![]() |
|
Log-Analyse und Auswertung: Nach Trojan.GenericKD.1704971 Fund, AdwCleaner Fund in C:\End -> Folgefund Applni.DLLsWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Nach Trojan.GenericKD.1704971 Fund, AdwCleaner Fund in C:\End -> Folgefund Applni.DLLs Hallo, mein Bitdefender hat mir Donnerstag zwei Funde mit dem Namen Trojan.GenericKD.1704971 gezeigt. Die wurden dann "Resolved". Bitdefender hat auf eine manuelle Entfernung der infizierten Dateianhänge verwiesen. Diese konnte ich nicht finden, habe dann die E-Mailkonten in Outlook gelöscht und danach Outlook deinstalliert. Ich hoffe die Beitragsformatierung geht soweit in Ordnung. Bitdefender-Log: Code:
ATTFilter <?xml version="1.0" encoding="utf-8"?> <?xml-stylesheet type="text/xsl" href="C:\Program Files\Bitdefender\Bitdefender 2017\ondemand.xsl"?> <ScanSession creator="Bitdefender Internet Security 2017" name="Vollständiger System-Scan" installPath="C:\Program Files\Bitdefender\Bitdefender 2017\" creationDate="Donnerstag, 2. März 2017 20:18:56" originalPath="C:\ProgramData\Bitdefender\Desktop\Profiles\Logs\dcf483c4-26d0-4e6f-ba28-6a53a00adae1\1488476785_1_02.xml" > <ScanSettings statisticsRefreshInterval="1000" scanSpeed="1.000000" lowPriority="0" enableExclusions="1" enableTaskExclusions="0" scanAdware="1" scanSpyware="1" scanApplications="1" scanDialers="1" scanKeyloggers="1" scanFiles="1" scanAllFiles="1" scanProgramsOnly="0" useCustomPrograms="0" customPrograms="" scanUserDefined="0" scanPacked="1" scanArchives="1" useSmartScan="1" scanEmails="1" scanRootkits="0" scanAllRootkits="1" scanBoot="1" scanMemory="1" scanRegistry="1" quickScan="1" quickScanMemory="0" quickScanAutoruns="0" quickScanPlugins="1" scanCookies="1" shutdownAfter="0" passwordPrompt="0" onlyAllowedActions="1" deepArchiveScan="1" maxArchiveLevel="15" maxArchiveSize="0" infectedAction1="3" infectedAction2="7" suspectAction1="7" suspectAction2="1" rootkitAction="3" userDefinedExtensions="" scanPua="-1" computeSha256Hash="0" disableIndexer="0" > <ScanPaths> <path>C:\</path> <path>E:\</path> </ScanPaths> <ExcludedPaths> </ExcludedPaths> <ExcludedExtensions> </ExcludedExtensions> </ScanSettings> <EngineSummary totalSignatures="8365808" /> <ScanSummary scannedArchives="739" scannedPacked="381" startTime="1488476785" duration="3264125" > <TypeSummary type="1" scanned="32" infected="0" suspicious="0" disinfected="0" deleted="0" moved="0" moved_reboot="0" delete_reboot="0" renamed="0" hidden="0" /> <TypeSummary type="4" scanned="0" infected="0" suspicious="0" disinfected="0" deleted="0" moved="0" moved_reboot="0" delete_reboot="0" renamed="0" hidden="0" /> <TypeSummary type="0" scanned="3697440" infected="2" suspicious="0" disinfected="0" deleted="1" moved="1" moved_reboot="0" delete_reboot="0" renamed="0" hidden="0" /> <TypeSummary type="5" scanned="0" infected="0" suspicious="0" disinfected="0" deleted="0" moved="0" moved_reboot="0" delete_reboot="0" renamed="0" hidden="0" /> <TypeSummary type="2" scanned="6842" infected="0" suspicious="0" disinfected="0" deleted="0" moved="0" moved_reboot="0" delete_reboot="0" renamed="0" hidden="0" /> <TypeSummary type="3" scanned="17043" infected="0" suspicious="0" disinfected="0" deleted="0" moved="0" moved_reboot="0" delete_reboot="0" renamed="0" hidden="0" /> <TypeSummary type="6" scanned="833" infected="0" suspicious="0" disinfected="0" deleted="0" moved="0" moved_reboot="0" delete_reboot="0" renamed="0" hidden="0" /> </ScanSummary> <ScanDetails> <UnresolvedDetails> </UnresolvedDetails> <ResolvedDetails> <Item type="0" objectType="0" path="C:\Users\Inxi\AppData\Local\Microsoft\Outlook\******@***.de.pst=>[Time: 2014=>06=>04 13:17:42][Subject: RE:Rechnung vom 04.06.2014][From: contact@regard-informatique.fr]=>nI04sKt310U3GHfhfhfhfh7979446462553.rar=>Rechnung vom_04062014_BCDERSTRT797854556455854555855541325.scr" threatType="0" threatName="Trojan.GenericKD.1704971" action="9" allActions="3 7 1 9 1 9" initialStatus="3" finalStatus="6" quarId="ddd97d83-19df-480f-bdc4-fada16422d2f" failReason="0" itemHash="" chainHash="no_hash" family="" rtvrType="" /> <Item type="0" objectType="0" path="C:\Users\Inxi\AppData\Local\Microsoft\Outlook\******@***.de.pst=>[Time: 2014=>06=>04 13:17:42][Subject: RE:Rechnung vom 04.06.2014][From: contact@regard-informatique.fr]=>nI04sKt310U3GH54555855541325.zip=>Rechnung vom_04062014_BCDERSTRT797854556455854555855541325.exe" threatType="0" threatName="Trojan.GenericKD.1704971" action="9" allActions="3 9" initialStatus="3" finalStatus="5" quarId="" failReason="0" itemHash="" chainHash="no_hash" family="" rtvrType="" /> </ResolvedDetails> <IgnoredDetails> </IgnoredDetails> <QuickScanDetails> </QuickScanDetails> <NotScannedDetails skipped="1055549" ioerrors="0" archiveBombs="0" passwordProtected="232" > <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Realtek\Audio\Drivers\HDADrv\WIN64\RTAIODAT.DAT=>rtkhdasetting=>103C82F2=>APO.zip=>APO=>00000924=>00000924.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Realtek\Audio\Drivers\HDADrv\WIN64\RTAIODAT.DAT=>rtkhdasetting=>103C82FF=>APO.zip=>APO=>00000924=>00000924.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/amd64/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/LIMITATIONS.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Realtek\Audio\Drivers\HDADrv\WIN64\RTAIODAT.DAT=>rtkhdasetting=>103C82F9=>APO.zip=>APO=>00000924=>00000924.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Realtek\Audio\Drivers\HDADrv\WIN32\Rtaiodat.dat=>rtkhdasetting=>103C82F2=>APO.zip=>APO=>00000924=>00000924.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Realtek\Audio\Drivers\HDADrv\WIN64\RTAIODAT.DAT=>rtkhdasetting=>103C82FE=>APO.zip=>APO=>00000924=>00000924.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Realtek\Audio\Drivers\HDADrv\WIN32\Rtaiodat.dat=>rtkhdasetting=>103C82F9=>APO.zip=>APO=>00000924=>00000924.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Realtek\Audio\Drivers\HDADrv\WIN32\Rtaiodat.dat=>rtkhdasetting=>103C82FE=>APO.zip=>APO=>00000924=>00000924.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Realtek\Audio\Drivers\HDADrv\WIN32\Rtaiodat.dat=>rtkhdasetting=>103C82FF=>APO.zip=>APO=>00000924=>00000924.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Help.pdf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/install.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/RELEASE_NOTES.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Help.pdf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/amd64/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/i386/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/amd64/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/i386/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/i386/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/amd64/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Autodesk\Autodesk Design Review 2013\EComposite\pdfnet.res" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/i386/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/i386/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/amd64/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files (x86)\Samsung Magician\Rapid\Rapid.dll=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files\Autodesk\DWG TrueView 2014\pdfnet.res" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos1-6.zip=>3_fem_pr„gung_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Program Files\Autodesk\AutoCAD 2014\pdfnet.res" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Autodesk\WI\Autodesk Inventor 2014\x86\de-DE\Components\adr2013\program files\Autodesk\Autodesk Design Review 2013\EComposite\pdfnet.res" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Autodesk\WI\Autodesk Inventor 2014\x64\Components\DWGVIEWER\Program Files\DWG TrueView 2014\pdfnet.res" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Autodesk\WI\Autodesk Entertainment Creation Suite Ultimate 2016\x64\MotionBuilder\ADSK\MB\bin\x64\python27.zip=>test=>test_zipfile.pyo=>zero" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Autodesk\WI\Autodesk Entertainment Creation Suite Ultimate 2016\x64\MotionBuilder\ADSK\MB\bin\x64\python27.zip=>test=>test_zipfile.pyc=>zero" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Autodesk\WI\Autodesk Entertainment Creation Suite Ultimate 2016\x64\Maya\Autodesk\Maya2016\bin\python27.zip=>test=>test_zipfile.pyo=>zero" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Autodesk\WI\Autodesk Entertainment Creation Suite Ultimate 2016\x64\Maya\Autodesk\Maya2016\bin\python27.zip=>test=>test_zipfile.pyc=>zero" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\Autodesk\AutoCAD_2014_German_Win_64bit_dlm\x64\acad\Program Files\Root\pdfnet.res" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos7-12.zip=>10_baugruppe1_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos7-12.zip=>11_baugruppe2_normteile_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos7-12.zip=>12_baugruppe_stueli_idw_posdarstellung_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos7-12.zip=>7_dwg zu ipt_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos7-12.zip=>8_blech1_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos7-12.zip=>9_blech2_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/RELEASE_NOTES.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Program Files\Autodesk\MotionBuilder 2016\bin\x64\python27.zip=>test=>test_zipfile.pyo=>zero" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Program Files\Autodesk\MotionBuilder 2016\bin\x64\python27.zip=>test=>test_zipfile.pyc=>zero" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos1-6.zip=>1_skizze_extrusion_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos1-6.zip=>2_element bearbeiten_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos1-6.zip=>4_lagerbock_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos1-6.zip=>5_lagerbock_zeichnung_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Inventortutorials\Inventor_2009_Schulungsvideos1-6.zip=>6_welle_Screen_Stream.avi" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Sicherung\alte Q-Nr\Nicole Ertl\Arbeitsanweisunge\Kopie von AUA_aktuell_22_03_Lagerfrist - englisch .xlsx" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/install.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/LIMITATIONS.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/amd64/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/amd64/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/i386/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/i386/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/install.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/amd64/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/amd64/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/i386/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/i386/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\SSD Magician\Site Link\Samsung_Magician_Setup_v45.zip=>Samsung_Magician_Setup_v45.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Help.pdf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/LIMITATIONS.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/RELEASE_NOTES.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/amd64/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/amd64/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_amd64/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/i386/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/CacheFilter/SamsungRapidFSFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win7_i386/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/amd64/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/CacheFilter/SamsungRapidFSFltr.cat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_amd64/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/dp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/addfilter.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/DIFxAPI.dll" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/i386/SamsungRapidDiskFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/i386/SamsungRapidFSFltr.sys" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/rp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidApp.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/CacheFilter/SamsungRapidDiskFltr.inf" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/OpenSourceAnnouncement.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/SamsungRapidSvc.exe" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/Tools/RAPIDCollectLogs/RAPIDCollectLogs.bat" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="C:\ProgramData\Samsung\Backup\Samsung_Magician_ML_Setup_Backup.exe=>(Instyler o)=>(Instyler Module 593)=>(ZIP Sfx r)=>Rapid/Win8_i386/RAPID/Tools/RAPIDCollectLogs/README.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Sicherung\alte Q-Nr\Stephanie Huebner\Archiv\STAT_150626_Managementreport_ErrorRate_2015B.xlsx" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Program Files\Autodesk\Maya2016\bin\python27.zip=>test=>test_zipfile.pyo=>zero" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Program Files\Autodesk\Maya2016\bin\python27.zip=>test=>test_zipfile.pyc=>zero" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> <Item type="0" objectType="0" path="E:\Downloads\DELL_WIRELESS-5630-EVDO-HSPA_A00_R298539.exe=>(ZIP Sfx o)=>SystemId.zip=>SystemId.txt" threatType="0" threatName="" action="1" allActions="" initialStatus="10" finalStatus="10" failReason="5" /> </NotScannedDetails> </ScanDetails> </ScanSession> https://malwaretips.com/blogs/trojan-generickd-removal/ Diesen habe ich durchgeführt, ohne Befunde, bis zum Adwcleaner step. Dieser fand ebenfalls zwei Sachen und ich habe diese gelöscht. Code:
ATTFilter # AdwCleaner v6.044 - Bericht erstellt am 02/03/2017 um 21:49:36 # Aktualisiert am 28/02/2017 von Malwarebytes # Datenbank : 2017-03-02.1 [Server] # Betriebssystem : Windows 10 Home (X64) # Benutzername : Inxi - INXI-PC # Gestartet von : C:\Users\Inxi\Downloads\adwcleaner_6.044.exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner gelöscht: C:\ProgramData\5c9e2523-c041-4bd3-924f-697ec2ef6bde ***** [ Dateien ] ***** [-] Datei gelöscht: C:\END ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [990 Bytes] - [02/03/2017 21:49:36] C:\AdwCleaner\AdwCleaner[S0].txt - [1357 Bytes] - [02/03/2017 21:42:10] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1135 Bytes] ########## auf der Suche nach C:\END bin ich auf diesen Thread gestoßen. http://www.trojaner-board.de/136098-...gen-c-end.html Ich habe Malware Bytes AntiRootkit installiert und beim Start wurde ein Verweis auf die Applnit.DLL gegeben. Ich habe auf "No" geklickt und MBAR lief problemslos durch. Heute habe ich dann alle Steps des obigen Guides wiederholt (im Safemode) und habe abschließend beim JunkwareRemovalTool folgendes Log erhalten. Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.1 (02.11.2017) Operating System: Windows 10 Home x64 Ran by Inxi (Limited) on 04.03.2017 at 11:05:48,93 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 4 Successfully deleted: C:\ProgramData\1481276973.bdinstall.bin (File) Successfully deleted: C:\Users\Inxi\AppData\Roaming\Mozilla\Firefox\Profiles\cgvoh6rn.default\extensions\trash (Folder) Successfully deleted: C:\WINDOWS\system32\Tasks\PCDEventLauncherTask (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\PCDoctorBackgroundMonitorTask (Task) Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 04.03.2017 at 11:06:38,59 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Bei einem abschließenden Test mit MBAR wurde wieder der Verweis auf die Applnit.DLLs gegeben ohne danach beim Scan einen Befund zu melden. Inweit ist mein PC noch infiziert bzw. was sollten denn jetzt meine weiteren Schritte sein? ![]() FSR.txt Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 03-03-2017 durchgeführt von Inxi (Administrator) auf INXI-PC (04-03-2017 11:39:33) Gestartet von C:\Users\Inxi\Downloads Geladene Profile: Inxi (Verfügbare Profile: Inxi & DefaultAppPool) Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2017\vsserv.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2016\Moldflow\bin\mitsijm.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2017\updatesrv.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe (WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Samsung Electronics.) C:\Program Files (x86)\Samsung Magician\Samsung Magician.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Spotify Ltd) C:\Users\Inxi\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Akamai Technologies, Inc.) C:\Users\Inxi\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Inxi\AppData\Local\Akamai\netsession_win.exe (Spotify Ltd) C:\Users\Inxi\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Hewlett-Packard Company) C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2017\bdagent.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2017\bdwtxag.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-08-03] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-03] (Realtek Semiconductor) HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe [281776 2014-09-16] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-08-07] (NVIDIA Corporation) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-30] (Microsoft Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-10-21] (NEC Electronics Corporation) HKLM-x32\...\Run: [ToolboxFX] => C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe [58936 2010-10-25] (Hewlett-Packard Company) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [522784 2015-11-17] (Autodesk Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3175323499-3369025214-2853444423-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3018528 2017-02-23] (Valve Corporation) HKU\S-1-5-21-3175323499-3369025214-2853444423-1000\...\Run: [Spotify] => C:\Users\Inxi\AppData\Roaming\Spotify\Spotify.exe [7067760 2017-02-17] (Spotify Ltd) HKU\S-1-5-21-3175323499-3369025214-2853444423-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Inxi\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.) HKU\S-1-5-21-3175323499-3369025214-2853444423-1000\...\Run: [Spotify Web Helper] => C:\Users\Inxi\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-02-17] (Spotify Ltd) HKU\S-1-5-21-3175323499-3369025214-2853444423-1000\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1336320 2015-11-25] (Autodesk, Inc.) HKU\S-1-5-21-3175323499-3369025214-2853444423-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1057848 2017-02-20] () HKU\S-1-5-21-3175323499-3369025214-2853444423-1000\...\Run: [Innkeeper] => C:\Users\Inxi\AppData\Local\Innkeeper\Update.exe --processStart Innkeeper.exe --process-start-args="-startup" HKU\S-1-5-21-3175323499-3369025214-2853444423-1000\...\Policies\Explorer: [] AppInit_DLLs: C:\Windows\system32\nvinitx.dll => Keine Datei AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => Keine Datei ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk [2016-07-28] ShortcutTarget: WDDMStatus.lnk -> C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 Tcpip\..\Interfaces\{027f6474-5d44-4977-ba82-1028262a6651}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{564ced59-5169-4294-a665-198236781d26}: [DhcpNameServer] 192.168.0.1 192.168.0.2 Tcpip\..\Interfaces\{A044B257-B0BB-4A90-A524-001E3E7A7C5C}: [DhcpNameServer] 7.254.254.254 Internet Explorer: ================== BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2017\pmbxie.dll [2017-01-17] (Bitdefender) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2017\Antispam32\pmbxie.dll [2017-01-17] (Bitdefender) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2017\pmbxie.dll [2017-01-17] (Bitdefender) Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2017\Antispam32\pmbxie.dll [2017-01-17] (Bitdefender) FireFox: ======== FF DefaultProfile: cgvoh6rn.default FF ProfilePath: C:\Users\Inxi\AppData\Roaming\Mozilla\Firefox\Profiles\cgvoh6rn.default [2017-03-04] FF Homepage: Mozilla\Firefox\Profiles\cgvoh6rn.default -> www.welt.de FF Extension: (Adblock Plus) - C:\Users\Inxi\AppData\Roaming\Mozilla\Firefox\Profiles\cgvoh6rn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23] FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\Inxi\AppData\Roaming\Mozilla\Firefox\Profiles\cgvoh6rn.default\features\{d22cf5b2-21dc-49bd-bc7c-9977629e5792}\disableSHA1rollout@mozilla.org.xpi [2017-03-04] FF HKLM\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2017\antispam32\bdwteff FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender 2017\antispam32\bdwteff [2017-01-18] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2017\bdtbext FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender 2017\bdtbext [2016-12-09] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2017\antispam32\bdwteff FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2017\bdtbext FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-18] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-18] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-08-07] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-08-07] (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1139744 2015-11-17] (Autodesk Inc.) R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) [Datei ist nicht signiert] R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2572024 2016-06-23] (Dell Inc.) R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [202488 2016-06-23] (Dell Inc.) R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.) U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [8704 2015-09-02] (Hi-Rez Studios) [Datei ist nicht signiert] R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-25] (HP) [Datei ist nicht signiert] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) S3 mi-raysat_3dsmax2016_64; E:\Program Files\Autodesk\3ds Max 2016\NVIDIA\Satellite\raysat_3dsmax2016_64server.exe [86016 2011-09-15] () [Datei ist nicht signiert] R2 mitsijm2016; C:\Program Files\Autodesk\Inventor 2016\Moldflow\bin\mitsijm.exe [968480 2014-09-30] (Autodesk, Inc.) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [Datei ist nicht signiert] S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119176 2017-01-18] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2181648 2017-01-18] (Electronic Arts) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1325112 2017-02-20] (Overwolf LTD) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [Datei ist nicht signiert] R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1100392 2016-10-28] (Bitdefender) R2 SamsungRapidSvc; C:\WINDOWS\System32\RAPID\SamsungRapidSvc.exe [28848 2014-09-16] (Samsung Electronics Co., Ltd.) S2 SetupARService; C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [10752 2016-12-08] () [Datei ist nicht signiert] R2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [31704 2016-09-09] (Dell Inc.) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [809424 2015-10-27] (Tunngle.net GmbH) [Datei ist nicht signiert] R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2017\updatesrv.exe [218416 2017-01-17] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2017\vsserv.exe [1526528 2017-01-17] (Bitdefender) R2 vsservp; C:\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe [524872 2016-08-25] (Bitdefender) R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-02-12] (Western Digital Technologies, Inc.) R2 WDDMService; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [288768 2011-03-09] (WDC) [Datei ist nicht signiert] R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [302968 2015-02-12] (Western Digital Technologies, Inc.) R2 WDFME; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [1066896 2011-03-09] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WDSC; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [491920 2011-03-09] () R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R0 avc3; C:\WINDOWS\System32\DRIVERS\avc3.sys [1605376 2016-09-20] (BitDefender) R3 avckf; C:\WINDOWS\System32\DRIVERS\avckf.sys [878072 2016-09-20] (BitDefender) S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [23672 2016-03-14] (Bitdefender) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [128400 2016-06-24] (BitDefender LLC) R1 BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [87912 2015-12-04] (BitDefender) R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [32464 2015-09-11] (Dell Computer Corporation) R3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation) R1 epp; C:\EEK\bin64\epp.sys [115216 2017-01-03] (Emsisoft Ltd) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77408 2017-02-24] () S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [30424 2015-04-14] (Sony Mobile Communications) R0 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [182944 2016-10-29] (BitDefender LLC) S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [54736 2017-03-04] () R0 ignis; C:\WINDOWS\system32\DRIVERS\ignis.sys [309280 2017-01-17] (Bitdefender) R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [186304 2017-03-04] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [111544 2017-03-04] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-03-04] (Malwarebytes) R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [251840 2017-03-04] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [92088 2017-03-04] (Malwarebytes) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmwu.inf_amd64_26aa6356770b2e86\nvlddmkm.sys [13754936 2016-09-12] (NVIDIA Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek ) R0 SamsungRapidDiskFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidDiskFltr.sys [268976 2014-09-16] (Samsung Electronics Co., Ltd.) R0 SamsungRapidFSFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidFSFltr.sys [111280 2014-09-16] (Samsung Electronics Co., Ltd.) R0 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [520032 2016-06-22] (BitDefender S.R.L.) R3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] () S3 vpnva; C:\WINDOWS\System32\DRIVERS\vpnva64-6.sys [52592 2015-02-19] (Cisco Systems, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) U3 idsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-04 11:39 - 2017-03-04 11:39 - 00021635 _____ C:\Users\Inxi\Downloads\FRST.txt 2017-03-04 11:39 - 2017-03-04 11:39 - 00000000 ____D C:\FRST 2017-03-04 11:38 - 2017-03-04 11:39 - 02423808 _____ (Farbar) C:\Users\Inxi\Downloads\FRST64.exe 2017-03-04 11:06 - 2017-03-04 11:06 - 00000896 _____ C:\Users\Inxi\Desktop\JRT.txt 2017-03-04 10:37 - 2017-03-04 10:37 - 00054736 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys 2017-03-04 10:15 - 2017-03-04 11:32 - 00000000 ____D C:\Users\Inxi\Desktop\Scan-Logs 2017-03-03 07:52 - 2017-03-03 07:52 - 00003760 _____ C:\Users\Inxi\Desktop\Rkill3_3_17.txt 2017-03-03 07:50 - 2017-03-04 10:22 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2017-03-03 07:16 - 2017-03-03 07:16 - 00001239 _____ C:\Users\Inxi\Desktop\Scan-Abends_03_03.txt 2017-03-02 22:11 - 2017-03-04 11:23 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-03-02 22:00 - 2017-03-02 22:00 - 00000000 ____D C:\Users\Inxi\Downloads\Hearthstone 2017-03-02 21:59 - 2017-03-04 11:04 - 00000000 ____D C:\Antivirus 2017-03-02 21:58 - 2017-03-02 21:59 - 00000000 ____D C:\Users\Inxi\Downloads\Projektarbeit + Inventor 2017-03-02 21:39 - 2017-03-02 22:01 - 00000000 ____D C:\Users\Inxi\Downloads\Musik 2017-03-02 21:31 - 2017-03-02 21:31 - 00000000 ____D C:\ProgramData\Emsisoft 2017-03-02 21:29 - 2017-03-04 10:52 - 00000000 ____D C:\EEK 2017-03-02 21:17 - 2017-03-04 11:00 - 00000000 ____D C:\AdwCleaner 2017-03-02 21:12 - 2017-03-02 21:12 - 00001978 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2017-03-02 21:12 - 2017-03-02 21:12 - 00000000 ____D C:\Program Files\HitmanPro 2017-03-02 21:10 - 2017-03-04 10:37 - 00000000 ____D C:\ProgramData\HitmanPro 2017-03-02 21:04 - 2017-03-04 11:35 - 00111544 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-03-02 21:04 - 2017-03-04 11:25 - 00186304 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-03-02 21:04 - 2017-03-04 11:25 - 00092088 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-03-02 21:04 - 2017-03-04 11:25 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-03-02 21:03 - 2017-03-04 11:25 - 00251840 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-03-02 21:03 - 2017-03-02 22:11 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-03-02 21:03 - 2017-03-02 21:03 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-03-02 21:03 - 2017-03-02 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-03-02 21:03 - 2017-03-02 21:03 - 00000000 ____D C:\Program Files\Malwarebytes 2017-03-02 21:03 - 2017-02-24 06:23 - 00077408 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-03-02 20:51 - 2017-03-04 10:23 - 00003760 _____ C:\Users\Inxi\Desktop\Rkill.txt 2017-03-02 20:44 - 2017-03-02 20:49 - 00285804 _____ C:\TDSSKiller.3.1.0.12_02.03.2017_20.44.29_log.txt 2017-03-02 20:20 - 2017-03-02 20:18 - 00078192 _____ C:\Users\Inxi\Desktop\1488476785_1_02.xml 2017-03-02 18:43 - 2017-03-02 18:43 - 00000336 _____ C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸㑬㜳⸰浴p翺 2017-03-02 18:43 - 2017-03-02 18:43 - 00000332 _____ C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸㍬䕂⸵浴p翺 2017-03-02 18:43 - 2017-03-02 18:43 - 00000326 _____ C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸㑬㠳⸱浴p翺 2017-02-26 19:48 - 2017-02-26 19:48 - 00029938 _____ C:\Users\Inxi\Downloads\rueckmeldung_152315_TCVXKXCZIHSD.pdf 2017-02-24 16:38 - 2017-02-24 16:38 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows 2017-02-24 16:38 - 2017-02-24 16:38 - 00000000 ____D C:\Program Files\Dell Support Center 2017-02-22 19:31 - 2017-02-22 19:31 - 01876505 _____ C:\Users\Inxi\Downloads\Übungen mit Kurzhanteln.pdf 2017-02-12 00:15 - 2017-02-12 00:15 - 01724748 _____ C:\Users\Inxi\Downloads\TM2-V202.pdf 2017-02-09 19:38 - 2017-02-09 19:38 - 00394680 _____ C:\Users\Inxi\Downloads\Formelsammlung_Bertram.pdf 2017-02-06 18:37 - 2017-02-06 18:37 - 00000759 _____ C:\WINDOWS\!sfxunst.ini 2017-02-06 18:37 - 2017-02-06 18:37 - 00000000 ____D C:\Users\Inxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lavalamp Screensaver 2017-02-06 18:37 - 2003-03-24 11:39 - 00044842 _____ (e-merge GmbH) C:\WINDOWS\SXUNINST.EXE 2017-02-06 18:37 - 2003-03-24 11:04 - 00022016 _____ C:\WINDOWS\InstHelper.exe 2017-02-06 18:37 - 2003-03-18 14:44 - 03674112 _____ (German IT Development Ltd.) C:\WINDOWS\LavaSaver.scr ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-03-04 11:34 - 2015-02-13 20:27 - 00000000 ____D C:\Users\Inxi\AppData\Local\Spotify 2017-03-04 11:32 - 2016-11-19 02:58 - 00000000 ____D C:\Users\Inxi\AppData\LocalLow\Mozilla 2017-03-04 11:32 - 2016-07-29 13:16 - 00000000 ____D C:\Program Files\Bitdefender Agent 2017-03-04 11:32 - 2015-02-13 20:27 - 00000000 ____D C:\Users\Inxi\AppData\Roaming\Spotify 2017-03-04 11:29 - 2016-09-30 16:11 - 09821480 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-03-04 11:29 - 2016-07-16 23:51 - 04998886 _____ C:\WINDOWS\system32\perfh007.dat 2017-03-04 11:29 - 2016-07-16 23:51 - 01358288 _____ C:\WINDOWS\system32\perfc007.dat 2017-03-04 11:25 - 2016-12-14 16:45 - 00008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat 2017-03-04 11:25 - 2016-09-30 16:26 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-03-04 11:25 - 2016-09-30 16:10 - 00000000 ____D C:\ProgramData\NVIDIA 2017-03-04 11:25 - 2016-07-16 07:04 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-03-04 11:25 - 2014-12-31 15:10 - 00000000 ____D C:\ProgramData\Western Digital 2017-03-04 10:20 - 2014-12-31 14:34 - 00817452 _____ C:\bdlog.txt 2017-03-04 10:07 - 2015-11-03 11:20 - 00000000 ____D C:\Users\Inxi\AppData\Local\Akamai 2017-03-03 23:02 - 2016-09-30 16:09 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-03-03 22:47 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-03-02 22:49 - 2016-07-16 07:04 - 00065536 _____ C:\WINDOWS\system32\config\ELAM 2017-03-02 21:50 - 2016-09-30 16:11 - 00000000 ____D C:\Users\Inxi 2017-03-02 21:50 - 2016-09-30 16:09 - 00468112 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-03-02 21:50 - 2015-11-04 09:11 - 00000344 _____ C:\WINDOWS\Tasks\HPCeeScheduleForInxi.job 2017-03-02 20:49 - 2015-02-13 20:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2017-03-02 20:48 - 2015-02-13 20:09 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-03-02 20:48 - 2009-07-14 03:34 - 00000387 _____ C:\WINDOWS\win.ini 2017-03-02 20:18 - 2015-08-24 11:46 - 00000000 ____D C:\Users\Inxi\Documents\Outlook-Dateien 2017-03-02 18:24 - 2016-12-16 08:52 - 00003272 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2017-03-02 18:24 - 2016-07-28 20:47 - 00002421 _____ C:\Users\Inxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-03-02 18:24 - 2016-07-28 20:47 - 00000000 ___RD C:\Users\Inxi\OneDrive 2017-03-02 16:39 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-03-02 12:35 - 2016-09-30 16:26 - 00003232 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForInxi 2017-03-01 23:02 - 2015-02-21 12:37 - 00000000 ____D C:\Users\Inxi\AppData\Local\Battle.net 2017-03-01 20:03 - 2015-02-21 12:38 - 00000000 ____D C:\Program Files (x86)\Diablo III 2017-03-01 19:05 - 2016-08-02 19:19 - 00000000 ____D C:\Program Files (x86)\Hearthstone 2017-03-01 19:02 - 2015-02-21 12:37 - 00000000 ____D C:\Program Files (x86)\Battle.net 2017-02-26 22:37 - 2015-02-13 20:25 - 00000000 ____D C:\Program Files (x86)\Steam 2017-02-24 16:38 - 2015-02-26 00:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell 2017-02-23 18:39 - 2014-12-31 14:00 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-02-23 18:37 - 2014-12-31 14:00 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-02-23 18:04 - 2015-11-02 08:54 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-02-23 12:58 - 2016-08-16 12:58 - 00000000 ____D C:\Program Files (x86)\Overwolf 2017-02-22 20:35 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-02-18 12:52 - 2015-04-29 00:36 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2017-02-18 01:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-02-18 01:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-02-06 20:48 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-02-06 20:48 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-06-28 17:22 - 2015-06-28 17:22 - 0000268 ___RH () C:\Users\Inxi\AppData\Roaming\PrintingModule 2015-06-28 17:22 - 2015-06-28 17:22 - 0000268 ___RH () C:\Users\Inxi\AppData\Roaming\PrintsService 2015-04-14 18:51 - 2015-04-14 18:51 - 28579392 _____ (Sony Mobile Communications ) C:\Users\Inxi\AppData\Local\pcc.exe 2017-01-18 17:31 - 2017-01-18 17:31 - 0007608 _____ () C:\Users\Inxi\AppData\Local\Resmon.ResmonCfg 2016-12-10 12:17 - 2016-12-10 12:17 - 0387571 _____ () C:\ProgramData\cl.1481368159.bdinstall.bin 2016-12-10 12:17 - 2016-12-10 12:17 - 0055847 _____ () C:\ProgramData\dm.1481368655.bdinstall.bin 2016-12-10 12:20 - 2016-12-10 12:20 - 0035254 _____ () C:\ProgramData\dm.1481368793.bdinstall.bin 2015-06-28 17:22 - 2015-06-28 17:22 - 0000012 ___RH () C:\ProgramData\laserjet 2015-06-28 17:22 - 2015-06-28 17:22 - 0000012 ___RH () C:\ProgramData\manual 2015-11-03 15:45 - 2015-11-03 15:45 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2015-06-28 17:20 - 2015-08-28 18:31 - 0000020 ____H () C:\ProgramData\PKP_DLbx.DAT 2015-06-28 17:22 - 2015-06-28 17:22 - 0000020 ____H () C:\ProgramData\PKP_DLck.DAT 2015-06-28 17:22 - 2015-06-28 17:22 - 0000268 ___RH () C:\ProgramData\Quartz Composer 2015-06-28 17:22 - 2015-06-28 17:22 - 0000268 ___RH () C:\ProgramData\Radio Sounds ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-02-22 20:35 ==================== Ende von FRST.txt ============================ |
Themen zu Nach Trojan.GenericKD.1704971 Fund, AdwCleaner Fund in C:\End -> Folgefund Applni.DLLs |
adware, browser, dateien, defender, desktop, einstellungen, explorer, firefox, google, home, infizierte, internet, internet explorer, microsoft, mozilla, object, ordner, realtek, registry, security, server, spyware, suche, windows, windowsapps, wmi |