Friedrich_ | 25.03.2015 09:21 | re4 Malwarebytes-LOG Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 25.03.2015 06:56:02, SYSTEM, DSLSERVICE, Manual, Malware Database, 2015.3.25.1, 2015.3.25.2,
Update, 25.03.2015 06:56:11, SYSTEM, DSLSERVICE, Manual, Failed, Unable to access update server,
Scan, 25.03.2015 07:25:35, SYSTEM, DSLSERVICE, Manual, Start: % 1 "% 2", Dauer: % 1 min 29 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 0-Malwareerkennung,
(end) ADWCleaner-LOG nicht gelöschte Beiträge sind FALSE-POSITIVES! und gehören zu meinem Programm und einstellungsrepertoire Code:
# AdwCleaner v4.113 - Bericht erstellt 25/03/2015 um 07:37:05
# Aktualisiert 22/03/2015 von Xplode
# Datenbank : 2015-03-23.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x86)
# Benutzername : Friedrich - DSLSERVICE
# Gestarted von : C:\Users\Friedrich\Desktop\Sicherheitsprogramme\AdwCleaner_4.113.exe
# Option : Löschen
***** [ Dienste ] *****
[x] Nicht Gelöscht : sp_rsdrv2
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Windows\Uninstaller
Ordner Gelöscht : C:\Users\Friedrich\AppData\Local\PackageAware
[x] Nicht Gelöscht : C:\Windows\system32\drivers\sp_rsdrv2.sys
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
[x] Nicht Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paragon Hard Disk Manager™ 14 Suite\Uninstall Paragon Hard Disk Manager™.lnk
[x] Nicht Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NovaLogic\Delta Force 2\Uninstall.lnk
[x] Nicht Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NovaLogic\Delta Force\Uninstall.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi
Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A1CCCE0D-AE21-42A2-BE58-8E6109410995}
Schlüssel Gelöscht : HKCU\Software\Headlight
Schlüssel Gelöscht : HKLM\SOFTWARE\Headlight
[x] Nicht Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\allSnap_is1
[x] Nicht Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sonic the Hedgehog 4 - Episode II (c) SEGA_is1
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v36.0.4 (x86 de)
-\\ Chromium v
*************************
AdwCleaner[R0].txt - [2696 Bytes] - [05/07/2014 01:32:15]
AdwCleaner[R10].txt - [2972 Bytes] - [19/03/2015 05:08:27]
AdwCleaner[R11].txt - [3033 Bytes] - [19/03/2015 08:52:58]
AdwCleaner[R12].txt - [2906 Bytes] - [22/03/2015 22:42:07]
AdwCleaner[R13].txt - [2748 Bytes] - [23/03/2015 03:01:35]
AdwCleaner[R14].txt - [2898 Bytes] - [25/03/2015 07:30:51]
AdwCleaner[R1].txt - [2108 Bytes] - [05/07/2014 01:44:43]
AdwCleaner[R2].txt - [2092 Bytes] - [05/07/2014 01:51:47]
AdwCleaner[R3].txt - [2152 Bytes] - [22/07/2014 16:45:56]
AdwCleaner[R4].txt - [2309 Bytes] - [27/08/2014 00:30:24]
AdwCleaner[R5].txt - [2646 Bytes] - [27/08/2014 15:45:37]
AdwCleaner[R6].txt - [2706 Bytes] - [27/08/2014 15:51:46]
AdwCleaner[R7].txt - [2858 Bytes] - [01/09/2014 18:35:30]
AdwCleaner[R8].txt - [2695 Bytes] - [20/12/2014 19:07:20]
AdwCleaner[R9].txt - [2912 Bytes] - [10/03/2015 19:00:19]
AdwCleaner[S0].txt - [2649 Bytes] - [05/07/2014 01:39:52]
AdwCleaner[S1].txt - [2061 Bytes] - [05/07/2014 01:48:59]
AdwCleaner[S2].txt - [2843 Bytes] - [19/03/2015 09:34:59]
AdwCleaner[S3].txt - [2996 Bytes] - [25/03/2015 07:37:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [3055 Bytes] ########## Junkware Removal Tool-LOG Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.5 (03.17.2015:1)
OS: Windows 7 Professional x86
Ran by Friedrich on 25.03.2015 at 7:50:49,49
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.03.2015 at 7:53:27,97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST-LOG
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by Friedrich (administrator) on DSLSERVICE on 25-03-2015 07:57:30
Running from C:\Users\Friedrich\Desktop\Sicherheitsprogramme
Loaded Profiles: Friedrich (Available profiles: Friedrich)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
(H+H Software GmbH) C:\Program Files\Virtual CD v10\System\VC10SecS.exe
(VMware, Inc.) C:\Windows\System32\vmnat.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(H+H Software GmbH) C:\Program Files\Virtual CD v10\System\VC10Play.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Check Point Software Technologies LTD) C:\Program Files\CheckPoint\AKL\AkSA.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe
(VMware, Inc.) C:\Windows\System32\vmnetdhcp.exe
(VMware, Inc.) C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
(NirSoft) C:\Program Files\TcpLogView v1.12\TcpLogView.exe
(NirSoft) C:\Program Files\HTTPNetworkSniffer v1.35\HTTPNetworkSniffer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [VC10Player] => C:\Program Files\Virtual CD v10\System\VC10Play.exe [411976 2011-10-19] (H+H Software GmbH)
HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM\...\Run: [ISW] => C:\Program Files\CheckPoint\AKL\AkSA.exe [638584 2014-05-14] (Check Point Software Technologies LTD)
HKLM\...\Run: [LifeCam] => C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Run: [Razer Synapse] => C:\Program Files\Razer\Synapse\RzSynapse.exe [590144 2015-02-28] (Razer Inc.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [153672 2010-06-14] (Logitech Inc.)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Run: [DMS-Kalenderchen] => C:\Program Files\Kalenderchen\Kalenderchen.exe [3498496 2010-05-18] (Daniel Manger Software)
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\allSnap.lnk
ShortcutTarget: allSnap.lnk -> C:\Program Files\allSnap\allSnap.exe (Ivan Heckman)
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll (Stardock.net, Inc)
BootExecute: autocheck autochk * OODBS
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3642466463-2128021046-2334674927-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-06] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-06] (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{540DE981-1465-410D-993D-5B1652998DCB}: [NameServer] 192.168.44.44
FireFox:
========
FF ProfilePath: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default
FF NewTab:
FF Homepage: about:blank
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.http", "");
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.http_port", 0);
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.no_proxies_on", "");
FF NetworkProxy: "user_pref("extensions.foxtor.network.proxy.share_proxy_settings", true);
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF NetworkProxy: "backup.ftp", "127.0.0.1"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.gopher", "www-proxy.t-online.de"
FF NetworkProxy: "backup.gopher_port", 80
FF NetworkProxy: "backup.socks", "127.0.0.1"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "127.0.0.1"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "127.0.0.1"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "gopher", "127.0.0.1"
FF NetworkProxy: "gopher_port", 4001
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "no_proxies_on", ""
FF NetworkProxy: "pong", ""
FF NetworkProxy: "pong_port", 0
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "127.0.0.1"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "127.0.0.1"
FF NetworkProxy: "ssl_port", 8080
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-12] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @esn/npbattlelog,version=2.4.0 -> C:\Program Files\Battlelog Web Plugins\2.4.0\npbattlelog.dll [2014-05-26] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-06] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-06] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @nullsoft.com/winampDetector;version=1 -> C:\Program Files\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\PDF-XChange Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: eyes.nasa.gov/NASAEyes -> C:\Users\Friedrich\AppData\Roaming\JPLNASAVTAD\NASAEyes\1.0.0.0\npNASAEyes.dll [2013-08-02] (JPL/NASA-Caltech)
FF Plugin HKU\S-1-5-21-3642466463-2128021046-2334674927-1002: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll [2013-03-18] (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-03-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-03-06] (Apple Inc.)
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\a9.xml [2013-06-01]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\blekko-https.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\blekko.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\duckduckgo.xml [2012-07-03]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\expediadotcom.xml [2007-03-08]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\flickr-tags.xml [2013-07-08]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\geizhalseu.xml [2015-03-02]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\geo-ip-tool.xml [2014-10-04]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\gutscheinrauschde-suche.xml [2011-03-22]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\hollywoodcom.xml [2013-10-05]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\imdb.xml [2008-10-22]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\ixquick-ssl.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\lycos-europe.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\MSN.xml [2013-10-05]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\neckermannde.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\otto.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\qwantcom.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\spinde.xml [2009-03-16]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\t-online.xml [2007-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\weathercom.xml [2015-03-18]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\wolframalpha.xml [2014-03-06]
FF SearchPlugin: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\searchplugins\youtube-videosuche.xml [2015-03-19]
FF Extension: Cache Status - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\cache@status.org [2014-05-03]
FF Extension: Chromifox Basic - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\chromifox@altmusictv.com [2013-01-29]
FF Extension: Blur (Formerly DoNotTrackMe) - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\donottrackplus@abine.com [2014-11-22]
FF Extension: FoxyProxy Standard - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\foxyproxy@eric.h.jung [2015-03-22]
FF Extension: HTTPS-Everywhere - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\https-everywhere@eff.org [2015-01-23]
FF Extension: GutscheinRausch.de - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\jl@leimbach-it.de [2013-01-29]
FF Extension: rein - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\rein@notiz.jp [2013-04-30]
FF Extension: TinEye Reverse Image Search - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\tineye@ideeinc.com [2013-01-29]
FF Extension: Forecastfox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013-01-29]
FF Extension: Elementary - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{05e38d80-09c1-11dd-bd0b-0800200c9a66} [2013-01-29]
FF Extension: Vista-aero - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{07b2a769-ed19-4483-87ce-c643914c81bb} [2013-01-29]
FF Extension: PONG! - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1368F36C-0370-419a-A408-28F94FD35974} [2013-01-29]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2013-01-29]
FF Extension: hmmXP - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{224d6e00-0336-11dd-95ff-0800200c9a66} [2013-01-29]
FF Extension: 8 Ultimo - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{2b6788a0-0ccd-11e1-be50-0800200c9a66} [2013-01-29]
FF Extension: HostIP.info Geolocation Plugin - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{49eba0b5-0393-4e13-8cc4-06298a281c5d} [2013-01-29]
FF Extension: Aero Fox XL - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66} [2013-01-29]
FF Extension: FT DeepDark - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2015-02-27]
FF Extension: W3v8 for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{7DA90D46-1B69-4cc5-9ACE-CB64D8D85B00} [2013-01-29]
FF Extension: iMacros for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2015-02-19]
FF Extension: Nightly Tester Tools - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29} [2013-11-01]
FF Extension: Proto_Dust - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8a39fe10-f553-11dd-87af-0800200c9a66} [2013-01-29]
FF Extension: Live HTTP Headers - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2013-06-12]
FF Extension: Bamboo Feed Reader - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{b2e69492-2358-071a-7056-24ad0c3defb1} [2015-02-21]
FF Extension: Gnome - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{bdc06860-70c3-11dd-ad8b-0800200c9a66} [2013-01-29]
FF Extension: iPox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66} [2013-01-29]
FF Extension: User Agent Switcher - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1} [2013-01-29]
FF Extension: PageZoom [de] - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{eeb299da-31d8-4683-aad4-9c9a045e0351} [2013-01-29]
FF Extension: CustomizeGoogle - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb} [2013-01-29]
FF Extension: SEOpen - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{ff6bdc07-eed6-4815-ad95-d7938b673ab5} [2013-01-29]
FF Extension: Classic Theme Restorer - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-06-16]
FF Extension: Classic Toolbar Buttons - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2014-06-19]
FF Extension: Firebug - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\firebug@software.joehewitt.com.xpi [2013-01-29]
FF Extension: Ghostery - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\firefox@ghostery.com.xpi [2015-02-24]
FF Extension: Glaze Black - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\glaze_black@www.theme-oasis.org.xpi [2013-01-29]
FF Extension: ipFuck - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\ipfuck@p4ul.info.xpi [2014-03-07]
FF Extension: Lightbeam - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2013-01-29]
FF Extension: NASA Night Launch - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\nasanightlaunch@example.com.xpi [2013-01-29]
FF Extension: Netscape Navigator Nostalgia - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\Netscape@gideas.xpi [2013-01-29]
FF Extension: Niederschlagsradar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\niederschlagsradar@sensiva.net.xpi [2013-01-29]
FF Extension: Classic Compact Options - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\notreal.ccoptions@environmentalchemistry.com.xpi [2013-01-29]
FF Extension: RightBar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\rightbar@realmtech.net.xpi [2014-06-19]
FF Extension: Secret Agent - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\SecretAgent@Dephormation.org.uk.xpi [2014-03-12]
FF Extension: Secure Login - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\secureLogin@blueimp.net.xpi [2015-02-11]
FF Extension: MZ8 - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\someone@somewhere.xpi [2014-07-27]
FF Extension: Throbber Restored - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\Throbber-Restored@jetpack.xpi [2014-09-07]
FF Extension: Flagfox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-10]
FF Extension: Image Zoom - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013-04-16]
FF Extension: Aeon Colors - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}.xpi [2013-01-29]
FF Extension: LittleFox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}.xpi [2014-06-20]
FF Extension: Leet Key - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{3335F91D-2AEF-4097-B831-C96C60349822}.xpi [2013-01-29]
FF Extension: Organize Status Bar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{35106bca-6c78-48c7-ac28-56df30b51d2c}.xpi [2013-01-29]
FF Extension: Qute Classic - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{5514CFC3-D9A8-4f1a-8DF1-930EBFB59901}.xpi [2013-01-29]
FF Extension: STEAM - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{678156d0-0e01-11df-8a39-0800200c9a66}.xpi [2013-01-29]
FF Extension: Nautipolis for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}.xpi [2013-01-29]
FF Extension: NoScript - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-01-29]
FF Extension: ReloadEvery - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-01-29]
FF Extension: n2scape - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{962229ad-1a31-4d4f-ac5b-a86cbc38f6bb}.xpi [2013-01-29]
FF Extension: Tamper Data - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi [2013-01-29]
FF Extension: Video DownloadHelper - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-03-06]
FF Extension: Sothink Flash Downloader for Firefox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{BAEBEF65-9289-47c5-8524-C345CC5D860D}.xpi [2013-01-29]
FF Extension: Web Developer - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2013-01-29]
FF Extension: classiccompact - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{D46E8522-6E86-44b1-A622-58C0668AD78E}.xpi [2013-01-29]
FF Extension: FOXSCAPE - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{da7f40f0-8675-11db-b606-0800200c9a66}.xpi [2013-01-29]
FF Extension: DownThemAll! - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2013-01-29]
FF Extension: Torbutton - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}.xpi [2013-01-29]
FF Extension: HackBar - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{F5DDF39C-9293-4d5e-9AA8-E04E6DD5E9B4}.xpi [2013-10-05]
FF Extension: Mosaic-Fox - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{f9bddc00-152b-11de-8c30-0800200c9a66}.xpi [2013-01-29]
FF Extension: Firefox 2, the theme, reloaded - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\bmct2hvv.default\Extensions\{fd2f951f-77ea-4938-9493-0c892c027a13}.xpi [2014-06-19]
FF Extension: QuickStores-Toolbar - C:\Program Files\Mozilla Firefox\extensions\quickstores@quickstores.de.xpi [2015-03-22]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-20] ()
S4 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
S4 CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
R2 DokanMounter; C:\Program Files\Paragon Software\Paragon ExtFS for Windows\Dokan\DokanLibrary\mounter.exe [22736 2014-08-25] ()
S4 EMET_Service; C:\Program Files\EMET 5.1\EMET_Service.exe [31880 2014-11-09] (Microsoft Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files\Futuremark\SystemInfo\FMSISvc.exe [614624 2015-02-09] (Futuremark)
S3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 IswSvc; C:\Program Files\CheckPoint\AKL\AkSVC.exe [749176 2014-05-14] (Check Point Software Technologies LTD)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [238288 2015-03-23] (McAfee, Inc.)
S2 nlndis; C:\Program Files\NetLimiter Ndis Miniport Service\nlndis.exe [32768 2011-10-05] (Locktime Software) [File not signed]
S3 nlsvc; C:\Program Files\NetLimiter 3\nlsvc.exe [1126400 2013-02-20] (Locktime Software) [File not signed]
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2505160 2013-01-07] (O&O Software GmbH)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [32568 2014-08-07] (The OpenVPN Project)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1910640 2015-03-04] (Electronic Arts)
S4 Razer Game Scanner Service; C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] ()
S3 Realtek87B; C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
S3 RUBotSrv; C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe [443416 2013-07-25] (Trend Micro Inc.)
S4 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-01-14] (Crawler.com)
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 VC10SecS; C:\Program Files\Virtual CD v10\System\VC10SecS.exe [144712 2011-10-19] (H+H Software GmbH)
R2 VMAuthdService; C:\Program Files\VMware\VMware Workstation\vmware-authd.exe [86744 2014-06-12] (VMware, Inc.)
R2 VMnetDHCP; C:\Windows\system32\vmnetdhcp.exe [359128 2014-06-12] (VMware, Inc.)
R2 VMUSBArbService; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [722624 2014-02-27] (VMware, Inc.)
R2 VMware NAT Service; C:\Windows\system32\vmnat.exe [437976 2014-06-12] (VMware, Inc.)
S2 VMwareHostd; C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe [14407384 2014-06-12] ()
S3 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)
R2 ZoneAlarm AntiTheft; C:\Program Files\CheckPoint\AntiTheft\Antitheft.exe [3128968 2014-05-30] (Check Point Software Technologies Ltd.)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] ()
R2 Dokan; C:\Windows\system32\drivers\dokan.sys [105680 2014-08-25] (Windows (R) Win 7 DDK provider)
S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan) [File not signed]
S3 es1371; C:\Windows\System32\drivers\es1371mp.sys [40832 2002-06-03] (Creative Technology Ltd.)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
S3 GKBFltr; C:\Windows\System32\Drivers\GameKB.sys [19328 2009-12-29] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R2 hcmon; C:\Windows\system32\drivers\hcmon.sys [43840 2014-02-27] (VMware, Inc.)
S3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [13952 2010-03-10] (H+H Software GmbH) [File not signed]
R0 iaStorA; C:\Windows\System32\drivers\iaStorA.sys [532536 2012-09-01] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [25656 2012-09-01] (Intel Corporation)
S3 icsak; C:\Program Files\CheckPoint\AKL\ak\icsak.sys [39296 2014-05-14] (Check Point Software Technologies LTD)
R2 ISWKL; C:\Program Files\CheckPoint\AKL\ISWKL.sys [42880 2014-05-14] (Check Point Software Technologies LTD)
R0 iusb3hcs; C:\Windows\System32\drivers\iusb3hcs.sys [16880 2013-02-22] (Intel Corporation)
R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [352752 2013-02-22] (Intel Corporation)
R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [796656 2013-02-22] (Intel Corporation)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [488032 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2014-04-30] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [43608 2014-04-30] (Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144352 2014-04-30] (Kaspersky Lab ZAO)
R3 MBfilt; C:\Windows\System32\drivers\MBfilt32.sys [24664 2009-11-18] (Creative Technology Ltd.)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-02] (Intel Corporation)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [648552 2015-03-23] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [91840 2015-03-23] (McAfee, Inc.)
R3 NLNdisMP; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software)
S3 NLNdisPT; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software)
R1 nltdi; C:\Program Files\NetLimiter 3\nltdi.sys [5281672 2011-03-21] (Locktime Software)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R2 ntk_PowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [71664 2011-04-20] (Cyberlink Corp.)
R2 ParagonLDM; C:\Windows\system32\drivers\biont_bs.sys [24512 2014-04-11] (Paragon Software GmbH)
S3 pneteth; C:\Windows\System32\DRIVERS\pneteth.sys [13440 2011-11-24] (June Fabrics Technology Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 RTCore32; C:\Program Files\MSI Afterburner\RTCore32.sys [5632 2013-03-11] () [File not signed]
S3 RTL8187; C:\Windows\System32\DRIVERS\rtl8187.sys [375808 2010-01-07] (Realtek Semiconductor Corporation )
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [35624 2014-12-17] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [20416 2015-02-05] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [97088 2014-11-17] (Razer, Inc.)
R3 rzudd; C:\Windows\System32\DRIVERS\rzudd.sys [151336 2014-12-30] (Razer Inc)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP2\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2013-01-30] () [File not signed]
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
R0 SscRdBus; C:\Windows\System32\DRIVERS\SscRdBus.sys [88296 2014-11-22] (SuperSpeed LLC) [File not signed]
R0 SscRdCls; C:\Windows\System32\DRIVERS\SscRdCls.sys [40984 2007-12-19] (SuperSpeed LLC)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [23040 2014-04-08] (The OpenVPN Project)
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [5120 2012-12-19] ()
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [91016 2013-12-26] ()
R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [20616 2013-12-26] ()
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [540168 2013-12-26] ()
S1 Uim_Vim; C:\Windows\System32\Drivers\Uim_Vim.sys [283600 2012-11-22] (Paragon)
R1 vdrv1000; C:\Windows\System32\DRIVERS\vdrv1000.sys [186392 2011-04-19] (H+H Software GmbH)
R3 vmkbd2; C:\Windows\system32\drivers\VMkbd.sys [26456 2014-06-12] (VMware, Inc.)
R3 VMnetAdapter; C:\Windows\System32\DRIVERS\vmnetadapter.sys [17104 2014-06-12] (VMware, Inc.)
R2 VMnetBridge; C:\Windows\System32\DRIVERS\vmnetbridge.sys [37456 2014-06-12] (VMware, Inc.)
R2 VMnetuserif; C:\Windows\system32\drivers\vmnetuserif.sys [26968 2014-06-12] (VMware, Inc.)
R2 vmx86; C:\Windows\system32\Drivers\vmx86.sys [66136 2014-06-12] (VMware, Inc.)
R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation)
R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation)
R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation)
R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation)
R1 Vsdatant; C:\Windows\System32\drivers\vsdatant.sys [456088 2014-05-30] (Check Point Software Technologies Ltd.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [63824 2013-10-08] (VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\System32\drivers\vstor2-mntapi20-shared.sys [23632 2013-02-22] (VMware, Inc.)
R2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam.sys [1068216 2012-04-15] (Windows (R) Win 7 DDK provider)
R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22856 2010-04-27] (Logitech Inc.)
S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [37704 2010-04-27] (Logitech Inc.)
S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [31816 2010-04-27] (Logitech Inc.)
R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [15048 2010-04-27] (Logitech Inc.)
R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66632 2010-04-27] (Logitech Inc.)
S3 xnacc; C:\Windows\System32\DRIVERS\xnacc.sys [465408 2009-07-14] (Microsoft Corporation)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [77296 2011-04-12] (CyberLink Corp.)
S3 catchme; \??\C:\Users\HAKENN~1\AppData\Local\Temp\catchme.sys [X]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2014-04-30] (Kaspersky Lab ZAO)
S4 NvStUSB; \SystemRoot\system32\drivers\nvstusb.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-23 09:32 - 2015-03-23 09:33 - 00000000 ____D () C:\Program Files\MiniTool Partition Wizard Free 9.0
2015-03-23 09:32 - 2015-03-23 09:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Free 9.0
2015-03-23 08:20 - 2015-03-23 08:20 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-03-23 06:22 - 2015-03-23 06:22 - 00648552 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfehidk.sys
2015-03-23 06:22 - 2015-03-23 06:22 - 00238288 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe
2015-03-23 06:22 - 2015-03-23 06:22 - 00091840 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mferkdet.sys
2015-03-23 03:20 - 2015-03-25 07:46 - 00000000 ____D () C:\Windows\erdnt
2015-03-23 03:07 - 2015-03-25 07:57 - 00000000 ____D () C:\FRST
2015-03-23 02:18 - 2015-03-23 09:37 - 00172576 _____ () C:\Users\Friedrich\Documents\pinfect.zip
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\VDLL.DLL
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\system32\runouce.exe
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\RUNDL132.EXE
2015-03-23 00:40 - 2015-03-23 00:40 - 00000000 ____D () C:\Windows\logo_1.exe
2015-03-23 00:29 - 2015-03-23 09:36 - 00000054 _____ () C:\Windows\Lic.xxx
2015-03-23 00:29 - 2015-03-23 00:29 - 00034048 _____ (MicroWorld Technologies Inc.) C:\Windows\system32\eEmpty.exe
2015-03-23 00:29 - 2015-03-23 00:29 - 00000000 ____D () C:\ProgramData\MicroWorld
2015-03-23 00:29 - 2015-03-23 00:29 - 00000000 ____D () C:\Program Files\Common Files\MicroWorld
2015-03-23 00:29 - 2005-09-22 23:22 - 00000522 _____ () C:\Windows\system32\Microsoft.VC80.CRT.manifest
2015-03-23 00:22 - 2015-03-25 06:58 - 00000000 ____D () C:\Users\Friedrich\Desktop\Sammlung fürs Board
2015-03-22 20:37 - 2015-03-22 20:37 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-03-22 20:25 - 2015-03-22 20:28 - 00000353 _____ () C:\Users\Friedrich\Desktop\Office AUTOKMS sehr Wichtig.txt
2015-03-22 19:00 - 2015-03-22 19:00 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-03-22 18:29 - 2015-03-22 18:29 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-20 23:13 - 2015-03-20 23:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro RUBotted
2015-03-20 23:13 - 2015-03-20 23:13 - 00000000 ____D () C:\Program Files\Trend Micro
2015-03-20 22:57 - 2015-03-20 22:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft HiJackFree
2015-03-20 22:57 - 2015-03-20 22:57 - 00000000 ____D () C:\Program Files\Emsisoft HiJackFree
2015-03-20 22:56 - 2015-03-20 22:56 - 02925920 _____ (Emsisoft GmbH ) C:\Users\Friedrich\Desktop\EmsisoftHiJackFreeSetup.exe
2015-03-20 22:47 - 2015-03-20 22:51 - 140425968 _____ (Microsoft Corporation) C:\Users\Friedrich\Desktop\Microsoft Security Scanner.exe
2015-03-20 19:07 - 2015-03-20 19:11 - 00000000 ____D () C:\TDSSKiller_Quarantine
2015-03-19 01:28 - 2015-03-19 02:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\ThinkpadpunkteVideo
2015-03-19 00:53 - 2015-03-22 19:01 - 00429152 _____ () C:\Users\Friedrich\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-19 00:52 - 2015-03-22 19:12 - 04703120 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-19 00:18 - 2015-03-19 00:20 - 00084562 _____ () C:\Users\Friedrich\Desktop\usbdeview.zip
2015-03-19 00:18 - 2015-03-19 00:20 - 00046516 _____ () C:\Users\Friedrich\Desktop\driverview.zip
2015-03-19 00:17 - 2015-03-19 00:20 - 00068998 _____ () C:\Users\Friedrich\Desktop\bluescreenview.zip
2015-03-18 21:39 - 2015-03-18 21:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GNavigia
2015-03-18 21:39 - 2010-04-07 02:29 - 00081920 _____ () C:\Windows\system32\GkSui20.EXE
2015-03-18 21:26 - 2015-03-18 21:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-03-18 21:26 - 2015-03-16 18:44 - 00749664 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-03-18 21:25 - 2015-03-18 21:25 - 00000000 ____D () C:\Program Files\Oracle
2015-03-18 21:25 - 2015-03-16 18:42 - 00104384 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-03-18 21:17 - 2015-03-18 21:17 - 00000000 ____D () C:\Windows\system32\RTCOM
2015-03-18 21:16 - 2014-12-03 13:51 - 00927960 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2015-03-18 21:16 - 2014-12-03 11:41 - 03365208 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2015-03-18 21:16 - 2014-12-03 10:15 - 01485163 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-03-18 21:16 - 2014-12-02 11:42 - 02381680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2015-03-18 21:16 - 2014-11-27 08:31 - 02510192 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO.dll
2015-03-18 21:16 - 2014-08-06 06:43 - 02588888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2015-03-18 21:16 - 2014-04-10 05:19 - 01940056 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2015-03-18 21:16 - 2014-03-06 09:35 - 01892056 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2015-03-18 21:16 - 2014-02-18 10:04 - 02421792 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2015-03-18 21:16 - 2014-01-08 08:25 - 00332568 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp32.dll
2015-03-18 21:16 - 2013-01-11 09:27 - 00563992 _____ (Creative Technology Ltd.) C:\Windows\system32\MBTHX32.dll
2015-03-18 21:16 - 2011-11-22 09:28 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll
2015-03-18 21:16 - 2010-11-08 00:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll
2015-03-18 21:16 - 2010-09-27 02:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-03-18 21:16 - 2009-12-04 08:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll
2015-03-18 21:16 - 2009-11-24 02:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll
2015-03-18 21:16 - 2009-11-18 11:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll
2015-03-18 21:16 - 2009-11-18 00:12 - 00024664 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\MBfilt32.sys
2015-03-18 21:15 - 2014-06-06 17:00 - 00519368 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2015-03-18 21:15 - 2013-10-11 05:47 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-03-18 21:15 - 2012-03-08 04:47 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2015-03-18 20:49 - 2015-01-25 11:20 - 00000000 ____D () C:\Users\Friedrich\Desktop\Baphomets Fluch 1-5 Deutsch
2015-03-17 14:44 - 2015-03-18 17:10 - 329252864 _____ () C:\Users\Friedrich\Desktop\openSUSE-13.2-DVD-i586.iso
2015-03-17 14:37 - 2015-03-17 14:41 - 79691776 _____ () C:\Users\Friedrich\Desktop\CorePlus-current.iso
2015-03-16 18:42 - 2015-03-16 18:42 - 00115672 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetAdp.sys
2015-03-12 15:27 - 2015-03-25 06:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Everything
2015-03-12 15:27 - 2015-03-12 15:27 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything
2015-03-11 20:41 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-03-11 20:41 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-03-11 20:41 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-03-11 20:41 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2015-03-11 20:02 - 2015-03-06 06:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 20:02 - 2015-03-06 06:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 20:02 - 2015-03-06 06:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 20:02 - 2015-03-06 06:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 20:02 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 20:02 - 2015-03-06 06:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 20:02 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 20:02 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 20:02 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 20:02 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 20:02 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 20:02 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 20:02 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 20:02 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 20:02 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 20:02 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 20:02 - 2015-02-20 03:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 20:02 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 20:02 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 20:02 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 20:02 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 20:02 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 20:02 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 20:02 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 20:02 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 20:02 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 20:02 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 20:02 - 2015-02-20 02:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 20:02 - 2015-02-20 02:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 20:02 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 20:02 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 20:02 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 20:02 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 20:02 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 20:02 - 2015-02-20 02:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 20:02 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 20:02 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 20:02 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 20:02 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 20:02 - 2015-01-31 00:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 20:02 - 2015-01-29 04:05 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-11 20:02 - 2015-01-29 04:05 - 03917752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 20:02 - 2015-01-29 04:01 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 20:02 - 2015-01-29 04:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 20:02 - 2015-01-29 04:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 20:02 - 2015-01-29 03:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 20:01 - 2015-02-26 04:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 20:01 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 20:01 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 20:01 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 20:01 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 20:01 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 20:01 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 20:01 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 20:01 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 20:00 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-03-11 17:12 - 2015-03-11 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PY Software
2015-03-11 17:12 - 2007-08-13 14:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\wmvdmoe.dll
2015-03-11 16:57 - 2015-03-11 17:03 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\WebcamZoneTrigger
2015-03-11 16:12 - 2015-03-11 16:12 - 00000000 ____D () C:\Users\Public\Documents\Xeoma
2015-03-11 12:19 - 2015-03-11 12:19 - 00000000 ____D () C:\Windows\system32\DCS
2015-03-11 01:10 - 2015-03-11 01:10 - 00003584 _____ () C:\Users\Friedrich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-08 10:55 - 2015-03-08 10:55 - 06208736 _____ (Tim Kosse) C:\Users\Friedrich\Downloads\FileZilla_3.10.2_win32-setup.exe
2015-03-08 10:55 - 2015-03-08 10:55 - 06057862 _____ (Tim Kosse) C:\Users\Friedrich\Downloads\FileZilla_3.9.0.5_win32-setup.exe
2015-03-08 03:47 - 2015-03-08 03:47 - 00000216 _____ () C:\Users\Friedrich\Desktop\rFactor Demo.url
2015-03-08 02:07 - 2015-03-08 02:07 - 00000623 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LEGO Batman 3 - Beyond Gotham.lnk
2015-03-08 02:02 - 2015-03-08 02:02 - 00000000 ____D () C:\Program Files\LEGO Batman 3 - Beyond Gotham
2015-03-06 05:12 - 2015-03-06 05:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Apple Computer
2015-03-06 05:10 - 2015-03-06 05:12 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-03-06 05:10 - 2015-03-06 05:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-03-06 05:08 - 2015-03-21 19:35 - 00000000 ____D () C:\Users\Friedrich\Desktop\LightWorks DE Tutorials
2015-03-06 04:28 - 2015-03-06 04:28 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-03-05 21:53 - 2015-03-05 21:53 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Stardock
2015-03-05 20:41 - 2015-03-13 19:42 - 00000000 ____D () C:\Users\Friedrich\Desktop\Chromanova.fm - crazy freak dance 24-7-
2015-03-05 07:50 - 2015-03-05 07:50 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\com.ohnoo.TormentumDemo
2015-03-05 07:31 - 2015-03-05 07:31 - 00000000 ____D () C:\Users\Friedrich\Documents\SpriteLamp
2015-03-05 07:31 - 2015-03-05 07:31 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\SpriteLampWinforms
2015-03-05 06:58 - 2015-03-05 07:03 - 00000000 ____D () C:\Program Files\TClock
2015-03-05 06:04 - 2015-03-05 06:04 - 00000000 ____D () C:\Windows Anmeldesounds +Icons AlleSys Bildschirmschoner
2015-03-05 05:49 - 2015-03-05 05:49 - 00000000 ____D () C:\ProgramData\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 __HDC () C:\ProgramData\{9C3F823B-4738-4CAF-A6B2-69E87FB636C0}
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\Users\Public\Documents\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2015-03-05 05:48 - 2015-03-05 05:48 - 00000000 ____D () C:\Program Files\Stardock
2015-03-05 05:28 - 2015-03-05 05:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPU
2015-03-05 05:28 - 2015-03-05 05:28 - 00000000 ____D () C:\Program Files\MPU
2015-03-05 05:20 - 2015-03-05 05:20 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Lern-o-Mat
2015-03-05 05:14 - 2015-03-05 05:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2.0
2015-03-05 05:14 - 2015-03-05 05:14 - 00000000 ____D () C:\Program Files\DVDlabPro2
2015-03-05 05:13 - 2015-03-05 05:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Doc Scrubber
2015-03-05 05:13 - 2015-03-05 05:13 - 00000000 ____D () C:\Program Files\Doc Scrubber
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\jStrip
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jStrip
2015-03-05 05:12 - 2015-03-05 05:12 - 00000000 ____D () C:\Program Files\jStrip
2015-03-05 05:12 - 1999-10-30 02:00 - 00167936 _____ (Common Controls Replacement Project (CCRP)) C:\Windows\system32\ccrpftv6.ocx
2015-03-04 06:03 - 2015-03-12 12:34 - 00000000 ____D () C:\Users\Friedrich\.mediathek3
2015-03-04 06:03 - 2015-03-04 06:03 - 00000000 ____D () C:\Program Files\Mediathekview
2015-03-03 19:32 - 2015-03-03 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2015-03-03 19:32 - 2015-03-03 19:32 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2015-03-03 18:52 - 2015-03-03 18:54 - 63361024 _____ () C:\Users\Friedrich\Desktop\EpicGamesLauncherInstaller-2.0.0-2465596.msi
2015-03-03 18:13 - 2015-03-03 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
2015-03-02 07:05 - 2015-03-02 07:05 - 00000000 ____D () C:\Users\Friedrich\Documents\Bandicam
2015-03-02 07:04 - 2015-03-23 16:41 - 00000000 ____D () C:\Program Files\Bandicam
2015-03-02 07:04 - 2015-03-02 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2015-03-02 07:04 - 2015-03-02 07:04 - 00000000 ____D () C:\Program Files\BandiMPEG1
2015-03-01 23:52 - 2015-03-01 23:52 - 00000000 ____D () C:\Users\Friedrich\Desktop\Silent Hill Downpour (Xbox 360 Gamerip)
2015-02-28 18:06 - 2015-02-05 18:51 - 00621384 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe
2015-02-28 18:05 - 2015-02-05 21:48 - 24768144 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 20465808 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 16016848 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 10773520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 10713256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 08473928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-02-28 18:05 - 2015-02-05 21:48 - 03247248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 01047880 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3234752.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00931136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00912528 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3234752.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00909120 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00877816 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshim.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00399504 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00345928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00305136 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim32.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00164568 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll
2015-02-28 18:05 - 2015-02-05 21:48 - 00161424 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda32v.sys
2015-02-28 18:05 - 2015-02-05 21:48 - 00027280 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap32.dll
2015-02-27 16:04 - 2015-02-27 19:00 - 00000000 ____D () C:\Program Files\EMET 5.1
2015-02-27 16:04 - 2015-02-27 16:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit
2015-02-27 03:00 - 2015-02-27 03:00 - 00000216 _____ () C:\Users\Friedrich\Desktop\Tormentum - Dark Sorrow Demo.url
2015-02-26 18:36 - 2015-02-26 18:36 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cain
2015-02-26 18:36 - 2015-02-26 18:36 - 00000000 ____D () C:\Program Files\Cain
2015-02-24 19:24 - 2015-03-20 23:09 - 00000000 ____D () C:\Users\Friedrich\Documents\Survarium
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-25 07:57 - 2013-01-30 06:57 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\NetSpeedMonitor
2015-03-25 07:57 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Sicherheitsprogramme
2015-03-25 07:46 - 2010-11-20 22:01 - 01639348 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-25 07:46 - 2009-07-14 05:34 - 00034848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-25 07:46 - 2009-07-14 05:34 - 00034848 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-25 07:42 - 2013-01-29 18:50 - 01286151 _____ () C:\Windows\WindowsUpdate.log
2015-03-25 07:39 - 2013-02-17 07:38 - 00000000 ____D () C:\ProgramData\VMware
2015-03-25 07:38 - 2014-07-03 02:07 - 00067682 _____ () C:\Windows\setupact.log
2015-03-25 07:38 - 2014-01-11 03:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-25 07:38 - 2013-01-30 08:01 - 01846372 _____ () C:\Windows\system32\oodbs.lor
2015-03-25 07:38 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-25 07:37 - 2014-07-05 01:31 - 00000000 ____D () C:\AdwCleaner
2015-03-25 06:56 - 2014-11-15 20:35 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-25 06:54 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Registration
2015-03-25 04:44 - 2013-01-30 05:14 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\CrashDumps
2015-03-23 20:27 - 2013-03-02 16:35 - 00000000 ____D () C:\Program Files\Pluto Client
2015-03-23 20:15 - 2014-07-05 01:41 - 00607496 _____ () C:\Windows\PFRO.log
2015-03-23 20:12 - 2014-01-11 01:33 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Apps\2.0
2015-03-23 20:12 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-03-23 20:08 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2015-03-23 16:50 - 2013-02-11 06:02 - 00000000 ____D () C:\Users\Friedrich\Desktop\Magic.Games.II
2015-03-23 16:41 - 2013-01-30 06:17 - 00000000 ____D () C:\Program Files\mIRC
2015-03-23 16:39 - 2013-02-18 03:52 - 00000000 ____D () C:\Program Files\Dead Space 3 Limited Edition uncut
2015-03-23 16:39 - 2013-02-09 08:44 - 00000000 ____D () C:\Program Files\Magic The Gathering - Duels of the Planeswalkers
2015-03-23 16:39 - 2013-02-04 05:20 - 00000000 ____D () C:\Program Files\Serials World
2015-03-23 16:38 - 2014-01-29 18:03 - 00000000 ____D () C:\Program Files\DLH98
2015-03-23 16:37 - 2013-01-31 03:54 - 00000000 ____D () C:\Program Files\DiRT 3
2015-03-23 16:34 - 2014-07-06 04:05 - 00000000 ____D () C:\Program Files\Assetto Corsa
2015-03-23 16:34 - 2013-02-11 03:53 - 00000000 ____D () C:\Program Files\Ricochet Infinity
2015-03-23 16:33 - 2014-06-12 00:18 - 00000000 ____D () C:\Program Files\HD Video Repair Utility
2015-03-23 16:33 - 2013-03-02 16:32 - 00000000 ____D () C:\Program Files\Portrait Professional Studio 9
2015-03-23 08:21 - 2013-01-30 01:31 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\KeePass
2015-03-23 08:21 - 2013-01-30 01:20 - 00042334 _____ () C:\Users\Friedrich\NeueDatenbank.kdbx
2015-03-23 08:21 - 2013-01-29 18:50 - 00000000 ____D () C:\Users\Friedrich
2015-03-23 07:02 - 2013-02-05 00:25 - 00000000 ____D () C:\Program Files\stinger
2015-03-23 06:21 - 2013-06-04 01:27 - 00000000 ____D () C:\Stinger_Quarantine
2015-03-23 06:15 - 2014-03-23 15:43 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-03-23 06:00 - 2014-03-23 15:42 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-23 05:25 - 2013-01-30 04:08 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\vlc
2015-03-23 04:16 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-23 03:38 - 2009-07-14 05:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-23 02:47 - 2014-11-16 21:36 - 00000000 ____D () C:\Program Files\Spezial 5.0
2015-03-22 22:33 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-03-22 22:10 - 2013-01-30 01:23 - 00000000 ____D () C:\Users\Friedrich\Desktop\Weitere Programme
2015-03-22 21:36 - 2013-01-30 06:18 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\NoNameScript
2015-03-22 20:24 - 2014-10-20 17:53 - 00000000 ____D () C:\ProgramData\GalaxyClient
2015-03-22 19:59 - 2013-01-30 06:17 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\mIRC
2015-03-22 19:03 - 2013-11-22 18:50 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\AIMP3
2015-03-22 19:03 - 2013-01-30 03:24 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-22 18:56 - 2014-05-14 17:55 - 00000000 ____D () C:\Users\Friedrich\Desktop\Rap Mai 2014
2015-03-22 18:44 - 2013-02-06 04:46 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-22 18:23 - 2014-02-07 14:18 - 00000600 _____ () C:\Users\Friedrich\AppData\Roaming\winscp.rnd
2015-03-22 18:10 - 2014-08-20 05:17 - 00000000 ____D () C:\Windows\Minidump
2015-03-21 06:12 - 2013-01-30 05:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-03-20 22:23 - 2013-02-06 02:07 - 00000000 ____D () C:\Temp
2015-03-20 21:39 - 2013-01-30 06:49 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2015-03-20 19:34 - 2014-05-04 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhoCrashed
2015-03-20 19:34 - 2014-05-04 18:34 - 00000000 ____D () C:\Program Files\WhoCrashed
2015-03-20 18:06 - 2013-02-01 15:18 - 00000000 ____D () C:\Program Files\Vuze
2015-03-19 07:56 - 2013-01-29 23:12 - 00000000 ____D () C:\Windows\pss
2015-03-19 06:48 - 2013-03-25 17:56 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\NPE
2015-03-19 03:53 - 2013-01-30 08:07 - 00000000 ____D () C:\Program Files\Steam
2015-03-19 02:39 - 2013-03-04 20:10 - 00000000 ____D () C:\Program Files\KaloMa
2015-03-19 00:48 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-19 00:26 - 2014-06-16 02:02 - 00064681 ____H () C:\Windows\system32\BTImages.dat
2015-03-19 00:25 - 2013-01-25 15:30 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-03-19 00:21 - 2013-02-04 05:24 - 00000000 ____D () C:\Program Files\USB Deview
2015-03-19 00:20 - 2014-09-14 21:01 - 00000000 ____D () C:\Program Files\Bluescreen View
2015-03-19 00:20 - 2014-02-14 02:24 - 00000000 ____D () C:\Program Files\DriverView v1.45
2015-03-18 22:11 - 2013-07-16 15:55 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\FileZilla
2015-03-18 21:27 - 2014-02-24 06:30 - 00000000 ____D () C:\Users\Friedrich\.VirtualBox
2015-03-18 21:17 - 2013-01-25 15:37 - 00000000 ___HD () C:\Program Files\Temp
2015-03-18 21:04 - 2013-02-01 15:18 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Azureus
2015-03-18 18:45 - 2013-02-17 08:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\VMware
2015-03-18 18:45 - 2013-02-17 08:12 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\VMware
2015-03-16 21:48 - 2013-01-30 01:16 - 00000000 ____D () C:\Users\Friedrich\Mädels u. Chatter
2015-03-16 14:56 - 2015-02-09 11:04 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\.Tribler
2015-03-15 13:50 - 2013-01-31 03:07 - 00000000 ____D () C:\Program Files\Trillian
2015-03-14 17:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-03-12 16:44 - 2014-08-17 15:52 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Adobe
2015-03-12 16:44 - 2013-01-29 22:44 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-12 16:44 - 2013-01-29 22:44 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-12 15:27 - 2013-02-01 15:44 - 00000000 ____D () C:\Program Files\Search Everything
2015-03-12 15:24 - 2013-03-19 12:11 - 00000000 ____D () C:\Windows\system32\MAGIX
2015-03-12 15:19 - 2013-01-30 02:18 - 00000000 ____D () C:\Users\Friedrich\Desktop\Spiele
2015-03-12 01:23 - 2013-02-01 16:32 - 00000000 ____D () C:\ProgramData\Origin
2015-03-11 20:42 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-03-11 20:32 - 2014-02-19 19:09 - 00000000 ___RD () C:\Users\Friedrich\Virtual Machines
2015-03-11 20:17 - 2013-08-03 23:48 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-11 15:19 - 2013-01-29 22:28 - 00007655 _____ () C:\Users\Friedrich\AppData\Local\Resmon.ResmonCfg
2015-03-11 13:36 - 2014-07-24 00:39 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\.minecraft
2015-03-11 13:26 - 2013-02-07 04:13 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Razer
2015-03-11 13:26 - 2013-02-07 04:12 - 00000000 ____D () C:\ProgramData\Razer
2015-03-11 13:26 - 2013-01-30 05:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-03-11 13:26 - 2013-01-30 05:03 - 00000000 ____D () C:\Program Files\Razer
2015-03-11 12:11 - 2013-08-21 03:42 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\midori
2015-03-11 02:35 - 2013-02-06 02:14 - 00000000 ____D () C:\ProgramData\TEMP
2015-03-10 04:18 - 2014-06-24 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRWare Iron
2015-03-10 04:18 - 2014-06-24 16:21 - 00000000 ____D () C:\Program Files\SRWare Iron
2015-03-09 09:57 - 2013-04-11 01:04 - 00000000 ____D () C:\Program Files\SpeedFan
2015-03-09 08:08 - 2014-08-23 16:30 - 00000000 ____D () C:\Users\Friedrich\Desktop\New Handy Root und ähnliches Tutorials
2015-03-08 10:56 - 2013-07-16 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-03-08 10:56 - 2013-07-16 15:55 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2015-03-08 04:48 - 2014-01-22 17:33 - 00000000 ____D () C:\Users\Friedrich\.dbus-keyrings
2015-03-08 04:25 - 2014-07-15 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live
2015-03-08 04:25 - 2014-07-15 21:51 - 00000000 ____D () C:\Program Files\GameforgeLive
2015-03-08 03:47 - 2014-04-09 00:13 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-03-08 02:35 - 2013-11-19 10:19 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Warner Bros. Interactive Entertainment
2015-03-06 05:11 - 2013-02-14 06:50 - 00000000 ____D () C:\Program Files\QuickTime
2015-03-06 04:28 - 2013-09-19 21:42 - 00000000 ____D () C:\ProgramData\Oracle
2015-03-06 04:25 - 2014-01-15 06:51 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-03-06 04:25 - 2013-03-05 05:07 - 00000000 ____D () C:\Program Files\Java
2015-03-05 08:01 - 2013-08-13 00:14 - 00000000 ____D () C:\Users\Friedrich\Documents\3DMark
2015-03-05 07:58 - 2014-06-16 05:52 - 00000022 _____ () C:\Windows\GPU-Z.INI
2015-03-05 07:04 - 2013-01-29 23:29 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-05 07:04 - 2013-01-29 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-03-05 05:28 - 2013-02-05 07:26 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2015-03-05 05:11 - 2013-02-07 01:16 - 00000000 ____D () C:\Westwood
2015-03-05 05:10 - 2013-02-07 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Westwood
2015-03-05 03:01 - 2014-04-11 03:10 - 00000000 ____D () C:\Program Files\prime95 v279
2015-03-05 02:40 - 2015-02-11 15:43 - 00000000 ____D () C:\Users\Friedrich\Desktop\Spionaufnahmen mit LifeCam
2015-03-05 02:18 - 2015-02-12 12:20 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\GetRight
2015-03-04 05:16 - 2014-03-11 20:56 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\MPC-HC
2015-03-04 01:56 - 2013-02-01 16:32 - 00000000 ____D () C:\Program Files\Origin
2015-03-04 00:57 - 2013-07-24 22:30 - 00000000 ____D () C:\HammerAutosave
2015-03-03 18:13 - 2013-11-22 18:50 - 00000000 ____D () C:\Program Files\AIMP3
2015-03-02 18:21 - 2013-01-30 02:15 - 00000000 ____D () C:\Users\Friedrich\Desktop\Ernährung u Sportinfos zusatz zur MAPPE
2015-03-02 02:15 - 2013-02-26 18:36 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Audacity
2015-03-02 02:11 - 2013-02-26 18:36 - 00001000 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-03-02 02:11 - 2013-02-26 18:36 - 00000000 ____D () C:\Program Files\Audacity
2015-03-01 23:47 - 2015-02-12 12:21 - 00000000 ____D () C:\ProgramData\GetRight
2015-02-28 19:33 - 2013-02-03 00:02 - 02712576 _____ () C:\Users\Friedrich\AppData\Local\file__0.localstorage
2015-02-28 18:06 - 2013-01-25 15:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-02-28 17:10 - 2013-05-10 04:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IsoBuster
2015-02-28 17:10 - 2013-05-10 04:41 - 00000000 ____D () C:\Program Files\IsoBuster
2015-02-27 17:38 - 2013-01-30 01:44 - 00000000 ____D () C:\Users\Friedrich\Desktop\Canon Shots
2015-02-27 16:52 - 2013-02-01 16:51 - 00000000 ____D () C:\Program Files\Futuremark
2015-02-27 16:03 - 2013-01-30 02:17 - 00000000 ____D () C:\Users\Friedrich\Desktop\POP-RADIO FAKE ACCOUNTS
2015-02-27 03:26 - 2013-02-26 18:48 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2015-02-27 03:20 - 2013-02-26 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks
2015-02-27 03:20 - 2013-02-26 18:48 - 00000000 ____D () C:\Program Files\Lightworks
2015-02-26 21:20 - 2011-04-28 16:10 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-26 18:36 - 2013-09-04 05:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain
2015-02-25 03:10 - 2014-06-28 07:22 - 00000000 ____D () C:\Users\Friedrich\Documents\EthanMeteorHunterDemo
2015-02-25 01:15 - 2013-01-30 01:16 - 00000000 ____D () C:\Users\Friedrich\Martin Krüger
2015-02-25 01:14 - 2013-05-24 01:11 - 00000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe PNG Format CS5 Prefs
2015-02-24 16:48 - 2013-01-29 23:37 - 00000000 ____D () C:\Program Files\CCleaner
==================== Files in the root of some directories =======
2013-10-28 21:15 - 2013-07-08 17:34 - 2699264 _____ (wPrime) C:\Program Files\wPrime.exe
2014-04-26 21:08 - 2014-04-26 21:08 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe GIF Format CS5 Prefs
2013-05-24 01:11 - 2015-02-25 01:14 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-08-06 07:11 - 2014-10-31 04:40 - 0000132 _____ () C:\Users\Friedrich\AppData\Roaming\Adobe Targa Format CS5 Prefs
2015-02-03 18:40 - 2015-02-04 21:05 - 0000623 _____ () C:\Users\Friedrich\AppData\Roaming\All CPU MeterV3_Settings.ini
2013-03-04 20:09 - 2014-02-28 15:35 - 0000540 _____ () C:\Users\Friedrich\AppData\Roaming\AutoGK.ini
2013-05-22 21:43 - 2013-08-25 04:47 - 0000000 _____ () C:\Users\Friedrich\AppData\Roaming\bfe_cddrives
2015-02-04 01:26 - 2015-02-04 01:26 - 0001002 _____ () C:\Users\Friedrich\AppData\Roaming\Currency Meter_Settings.ini
2015-02-04 01:27 - 2015-02-04 01:28 - 0000841 _____ () C:\Users\Friedrich\AppData\Roaming\Drives Meter_Settings.ini
2015-02-03 19:19 - 2015-02-03 19:21 - 0000310 _____ () C:\Users\Friedrich\AppData\Roaming\Earthquakes Meter_Settings.ini
2014-04-20 21:35 - 2015-02-03 17:31 - 0000284 _____ () C:\Users\Friedrich\AppData\Roaming\GPU MeterV2_Settings.ini
2013-06-01 08:16 - 2013-09-22 08:28 - 0001870 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile0.dat
2013-06-01 08:16 - 2013-09-22 08:28 - 0001872 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile1.dat
2013-06-01 08:16 - 2013-09-22 08:28 - 0001876 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile2.dat
2013-09-22 08:27 - 2013-09-22 08:28 - 0001832 _____ () C:\Users\Friedrich\AppData\Roaming\ImperatorProfile3.dat
2015-02-04 01:30 - 2015-02-04 01:30 - 0001209 _____ () C:\Users\Friedrich\AppData\Roaming\Network Meter_Settings.ini
2015-02-04 01:30 - 2015-02-04 01:30 - 0000008 _____ () C:\Users\Friedrich\AppData\Roaming\Network Meter_Usage.ini
2013-02-18 05:16 - 2014-07-16 01:03 - 0138904 _____ () C:\Users\Friedrich\AppData\Roaming\PnkBstrK.sys
2014-04-18 16:25 - 2014-07-02 10:13 - 14315520 _____ () C:\Users\Friedrich\AppData\Roaming\Sandra.mdb
2014-02-07 14:18 - 2015-03-22 18:23 - 0000600 _____ () C:\Users\Friedrich\AppData\Roaming\winscp.rnd
2013-11-15 04:48 - 2013-11-15 05:13 - 0001456 _____ () C:\Users\Friedrich\AppData\Local\Adobe Für Web speichern 12.0 Prefs
2013-10-29 18:14 - 2013-10-29 18:14 - 0242095 _____ () C:\Users\Friedrich\AppData\Local\ars.cache
2013-10-29 18:14 - 2013-10-29 18:14 - 0377163 _____ () C:\Users\Friedrich\AppData\Local\census.cache
2015-03-11 01:10 - 2015-03-11 01:10 - 0003584 _____ () C:\Users\Friedrich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-02-03 00:02 - 2015-02-28 19:33 - 2712576 _____ () C:\Users\Friedrich\AppData\Local\file__0.localstorage
2013-10-29 17:44 - 2013-10-29 17:44 - 0000036 _____ () C:\Users\Friedrich\AppData\Local\housecall.guid.cache
2014-02-09 23:50 - 2014-06-27 05:58 - 0000600 _____ () C:\Users\Friedrich\AppData\Local\PUTTY.RND
2015-02-02 18:15 - 2015-02-02 18:15 - 0000733 _____ () C:\Users\Friedrich\AppData\Local\recently-used.xbel
2013-01-29 22:28 - 2015-03-11 15:19 - 0007655 _____ () C:\Users\Friedrich\AppData\Local\Resmon.ResmonCfg
2013-03-19 12:49 - 2013-03-19 12:52 - 0000041 ___SH () C:\ProgramData\.zreglib
Files to move or delete:
====================
C:\Users\Friedrich\Bsb.exe
C:\Users\Friedrich\cc_20140124_180349.reg
C:\Users\Friedrich\cc_20140315_160443.reg
C:\Users\Friedrich\cc_20140718_151624.reg
C:\Users\Friedrich\cc_20140905_190648.reg
C:\Users\Friedrich\cc_20141008_060204.reg
C:\Users\Friedrich\IP_Log_Data.js
C:\Users\Friedrich\regsicherung.reg
C:\Users\Friedrich\Sicherung reg von CCleaner 2.reg
Some content of TEMP:
====================
C:\Users\Friedrich\AppData\Local\Temp\Quarantine.exe
C:\Users\Friedrich\AppData\Local\Temp\sqlite3.dll
Some zero byte size files/folders:
==========================
C:\Windows\logo_1.exe
C:\Windows\RUNDL132.EXE
C:\Windows\VDLL.DLL
C:\Windows\System32\runouce.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-20 19:59
==================== End Of Log ============================ --- --- --- |