FIRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by D (administrator) on DS on 03-10-2013 22:02:27
Running from C:\Users\D\Downloads\000 Trojaner
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(HP) C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
() C:\Windows\system32\valWBFPolicyService.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(AuthenTec Inc.) C:\Program Files (x86)\HP SimplePass\TouchControl.exe
() C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(SWE Sven Ritter) C:\Program Files\SpeedProject\SpeedCommander 14\SpeedCommander.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Microsoft Corporation) C:\Users\D\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(CANON INC.) C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1702912 2013-02-05] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3053808 2013-04-24] (Synaptics Incorporated)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [519408 2013-07-18] (Acronis)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [SkyDrive] - C:\Users\D\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257136 2013-09-10] (Microsoft Corporation)
HKCU\...\Run: [AdobeBridge] - [x]
HKLM-x32\...\Run: [BtTray] - C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [379904 2013-01-10] (IVT Corporation)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] - C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-03-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [HPMessageService] - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-02-25] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1343904 2012-11-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [206240 2010-08-24] (CANON INC.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [7818392 2013-08-22] (Acronis)
HKLM-x32\...\Run: [AcronisTibMounterMonitor] - C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1105848 2013-01-10] (Acronis)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-09-03] (Adobe Systems Inc.)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [266448 2013-06-21] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll [214448 2013-06-21] (NVIDIA Corporation)
Startup: C:\Users\D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
SearchScopes: HKLM - DefaultScope {6AA080A9-0BE1-4575-BD9B-9E2E0D024E56} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd84&cd=2XzuyEtN2Y1L1Qzu0B0CzzyDyDyC0FyDtByBtD0B0FyCtDtBtN0D0Tzu0SyCtDzytN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QzzyE&cr=999001734&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {4F624BB8-CB85-3D44-A096-1D29442FECE4} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM - {5206B463-D67E-4B49-94CD-816FDB867C50} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {6AA080A9-0BE1-4575-BD9B-9E2E0D024E56} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd84&cd=2XzuyEtN2Y1L1Qzu0B0CzzyDyDyC0FyDtByBtD0B0FyCtDtBtN0D0Tzu0SyCtDzytN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QzzyE&cr=999001734&ir=
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - {0C70D6A6-AC2B-DC86-4524-337800CC984A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {5206B463-D67E-4B49-94CD-816FDB867C50} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {4F624BB8-CB85-3D44-A096-1D29442FECE4} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - {5206B463-D67E-4B49-94CD-816FDB867C50} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {6AA080A9-0BE1-4575-BD9B-9E2E0D024E56} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd84&cd=2XzuyEtN2Y1L1Qzu0B0CzzyDyDyC0FyDtByBtD0B0FyCtDtBtN0D0Tzu0SyCtDzytN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QzzyE&cr=999001734&ir=
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\SysWow64\skype4com.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\D\AppData\Roaming\Mozilla\Firefox\Profiles\y58pgsg6.default-1380739040304
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files (x86)\HP SimplePass\npffwloplugin.dll ( HP)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\D\AppData\Roaming\Mozilla\Firefox\Profiles\y58pgsg6.default-1380739040304\Extensions\93abedcf-8e3a-4d02-b761-d1441e437c09@243f129d-aee2-42c2-bcd1-48858e1c22fd.com
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn\
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (SuperLyrics-1) - C:\Users\D\AppData\Local\Google\Chrome\User Data\Default\Extensions\akjeeijengimhajmemcjoocganikbopa\1.24.12_0
CHR HKLM-x32\...\Chrome\Extension: [hmbkhknacohfhbmmpnmbkgdffdbildof] - C:\Program Files (x86)\HP SimplePass\tschrome.crx
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Exts\Chrome.crx
==================== Services (Whitelisted) =================
R2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1626872 2013-01-31] (IVT Corporation)
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2013-01-10] (IVT Corporation)
R2 FPLService; C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [1641768 2013-02-07] (HP)
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-02-01] (Hewlett-Packard Development Company, L.P.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-10] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [180200 2013-02-13] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-01-14] (Intel Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1901752 2013-07-22] (Microsoft Corporation)
S3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401856 2013-01-07] (AuthenTec, Inc.)
R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [28160 2013-03-19] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20130924.001\BHDrvx64.sys [1525848 2013-09-24] (Symantec Corporation)
R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20130924.001\BHDrvx64.sys [1525848 2013-09-24] (Symantec Corporation)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
U4 BthAvrcpTg;
U4 BthHFEnum;
U4 bthhfhid;
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [49200 2013-02-26] (Ralink Corporation)
R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-31] (Symantec Corporation)
R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-31] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-31] (Symantec Corporation)
R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20131002.001\IDSvia64.sys [520280 2013-08-30] (Symantec Corporation)
R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20131002.001\IDSvia64.sys [520280 2013-08-30] (Symantec Corporation)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21048 2013-02-13] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21048 2013-02-13] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-02-13] ()
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20131003.002\ENG64.SYS [126040 2013-08-31] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20131003.002\ENG64.SYS [126040 2013-08-31] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20131003.002\EX64.SYS [2099288 2013-08-31] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20131003.002\EX64.SYS [2099288 2013-08-31] (Symantec Corporation)
S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [288328 2013-01-24] (Realtek Semiconductor Corp.)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1149232 2013-03-09] (Ralink Technology, Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29424 2013-04-24] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2013-04-24] (Synaptics Incorporated)
R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
R3 SymDS; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R3 SymEFA; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-06-20] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-09-01] (Symantec Corporation)
R3 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2013-09-29] (Acronis International GmbH)
R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2013-09-29] (Acronis)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-10-03] ()
U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [33968 2012-12-19] (IVT Corporation)
U5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [33968 2012-12-19] (IVT Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-03 22:02 - 2013-10-03 22:02 - 00000000 ____D C:\FRST
2013-10-03 21:59 - 2013-10-03 21:59 - 00000000 _____ C:\Users\D\defogger_reenable
2013-10-03 21:55 - 2013-10-03 21:59 - 00000000 ____D C:\Users\D\Downloads\000 Trojaner
2013-10-03 21:49 - 2013-10-03 21:49 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-10-03 21:48 - 2013-10-03 21:48 - 00001186 _____ C:\Windows\PFRO.log
2013-10-03 16:41 - 2013-10-03 16:41 - 02296952 _____ C:\Users\D\Downloads\avira_free_antivirus.exe
2013-10-03 14:47 - 2013-10-03 14:47 - 00128479 _____ C:\Users\D\Downloads\alle_arbeitsblaetter_mit_loesungen.zip
2013-10-03 13:52 - 2013-10-03 13:52 - 02347384 _____ (ESET) C:\Users\D\Downloads\esetsmartinstaller_deu.exe
2013-10-03 13:52 - 2013-10-03 13:52 - 00000000 ____D C:\Users\D\AppData\Roaming\ESET
2013-10-03 13:52 - 2013-10-03 13:52 - 00000000 ____D C:\Users\D\AppData\Local\ESET
2013-10-03 13:26 - 2013-10-03 13:26 - 00001116 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-03 13:26 - 2013-10-03 13:26 - 00000000 ____D C:\Users\D\AppData\Roaming\Malwarebytes
2013-10-03 13:26 - 2013-10-03 13:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-03 13:26 - 2013-10-03 13:26 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-03 13:26 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-03 13:25 - 2013-10-03 13:25 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\D\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-02 21:27 - 2013-10-02 21:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-02 20:37 - 2013-10-02 20:37 - 00000000 ____D C:\Users\D\Desktop\Alte Firefox-Daten
2013-10-01 17:02 - 2013-10-01 17:02 - 00011264 ___SH C:\Users\D\Thumbs.db
2013-10-01 16:51 - 2013-10-03 21:48 - 00000000 ____D C:\AdwCleaner
2013-10-01 16:50 - 2013-10-01 16:50 - 01045226 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-30 20:38 - 2013-09-30 20:38 - 04653860 _____ C:\Users\D\Downloads\e*****@*****.**
2013-09-30 20:38 - 2013-09-30 20:38 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-30 20:37 - 2013-09-30 20:37 - 03341001 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-30 20:37 - 2013-09-30 20:37 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 22:25 - 2013-09-29 22:25 - 00000000 ____D C:\Users\D\Documents\*****@*****.**
2013-09-29 22:25 - 2013-09-29 22:25 - 00000000 ____D C:\Users\D\AppData\Roaming\PACE Anti-Piracy
2013-09-29 22:25 - 2013-09-29 22:25 - 00000000 ____D C:\Users\D\AppData\Local\PACE Anti-Piracy
2013-09-29 22:25 - 2013-09-29 22:25 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2013-09-29 21:19 - 2013-09-29 21:19 - 00000000 ____D C:\Users\D\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-09-29 21:09 - 2013-09-29 21:09 - 00003482 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-*****@*****.**
2013-09-29 20:58 - 2013-09-29 20:58 - 00000000 ____D C:\ProgramData\ALM
2013-09-29 20:55 - 2013-09-29 20:55 - 00000000 ____D C:\Users\D\Adobe Flash Builder 4.6
2013-09-29 20:51 - 2013-09-29 21:24 - 00002033 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2013-09-29 20:48 - 2013-09-29 20:48 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-09-29 20:48 - 2011-11-03 03:01 - 00056208 ____N (Rovi Corporation) C:\Windows\system32\Drivers\PxHlpa64.sys
2013-09-29 20:48 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys
2013-09-29 20:48 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys
2013-09-29 20:45 - 2013-09-29 20:45 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-09-29 20:45 - 2013-09-29 20:45 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-09-29 20:41 - 2013-09-29 21:03 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-29 20:40 - 2013-09-29 21:04 - 00000000 ____D C:\Program Files\Adobe
2013-09-29 20:39 - 2013-09-29 21:04 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-09-29 20:34 - 2013-10-03 21:38 - 00000000 ____D C:\Users\D\AppData\*****@*****.**
2013-09-29 20:34 - 2013-09-29 22:26 - 00000000 ____D C:\ProgramData\Adobe
2013-09-29 20:13 - 2013-09-29 20:13 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 20:11 - 2013-09-29 22:24 - 00000000 ____D C:\Users\D\AppData\*****@*****.**
2013-09-29 20:00 - 2012-06-30 17:47 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 17:05 - 2013-10-03 21:19 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 17:04 - 2013-09-29 17:04 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 16:50 - 2013-09-29 16:54 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 15:58 - 2013-09-29 15:58 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-09-29 15:58 - 2013-09-29 15:58 - 00000829 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-29 15:58 - 2013-09-29 15:58 - 00000000 ____D C:\Program Files\CCleaner
2013-09-29 15:09 - 2013-09-29 15:09 - 06287769 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 13:40 - 2013-09-29 13:40 - 145672688 _____ C:\Users\D\AppData\Local\ACCCx2_1_2_232.zip.aamdownload
2013-09-29 13:40 - 2013-09-29 13:40 - 00001817 _____ C:\Users\D\AppData\Local\ACCCx2_1_2_232.zip.aamdownload.aamd
2013-09-29 12:53 - 2013-10-03 21:00 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 11:27 - 2013-09-29 11:27 - 00000000 ____D C:\Users\D\AppData\Roaming\Acronis
2013-09-29 11:25 - 2013-09-29 12:33 - 00000000 ____D C:\ProgramData\Acronis
2013-09-29 11:25 - 2013-09-29 11:25 - 01464096 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tdrpman.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 01120032 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tib.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00367200 _____ (Acronis) C:\Windows\system32\Drivers\afcdp.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00269600 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\snapman.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00183224 _____ (Acronis) C:\Windows\system32\Drivers\tib_mounter.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00116000 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\fltsrv.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00001208 _____ C:\Users\Public\Desktop\*****@*****.**
2013-09-29 11:24 - 2013-09-29 11:24 - 00000000 ____D C:\Program Files (x86)\Acronis
2013-09-29 11:16 - 2013-09-29 11:17 - 00000000 ____D C:\Users\D\Downloads\A*****@*****.**
2013-09-29 10:48 - 2013-09-29 10:51 - 120291328 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 08:50 - 2013-09-29 13:33 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 01:40 - 2013-09-29 01:40 - 03752202 _____ C:\Users\D\Downloads\8*****@*****.**
2013-09-29 01:37 - 2013-09-29 01:38 - 09502479 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 01:16 - 2013-09-29 01:17 - 00581632 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 01:12 - 2013-09-29 01:12 - 01182697 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 00:55 - 2013-09-29 00:55 - 05670459 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 00:40 - 2013-09-29 00:45 - 58375053 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 00:37 - 2013-09-29 00:37 - 00546854 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 00:29 - 2013-09-29 00:30 - 05987546 _____ C:\Users\D\Downloads\d*****@*****.**
2013-09-29 00:28 - 2013-09-29 00:28 - 00647455 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 00:08 - 2013-09-29 00:08 - 00000000 ____D C:\Users\D\Downloads\extracted
2013-09-23 13:29 - 2013-09-23 02:25 - 613343575 _____ C:\Users\D\*****@*****.**
2013-09-23 13:13 - 2013-09-22 22:11 - 1030300676 _____ C:\Users\D\*****@*****.**
2013-09-23 12:46 - 2013-09-22 22:13 - 366396810 _____ C:\Users\D\*****@*****.**
2013-09-23 11:12 - 2013-09-23 11:13 - 00000000 ____D C:\Bilder *****@*****.**
2013-09-22 13:13 - 2013-09-22 13:54 - 00010594 _____ C:\Users\D\Downloads\***************.xlsx
2013-09-19 10:03 - 2013-09-19 10:03 - 00799781 _____ C:\Users\D\Downloads\Elternbrief_Schulfest_2013_Bitte.docm
2013-09-18 10:23 - 2013-09-19 10:03 - 00000000 ____D C:\Users\D\Downloads\*************
2013-09-17 18:21 - 2013-09-17 18:21 - 00000000 ____D C:\Users\D\Documents\Red Alert 3 Uprising
2013-09-15 11:07 - 2013-09-29 21:28 - 05126064 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-14 23:21 - 2013-09-14 23:23 - 00000000 ____D C:\Users\D\AppData\Roaming\Apple Computer
2013-09-14 23:21 - 2013-09-14 23:21 - 00001790 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-09-14 23:21 - 2013-09-14 23:21 - 00000000 ____D C:\Users\D\AppData\Local\Apple Computer
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\ProgramData\Apple Computer
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\Program Files\iTunes
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\Program Files\iPod
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-09-14 23:20 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2013-09-14 23:19 - 2013-09-14 23:19 - 00000000 ____D C:\Users\D\AppData\Local\Apple
2013-09-14 23:19 - 2013-09-14 23:19 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-09-14 23:19 - 2013-09-14 23:19 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-09-14 23:15 - 2013-09-29 01:47 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-14 23:14 - 2013-09-20 22:28 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-14 11:05 - 2013-09-14 11:10 - 90889040 _____ (Apple Inc.) C:\Users\D\Downloads\iTunes64Setup.exe
2013-09-13 21:25 - 2013-09-13 21:25 - 00000000 ____D C:\Users\D\AppData\Roaming\Red Alert 3 Uprising
2013-09-13 21:25 - 2013-09-13 21:25 - 00000000 ____D C:\Users\D\AppData\Roaming\Red Alert 3
2013-09-13 21:06 - 2013-09-13 21:06 - 00001349 _____ C:\Users\Public\Desktop\Command and Conquer Red Alert 3 and Uprising.lnk
2013-09-13 18:32 - 2013-09-13 18:33 - 00000000 ____D C:\Users\D\Downloads\C&C 3 - Kanes Rach Maps
2013-09-13 18:32 - 2013-09-13 18:32 - 06052462 _____ (InstallShield Software Corporation) C:\Users\D\Downloads\CC3Worldbuilder.exe
2013-09-12 17:06 - 2013-09-12 17:06 - 00001356 _____ C:\Users\Public\Desktop\Command and Conquer Red Alert 2.lnk
2013-09-12 17:06 - 2013-09-12 17:06 - 00000000 ____D C:\Program Files (x86)\WestwoodOnline
2013-09-11 18:47 - 2013-08-21 06:11 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-11 18:47 - 2013-08-21 06:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-11 18:47 - 2013-08-21 06:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-11 18:47 - 2013-08-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 18:47 - 2013-08-21 06:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-11 18:47 - 2013-08-21 04:05 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-11 18:47 - 2013-08-21 04:05 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-11 18:47 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2013-09-11 18:47 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2013-09-11 18:47 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-09-11 18:47 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2013-09-11 18:47 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2013-09-11 18:47 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-09-11 18:47 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2013-09-11 18:47 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2013-09-11 18:47 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll
2013-09-11 18:47 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-09-11 18:47 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2013-09-11 18:47 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2013-09-11 18:47 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll
2013-09-11 18:46 - 2013-08-21 06:12 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-11 18:46 - 2013-08-21 06:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-11 18:46 - 2013-08-21 06:11 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-09-11 18:46 - 2013-08-21 06:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-11 18:46 - 2013-08-21 06:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-11 18:46 - 2013-08-21 06:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-11 18:46 - 2013-08-21 06:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-11 18:46 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-09-11 18:46 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-11 18:46 - 2013-08-21 06:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-11 18:46 - 2013-08-21 04:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-11 18:46 - 2013-08-21 04:06 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-11 18:46 - 2013-08-21 04:06 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-11 18:46 - 2013-08-21 04:06 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-09-11 18:46 - 2013-08-21 04:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-11 18:46 - 2013-08-21 04:05 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-11 18:46 - 2013-08-21 04:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-11 18:46 - 2013-08-21 04:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-11 18:46 - 2013-08-21 04:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-11 18:46 - 2013-08-21 04:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-11 18:46 - 2013-08-21 04:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-11 18:46 - 2013-08-21 04:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-11 18:46 - 2013-08-21 03:43 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-11 18:46 - 2013-08-21 01:52 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-09-11 18:46 - 2013-08-07 07:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2013-09-11 18:46 - 2013-08-03 06:30 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 18:46 - 2013-07-09 10:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys
2013-09-11 18:46 - 2013-07-09 08:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2013-09-11 18:46 - 2013-07-09 06:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2013-09-11 18:46 - 2013-07-09 05:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2013-09-11 18:46 - 2013-07-09 00:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2013-09-11 18:46 - 2013-07-09 00:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2013-09-11 18:46 - 2013-07-09 00:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Wwanadvui.dll
2013-09-11 18:46 - 2013-07-09 00:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2013-09-11 18:46 - 2013-07-06 02:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2013-09-11 18:46 - 2013-07-03 02:23 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-09-11 18:46 - 2013-07-03 02:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2013-09-11 18:46 - 2013-07-03 02:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2013-09-11 18:46 - 2013-07-03 02:22 - 01300480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-09-11 18:46 - 2013-07-03 02:11 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-09-11 18:46 - 2013-07-03 02:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-09-11 18:46 - 2013-07-03 02:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2013-09-11 18:46 - 2013-07-02 00:08 - 00387583 _____ C:\Windows\system32\ApnDatabase.xml
2013-09-11 18:46 - 2013-07-01 00:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe
2013-09-11 18:46 - 2013-07-01 00:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\openfiles.exe
2013-09-11 18:46 - 2013-06-29 08:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-09-11 18:46 - 2013-06-29 08:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-09-11 18:46 - 2013-06-29 07:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2013-09-11 18:46 - 2013-06-29 03:12 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-09-11 18:46 - 2013-06-26 05:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2013-09-11 18:46 - 2013-06-26 04:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2013-09-11 18:46 - 2013-06-25 00:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-09-11 18:46 - 2013-06-25 00:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2013-09-11 18:46 - 2013-06-25 00:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2013-09-11 18:46 - 2013-06-19 07:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll
2013-09-11 18:46 - 2013-06-19 07:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2013-09-11 18:46 - 2013-06-19 00:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll
2013-09-11 18:46 - 2013-06-19 00:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2013-09-11 18:46 - 2013-06-12 01:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2013-09-11 18:46 - 2013-06-12 01:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2013-09-11 18:46 - 2013-06-10 23:17 - 00096512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2013-09-11 18:46 - 2013-06-10 21:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-09-11 18:46 - 2013-06-10 21:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-09-11 18:46 - 2013-06-10 21:15 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2013-09-11 18:46 - 2013-06-10 21:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-09-11 18:46 - 2013-06-10 21:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-09-11 18:46 - 2013-06-10 21:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-09-11 18:46 - 2013-06-06 10:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2013-09-11 09:58 - 2013-09-11 09:58 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-09-10 20:57 - 2013-09-10 20:57 - 00000878 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-10 15:26 - 2013-09-10 15:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-09-10 15:10 - 2013-09-10 15:43 - 960600988 _____ C:\Users\D\Downloads\UT3TitanPack.exe
2013-09-10 15:07 - 2013-09-10 15:26 - 343926484 _____ C:\Users\D\Downloads\UT3-Patch5.exe
2013-09-10 14:26 - 2013-09-11 17:36 - 01995034 _____ C:\Users\D\Downloads\Vanessa Zeitstrahl.xlsx
2013-09-10 14:25 - 2013-10-03 21:51 - 00005096 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for DS-D DS
2013-09-08 20:02 - 2013-09-08 20:02 - 00466944 _____ (Benjamin Bentmann) C:\Users\D\Downloads\BeCyPDFMetaEdit-2.37.0-de.exe
2013-09-08 20:02 - 2013-09-08 20:02 - 00001020 _____ C:\Users\Public\Desktop\BeCyPDFMetaEdit.lnk
2013-09-08 20:02 - 2013-09-08 20:02 - 00000000 ____D C:\Program Files (x86)\BeCyPDFMetaEdit
2013-09-08 17:22 - 2013-09-29 21:16 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-09-08 16:57 - 2013-09-08 16:57 - 00000000 ___HD C:\ProgramData\CanonIJScan
2013-09-08 16:56 - 2013-09-08 16:57 - 00000000 ____D C:\Users\D\AppData\Roaming\Canon
2013-09-08 16:50 - 2013-09-08 16:50 - 00002016 _____ C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2013-09-08 16:50 - 2013-09-08 16:50 - 00000000 ____D C:\ProgramData\Canon IJ Network Tool
2013-09-08 16:50 - 2010-03-18 19:25 - 00307200 _____ (CANON INC.) C:\Windows\SysWOW64\CNC5200L.dll
2013-09-08 16:50 - 2010-03-18 17:11 - 00106496 _____ (CANON INC.) C:\Windows\SysWOW64\CNC5200U.dll
2013-09-08 16:50 - 2009-11-27 14:29 - 00013056 _____ C:\Windows\SysWOW64\CNC1749D.TBL
2013-09-08 16:50 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2013-09-08 16:49 - 2013-09-08 16:49 - 00000000 ___HD C:\Program Files\CanonBJ
2013-09-08 16:49 - 2013-09-08 16:49 - 00000000 ____D C:\Windows\system32\STRING
2013-09-08 16:49 - 2012-06-14 17:18 - 00366592 _____ (CANON INC.) C:\Windows\SysWOW64\CNMNPPM.DLL
2013-09-08 16:49 - 2012-06-14 17:18 - 00359936 _____ (CANON INC.) C:\Windows\system32\CNMN6PPM.DLL
2013-09-08 16:49 - 2012-06-14 17:18 - 00039424 _____ (CANON INC.) C:\Windows\system32\CNMN6UI.DLL
2013-09-08 16:49 - 2012-03-14 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMAE.DLL
2013-09-08 16:49 - 2010-03-11 08:57 - 00248320 _____ (CANON INC.) C:\Windows\system32\CNMIUAE.DLL
2013-09-08 16:45 - 2013-09-08 16:50 - 00000000 ____D C:\Program Files (x86)\Canon
2013-09-08 16:45 - 2013-09-08 16:45 - 00002102 _____ C:\Users\Public\Desktop\Canon MP Navigator EX 4.0.lnk
2013-09-08 13:18 - 2013-09-08 13:18 - 00000000 ____D C:\Users\D\Documents\Benutzerdefinierte Office-Vorlagen
2013-09-08 11:00 - 2013-09-21 12:11 - 00299008 ___SH C:\Users\D\Downloads\Thumbs.db
2013-09-08 10:23 - 2013-09-18 17:52 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\CrashDumps
2013-09-07 09:11 - 2013-09-07 09:11 - 00000000 ____D C:\Users\D\AppData\Roaming\TuneUp Software
2013-09-07 09:10 - 2013-09-20 22:35 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-09-07 09:10 - 2013-09-07 09:17 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-09-07 09:08 - 2013-09-07 09:09 - 32555432 _____ (TuneUp Software) C:\Users\D\Downloads\T*****@*****.**
2013-09-07 08:55 - 2013-09-07 08:55 - 00000000 ___HD C:\Windows\system32\CanonIJ Uninstaller Information
2013-09-07 08:54 - 2013-09-07 08:54 - 00000000 ___HD C:\ProgramData\CanonBJ
2013-09-07 08:54 - 2013-09-07 08:54 - 00000000 ____D C:\Users\D\Documents\OneNote-Notizbücher
2013-09-06 17:31 - 2013-09-06 17:33 - 58232832 _____ C:\Users\D\Downloads\calibre-64bit-1.2.0.msi
2013-09-06 17:31 - 2013-09-06 17:31 - 00000000 ____D C:\Users\D\AppData\Local\calibre-cache
2013-09-06 17:30 - 2013-09-06 17:39 - 00000000 ____D C:\Users\D\Documents\Calibre-Bibliothek
2013-09-06 17:30 - 2013-09-06 17:31 - 00000000 ____D C:\Users\D\AppData\Roaming\calibre
2013-09-06 13:17 - 2013-09-27 23:28 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-06 13:16 - 2013-09-10 17:08 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-06 11:57 - 2013-10-03 21:51 - 00000000 ___RD C:\Users\D\SkyDrive
2013-09-06 11:51 - 2013-09-18 09:53 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-09-06 11:51 - 2013-09-06 11:51 - 00574656 _____ (Microsoft Corporation) C:\Users\D\Downloads\Setup.X86.de-DE_O365HomePremRetail_6d9ddcd2-9e99-4349-a015-9ce0b8163eb3_TX_DB_.exe
2013-09-05 14:27 - 2013-09-05 14:27 - 00002621 _____ C:\Users\Public\Desktop\Nero Burning ROM 12.lnk
2013-09-05 14:26 - 2013-09-05 14:27 - 00000000 ____D C:\Program Files (x86)\Nero
2013-09-05 12:52 - 2013-09-05 12:52 - 00000000 ____D C:\Users\D\Documents\My Games
2013-09-05 12:51 - 2013-09-05 12:51 - 00001040 _____ C:\Users\Public\Desktop\Unreal Tournament 3.lnk
2013-09-05 12:51 - 2013-09-05 12:51 - 00000000 ____D C:\Users\D\AppData\Roaming\InstallShield Installation Information
2013-09-05 12:29 - 2013-09-05 12:29 - 00000000 ____D C:\Program Files (x86)\Unreal Tournament 3 (LG)
2013-09-05 12:27 - 2013-09-05 12:27 - 00000000 ____D C:\Windows\45235788142C44BE8A4DDDE9A84492E5.TMP
2013-09-03 21:35 - 2013-09-03 21:36 - 00000000 ____D C:\Users\D\Downloads\C&C 3 Maps
2013-09-03 15:54 - 2013-09-03 15:54 - 00055872 _____ (Adobe Systems Inc) C:\Windows\system32\AdobePDF.dll
2013-09-03 15:54 - 2013-09-03 15:54 - 00027208 _____ (Adobe Systems Inc.) C:\Windows\system32\AdobePDFUI.dll
==================== One Month Modified Files and Folders =======
2013-10-03 22:02 - 2013-10-03 22:02 - 00000000 ____D C:\FRST
2013-10-03 22:02 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-10-03 21:59 - 2013-10-03 21:59 - 00000000 _____ C:\Users\D\defogger_reenable
2013-10-03 21:59 - 2013-10-03 21:55 - 00000000 ____D C:\Users\D\Downloads\000 Trojaner
2013-10-03 21:59 - 2013-08-31 21:38 - 00000000 ____D C:\Users\D
2013-10-03 21:56 - 2013-08-31 21:50 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1392920883-501263863-1927298622-1002
2013-10-03 21:52 - 2013-03-04 16:30 - 00000983 _____ C:\Windows\SysWOW64\bscs.ini
2013-10-03 21:51 - 2013-09-10 14:25 - 00005096 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for DS-D DS
2013-10-03 21:51 - 2013-09-06 11:57 - 00000000 ___RD C:\Users\D\SkyDrive
2013-10-03 21:51 - 2013-07-01 09:22 - 00003620 _____ C:\Windows\SysWOW64\LOCALSERVICE.INI
2013-10-03 21:49 - 2013-10-03 21:49 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-10-03 21:49 - 2013-07-01 09:22 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2013-10-03 21:49 - 2013-07-01 09:22 - 00000043 _____ C:\Windows\SysWOW64\LOCALDEVICE.INI
2013-10-03 21:49 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-03 21:48 - 2013-10-03 21:48 - 00001186 _____ C:\Windows\PFRO.log
2013-10-03 21:48 - 2013-10-01 16:51 - 00000000 ____D C:\AdwCleaner
2013-10-03 21:38 - 2013-09-29 20:34 - 00000000 ____D C:\Users\D\AppData\Local\Adobe
2013-10-03 21:29 - 2013-09-01 11:29 - 00000000 ____D C:\Users\D\AppData\Local\CrashDumps
2013-10-03 21:19 - 2013-09-29 17:05 - 00000000 ____D C:\Users\D\Downloads\Red Alert 3 Uprising Trainer 2
2013-10-03 21:00 - 2013-09-29 12:53 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-10-03 20:24 - 2013-09-01 18:21 - 00000000 ____D C:\Program Files (x86)\Origin
2013-10-03 17:29 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-10-03 16:41 - 2013-10-03 16:41 - 02296952 _____ C:\Users\D\Downloads\avira_free_antivirus.exe
2013-10-03 14:47 - 2013-10-03 14:47 - 00128479 _____ C:\Users\D\Downloads\alle_arbeitsblaetter_mit_loesungen.zip
2013-10-03 13:52 - 2013-10-03 13:52 - 02347384 _____ (ESET) C:\Users\D\Downloads\esetsmartinstaller_deu.exe
2013-10-03 13:52 - 2013-10-03 13:52 - 00000000 ____D C:\Users\D\AppData\Roaming\ESET
2013-10-03 13:52 - 2013-10-03 13:52 - 00000000 ____D C:\Users\D\AppData\Local\ESET
2013-10-03 13:33 - 2013-09-01 16:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-03 13:26 - 2013-10-03 13:26 - 00001116 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-03 13:26 - 2013-10-03 13:26 - 00000000 ____D C:\Users\D\AppData\Roaming\Malwarebytes
2013-10-03 13:26 - 2013-10-03 13:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-03 13:26 - 2013-10-03 13:26 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-03 13:25 - 2013-10-03 13:25 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\D\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-03 01:32 - 2013-09-01 16:53 - 00000000 ____D C:\Users\D\AppData\Local\Mozilla
2013-10-03 01:28 - 2013-09-01 11:27 - 00000000 ____D C:\Users\D\AppData\Roaming\vlc
2013-10-02 21:27 - 2013-10-02 21:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-02 20:37 - 2013-10-02 20:37 - 00000000 ____D C:\Users\D\Desktop\Alte Firefox-Daten
2013-10-01 17:02 - 2013-10-01 17:02 - 00011264 ___SH C:\Users\D\Thumbs.db
2013-10-01 17:00 - 2013-05-24 23:11 - 00831158 _____ C:\Windows\system32\perfh007.dat
2013-10-01 17:00 - 2013-05-24 23:11 - 00188760 _____ C:\Windows\system32\perfc007.dat
2013-10-01 17:00 - 2012-07-26 09:28 - 01952854 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-01 16:50 - 2013-10-01 16:50 - 01045226 _____ C:\Users\D\Downloads\adwcleaner.exe
2013-09-30 20:55 - 2013-09-01 11:31 - 00000000 ____D C:\Users\D\AppData\Local\JDownloader v2.0
2013-09-30 20:38 - 2013-09-30 20:38 - 04653860 _____ C:\Users\D\Downloads\e*****@*****.**
2013-09-30 20:38 - 2013-09-30 20:38 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-30 20:37 - 2013-09-30 20:37 - 03341001 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-30 20:37 - 2013-09-30 20:37 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-30 08:02 - 2013-09-02 09:11 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-09-30 08:02 - 2013-09-01 18:09 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2013-09-29 22:26 - 2013-09-29 20:34 - 00000000 ____D C:\ProgramData\Adobe
2013-09-29 22:25 - 2013-09-29 22:25 - 00000000 ____D C:\Users\D\Documents\Adobe
2013-09-29 22:25 - 2013-09-29 22:25 - 00000000 ____D C:\Users\D\AppData\Roaming\PACE Anti-Piracy
2013-09-29 22:25 - 2013-09-29 22:25 - 00000000 ____D C:\Users\D\AppData\Local\PACE Anti-Piracy
2013-09-29 22:25 - 2013-09-29 22:25 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2013-09-29 22:25 - 2013-03-06 10:55 - 00000000 ___HD C:\Users\D\AppData\Local\MSZZzqWe
2013-09-29 22:25 - 2013-01-15 11:38 - 00000000 ___HD C:\Users\D\AppData\Local\MBUJt4MZDEUjViH
2013-09-29 22:25 - 2012-02-05 22:58 - 00000000 ___HD C:\Users\D\AppData\Local\IYLpuET0edeY8d
2013-09-29 22:24 - 2013-09-29 20:11 - 00000000 ____D C:\Users\D\AppData\Roaming\Adobe
2013-09-29 21:28 - 2013-09-15 11:07 - 05126064 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-29 21:24 - 2013-09-29 20:51 - 00002033 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2013-09-29 21:19 - 2013-09-29 21:19 - 00000000 ____D C:\Users\D\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-09-29 21:16 - 2013-09-08 17:22 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-09-29 21:09 - 2013-09-29 21:09 - 00003482 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-*****@*****.**
2013-09-29 21:04 - 2013-09-29 20:40 - 00000000 ____D C:\Program Files\Adobe
2013-09-29 21:04 - 2013-09-29 20:39 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-09-29 21:03 - 2013-09-29 20:41 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-29 20:58 - 2013-09-29 20:58 - 00000000 ____D C:\ProgramData\ALM
2013-09-29 20:55 - 2013-09-29 20:55 - 00000000 ____D C:\Users\D\Adobe Flash Builder 4.6
2013-09-29 20:48 - 2013-09-29 20:48 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-09-29 20:45 - 2013-09-29 20:45 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-09-29 20:45 - 2013-09-29 20:45 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-09-29 20:29 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2013-09-29 20:13 - 2013-09-29 20:13 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 17:04 - 2013-09-29 17:04 - 00000000 ____D C:\Users\D\Downloads\Red Alert 3 Uprising Trainer
2013-09-29 16:54 - 2013-09-29 16:50 - 00000000 ____D C:\Users\D\Downloads\C&C Trainer 1
2013-09-29 16:05 - 2013-08-31 21:42 - 00000000 ___RD C:\Users\D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-29 15:59 - 2012-08-04 01:21 - 00000000 ____D C:\Windows\Panther
2013-09-29 15:58 - 2013-09-29 15:58 - 00002764 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-09-29 15:58 - 2013-09-29 15:58 - 00000829 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-29 15:58 - 2013-09-29 15:58 - 00000000 ____D C:\Program Files\CCleaner
2013-09-29 15:09 - 2013-09-29 15:09 - 06287769 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 13:40 - 2013-09-29 13:40 - 145672688 _____ C:\Users\D\AppData\Local\ACCCx2_1_2_232.zip.aamdownload
2013-09-29 13:40 - 2013-09-29 13:40 - 00001817 _____ C:\Users\D\AppData\Local\ACCCx2_1_2_232.zip.aamdownload.aamd
2013-09-29 13:33 - 2013-09-29 08:50 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 12:33 - 2013-09-29 11:25 - 00000000 ____D C:\ProgramData\Acronis
2013-09-29 11:27 - 2013-09-29 11:27 - 00000000 ____D C:\Users\D\AppData\Roaming\Acronis
2013-09-29 11:25 - 2013-09-29 11:25 - 01464096 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tdrpman.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 01120032 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tib.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00367200 _____ (Acronis) C:\Windows\system32\Drivers\afcdp.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00269600 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\snapman.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00183224 _____ (Acronis) C:\Windows\system32\Drivers\tib_mounter.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00116000 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\fltsrv.sys
2013-09-29 11:25 - 2013-09-29 11:25 - 00001208 _____ C:\Users\Public\Desktop\Acronis True Image 2014.lnk
2013-09-29 11:24 - 2013-09-29 11:24 - 00000000 ____D C:\Program Files (x86)\Acronis
2013-09-29 11:17 - 2013-09-29 11:16 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 10:51 - 2013-09-29 10:48 - 120291328 _____ C:\Users\D\Downloads\br_free_g_2013_chip.msi
2013-09-29 01:47 - 2013-09-14 23:15 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-29 01:40 - 2013-09-29 01:40 - 03752202 _____ C:\Users\D\Downloads\8-page-booklet.zip
2013-09-29 01:38 - 2013-09-29 01:37 - 09502479 _____ C:\Users\D\Downloads\Brochure Template.zip
2013-09-29 01:17 - 2013-09-29 01:16 - 00581632 _____ C:\Users\D\Downloads\ID_04_CS.indd
2013-09-29 01:16 - 2013-09-29 01:16 - 00724992 _____ C:\Users\D\Downloads\ID_01-CS.indd
2013-09-29 01:12 - 2013-09-29 01:12 - 01182697 _____ C:\Users\D\Downloads\download-downloadfile-5593.zip
2013-09-29 00:55 - 2013-09-29 00:55 - 05670459 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 00:45 - 2013-09-29 00:40 - 58375053 _____ C:\Users\D\Downloads\designfreebies-free-indesign-magazine-template.rar
2013-09-29 00:37 - 2013-09-29 00:37 - 00546854 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-29 00:30 - 2013-09-29 00:29 - 05987546 _____ C:\Users\D\Downloads\designvorlage-abizeitung.zip
2013-09-29 00:28 - 2013-09-29 00:28 - 00647455 _____ C:\Users\D\Downloads\Templates_30x30_InDesign.zip
2013-09-29 00:08 - 2013-09-29 00:08 - 00000000 ____D C:\Users\D\Downloads\extracted
2013-09-27 23:28 - 2013-09-06 13:17 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-26 21:52 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-09-24 19:28 - 2013-08-31 21:39 - 00000000 ____D C:\Users\D\AppData\Local\Packages
2013-09-23 11:13 - 2013-09-23 11:12 - 00000000 ____D C:\Bilder *****@*****.**
2013-09-23 02:25 - 2013-09-23 13:29 - 613343575 _____ C:\Users\D\*****@*****.**
2013-09-22 22:13 - 2013-09-23 12:46 - 366396810 _____ C:\Users\D\*****@*****.**
2013-09-22 22:11 - 2013-09-23 13:13 - 1030300676 _____ C:\Users\D\*****@*****.**
2013-09-22 13:54 - 2013-09-22 13:13 - 00010594 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-21 12:11 - 2013-09-08 11:00 - 00299008 ___SH C:\Users\D\Downloads\Thumbs.db
2013-09-20 22:35 - 2013-09-07 09:10 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-09-20 22:28 - 2013-09-14 23:14 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-19 10:03 - 2013-09-19 10:03 - 00799781 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-19 10:03 - 2013-09-18 10:23 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-19 01:26 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-19 01:26 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-18 17:52 - 2013-09-08 10:23 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\CrashDumps
2013-09-18 09:53 - 2013-09-06 11:51 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-09-17 19:16 - 2013-08-31 22:14 - 00000000 ____D C:\Users\D\Downloads\usb speicher
2013-09-17 18:21 - 2013-09-17 18:21 - 00000000 ____D C:\Users\D\Documents\Red Alert 3 Uprising
2013-09-17 16:32 - 2013-08-26 09:13 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-15 15:40 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-09-15 11:04 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-09-15 11:04 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-15 11:04 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe
2013-09-14 23:23 - 2013-09-14 23:21 - 00000000 ____D C:\Users\D\AppData\Roaming\Apple Computer
2013-09-14 23:21 - 2013-09-14 23:21 - 00001790 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-09-14 23:21 - 2013-09-14 23:21 - 00000000 ____D C:\Users\D\AppData\Local\Apple Computer
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\ProgramData\Apple Computer
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\Program Files\iTunes
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\Program Files\iPod
2013-09-14 23:20 - 2013-09-14 23:20 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-09-14 23:19 - 2013-09-14 23:19 - 00000000 ____D C:\Users\D\AppData\Local\Apple
2013-09-14 23:19 - 2013-09-14 23:19 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-09-14 23:19 - 2013-09-14 23:19 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-09-14 23:19 - 2013-07-01 09:12 - 00000000 ____D C:\ProgramData\Apple
2013-09-14 11:10 - 2013-09-14 11:05 - 90889040 _____ (Apple Inc.) C:\Users\D\Downloads\iTunes64Setup.exe
2013-09-13 21:25 - 2013-09-13 21:25 - 00000000 ____D C:\Users\D\AppData\Roaming\Red Alert 3 Uprising
2013-09-13 21:25 - 2013-09-13 21:25 - 00000000 ____D C:\Users\D\AppData\Roaming\Red Alert 3
2013-09-13 21:06 - 2013-09-13 21:06 - 00001349 _____ C:\Users\Public\Desktop\Command and Conquer Red Alert 3 and Uprising.lnk
2013-09-13 18:35 - 2013-09-01 23:56 - 00000000 ____D C:\Users\D\AppData\Roaming\Command and Conquer 3 Tiberium Wars
2013-09-13 18:34 - 2013-05-24 14:48 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-13 18:33 - 2013-09-13 18:32 - 00000000 ____D C:\Users\D\Downloads\C&C 3 - Kanes Rach Maps
2013-09-13 18:32 - 2013-09-13 18:32 - 06052462 _____ (InstallShield Software Corporation) C:\Users\D\Downloads\CC3Worldbuilder.exe
2013-09-13 08:58 - 2013-09-01 18:23 - 00000000 ____D C:\Program Files (x86)\Origin Games
2013-09-12 17:41 - 2013-09-02 11:09 - 00000000 ____D C:\Windows\system32\MRT
2013-09-12 17:36 - 2013-09-02 11:09 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-12 17:06 - 2013-09-12 17:06 - 00001356 _____ C:\Users\Public\Desktop\Command and Conquer Red Alert 2.lnk
2013-09-12 17:06 - 2013-09-12 17:06 - 00000000 ____D C:\Program Files (x86)\WestwoodOnline
2013-09-12 16:15 - 2013-09-01 23:56 - 00000000 ___RD C:\Users\D\AppData\Roaming\Command and Conquer 3 Kanes Wrath
2013-09-11 17:36 - 2013-09-10 14:26 - 01995034 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-11 09:58 - 2013-09-11 09:58 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2013-09-10 21:51 - 2013-08-26 09:13 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-10 20:57 - 2013-09-10 20:57 - 00000878 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-10 17:08 - 2013-09-06 13:16 - 00000000 ____D C:\Users\D\Downloads\EBook
2013-09-10 15:43 - 2013-09-10 15:10 - 960600988 _____ C:\Users\D\Downloads\UT3TitanPack.exe
2013-09-10 15:26 - 2013-09-10 15:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-09-10 15:26 - 2013-09-10 15:07 - 343926484 _____ C:\Users\D\Downloads\UT3-Patch5.exe
2013-09-10 14:27 - 2013-08-31 21:38 - 00002267 _____ C:\Users\D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-09-08 20:02 - 2013-09-08 20:02 - 00466944 _____ (Benjamin Bentmann) C:\Users\D\Downloads\BeCyPDFMetaEdit-2.37.0-de.exe
2013-09-08 20:02 - 2013-09-08 20:02 - 00001020 _____ C:\Users\Public\Desktop\BeCyPDFMetaEdit.lnk
2013-09-08 20:02 - 2013-09-08 20:02 - 00000000 ____D C:\Program Files (x86)\BeCyPDFMetaEdit
2013-09-08 16:57 - 2013-09-08 16:57 - 00000000 ___HD C:\ProgramData\CanonIJScan
2013-09-08 16:57 - 2013-09-08 16:56 - 00000000 ____D C:\Users\D\AppData\Roaming\Canon
2013-09-08 16:50 - 2013-09-08 16:50 - 00002016 _____ C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2013-09-08 16:50 - 2013-09-08 16:50 - 00000000 ____D C:\ProgramData\Canon IJ Network Tool
2013-09-08 16:50 - 2013-09-08 16:45 - 00000000 ____D C:\Program Files (x86)\Canon
2013-09-08 16:50 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media
2013-09-08 16:49 - 2013-09-08 16:49 - 00000000 ___HD C:\Program Files\CanonBJ
2013-09-08 16:49 - 2013-09-08 16:49 - 00000000 ____D C:\Windows\system32\STRING
2013-09-08 16:45 - 2013-09-08 16:45 - 00002102 _____ C:\Users\Public\Desktop\Canon MP Navigator EX 4.0.lnk
2013-09-08 13:18 - 2013-09-08 13:18 - 00000000 ____D C:\Users\D\Documents\Benutzerdefinierte Office-Vorlagen
2013-09-08 11:28 - 2013-08-31 21:39 - 00000000 ____D C:\Users\D\AppData\Local\VirtualStore
2013-09-07 09:17 - 2013-09-07 09:10 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-09-07 09:17 - 2013-05-24 14:47 - 00000000 ____D C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}
2013-09-07 09:11 - 2013-09-07 09:11 - 00000000 ____D C:\Users\D\AppData\Roaming\TuneUp Software
2013-09-07 09:09 - 2013-09-07 09:08 - 32555432 _____ (TuneUp Software) C:\Users\D\Downloads\*****@*****.**
2013-09-07 08:55 - 2013-09-07 08:55 - 00000000 ___HD C:\Windows\system32\CanonIJ Uninstaller Information
2013-09-07 08:54 - 2013-09-07 08:54 - 00000000 ___HD C:\ProgramData\CanonBJ
2013-09-07 08:54 - 2013-09-07 08:54 - 00000000 ____D C:\Users\D\Documents\OneNote-Notizbücher
2013-09-06 17:39 - 2013-09-06 17:30 - 00000000 ____D C:\Users\D\Documents\Calibre-Bibliothek
2013-09-06 17:34 - 2013-09-02 18:59 - 00000937 _____ C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk
2013-09-06 17:34 - 2013-09-02 18:59 - 00000000 ____D C:\Program Files\Calibre2
2013-09-06 17:33 - 2013-09-06 17:31 - 58232832 _____ C:\Users\D\Downloads\*****@*****.**
2013-09-06 17:31 - 2013-09-06 17:31 - 00000000 ____D C:\Users\D\AppData\Local\c*****@*****.**
2013-09-06 17:31 - 2013-09-06 17:30 - 00000000 ____D C:\Users\D\AppData\Roaming\*****@*****.**
2013-09-06 13:17 - 2013-08-26 13:10 - 00000000 ____D C:\Users\D\Downloads\*****@*****.**
2013-09-06 11:51 - 2013-09-06 11:51 - 00574656 _____ (Microsoft Corporation) C:\Users\D\Downloads\S*****@*****.**
2013-09-05 14:27 - 2013-09-05 14:27 - 00002621 _____ C:\Users\Public\Desktop\Nero Burning ROM 12.lnk
2013-09-05 14:27 - 2013-09-05 14:26 - 00000000 ____D C:\Program Files (x86)\Nero
2013-09-05 14:27 - 2013-09-01 16:00 - 00000000 ____D C:\ProgramData\Nero
2013-09-05 12:52 - 2013-09-05 12:52 - 00000000 ____D C:\Users\D\Documents\My Games
2013-09-05 12:51 - 2013-09-05 12:51 - 00001040 _____ C:\Users\Public\Desktop\Unreal Tournament 3.lnk
2013-09-05 12:51 - 2013-09-05 12:51 - 00000000 ____D C:\Users\D\AppData\Roaming\InstallShield Installation Information
2013-09-05 12:29 - 2013-09-05 12:29 - 00000000 ____D C:\Program Files (x86)\Unreal Tournament 3 (LG)
2013-09-05 12:27 - 2013-09-05 12:27 - 00000000 ____D C:\Windows\45235788142C44BE8A4DDDE9A84492E5.TMP
2013-09-04 18:15 - 2013-08-31 21:42 - 00000000 ___RD C:\Users\D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-04 18:06 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2013-09-04 18:06 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-09-04 18:06 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-09-04 18:06 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-09-04 18:06 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-09-04 18:06 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-09-04 18:06 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\Dism
2013-09-03 21:36 - 2013-09-03 21:35 - 00000000 ____D C:\Users\D\Downloads\C&C 3 Maps
2013-09-03 15:54 - 2013-09-03 15:54 - 00055872 _____ (Adobe Systems Inc) C:\Windows\system32\AdobePDF.dll
2013-09-03 15:54 - 2013-09-03 15:54 - 00027208 _____ (Adobe Systems Inc.) C:\Windows\system32\AdobePDFUI.dll
Some content of TEMP:
====================
C:\Users\D\AppData\Local\Temp\InstHelper.exe
C:\Users\D\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-30 08:21
==================== End Of Log ============================ --- --- ---
Gmer.txt Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-10-03 22:09:15
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003e HGST_HTS545050A7E380 rev.GG2OACA0 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\D\AppData\Local\Temp\pgloapow.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007fecd10257c 8 bytes JMP 000007ffcab703b0
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007fecd106b10 9 bytes JMP 000007ffcab70308
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNEL32.DLL!K32GetModuleFileNameExW 000007fecd185658 7 bytes JMP 000007ffcab70260
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007fecd185778 7 bytes JMP 000007ffcab702d0
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007fecd1a1564 7 bytes JMP 000007ffcab70340
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007fecd1b40e4 7 bytes JMP 000007ffcab70298
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007fecd1b4178 8 bytes JMP 000007ffcab70228
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007fecd1b479c 8 bytes JMP 000007ffcab70378
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fecab828a0 7 bytes JMP 000007ffcab700d8
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fecab828e8 5 bytes JMP 000007ffcab70180
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fecab9f590 6 bytes JMP 000007ffcab70148
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fecab9f8ac 5 bytes JMP 000007ffcab70110
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\USER32.dll!CreateWindowExW 000007fecd60c5b0 7 bytes JMP 000007ffcab70490
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007fecd6131f0 9 bytes JMP 000007ffcab703e8
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007fecd6133e0 5 bytes JMP 000007ffcab70458
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007fecd617160 5 bytes JMP 000007ffcab70420
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fecd4b1070 8 bytes JMP 000007ffcab701f0
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fecd4d0bc0 8 bytes JMP 000007ffcab701b8
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fec83d6d10 5 bytes JMP 000007ffc81c0110
.text C:\Windows\system32\dwm.exe[440] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fec83dd060 5 bytes JMP 000007ffc81c00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1060] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fec73e1532 4 bytes [3E, C7, FE, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1060] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fec73e153a 4 bytes [3E, C7, FE, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1060] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fec73e165a 4 bytes [3E, C7, FE, 07]
.text C:\Windows\system32\nvvsvc.exe[1068] C:\Windows\system32\MSIMG32.dll!GradientFill + 690 000007fec73e1532 4 bytes [3E, C7, FE, 07]
.text C:\Windows\system32\nvvsvc.exe[1068] C:\Windows\system32\MSIMG32.dll!GradientFill + 698 000007fec73e153a 4 bytes [3E, C7, FE, 07]
.text C:\Windows\system32\nvvsvc.exe[1068] C:\Windows\system32\MSIMG32.dll!TransparentBlt + 246 000007fec73e165a 4 bytes [3E, C7, FE, 07]
.text C:\Windows\system32\nvvsvc.exe[1068] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fecc34177a 4 bytes [34, CC, FE, 07]
.text C:\Windows\system32\nvvsvc.exe[1068] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fecc341782 4 bytes [34, CC, FE, 07]
.text C:\Windows\System32\WUDFHost.exe[1364] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fecc34177a 4 bytes [34, CC, FE, 07]
.text C:\Windows\System32\WUDFHost.exe[1364] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fecc341782 4 bytes [34, CC, FE, 07]
.text C:\Windows\System32\spoolsv.exe[1748] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fecc34177a 4 bytes [34, CC, FE, 07]
.text C:\Windows\System32\spoolsv.exe[1748] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fecc341782 4 bytes [34, CC, FE, 07]
? C:\Windows\SYSTEM32\BsHelpCSps.dll [1844] entry point in ".data" section 0000000000bd5055
? C:\Windows\SYSTEM32\BlueSoleilCSps.dll [1844] entry point in ".rdata" section 0000000000c14085
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[2284] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fec73e1532 4 bytes [3E, C7, FE, 07]
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[2284] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fec73e153a 4 bytes [3E, C7, FE, 07]
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[2284] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fec73e165a 4 bytes [3E, C7, FE, 07]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2332] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fecc34177a 4 bytes [34, CC, FE, 07]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2332] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fecc341782 4 bytes [34, CC, FE, 07]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2332] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fec73e1532 4 bytes [3E, C7, FE, 07]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2332] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fec73e153a 4 bytes [3E, C7, FE, 07]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2332] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fec73e165a 4 bytes [3E, C7, FE, 07]
.text C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe[2604] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fecc34177a 4 bytes [34, CC, FE, 07]
.text C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe[2604] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fecc341782 4 bytes [34, CC, FE, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4304] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fec73e1532 4 bytes [3E, C7, FE, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4304] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fec73e153a 4 bytes [3E, C7, FE, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4304] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fec73e165a 4 bytes [3E, C7, FE, 07]
.text C:\Windows\System32\igfxpers.exe[4264] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fecc34177a 4 bytes [34, CC, FE, 07]
.text C:\Windows\System32\igfxpers.exe[4264] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fecc341782 4 bytes [34, CC, FE, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4444] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fecc34177a 4 bytes [34, CC, FE, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4444] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fecc341782 4 bytes [34, CC, FE, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4768] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fecc34177a 4 bytes [34, CC, FE, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4768] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fecc341782 4 bytes [34, CC, FE, 07]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [612:636] fffff960008e15e8
---- Processes - GMER 2.1 ----
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE [5764] 00000000674a0000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\csi.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE [5764] 0000000062880000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\ACEOLEDB.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE [5764] 0000000069970000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 00000000674a0000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 0000000062040000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\MSPTLS.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 0000000061f20000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\csi.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 0000000062880000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\ACEOLEDB.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 0000000069970000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\ACECORE.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 00000000625e0000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\1031\ACEWSTR.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 0000000062500000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\ACEES.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 0000000062460000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\VBAJET32.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 000000006bb10000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\expsrv.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5900] 0000000062400000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |