Hilflos81 | 06.10.2013 15:50 | FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by StanglW (administrator) on AUSWKS-0035 on 03-10-2013 14:35:36
Running from F:\
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Safe Mode (minimal)
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\cmd.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [7177728 2013-09-21] (Broadcom Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [HPPowerAssistant] - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [3488640 2012-03-14] (Hewlett-Packard Company)
HKLM\...\Run: [MfeEpePcMonitor] - "C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe"
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-09-14] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3011824 2013-09-14] (Synaptics Incorporated)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [rfxsrvtray] - C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-tray.exe [2057048 2012-01-18] (Tobit.Software)
HKCU\...\Winlogon: [Shell] explorer.exe,C:\Users\StanglW\AppData\Roaming\data.dat [155648 2012-05-17] () <==== ATTENTION
HKCU\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
MountPoints2: {8c5ba55f-304c-11e2-96a5-e006e6b58c5a} - F:\EasySuite.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-10-24] (Intel Corporation)
HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-09-12] (Hewlett-Packard Company)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291280 2013-07-14] (Intel Corporation)
HKLM-x32\...\Run: [File Sanitizer] - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [12313720 2012-08-07] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162408 2012-09-06] (Geek Software GmbH)
HKLM-x32\...\Run: [IFXSPMGT] - C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [1128312 2012-10-24] (Infineon Technologies AG)
HKLM-x32\...\Run: [EPA_EZ_GPO_Tool] - C:\windows\system32\EZ_GPO_Tool.exe
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ITSecMng] - C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [UnlockerAssistant] - "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe"
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [185144 2013-04-23] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [] - [x]
Lsa: [Notification Packages] DPPassFilter scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
==================== Internet (Whitelisted) ====================
ProxyServer: gate.euralis.de:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM/10
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM/10
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\bin\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM-x32 - QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{DCA06BF6-06B2-4146-AB38-3FE72F8190DA}: [NameServer]10.74.210.210 10.74.210.211
==================== Services (Whitelisted) =================
S2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [494456 2012-07-20] (DigitalPersona, Inc.)
S2 EPA_GPO_PMService; C:\Windows\SysWow64\PMService.exe [94208 2011-02-12] (TerraNovum)
S3 FLCDLOCK; c:\windows\SysWOW64\flcdlock.exe [477088 2012-09-04] (Hewlett-Packard Company)
S2 GobiQDLService; C:\Program Files (x86)\Sierra Wireless Inc\Gobi\QDLService\GobiQDLService.exe [312688 2011-11-26] (Sierra Wireless, Inc.)
S2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [523680 2012-09-12] (Hewlett-Packard Company)
S2 IFXSpMgtSrv; C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [1128312 2012-10-24] (Infineon Technologies AG)
S2 IFXTCS; C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [984440 2012-10-24] (Infineon Technologies AG)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-11-02] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-11-02] (Intel Corporation)
S2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1327104 2013-03-27] ()
S2 PersonalSecureDriveService; C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe [212344 2012-10-24] (Infineon Technologies AG)
S2 Radio.fx; C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe [3665752 2012-01-26] ()
S2 RoxioBurnLauncher; C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [536848 2012-03-21] ()
S2 SepMasterService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Bin\ccSvcHst.exe [137208 2012-11-02] (Symantec Corporation)
S3 SmcService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Bin64\Smc.exe [2601544 2012-11-02] (Symantec Corporation)
S3 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Bin64\snac64.exe [325040 2012-11-02] (Symantec Corporation)
S2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [498352 2012-02-03] (ArcSoft, Inc.)
S2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE [48128 2013-09-21] (Broadcom Corporation)
==================== Drivers (Whitelisted) ====================
S3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [42816 2012-02-03] (ArcSoft, Inc.)
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2012-02-02] (Broadcom Corporation.)
S1 BHDrvx64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Data\Definitions\BASHDefs\20121031.011\BHDrvx64.sys [1384608 2012-11-27] (Symantec Corporation)
S1 BHDrvx64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Data\Definitions\BASHDefs\20121031.011\BHDrvx64.sys [1384608 2012-11-27] (Symantec Corporation)
S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2012-02-02] (Broadcom Corporation.)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [64832 2012-09-04] (Hewlett-Packard Company)
S1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-11-02] (Symantec Corporation)
S1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2012-11-02] (Symantec Corporation)
S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-11-02] (Symantec Corporation)
S1 IDSVia64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Data\Definitions\IPSDefs\20121127.001\IDSvia64.sys [513184 2012-11-27] (Symantec Corporation)
S1 IDSVia64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Data\Definitions\IPSDefs\20121127.001\IDSvia64.sys [513184 2012-11-27] (Symantec Corporation)
R3 johci; C:\Windows\System32\DRIVERS\johci.sys [26208 2012-11-02] (JMicron Technology Corp.)
R0 MfeEpeOpal; C:\Windows\System32\Drivers\MfeEpeOpal.sys [91432 2013-03-27] (McAfee, Inc.)
R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [158760 2013-03-27] (McAfee, Inc.)
S3 NAVENG; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Data\Definitions\VirusDefs\20121127.021\ENG64.SYS [126112 2012-11-27] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Data\Definitions\VirusDefs\20121127.021\ENG64.SYS [126112 2012-11-27] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Data\Definitions\VirusDefs\20121127.021\EX64.SYS [2084000 2012-11-27] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Data\Definitions\VirusDefs\20121127.021\EX64.SYS [2084000 2012-11-27] (Symantec Corporation)
R1 PersonalSecureDrive; C:\Windows\System32\drivers\psd.sys [44576 2012-10-24] (Infineon Technologies AG)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1866080 2012-11-20] ()
S1 SRTSP; C:\Windows\System32\Drivers\SEP\0C01044D\0191.105\x64\SRTSP64.SYS [678008 2012-11-02] (Symantec Corporation)
S1 SRTSPX; C:\Windows\System32\Drivers\SEP\0C01044D\0191.105\x64\SRTSPX64.SYS [39032 2012-11-02] (Symantec Corporation)
S3 swg3kflt02; C:\Windows\System32\DRIVERS\swg3kflt02.sys [34304 2011-02-04] (Sierra Wireless Incorporated)
S3 swg3kmbb02; C:\Windows\System32\DRIVERS\swg3kmbb02.sys [458752 2011-11-10] (Sierra Wireless Incorporated)
S3 swg3knmea02; C:\Windows\System32\DRIVERS\swg3knmea02.sys [259200 2011-08-18] (Sierra Wireless Incorporated)
S3 swg3kser02; C:\Windows\System32\DRIVERS\swg3kser02.sys [259200 2011-08-18] (Sierra Wireless Incorporated)
R3 swibus02; C:\Windows\System32\DRIVERS\swibus02.sys [74752 2011-08-18] (Sierra Wireless Inc.)
R3 swibusflt02; C:\Windows\System32\DRIVERS\swibusflt02.sys [74752 2011-08-18] (Sierra Wireless Inc.)
S3 SyDvCtrl; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Bin64\SyDvCtrl64.sys [29664 2012-11-02] (Symantec Corporation)
S3 SyDvCtrl; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1101.401.105\Bin64\SyDvCtrl64.sys [29664 2012-11-02] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\Drivers\SEP\0C01044D\0191.105\x64\SYMDS64.SYS [451192 2012-11-02] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\Drivers\SEP\0C01044D\0191.105\x64\SYMEFA64.SYS [932472 2012-11-02] (Symantec Corporation)
S3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2012-11-02] (Symantec Corporation)
S1 SymIRON; C:\Windows\System32\Drivers\SEP\0C01044D\0191.105\x64\Ironx64.SYS [171128 2012-11-02] (Symantec Corporation)
S1 SYMNETS; C:\Windows\System32\Drivers\SEP\0C01044D\0191.105\x64\SYMNETS.SYS [386168 2012-11-02] (Symantec Corporation)
S1 SysPlant; C:\Windows\System32\Drivers\SysPlant.sys [119816 2012-11-02] (Symantec Corporation)
S1 Teefer2; C:\Windows\System32\DRIVERS\Teefer.sys [62672 2012-11-02] (Symantec Corporation)
S3 Tosrfcom; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-03 14:23 - 2013-10-03 14:23 - 00000000 ____D C:\FRST
2013-10-03 02:24 - 2013-10-03 02:30 - 00000004 _____ C:\Users\StanglW\AppData\Roaming\settings.ini
2013-10-03 02:23 - 2013-10-03 02:23 - 00155648 _____ C:\Users\StanglW\yipiuqvoxorylcnkohw.bfg
2013-09-21 20:29 - 2013-09-21 20:29 - 00000000 ____D C:\Users\StanglW\AppData\Roaming\InstallShield
2013-09-14 21:14 - 2012-11-28 11:17 - 00482128 _____ (Intel Corporation) C:\windows\system32\Drivers\e1c62x64.sys
2013-09-14 21:14 - 2012-08-09 12:56 - 00101224 _____ (Intel Corporation) C:\windows\system32\NicInstC.dll
2013-09-14 21:14 - 2012-08-09 08:54 - 00073032 _____ (Intel Corporation) C:\windows\system32\e1cmsg.dll
2013-09-14 20:29 - 2013-09-14 20:29 - 00000000 ____D C:\windows\DPDrv
2013-09-14 20:28 - 2013-09-14 20:28 - 00003148 _____ C:\windows\System32\Tasks\SidebarExecute
2013-09-14 19:51 - 2013-09-14 19:51 - 00532208 _____ (Synaptics Incorporated) C:\windows\SysWOW64\SynCOM.dll
2013-09-14 19:51 - 2013-09-14 19:51 - 00468720 _____ (Synaptics Incorporated) C:\windows\system32\Drivers\SynTP.sys
2013-09-14 19:51 - 2013-09-14 19:51 - 00229616 _____ (Synaptics Incorporated) C:\windows\system32\SynTPAPI.dll
2013-09-14 19:51 - 2013-09-14 19:51 - 00180464 _____ (Synaptics Incorporated) C:\windows\system32\SynTPCo16.dll
2013-09-14 19:51 - 2013-09-14 19:51 - 00114416 _____ (Synaptics Incorporated) C:\windows\SysWOW64\SynTPCOM.dll
2013-09-14 19:21 - 2013-09-14 19:22 - 00000000 ____D C:\Program Files\IDT
2013-09-14 19:21 - 2013-09-14 19:21 - 02186752 _____ (IDT, Inc.) C:\windows\system32\stapo64.dll
2013-09-14 19:21 - 2013-09-14 19:21 - 00672256 ____N (IDT, Inc.) C:\windows\system32\stapi64.dll
2013-09-14 19:21 - 2013-09-14 19:21 - 00543744 _____ (IDT, Inc.) C:\windows\system32\Drivers\stwrt64.sys
2013-09-14 19:21 - 2013-09-14 19:21 - 00499200 _____ (IDT, Inc.) C:\windows\system32\stcplx64.dll
2013-09-14 19:21 - 2013-09-14 19:21 - 00256000 _____ (IDT, Inc.) C:\windows\system32\st646435.dll
2013-09-14 16:11 - 2013-09-14 16:11 - 01478397 _____ C:\Users\Public\Documents\Flutlichtfeldtag Hofer.ppsx
2013-09-09 10:08 - 2013-09-09 09:46 - 00000822 _____ C:\Users\Public\Documents\Hillebrand Feldtagseinladung 13.lnk
2013-09-07 09:17 - 2013-09-07 09:17 - 00174080 _____ C:\Users\Public\Documents\RK WS 2013 Aug.xls
2013-09-04 18:25 - 2013-09-04 18:25 - 00014538 _____ C:\Users\Public\Documents\Kopie von Inv VZ Stangl Werner.xlsx
2013-09-04 18:21 - 2013-09-04 18:21 - 00014107 _____ C:\Users\Public\Documents\Kopie von Inv VZ Team Süd PP.xlsx
2013-09-04 18:07 - 2013-09-04 18:07 - 00049664 _____ C:\Users\Public\Documents\Kopie von Leistungsbeurteilungsbogen 05-2008 SaHe.xls
2013-09-04 18:03 - 2013-09-04 18:03 - 00049664 _____ C:\Users\Public\Documents\Kopie von Leistungsbeurteilungsbogen 05-2008 RS.xls
==================== One Month Modified Files and Folders =======
2013-10-03 14:23 - 2013-10-03 14:23 - 00000000 ____D C:\FRST
2013-10-03 14:11 - 2012-05-17 21:15 - 00696620 _____ C:\windows\system32\perfh007.dat
2013-10-03 14:11 - 2012-05-17 21:15 - 00147916 _____ C:\windows\system32\perfc007.dat
2013-10-03 14:11 - 2009-07-14 07:13 - 01612484 _____ C:\windows\system32\PerfStringBackup.INI
2013-10-03 14:08 - 2009-07-14 06:51 - 00083945 _____ C:\windows\setupact.log
2013-10-03 14:06 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-10-03 09:35 - 2012-09-05 21:25 - 01272257 _____ C:\windows\WindowsUpdate.log
2013-10-03 09:09 - 2009-07-14 06:45 - 00031312 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-03 09:09 - 2009-07-14 06:45 - 00031312 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-03 02:30 - 2013-10-03 02:24 - 00000004 _____ C:\Users\StanglW\AppData\Roaming\settings.ini
2013-10-03 02:23 - 2013-10-03 02:23 - 00155648 _____ C:\Users\StanglW\yipiuqvoxorylcnkohw.bfg
2013-10-03 02:23 - 2012-11-02 13:29 - 00000000 ____D C:\Users\StanglW
2013-10-03 02:13 - 2012-11-07 02:20 - 00000340 _____ C:\windows\Tasks\HPCeeScheduleForStanglW.job
2013-10-03 02:13 - 2012-05-17 22:30 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-10-02 20:57 - 2012-05-17 22:30 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-10-02 20:38 - 2012-11-07 02:20 - 00003198 _____ C:\windows\System32\Tasks\HPCeeScheduleForStanglW
2013-10-02 20:35 - 2012-09-27 09:17 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2013-10-02 20:34 - 2012-12-08 19:55 - 00000000 _____ C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-09-30 17:26 - 2012-05-17 22:23 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2013-09-29 18:31 - 2012-11-12 10:01 - 00000000 ____D C:\Users\StanglW\Desktop\Euralis
2013-09-25 17:11 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\NDF
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\zh-HK
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\tr-TR
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\th-TH
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\sl-SI
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\sk-SK
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\ro-RO
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\lv-LV
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\lt-LT
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\hr-HR
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\he-IL
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\et-EE
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\bg-BG
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\ar-SA
2013-09-21 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\windows\Help
2013-09-21 20:29 - 2013-09-21 20:29 - 00000000 ____D C:\Users\StanglW\AppData\Roaming\InstallShield
2013-09-21 20:29 - 2012-09-05 21:30 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-09-21 20:28 - 2012-09-05 21:30 - 07930368 _____ (Broadcom Corporation) C:\windows\system32\BCMWLCPL.CPL
2013-09-21 20:28 - 2012-09-05 21:30 - 04961800 _____ (Microsoft Corporation) C:\windows\SysWOW64\vcredist_x64.exe
2013-09-21 20:28 - 2012-09-05 21:30 - 04747880 _____ (Broadcom Corporation) C:\windows\system32\Drivers\BCMWL664.SYS
2013-09-21 20:28 - 2012-09-05 21:30 - 04698112 _____ (Broadcom Corporation) C:\windows\system32\bcmttls.dll
2013-09-21 20:28 - 2012-09-05 21:30 - 03952640 _____ (Broadcom Corporation) C:\windows\system32\bcmihvsrv64.dll
2013-09-21 20:28 - 2012-09-05 21:30 - 03617792 _____ (Broadcom Corporation) C:\windows\system32\bcmihvui64.dll
2013-09-21 20:28 - 2012-09-05 21:30 - 03161088 _____ (Microsoft Corporation) C:\windows\system32\vcredist_x64.exe
2013-09-21 20:28 - 2012-09-05 21:30 - 01058816 _____ (Broadcom Corporation) C:\windows\system32\BCMLogon.dll
2013-09-21 20:28 - 2012-09-05 21:30 - 00095584 _____ (Broadcom Corporation) C:\windows\system32\bcmwlcoi.dll
2013-09-21 20:28 - 2012-09-05 21:30 - 00073728 _____ (Broadcom Corporation) C:\windows\system32\wltrynt.dll
2013-09-21 20:28 - 2012-09-05 21:30 - 00035344 _____ (CACE Technologies, Inc.) C:\windows\system32\Drivers\npf.sys
2013-09-21 20:28 - 2012-09-05 21:30 - 00022632 _____ (Broadcom Corporation) C:\windows\system32\Drivers\bcm42rly.sys
2013-09-21 20:28 - 2012-09-05 21:30 - 00006656 _____ C:\windows\system32\bcmwlrc.dll
2013-09-21 20:28 - 2012-09-05 21:30 - 00000446 _____ C:\windows\SysWOW64\vcredist_x64.bat
2013-09-21 20:28 - 2012-09-05 21:30 - 00000445 _____ C:\windows\system32\vcredist_x64.bat
2013-09-21 20:28 - 2011-07-29 01:51 - 00000000 ____D C:\swsetup
2013-09-19 16:48 - 2013-08-12 08:31 - 00000000 ____D C:\Users\StanglW\Desktop\Feldtage 13
2013-09-19 16:09 - 2012-12-10 10:29 - 00000000 ____D C:\Users\StanglW\Desktop\RK
2013-09-14 21:38 - 2013-04-28 13:00 - 00000178 _____ C:\camera.log
2013-09-14 21:38 - 2013-04-28 12:59 - 00001587 _____ C:\HPCamDrv.log
2013-09-14 21:37 - 2012-09-05 21:37 - 00004096 _____ (Hewlett-Packard Company) C:\windows\SysWOW64\sigfile.exe
2013-09-14 21:27 - 2012-05-17 22:13 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2013-09-14 21:25 - 2012-11-02 13:30 - 00000000 ____D C:\Users\StanglW\AppData\Roaming\hpqLog
2013-09-14 20:30 - 2012-11-02 13:29 - 00000000 ___RD C:\Users\StanglW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-14 20:30 - 2012-11-02 13:29 - 00000000 ___RD C:\Users\StanglW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-14 20:30 - 2012-05-17 22:34 - 00034272 _____ C:\windows\DPINST.LOG
2013-09-14 20:29 - 2013-09-14 20:29 - 00000000 ____D C:\windows\DPDrv
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\SysWOW64\zh-Hant
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\SysWOW64\zh-Hans
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\SysWOW64\ru
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\SysWOW64\ko
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\SysWOW64\ja
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\SysWOW64\es
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\SysWOW64\cs
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\system32\zh-Hant
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\system32\zh-Hans
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\system32\ru
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\system32\ko
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\system32\ja
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\system32\es
2013-09-14 20:29 - 2012-09-05 21:26 - 00000000 ____D C:\windows\system32\cs
2013-09-14 20:29 - 2012-05-17 22:28 - 00000000 ____D C:\Program Files\Hewlett-Packard
2013-09-14 20:29 - 2012-05-17 21:18 - 00000000 ____D C:\windows\SysWOW64\it
2013-09-14 20:29 - 2012-05-17 21:18 - 00000000 ____D C:\windows\system32\it
2013-09-14 20:29 - 2012-05-17 21:15 - 00000000 ____D C:\windows\SysWOW64\de
2013-09-14 20:29 - 2012-05-17 21:15 - 00000000 ____D C:\windows\system32\de
2013-09-14 20:29 - 2012-05-17 21:12 - 00000000 ____D C:\windows\SysWOW64\fr
2013-09-14 20:29 - 2012-05-17 21:12 - 00000000 ____D C:\windows\system32\fr
2013-09-14 20:28 - 2013-09-14 20:28 - 00003148 _____ C:\windows\System32\Tasks\SidebarExecute
2013-09-14 19:52 - 2012-05-17 22:34 - 00001324 _____ C:\windows\Synaptics.log
2013-09-14 19:51 - 2013-09-14 19:51 - 00532208 _____ (Synaptics Incorporated) C:\windows\SysWOW64\SynCOM.dll
2013-09-14 19:51 - 2013-09-14 19:51 - 00468720 _____ (Synaptics Incorporated) C:\windows\system32\Drivers\SynTP.sys
2013-09-14 19:51 - 2013-09-14 19:51 - 00229616 _____ (Synaptics Incorporated) C:\windows\system32\SynTPAPI.dll
2013-09-14 19:51 - 2013-09-14 19:51 - 00180464 _____ (Synaptics Incorporated) C:\windows\system32\SynTPCo16.dll
2013-09-14 19:51 - 2013-09-14 19:51 - 00114416 _____ (Synaptics Incorporated) C:\windows\SysWOW64\SynTPCOM.dll
2013-09-14 19:51 - 2012-03-09 05:55 - 01035504 _____ (Synaptics Incorporated) C:\windows\system32\SynCOM.dll
2013-09-14 19:22 - 2013-09-14 19:21 - 00000000 ____D C:\Program Files\IDT
2013-09-14 19:21 - 2013-09-14 19:21 - 02186752 _____ (IDT, Inc.) C:\windows\system32\stapo64.dll
2013-09-14 19:21 - 2013-09-14 19:21 - 00672256 ____N (IDT, Inc.) C:\windows\system32\stapi64.dll
2013-09-14 19:21 - 2013-09-14 19:21 - 00543744 _____ (IDT, Inc.) C:\windows\system32\Drivers\stwrt64.sys
2013-09-14 19:21 - 2013-09-14 19:21 - 00499200 _____ (IDT, Inc.) C:\windows\system32\stcplx64.dll
2013-09-14 19:21 - 2013-09-14 19:21 - 00256000 _____ (IDT, Inc.) C:\windows\system32\st646435.dll
2013-09-14 19:21 - 2012-11-02 15:35 - 08013824 _____ (IDT, Inc.) C:\windows\system32\IDTNHP.dll
2013-09-14 19:21 - 2012-11-02 15:35 - 08003072 _____ (IDT, Inc.) C:\windows\system32\IDTNGUI.exe
2013-09-14 19:21 - 2012-11-02 15:35 - 06102016 _____ (IDT, Inc.) C:\windows\system32\stlang64.dll
2013-09-14 19:21 - 2012-11-02 15:35 - 02217984 _____ (IDT, Inc.) C:\windows\system32\IDTNX.dll
2013-09-14 19:21 - 2012-11-02 15:35 - 01821184 _____ (IDT, Inc.) C:\windows\system32\IDTNC64.cpl
2013-09-14 19:21 - 2012-11-02 15:35 - 00253952 _____ (IDT, Inc.) C:\windows\system32\IDTNJ.exe
2013-09-14 19:21 - 2012-11-02 15:35 - 00224256 _____ (IDT, Inc.) C:\windows\system32\HPToneCtrls64.dll
2013-09-14 19:21 - 2012-09-05 21:55 - 01664000 _____ (IDT, Inc.) C:\windows\sttray64.exe
2013-09-14 19:21 - 2012-09-05 21:55 - 00464384 _____ (SRS Labs, Inc.) C:\windows\system32\slapoi64.dll
2013-09-14 19:21 - 2012-09-05 21:55 - 00031771 _____ C:\windows\system32\CasperPS2.xml
2013-09-14 16:11 - 2013-09-14 16:11 - 01478397 _____ C:\Users\Public\Documents\Flutlichtfeldtag Hofer.ppsx
2013-09-09 09:46 - 2013-09-09 10:08 - 00000822 _____ C:\Users\Public\Documents\Hillebrand Feldtagseinladung 13.lnk
2013-09-07 09:17 - 2013-09-07 09:17 - 00174080 _____ C:\Users\Public\Documents\RK WS 2013 Aug.xls
2013-09-04 18:25 - 2013-09-04 18:25 - 00014538 _____ C:\Users\Public\Documents\Kopie von Inv VZ Stangl Werner.xlsx
2013-09-04 18:21 - 2013-09-04 18:21 - 00014107 _____ C:\Users\Public\Documents\Kopie von Inv VZ Team Süd PP.xlsx
2013-09-04 18:07 - 2013-09-04 18:07 - 00049664 _____ C:\Users\Public\Documents\Kopie von Leistungsbeurteilungsbogen 05-2008 SaHe.xls
2013-09-04 18:03 - 2013-09-04 18:03 - 00049664 _____ C:\Users\Public\Documents\Kopie von Leistungsbeurteilungsbogen 05-2008 RS.xls
Files to move or delete:
====================
C:\Users\StanglW\AppData\Roaming\data.dat
C:\Users\StanglW\AppData\Roaming\settings.ini
C:\Users\StanglW\AppData\Roaming\i.ini
Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\HPSWF.EXE
C:\Users\Administrator\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
C:\Users\Administrator\AppData\Local\Temp\pdf24-creator-update.exe
C:\Users\Administrator\AppData\Local\Temp\SWHelperQueryW.dll
C:\Users\Administrator\AppData\Local\Temp\SWHelperWrapper.exe
C:\Users\EURALIS\AppData\Local\Temp\HPSWF.EXE
C:\Users\EURALIS\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
C:\Users\EURALIS\AppData\Local\Temp\Resource.exe
C:\Users\EURALIS\AppData\Local\Temp\SWHelperQueryW.dll
C:\Users\EURALIS\AppData\Local\Temp\uninstall.exe
C:\Users\EURALIS\AppData\Local\Temp\UninstallHPSA.exe
C:\Users\StanglW\AppData\Local\Temp\AtpTimerInfo.dll
C:\Users\StanglW\AppData\Local\Temp\Extract.exe
C:\Users\StanglW\AppData\Local\Temp\HPSWF.EXE
C:\Users\StanglW\AppData\Local\Temp\pdf24-creator-update.exe
C:\Users\StanglW\AppData\Local\Temp\QuickStores_Unlocker.exe
C:\Users\StanglW\AppData\Local\Temp\SP56967.exe
C:\Users\StanglW\AppData\Local\Temp\SP57009.exe
C:\Users\StanglW\AppData\Local\Temp\SP57443.exe
C:\Users\StanglW\AppData\Local\Temp\SP57486.exe
C:\Users\StanglW\AppData\Local\Temp\SP57489.exe
C:\Users\StanglW\AppData\Local\Temp\SP57555.exe
C:\Users\StanglW\AppData\Local\Temp\SP57556.exe
C:\Users\StanglW\AppData\Local\Temp\SP57879.exe
C:\Users\StanglW\AppData\Local\Temp\SP57918.exe
C:\Users\StanglW\AppData\Local\Temp\SP58266.exe
C:\Users\StanglW\AppData\Local\Temp\SP58268.exe
C:\Users\StanglW\AppData\Local\Temp\SP58322.exe
C:\Users\StanglW\AppData\Local\Temp\SP58404.exe
C:\Users\StanglW\AppData\Local\Temp\SP58647.exe
C:\Users\StanglW\AppData\Local\Temp\SP58738.exe
C:\Users\StanglW\AppData\Local\Temp\sp58915.exe
C:\Users\StanglW\AppData\Local\Temp\SP58940.exe
C:\Users\StanglW\AppData\Local\Temp\SP59068.exe
C:\Users\StanglW\AppData\Local\Temp\SP59202.exe
C:\Users\StanglW\AppData\Local\Temp\SP59240.exe
C:\Users\StanglW\AppData\Local\Temp\SP59257.exe
C:\Users\StanglW\AppData\Local\Temp\SP59282.exe
C:\Users\StanglW\AppData\Local\Temp\SP59346.exe
C:\Users\StanglW\AppData\Local\Temp\SP59529.exe
C:\Users\StanglW\AppData\Local\Temp\SP59530.exe
C:\Users\StanglW\AppData\Local\Temp\SP59885.exe
C:\Users\StanglW\AppData\Local\Temp\SP59982.exe
C:\Users\StanglW\AppData\Local\Temp\SP60202.exe
C:\Users\StanglW\AppData\Local\Temp\SP60317.exe
C:\Users\StanglW\AppData\Local\Temp\SP60504.exe
C:\Users\StanglW\AppData\Local\Temp\SP60686.exe
C:\Users\StanglW\AppData\Local\Temp\SP60775.exe
C:\Users\StanglW\AppData\Local\Temp\SP60832.exe
C:\Users\StanglW\AppData\Local\Temp\SP60921.exe
C:\Users\StanglW\AppData\Local\Temp\SP61040.exe
C:\Users\StanglW\AppData\Local\Temp\SP61293.exe
C:\Users\StanglW\AppData\Local\Temp\SP61617.exe
C:\Users\StanglW\AppData\Local\Temp\SP61822.exe
C:\Users\StanglW\AppData\Local\Temp\SP61962.exe
C:\Users\StanglW\AppData\Local\Temp\SP62171.exe
C:\Users\StanglW\AppData\Local\Temp\SP62737.exe
C:\Users\StanglW\AppData\Local\Temp\SWHelperQueryW.dll
C:\Users\StanglW\AppData\Local\Temp\SWHelperWrapper.exe
C:\Users\StanglW\AppData\Local\Temp\UninstallHPSA.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-21 10:20
==================== End Of Log ============================ --- --- ---
--- --- ---
So richtig ??? |