleaner_Start -> Keine Datei <==== ACHTUNG
Task: {CAD68D5D-6CFD-45D5-94DC-BB00116DF5AB} - \{25059126-90E9-4B17-9F87-45C87C21A8BF} -> Keine Datei <==== ACHTUNG
Task: {CE157836-4F37-44AF-A43C-C1BA6D1B3BE9} - \CCleanerSkipUAC -> Keine Datei <==== ACHTUNG
Task: {F65255A3-6739-4815-B76A-B14C22706714} - \ProPCCleaner_Popup -> Keine Datei <==== ACHTUNG
Task: {F9E8E8DD-1416-49B9-A373-234659E52054} - \WinKit -> Keine Datei <==== ACHTUNG
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\Windows\Tasks\AlcoProof.job => c:\programdata\{430548d0-bab8-9b04-4305-548d0bab2342}\kis-2015 patch.exe <==== ACHTUNG
Task: C:\Windows\Tasks\LoudProof.job => c:\programdata\{976ab3cf-d8d2-3e4a-976a-ab3cfd8dcf3f}\gamesetup.exe <==== ACHTUNG
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
Gmer.txt: Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-08-31 08:58:47
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MQ01ABD100 rev.AX002M 931,51GB
Running: 9ie9fcez.exe; Driver: C:\Users\xxx\AppData\Local\Temp\pxldipow.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\446d57d52051 (not active ControlSet)
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\446d57d52051
Reg HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\446d57d52051 (not active ControlSet)
---- EOF - GMER 2.1 ----
Code:
ATTFilter HitmanPro 3.7.9.245
www.hitmanpro.com
Computer name . . . . : XXX
Windows . . . . . . . : 6.1.1.7601.X64/8
Safe Mode Boot . . . : NETWORK
User name . . . . . . : XXX\xxx
UAC . . . . . . . . . : Disabled
License . . . . . . . : Trial (29 days left)
Scan date . . . . . . : 2015-08-31 23:34:16
Scan mode . . . . . . : Normal
Scan duration . . . . : 8m 57s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 3
Traces . . . . . . . : 9
Objects scanned . . . : 2.066.943
Files scanned . . . . : 115.049
Remnants scanned . . : 675.782 files / 1.276.112 keys
Malware _____________________________________________________________________
C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\multi-player.exe
Size . . . . . . . : 8.045.588 bytes
Age . . . . . . . : 21.4 days (2015-08-10 14:40:18)
Entropy . . . . . : 8.0
SHA-256 . . . . . : 19BF61F477F8A0653ECB6EE3EA87F78DC297E31136E69FB670B166BC9DBDEC62
> Bitdefender . . . : Trojan.Generic.12373416
Fuzzy . . . . . . : 109.0
References
HKU\S-1-5-21-3674743092-987190976-2435912599-1003\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\multi-player.exe
Forensic Cluster
-1.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\exposed.dll
-0.9s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\gener.dll
-0.9s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\generico.dll
-0.9s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\How-to-play-after-update.txt
0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\multi-player.exe
0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\MW3 Launcher Update.exe
0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\single-player.exe
0.9s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\steam_appid.txt
1.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\VMProtectSDK32.dll
1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\dw\Favorities.slist
1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\0.sdm
1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\42695.sdm
1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\42696.sdm
1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\42697.sdm
1.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\42698.sdm
C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\TeknoMW3.dll
Size . . . . . . . : 1.158.144 bytes
Age . . . . . . . : 21.4 days (2015-08-10 14:51:03)
Entropy . . . . . : 7.9
SHA-256 . . . . . : E743B6B2EC8F49ACF8CCDE78445D0CC023147CE8ECBE0E4F0CEF281AF2FAAC62
> Bitdefender . . . : Trojan.Generic.12373416
Fuzzy . . . . . . : 114.0
Forensic Cluster
-0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\
-0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\main\
-0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\main\iw_23.iwd
-0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\main\iw_24.iwd
-0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\
-0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\
-0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\code_post_gfx.ff
-0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\code_post_gfx_mp.ff
-0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\code_pre_gfx.ff
-0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\code_pre_gfx_mp.ff
-0.3s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\localized_code_post_gfx_mp.ff
-0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\localized_code_pre_gfx_mp.ff
-0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\localized_ui_mp.ff
-0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch.ff
-0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_hamburg.ff
-0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_hijack.ff
-0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_innocent.ff
-0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_london.ff
-0.2s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_aground_ss.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_burn_ss.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_cement.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_courtyard_ss.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_crosswalk_ss.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_dome.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_exchange.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_hillside_ss.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_lambeth.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_morningwood.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_paris.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_park.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_qadeem.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_radar.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_restrepo_ss.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_six_ss.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_underground.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_mp_village.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_paris_ac130.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_prague_escape.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_escape_hamburg.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_ied_berlin.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_littlebird_payback.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_bootleg.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_cement.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_dome.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_morningwood.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_park.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_survival_mp_village.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_so_zodiac2_ny_harbor.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_specialops.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_berlin.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_intro.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_ny_harbor.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_ny_manhattan.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_sp_warlord.ff
-0.1s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\patch_survival.ff
-0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\ui.ff
-0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\zone\english\ui_mp.ff
-0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\client.wyc
-0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\steam_api.dll
0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\TeknoMW3.dll
0.0s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\TeknoMW3.exe
0.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\cclient_2.7.3.7\TeknoMW3_Update.exe
18.8s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\TeknoMW3_Update.exe
21.5s C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\Call of Duty Modern Warfare 3\main\iw_24.iwd
C:\Users\xxx\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^\TEKNOMW3FILES\client_2.7.3.7\TeknoMW3.dll
Size . . . . . . . : 1.158.144 bytes
Age . . . . . . . : 41.6 days (2015-07-21 10:08:53)
Entropy . . . . . : 7.9
SHA-256 . . . . . : E743B6B2EC8F49ACF8CCDE78445D0CC023147CE8ECBE0E4F0CEF281AF2FAAC62
> Bitdefender . . . : Trojan.Generic.12373416
Fuzzy . . . . . . : 114.0
Suspicious files ____________________________________________________________
C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-shm
Size . . . . . . . : 32.768 bytes
Age . . . . . . . : 0.0 days (2015-08-31 22:53:56)
Entropy . . . . . : 5.6
SHA-256 . . . . . : 321E810FB5ACDC59E5A2F24B380C82E187ED15F5F1FB3762AE2B99B15A1DDC55
Product . . . . . : Microsoft® Windows® Operating System
Publisher . . . . : Microsoft Corporation
Description . . . : Remote Desktop Generic USB Driver
Version . . . . . : 6.1.7601.17514
Copyright . . . . : © Microsoft Corporation. All rights reserved.
LanguageID . . . . : 1033
Fuzzy . . . . . . : 48.0
The file is hidden from Windows API. This is typical for malware.
The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
The file name extension of this program is not common.
Time indicates that the file appeared recently on this computer.
The file is in use by one or more active processes.
The file is a device driver. Device drivers run as trusted (highly privileged) code.
Forensic Cluster
-16.6s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\revocations.txt
-15.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-wal
-15.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-shm
-15.5s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webapps\webapps.json
-15.4s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\sessionCheckpoints.json
-15.1s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cookies.sqlite-wal
-15.1s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cookies.sqlite-shm
-11.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\08390A20B59A7060A1C2F75B0F327F62A023CEE6
-11.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\39FF5907CAB2DAA38CA0327D3206B962B3B3E745
-10.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\36569E711477EE052773D7D72F738A4719B48377
-9.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webappsstore.sqlite-wal
-9.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webappsstore.sqlite-shm
-9.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\directoryLinks.json
-6.8s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\sessionstore-backups\recovery.bak
-6.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EB748F82B405287A0C467E1289B4A25ED0A363A1
-5.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3ADCE44D1AEDA7677FC3F83EC20BBF2B1ADCB7B7
-5.0s C:\Users\xxx\AppData\Local\Temp\etilqs_bRrFuFtgj5ocWxi
-5.0s C:\Users\xxx\AppData\Local\Temp\etilqs_FLv6uQezXbd9Mzs
-4.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\4F53355D5A7A33C43A579E6A37E7ADC48F13CEC9
-4.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E0CDEFC7594B66588A783144A2DFCFBDDC604C36
-3.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D103B4C13B80196FD20D11F5EF2A76B61CC8D7F8
-0.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1686520AE5A04A249C5F4B73063B1ED2861894E5
-0.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\B8A5D55A6A1E5E8FDAC2D0C6356CBCF99157B9D4
-0.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-wal
0.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-shm
0.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C760A8FDDB87F07F0B76CC26655736C1BFB32978
0.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\8608C899AE5A354371E1055D50A6DC9325A4FC17
1.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A128FF81D21259C26E770DBEDD7168C1CFDB25E1
1.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\679DBEBB015A009317946FB791A8797ACEF0BDBD
2.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\694C24F8BAB03DE803E25A18F3EE2A2594997E68
4.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\56CBC047DCBB5AB07CFCBA84ABF338CB2F1FC6DC
5.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3AA08DA7102A7B37A81ED99732EF2F240A626469
5.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DDA136C8BDCC5D6A89E403D0F0861969783DB5A4
6.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31F63A3D6DC081D114C22FEB4D917AAE29152C43
6.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E4C7FF3F2A85A6A0BB8F74ACA7DA48A57376E338
7.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\CC3FA6DA28A4CBC6E00744F0AECB2800A7E4E632
9.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\9BA79DEE79C3F2261B9E4042657756B35FB38B27
9.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DFFDC978BEE11579705ED27DD479C3E471F22E59
10.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\AE6CEF5AC399403C340F019E30042F3B09528E2C
13.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\352ADD13304A8EA6BCEACDE948E85EE15A5536DF
17.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F4EF60D2DD717CC8C7167E9AFEDF685A19F657B4
18.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\05A38ABF159077A9B86B8CD447AE9DFA713822AF
18.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\630967E047618112554D86B317740983B7EA941B
18.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D3233DC1A750F0BCBD0E30B3EF74CF09FBAFCCC0
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\01CE926D1AF998DFB14DC38ECB660437C799E1D9
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A77CA4B03778D91B9A1E8C3F819265AE851E805B
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\72F27A73F60E232FE099C70D7E3460D01B68D059
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\27EBBD4959998E6DC866C944712C87638615D449
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\59C73A640FAEF18D5E915E71F540A3DA6CE66941
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0BE107C9106736426E1C782BD276CFFAE6E31254
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A76272BAD977F006EEFDDC6A91550FA32792473B
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\8415235A64BC3B87475D6BB8845381A03461ADAE
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0CA7A5A4F8226D22B92E85A5E18AB1742214BEC0
18.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C6934EFB0F32BA60EB8B572D8D272D1650A39446
18.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F73521CA494258FCC3B2A0A09DFA5093B1AEE612
18.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0957C95B0A19F22426127910130B6CD4B3FF987A
18.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F1343EBFA146EF7382E54FEBCC57FD22B731673A
18.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D0409148DFB2CB6A488A462DA4E89E1E22E5AAE2
18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\7D9BA45C7451E5EC64D8D5906322EDCFF659E16A
18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\9AE52A91C9DE51D341DD41E6390AC5E0EDED17A4
18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\667793EFF3A274291541CD256CB070593EB79B19
18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F56260859FFF9F054B435363CE122CBA06DCFC9F
18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\27A453963E993390A5CD9CCD1868B11D44A81EDA
18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DAC7F766D262263CE7BCA551CA0A3C1975D87A10
18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\4AE6E3AA65D9D60916361725268EAEC2CA34B6AF
18.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31196827406DA57C90881A88195B8849C8BF0BEA
18.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\6818565905DCF3E6663570F8DF800AD4F6527DE7
19.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\75B4A8CBFA98A3884D8115A47DB099989AA14FB5
22.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D91B00DDD7EC21BDD5D0ABD4FEF1F2E7690F73F1
41.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\crashes\store.json.mozlz4
43.4s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\adblockplus\patterns.ini
44.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\84B06F9721F0BBD5FFB2BDED44BA98CE8FF03F66
44.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1B64EB7463DB9D7DC9745EA37AA263B739E35C14
48.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\adblockplus\elemhide.css
48.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0783065335759578BEAD953BDB648B309F5A0A12
48.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\CEA2DD6F31D9D48A6BAE06940A28D7D9ABE10DDC
48.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\43D0A329B2F370975E0562603A8E0D63151C453B
48.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3583C39E2DC1D70D1A9FA4F66F92D0985CBB8DE8
61.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C8280EA2FFA428364EE23F31758CF31810005E1E
61.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A454585B024CBD141D85594968B33288DAADD713
61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C30EFFDBB49AE0B20BD4ED3903E9486A78B03284
61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EB9F7E6523DF30ED3C4F21C342211C4DAA0599E6
61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31C13251D2BDF7641D6134057AB64B2D2D1BCD1F
61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\794C8766DA5A87E4DFA72D6684F07ADF1E5589A9
61.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D9694BA649B822C154EF7CDC694DBA3BE42FABAB
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F05C999A73F203853BEC696830B6A73F615641FE
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\ECE118C79EF305336862F896E8E43307D79C10F9
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\B1570C6EBCA59F8100614FC8C30A8C9E6FB41AEA
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E0C2FA7DC37DA3F98E7448323522FFCC81AD461A
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0773B826DD1C2064375C255B7AF9035367CDBA8A
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E62CC7CB72EB558F6DA3C625AECA1A6F2450655A
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\290CAEC5E0A8A078A4738F1D0367B947525100BF
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1994A21070F0BE056ED2AF54D8C9CD946B029452
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EBF32C8EE33B785EBB787522EC7460D6EA01A964
61.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\711A8797FEF201C319196FF97A58A08D93557998
62.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\97F9495FAE777BDDA5EEAF8CB6FA2BA5FBCE3CEA
62.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\025E754E03664FA82C72BD5C010D4149A7C14B63
69.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A2D141634F2EF4238440EECD0D155B4ECDED7D98
70.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D8B7F5F0A7403645D443D2E804EEC41AE0726301
70.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\FB59CA83515EBB883B60A4A595D0C1F286FF5D6A
70.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\346A94DA1FC4D458E00BB346625FAB0C6D346F6B
70.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\430FABFBDDAF5B10292D83A6012C8ABEE4AA0247
70.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\42691B662FE5595D2EA40D22D213DD5B8F1D4C17
C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-shm
Size . . . . . . . : 32.768 bytes
Age . . . . . . . : 0.0 days (2015-08-31 22:53:40)
Entropy . . . . . : 5.4
SHA-256 . . . . . : FE1947F538EE41FFFAF2D805C99FBD7C78F0C48CC5DB70CEDFED108F7A7085DE
Product . . . . . : Microsoft® Windows® Operating System
Publisher . . . . : Microsoft Corporation
Description . . . : VGA/Super VGA Video Driver
Version . . . . . : 6.1.7600.16385
LanguageID . . . . : 0
Fuzzy . . . . . . : 48.0
The file is hidden from Windows API. This is typical for malware.
The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
The file name extension of this program is not common.
Time indicates that the file appeared recently on this computer.
The file is in use by one or more active processes.
The file is a device driver. Device drivers run as trusted (highly privileged) code.
Forensic Cluster
-0.7s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\revocations.txt
0.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-wal
0.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\places.sqlite-shm
0.4s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webapps\webapps.json
0.4s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\sessionCheckpoints.json
0.7s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cookies.sqlite-wal
0.7s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cookies.sqlite-shm
4.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\08390A20B59A7060A1C2F75B0F327F62A023CEE6
4.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\39FF5907CAB2DAA38CA0327D3206B962B3B3E745
5.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\36569E711477EE052773D7D72F738A4719B48377
6.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webappsstore.sqlite-wal
6.0s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\webappsstore.sqlite-shm
6.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\directoryLinks.json
9.1s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\sessionstore-backups\recovery.bak
9.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EB748F82B405287A0C467E1289B4A25ED0A363A1
10.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3ADCE44D1AEDA7677FC3F83EC20BBF2B1ADCB7B7
10.9s C:\Users\xxx\AppData\Local\Temp\etilqs_bRrFuFtgj5ocWxi
10.9s C:\Users\xxx\AppData\Local\Temp\etilqs_FLv6uQezXbd9Mzs
11.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\4F53355D5A7A33C43A579E6A37E7ADC48F13CEC9
11.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E0CDEFC7594B66588A783144A2DFCFBDDC604C36
12.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D103B4C13B80196FD20D11F5EF2A76B61CC8D7F8
15.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1686520AE5A04A249C5F4B73063B1ED2861894E5
15.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\B8A5D55A6A1E5E8FDAC2D0C6356CBCF99157B9D4
15.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-wal
15.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\healthreport.sqlite-shm
16.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C760A8FDDB87F07F0B76CC26655736C1BFB32978
16.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\8608C899AE5A354371E1055D50A6DC9325A4FC17
17.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A128FF81D21259C26E770DBEDD7168C1CFDB25E1
17.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\679DBEBB015A009317946FB791A8797ACEF0BDBD
17.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\694C24F8BAB03DE803E25A18F3EE2A2594997E68
20.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\56CBC047DCBB5AB07CFCBA84ABF338CB2F1FC6DC
20.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3AA08DA7102A7B37A81ED99732EF2F240A626469
21.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DDA136C8BDCC5D6A89E403D0F0861969783DB5A4
22.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31F63A3D6DC081D114C22FEB4D917AAE29152C43
22.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E4C7FF3F2A85A6A0BB8F74ACA7DA48A57376E338
23.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\CC3FA6DA28A4CBC6E00744F0AECB2800A7E4E632
25.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\9BA79DEE79C3F2261B9E4042657756B35FB38B27
25.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DFFDC978BEE11579705ED27DD479C3E471F22E59
26.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\AE6CEF5AC399403C340F019E30042F3B09528E2C
29.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\352ADD13304A8EA6BCEACDE948E85EE15A5536DF
33.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F4EF60D2DD717CC8C7167E9AFEDF685A19F657B4
34.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\05A38ABF159077A9B86B8CD447AE9DFA713822AF
34.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\630967E047618112554D86B317740983B7EA941B
34.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D3233DC1A750F0BCBD0E30B3EF74CF09FBAFCCC0
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\01CE926D1AF998DFB14DC38ECB660437C799E1D9
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A77CA4B03778D91B9A1E8C3F819265AE851E805B
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\72F27A73F60E232FE099C70D7E3460D01B68D059
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\27EBBD4959998E6DC866C944712C87638615D449
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\59C73A640FAEF18D5E915E71F540A3DA6CE66941
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0BE107C9106736426E1C782BD276CFFAE6E31254
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A76272BAD977F006EEFDDC6A91550FA32792473B
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\8415235A64BC3B87475D6BB8845381A03461ADAE
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0CA7A5A4F8226D22B92E85A5E18AB1742214BEC0
34.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C6934EFB0F32BA60EB8B572D8D272D1650A39446
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F73521CA494258FCC3B2A0A09DFA5093B1AEE612
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0957C95B0A19F22426127910130B6CD4B3FF987A
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F1343EBFA146EF7382E54FEBCC57FD22B731673A
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D0409148DFB2CB6A488A462DA4E89E1E22E5AAE2
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\7D9BA45C7451E5EC64D8D5906322EDCFF659E16A
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\9AE52A91C9DE51D341DD41E6390AC5E0EDED17A4
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\667793EFF3A274291541CD256CB070593EB79B19
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F56260859FFF9F054B435363CE122CBA06DCFC9F
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\27A453963E993390A5CD9CCD1868B11D44A81EDA
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\DAC7F766D262263CE7BCA551CA0A3C1975D87A10
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\4AE6E3AA65D9D60916361725268EAEC2CA34B6AF
34.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31196827406DA57C90881A88195B8849C8BF0BEA
34.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\6818565905DCF3E6663570F8DF800AD4F6527DE7
35.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\75B4A8CBFA98A3884D8115A47DB099989AA14FB5
38.2s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D91B00DDD7EC21BDD5D0ABD4FEF1F2E7690F73F1
56.8s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\crashes\store.json.mozlz4
59.3s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\adblockplus\patterns.ini
60.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\84B06F9721F0BBD5FFB2BDED44BA98CE8FF03F66
60.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1B64EB7463DB9D7DC9745EA37AA263B739E35C14
63.9s C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\adblockplus\elemhide.css
64.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0783065335759578BEAD953BDB648B309F5A0A12
64.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\CEA2DD6F31D9D48A6BAE06940A28D7D9ABE10DDC
64.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\43D0A329B2F370975E0562603A8E0D63151C453B
64.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\3583C39E2DC1D70D1A9FA4F66F92D0985CBB8DE8
77.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C8280EA2FFA428364EE23F31758CF31810005E1E
77.4s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A454585B024CBD141D85594968B33288DAADD713
77.5s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\C30EFFDBB49AE0B20BD4ED3903E9486A78B03284
77.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EB9F7E6523DF30ED3C4F21C342211C4DAA0599E6
77.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\31C13251D2BDF7641D6134057AB64B2D2D1BCD1F
77.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\794C8766DA5A87E4DFA72D6684F07ADF1E5589A9
77.6s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D9694BA649B822C154EF7CDC694DBA3BE42FABAB
77.7s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\F05C999A73F203853BEC696830B6A73F615641FE
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\ECE118C79EF305336862F896E8E43307D79C10F9
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\B1570C6EBCA59F8100614FC8C30A8C9E6FB41AEA
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E0C2FA7DC37DA3F98E7448323522FFCC81AD461A
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\0773B826DD1C2064375C255B7AF9035367CDBA8A
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\E62CC7CB72EB558F6DA3C625AECA1A6F2450655A
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\290CAEC5E0A8A078A4738F1D0367B947525100BF
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\1994A21070F0BE056ED2AF54D8C9CD946B029452
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\EBF32C8EE33B785EBB787522EC7460D6EA01A964
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\711A8797FEF201C319196FF97A58A08D93557998
77.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\97F9495FAE777BDDA5EEAF8CB6FA2BA5FBCE3CEA
77.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\025E754E03664FA82C72BD5C010D4149A7C14B63
85.8s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\A2D141634F2EF4238440EECD0D155B4ECDED7D98
85.9s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\D8B7F5F0A7403645D443D2E804EEC41AE0726301
86.0s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\FB59CA83515EBB883B60A4A595D0C1F286FF5D6A
86.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\346A94DA1FC4D458E00BB346625FAB0C6D346F6B
86.1s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\430FABFBDDAF5B10292D83A6012C8ABEE4AA0247
86.3s C:\Users\xxx\AppData\Local\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\cache2\entries\42691B662FE5595D2EA40D22D213DD5B8F1D4C17
C:\Users\xxx\Desktop\FRST64.exe
Size . . . . . . . : 2.188.288 bytes
Age . . . . . . . : 0.9 days (2015-08-31 02:22:34)
Entropy . . . . . : 7.5
SHA-256 . . . . . : 06B2C8DEAA568DD38CB8451EA21AE7BAECFAFB8F7FA674D8C3EA035493FBA8FD
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-398.9s C:\Users\xxx\Desktop\9ie9fcez.exe
-388.8s C:\Users\xxx\Desktop\FRST64.exe
Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 31.08.2015 Suchlaufzeit: 23:56 Protokolldatei: Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.08.31.04 Rootkit-Datenbank: v2015.08.16.01 Lizenz: Premium-Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: xxx Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 432242 Abgelaufene Zeit: 28 Min., 13 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Warnen PUM: Warnen Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) Code:
ATTFilter # AdwCleaner v3.001 - Report created 01/09/2015 at 00:32:18
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : xxx - XXX
# Running from : C:\Users\xxx\Desktop\Stuff\tools\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\jetpack
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16750
-\\ Mozilla Firefox v40.0.2 (x86 de)
[ File : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\ks5t7hh7.default-1435098893833\prefs.js ]
*************************
AdwCleaner[R0].txt - [4071 octets] - [21/06/2015 18:51:12]
AdwCleaner[R10].txt - [4613 octets] - [19/08/2015 12:13:22]
AdwCleaner[R11].txt - [2114 octets] - [19/08/2015 17:34:28]
AdwCleaner[R12].txt - [2343 octets] - [29/08/2015 03:40:58]
AdwCleaner[R13].txt - [2466 octets] - [30/08/2015 14:39:39]
AdwCleaner[R14].txt - [2588 octets] - [31/08/2015 02:52:00]
AdwCleaner[R15].txt - [1123 octets] - [01/09/2015 00:32:18]
AdwCleaner[R1].txt - [1835 octets] - [22/06/2015 01:17:53]
AdwCleaner[R2].txt - [1223 octets] - [22/06/2015 03:20:17]
AdwCleaner[R3].txt - [1115 octets] - [22/06/2015 03:42:19]
AdwCleaner[R4].txt - [1345 octets] - [22/06/2015 12:20:06]
AdwCleaner[R5].txt - [3009 octets] - [23/06/2015 23:18:29]
AdwCleaner[R6].txt - [1501 octets] - [23/06/2015 23:23:44]
AdwCleaner[R7].txt - [1703 octets] - [27/06/2015 01:12:09]
AdwCleaner[R8].txt - [1755 octets] - [27/06/2015 01:16:14]
AdwCleaner[R9].txt - [2329 octets] - [14/08/2015 20:52:41]
AdwCleaner[S0].txt - [3171 octets] - [21/06/2015 18:52:02]
AdwCleaner[S10].txt - [3160 octets] - [19/08/2015 17:21:36]
AdwCleaner[S11].txt - [2177 octets] - [19/08/2015 17:35:20]
AdwCleaner[S12].txt - [2410 octets] - [29/08/2015 03:41:49]
AdwCleaner[S13].txt - [2532 octets] - [30/08/2015 14:40:43]
AdwCleaner[S1].txt - [1741 octets] - [22/06/2015 01:18:40]
AdwCleaner[S2].txt - [1293 octets] - [22/06/2015 03:21:13]
AdwCleaner[S3].txt - [1177 octets] - [22/06/2015 03:42:56]
AdwCleaner[S4].txt - [1411 octets] - [22/06/2015 12:21:39]
AdwCleaner[S5].txt - [2858 octets] - [23/06/2015 23:19:37]
AdwCleaner[S6].txt - [1562 octets] - [23/06/2015 23:24:23]
AdwCleaner[S7].txt - [1729 octets] - [27/06/2015 01:13:07]
AdwCleaner[S8].txt - [1816 octets] - [27/06/2015 01:17:13]
AdwCleaner[S9].txt - [2371 octets] - [14/08/2015 20:57:06]
########## EOF - C:\AdwCleaner\AdwCleaner[R15].txt - [2568 octets] ##########
Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 7 Professional x64
Ran by xxx on 01.09.2015 at 1:00:05,80
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update thirteen degrees
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util thirteen degrees
~~~ Files
Failed to delete: [File] C:\Windows\SysWOW64\number of results
Successfully deleted: [File] C:\ProgramData\1439035440.bdinstall.bin
Successfully deleted: [File] C:\Users\xxx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\hotspot shield.lnk
~~~ Folders
Successfully deleted: [Folder] C:\Program Files (x86)\predm
Successfully deleted: [Folder] C:\ProgramData\abc
Successfully deleted: [Folder] C:\Users\xxx\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\ProgramData\0f3b5471928b4fd3834dad205fba7597
Successfully deleted: [Folder] C:\ProgramData\28341ff220e0446c9fff27c4493d622e
~~~ FireFox
Successfully deleted the following from C:\Users\xxx\AppData\Roaming\mozilla\firefox\profiles\ks5t7hh7.default-1435098893833\prefs.js
user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine);
user_pref(browser.search.searchengine.ptid, wpc);
user_pref(browser.search.searchengine.uid, TOSHIBAXMQ01ABD100_523IS39ISXX523IS39IS);
user_pref(extensions.quick_start.enable_search1, false);
user_pref(extensions.quick_start.sd.closeWindowWithLastTab_prev_state, false);
Emptied folder: C:\Users\xxx\AppData\Roaming\mozilla\firefox\profiles\ks5t7hh7.default-1435098893833\minidumps [6 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.09.2015 at 1:01:20,33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Geändert von daniel1989 (01.09.2015 um 00:03 Uhr) Grund: JRT log vergessen... |
| Themen zu Windows 7: Programme lassen sich nicht oeffnen und oder brauchen ewig, Fehlermeldungen wie microsoft explorer reagiert nicht, schwarzes Bild |
| antivirus, askbar, avp, bildschirm, computer, device driver, dnsapi.dll, downloader, dringend, ebanking, explorer reagiert nicht, flash player, gebraucht, google, helper, homepage, hotspot, iexplore.exe, installation, internet, kaspersky, langsam, lightning, mozilla, programm, registry, schwarzer bildschim, schwarzer bildschirm, security, software, svchost.exe, system, virus, windows, windows7 |