Trojan.Generic.KDV.182338 (B) Problem:
Diverse Sites ließen sich in Chrome nicht mehr aufrufen. Neustart des T-Online Routers. Keine Besserung. Scan mit Emsisoft Anti-Malware nach manueller Virenlistenaktualisierung am 10.11.2012 – Fund: Trojan.Generic.KDV.182338 (B) Beschreibung wie es dazu kam:
Ehemals Win7 Pro System mit div. Programmen auf c:
Neuinstallation Win 7 Pro auf F: und update mit Win 8 pro
Über Bootmenu wird überlicherweise die Win 8 pro Installation aufgerufen.
Chrome und Addons, kein Sandboxie (ich bin dumm und faul). Secunia und FileHippo werden bei Systemstart geladen. Letzte Aktualisierung nach Hinweis durch Secunia, war eine manuelle Installation von Adobe Flash Player, dabei InstallDatei von web-Site manuell geladen und ausgeführt.
unternommene Schritte:
Defogger -> Disable -> o.k. -> kein Neustart erforderlich.
OTL-Download und Ausführung. Code:
OTL logfile created on: 11.11.2012 10:13:56 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\Users\***\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16420)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,98 Gb Total Physical Memory | 6,53 Gb Available Physical Memory | 81,86% Memory free
9,16 Gb Paging File | 6,99 Gb Available in Paging File | 76,25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files (x86)
Drive C: | 111,79 Gb Total Space | 49,87 Gb Free Space | 44,61% Space Free | Partition Type: NTFS
Drive D: | 37,43 Gb Total Space | 37,33 Gb Free Space | 99,74% Space Free | Partition Type: NTFS
Drive E: | 214,17 Gb Total Space | 201,86 Gb Free Space | 94,25% Space Free | Partition Type: NTFS
Drive F: | 214,16 Gb Total Space | 137,80 Gb Free Space | 64,34% Space Free | Partition Type: NTFS
Drive Z: | 465,64 Gb Total Space | 375,81 Gb Free Space | 80,71% Space Free | Partition Type: FAT32
Computer Name: WIN8-VERSUCH | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found --
PRC - [2012.11.11 10:13:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- F:\Users\***\Downloads\OTL.exe
PRC - [2012.11.07 20:40:00 | 001,581,592 | ---- | M] (Google Inc.) -- F:\Windows\Temp\CR_4D744.tmp\setup.exe
PRC - [2012.10.28 19:29:47 | 000,843,208 | ---- | M] (Samsung) -- F:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2012.10.27 20:23:16 | 000,212,432 | ---- | M] (Google Inc.) -- F:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012.10.17 17:02:24 | 003,364,264 | ---- | M] (Emsisoft GmbH) -- F:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
PRC - [2012.10.06 17:01:48 | 003,084,176 | ---- | M] (Emsisoft GmbH) -- F:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
PRC - [2012.10.02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- F:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.09.24 13:46:16 | 001,328,736 | ---- | M] (Secunia) -- F:\Program Files (x86)\Secunia\PSI\PSIA.exe
PRC - [2012.09.24 13:46:16 | 000,656,480 | ---- | M] (Secunia) -- F:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2012.09.24 13:46:14 | 000,573,536 | ---- | M] (Secunia) -- F:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- F:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.09.05 16:57:26 | 000,271,808 | ---- | M] (McAfee, Inc.) -- F:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV:64bit: - [2012.09.20 10:10:47 | 002,367,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2012.09.20 09:18:03 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2012.09.20 07:32:59 | 000,169,984 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2012.09.20 07:32:58 | 000,178,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2012.09.20 07:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2012.09.20 07:30:41 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- F:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2012.09.20 07:30:38 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- F:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2012.08.29 14:22:36 | 000,208,384 | ---- | M] (Atheros Commnucations) [Auto | Running] -- F:\Windows\SysNative\AdminService.exe -- (AtherosSvc)
SRV:64bit: - [2012.07.26 04:08:04 | 001,968,128 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2012.07.26 04:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2012.07.26 04:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- F:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2012.07.26 04:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2012.07.26 04:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2012.07.26 04:06:36 | 000,463,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2012.07.26 04:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2012.07.26 04:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2012.07.26 04:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2012.07.26 04:06:00 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- F:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2012.07.26 04:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2012.07.26 04:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2012.07.26 04:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2012.07.26 04:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- F:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2012.07.26 04:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)
SRV:64bit: - [2012.07.26 04:05:04 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV - [2012.11.10 20:40:11 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- F:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.10.29 18:45:37 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- F:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.19 16:14:08 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- F:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.10.06 17:01:48 | 003,084,176 | ---- | M] (Emsisoft GmbH) [Auto | Running] -- F:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2012.10.02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- F:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012.09.24 13:46:16 | 001,328,736 | ---- | M] (Secunia) [Auto | Running] -- F:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2012.09.24 13:46:16 | 000,656,480 | ---- | M] (Secunia) [Auto | Running] -- F:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- F:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.09.20 09:18:03 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2012.09.05 16:56:44 | 000,234,776 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- F:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe -- (McComponentHostService)
SRV - [2012.07.26 04:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- F:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.09.20 09:31:29 | 000,068,840 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- F:\Windows\SysNative\Drivers\pdc.sys -- (pdc)
DRV:64bit: - [2012.09.20 08:55:33 | 000,445,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2012.09.20 08:55:33 | 000,337,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2012.09.20 08:55:33 | 000,212,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2012.09.20 08:55:30 | 000,120,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2012.09.20 08:55:30 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2012.09.20 08:55:29 | 000,028,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2012.09.20 08:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2012.09.20 08:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2012.09.20 08:03:08 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\tpm.sys -- (TPM)
DRV:64bit: - [2012.09.20 08:03:06 | 000,194,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2012.09.20 08:03:03 | 000,055,528 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- F:\Windows\SysNative\Drivers\dam.sys -- (dam)
DRV:64bit: - [2012.09.20 07:09:11 | 000,031,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2012.09.20 07:08:27 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2012.09.13 06:13:42 | 000,131,416 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2012.08.29 14:22:38 | 000,565,760 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2012.08.22 00:12:20 | 000,055,336 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\AthDfu.sys -- (AthDfu)
DRV:64bit: - [2012.07.26 06:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- F:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.07.26 06:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\condrv.sys -- (condrv)
DRV:64bit: - [2012.07.26 06:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2012.07.26 06:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2012.07.26 06:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2012.07.26 06:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- F:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2012.07.26 06:00:55 | 000,283,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- F:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2012.07.26 06:00:55 | 000,077,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- F:\Windows\SysNative\Drivers\storahci.sys -- (storahci)
DRV:64bit: - [2012.07.26 06:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2012.07.26 06:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2012.07.26 06:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2012.07.26 06:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2012.07.26 06:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2012.07.26 06:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2012.07.26 06:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2012.07.26 06:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2012.07.26 06:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\3ware.sys -- (3ware)
DRV:64bit: - [2012.07.26 06:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2012.07.26 06:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- F:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2012.07.26 05:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- F:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2012.07.26 05:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- F:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2012.07.26 05:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\vpci.sys -- (vpci)
DRV:64bit: - [2012.07.26 05:44:30 | 000,258,288 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2012.07.26 05:36:15 | 000,034,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2012.07.26 04:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2012.07.26 04:17:38 | 000,027,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.07.26 03:29:47 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2012.07.26 03:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2012.07.26 03:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- F:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2012.07.26 03:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2012.07.26 03:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- F:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2012.07.26 03:27:58 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2012.07.26 03:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2012.07.26 03:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2012.07.26 03:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2012.07.26 03:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- F:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2012.07.26 03:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2012.07.26 03:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2012.07.26 03:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2012.07.26 03:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2012.07.26 03:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2012.07.26 03:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012.07.26 03:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2012.07.26 03:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2012.07.26 03:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.07.26 03:25:54 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2012.07.26 03:25:26 | 000,203,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\Vid.sys -- (Vid)
DRV:64bit: - [2012.07.26 03:25:22 | 000,067,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\storvsp.sys -- (storvsp)
DRV:64bit: - [2012.07.26 03:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2012.07.26 03:25:12 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\vmbusr.sys -- (vmbusr)
DRV:64bit: - [2012.07.26 03:25:12 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\vpcivsp.sys -- (vpcivsp)
DRV:64bit: - [2012.07.26 03:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2012.07.26 03:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2012.07.26 03:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- F:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2012.07.25 23:53:22 | 011,926,528 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.06.29 03:00:48 | 000,360,448 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.06.02 15:31:56 | 000,589,824 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2012.06.02 15:31:55 | 001,855,520 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- F:\Windows\SysNative\Drivers\netr28ux.sys -- (netr28ux)
DRV:64bit: - [2011.12.16 15:20:10 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- F:\Windows\SysNative\Drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.10.19 22:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.01.07 02:20:22 | 000,448,512 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- F:\Windows\SysNative\Drivers\RTL8187.sys -- (RTL8187)
DRV - [2012.04.30 17:45:28 | 000,066,320 | ---- | M] (Emsisoft GmbH) [File_System | On_Demand | Running] -- F:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys -- (a2acc)
DRV - [2012.04.30 17:45:00 | 000,044,688 | ---- | M] (Emsisoft GmbH) [File_System | System | Running] -- F:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys -- (a2injectiondriver)
DRV - [2011.05.19 13:10:34 | 000,023,208 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- F:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys -- (A2DDA)
DRV - [2010.05.05 08:40:54 | 000,014,720 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- F:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys -- (a2util)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = F:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3B C6 B6 72 78 B4 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {4B00392A-C410-4A53-9706-1F56FDED3CEC}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\..\SearchScopes\{4B00392A-C410-4A53-9706-1F56FDED3CEC}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searcerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: F:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: F:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: F:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: F:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: F:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: F:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: F:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: F:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: F:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: F:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: F:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: F:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: F:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: F:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: F:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: F:\Program Files (x86)\Mozilla Firefox\components [2012.10.27 22:01:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: F:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.29 21:32:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: F:\Program Files (x86)\Mozilla Thunderbird\components [2012.10.29 18:45:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: F:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: F:\Program Files (x86)\Mozilla Thunderbird\components [2012.10.29 18:45:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: F:\Program Files (x86)\Mozilla Thunderbird\plugins
[2012.10.27 22:07:42 | 000,000,000 | ---D | M] (No name found) -- F:\Users\***\AppData\Roaming\mozilla\Extensions
[2012.11.03 21:23:38 | 000,000,000 | ---D | M] (No name found) -- F:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\ly48x1iy.default\extensions
[2012.10.28 19:26:37 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- F:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\ly48x1iy.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.11.03 21:23:38 | 000,000,000 | ---D | M] (No name found) -- F:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\ly48x1iy.default\extensions\staged
[2012.10.31 18:21:57 | 000,000,000 | ---D | M] (No name found) -- F:\Program Files (x86)\mozilla firefox\extensions
[2012.10.31 18:21:58 | 000,000,000 | ---D | M] (Skype Click to Call) -- F:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.10.27 22:07:20 | 000,000,000 | ---D | M] (Java Console) -- F:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012.10.24 18:50:04 | 000,261,600 | ---- | M] (Mozilla Foundation) -- F:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.28 16:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- F:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.10.24 23:03:12 | 000,001,392 | ---- | M] () -- F:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.10.24 23:03:11 | 000,002,465 | ---- | M] () -- F:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.24 23:03:12 | 000,001,153 | ---- | M] () -- F:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.10.24 23:03:12 | 000,006,805 | ---- | M] () -- F:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.10.24 23:03:12 | 000,001,178 | ---- | M] () -- F:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.10.24 23:03:11 | 000,001,105 | ---- | M] () -- F:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = F:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = F:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = F:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = F:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: Skype Click to Call (Enabled) = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = F:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Winamp Application Detector (Enabled) = F:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = F:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = F:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Picasa (Enabled) = F:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = F:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U9 (Enabled) = F:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.90.5 (Enabled) = F:\WINDOWS\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = F:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: VLC Web Plugin (Enabled) = F:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - Extension: Fast Search = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\afnaofjbkflgabdhippkhhinnnnfdopk\1.8_0\
CHR - Extension: Session Manager = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbcnbpafconjjigibnhbfmmgdbbkcjfi\0.4_0\
CHR - Extension: Funmoods = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\1.0_0\
CHR - Extension: Bulk Download Images(ZIG) = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bedbigoemkinkepgmcmgnapjcahnedmn\2.1.5_0\
CHR - Extension: WOT = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.3.7_0\
CHR - Extension: YouTube = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Firebug Lite for Google Chrome\u2122 = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench\1.4.0.11967_0\
CHR - Extension: Meine IP-Adresse = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccfphbgnmmhjfalloifioeeeokjemobf\1.24_0\
CHR - Extension: FlashBlock = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdngiadmnkhgemkimkhiilgffbjijcie\1.2.11.12_0\
CHR - Extension: Adblock Plus = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.1_0\
CHR - Extension: Puk-Puk = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\cngkcldnnppckgbmndaccoffaikjbemc\3_0\
CHR - Extension: Image Downloader = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj\1.3_0\
CHR - Extension: Google-Suche = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Best Utility Apps = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnfkmehkjocihlfmcjkmdiekloihfaog\1.0.0.1_0\
CHR - Extension: Google Earth The Instant Way = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpifhlbldgbpgcgpcmiakanpghoddbme\0.7_0\
CHR - Extension: YouTube 2 Mp3 Converter = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\epkjgmpenmohanjnliedcekhjkbgbinj\1.0_0\
CHR - Extension: Torrent Turbo Search = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcdgomceilgkonhjheaijcmgfhabmpio\3.5.5.9_0\
CHR - Extension: Ultimate Searcher = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfkkggpdieeljhcpgbdimpnlnpijccic\2.0_0\
CHR - Extension: Eye Dropper = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka\0.2.6_0\
CHR - Extension: MP3 Converter = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggjepemmdkieakihpomccndhdfcljdp\3.0.0.0_0\
CHR - Extension: colorPicker 0.9 = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jegimleidpfmpepbfajjlielaheedkdo\0.9.90_0\
CHR - Extension: Bubble Translate = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhlebbhengjlhmcjebbkambaekglhkf\1.5_0\
CHR - Extension: My IP = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaookbilagohkmkobbhanefacdhlcjdi\1.0_0\
CHR - Extension: FVD Video Downloader = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp\1.3.9_0\
CHR - Extension: FVD Video Downloader = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp\1.4.0_0\
CHR - Extension: Skype Click to Call = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0\
CHR - Extension: DownAll = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljkdhninipglbomdgpakmhfbbggcfmog\0.4.1_0\
CHR - Extension: YouTube Instant = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnajachlebjlnfeglgoecpfcbaiigbja\0.8_0\
CHR - Extension: Google Maps = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.7_0\
CHR - Extension: Ghostery = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.0.0_0\
CHR - Extension: NotScripts = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\odjhifogjcknibkahlpidmdajjpkkcfn\0.9.6_0\
CHR - Extension: Google Mail = F:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2012.07.26 06:26:49 | 000,000,824 | ---- | M]) - F:\Windows\SysNative\Drivers\etc\hosts
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - F:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - F:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - F:\Program Files (x86)\Funmoods\1.5.23.22\bh\escort.dll (Funmoods BHO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - F:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - F:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - F:\Program Files (x86)\Funmoods\1.5.23.22\escorTlbr.dll (Funmoods)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [emsisoft anti-malware] f:\program files (x86)\emsisoft anti-malware\a2guard.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [KiesTrayAgent] F:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [WinampAgent] F:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [] F:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKCU..\Run: [FileHippo.com] F:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKCU..\Run: [GoogleDriveSync] F:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [KiesAirMessage] F:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe (Samsung Electronics)
O4 - HKCU..\Run: [KiesPreload] F:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://F:\WINDOWS\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: An OneNote s&enden - res://F:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Free YouTube Download - F:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - F:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://F:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - F:\WINDOWS\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: An OneNote s&enden - res://F:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Free YouTube Download - F:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - F:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://F:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 10.9.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2257C3CF-27CC-423A-B5F3-07F564E20BEE}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9A732324-48A3-4880-ACA9-9359D7080B96}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - F:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (F:\Windows\system32\userinit.exe) - F:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - F:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - F:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002.10.17 09:56:50 | 000,000,036 | RH-- | M] () - Z:\Autorun.inf.bak -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.11.04 21:37:56 | 000,000,000 | ---D | C] -- F:\Users\***\Documents\WISO Mein Geld
[2012.11.03 21:23:35 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Funmoods
[2012.11.03 21:23:31 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\IrfanView
[2012.11.03 21:23:31 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012.11.03 21:23:30 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\IrfanView
[2012.11.03 21:20:27 | 001,820,672 | ---- | C] (Irfan Skiljan) -- F:\Users\***\Desktop\iview433g_setup.exe
[2012.11.03 21:20:27 | 001,725,680 | ---- | C] (Setup © ) -- F:\Users\***\Desktop\FunmoodsSetup.exe
[2012.11.03 21:01:10 | 000,000,000 | ---D | C] -- F:\ProgramData\Visan
[2012.11.03 21:01:10 | 000,000,000 | ---D | C] -- F:\ProgramData\HP Photo Creations
[2012.11.03 21:01:10 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\HP Photo Creations
[2012.11.03 21:01:04 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\HpUpdate
[2012.11.03 21:00:59 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2012.11.03 21:00:44 | 000,000,000 | ---D | C] -- F:\Program Files\HP
[2012.11.03 21:00:44 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\HP
[2012.11.03 21:00:09 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\HP
[2012.11.02 20:24:21 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.11.02 20:24:04 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Deployment
[2012.11.02 20:24:04 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Apps
[2012.11.02 18:28:15 | 000,000,000 | -HSD | C] -- F:\Config.Msi
[2012.11.02 17:45:09 | 000,000,000 | ---D | C] -- F:\Program Files\Java
[2012.11.02 17:43:23 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Common Files\Java
[2012.10.31 18:21:53 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Skype
[2012.10.31 18:21:51 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.10.31 18:21:51 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Common Files\Skype
[2012.10.31 18:21:50 | 000,000,000 | R--D | C] -- F:\Program Files (x86)\Skype
[2012.10.31 18:21:46 | 000,000,000 | ---D | C] -- F:\ProgramData\Skype
[2012.10.30 18:40:57 | 000,000,000 | ---D | C] -- F:\WINDOWS\ehome
[2012.10.29 21:33:19 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
[2012.10.29 21:32:49 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
[2012.10.29 21:32:49 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Winamp Detect
[2012.10.29 21:32:43 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Common Files\PX Storage Engine
[2012.10.29 21:32:39 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Winamp
[2012.10.29 21:32:39 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Winamp
[2012.10.29 21:00:01 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\vlc
[2012.10.29 20:37:36 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.10.29 20:37:24 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\VideoLAN
[2012.10.29 20:19:05 | 000,000,000 | ---D | C] -- F:\Users\***\Documents\Outlook-Dateien
[2012.10.29 18:45:34 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Mozilla Thunderbird
[2012.10.29 17:45:50 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Identities
[2012.10.28 19:38:27 | 000,000,000 | ---D | C] -- F:\Users\Public\Documents\CrashDump
[2012.10.28 19:35:55 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Adobe
[2012.10.28 19:29:30 | 000,000,000 | ---D | C] -- F:\Users\Public\Documents\NativeFus_Log
[2012.10.28 19:29:27 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Samsung
[2012.10.28 19:29:27 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Samsung
[2012.10.28 19:29:26 | 000,000,000 | ---D | C] -- F:\Users\***\Documents\samsung
[2012.10.28 19:28:07 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Plugins
[2012.10.28 19:26:36 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.10.28 19:26:35 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2012.10.28 19:26:33 | 000,405,144 | ---- | C] (Newtonsoft) -- F:\WINDOWS\SysWow64\Newtonsoft.Json.Net20.dll
[2012.10.28 19:26:26 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\DVDVideoSoft
[2012.10.28 19:26:26 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Common Files\DVDVideoSoft
[2012.10.28 19:25:35 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\DVDVideoSoft
[2012.10.28 19:23:38 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\GHISLER
[2012.10.28 19:21:24 | 000,000,000 | ---D | C] -- F:\totalcmd
[2012.10.28 19:21:24 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
[2012.10.28 19:20:42 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\GHISLER
[2012.10.28 19:12:17 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2012.10.28 19:12:15 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- F:\WINDOWS\SysWow64\Redemption.dll
[2012.10.28 19:12:10 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- F:\WINDOWS\SysWow64\dgderapi.dll
[2012.10.28 19:12:10 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\MarkAny
[2012.10.28 19:11:46 | 000,000,000 | ---D | C] -- F:\ProgramData\Samsung
[2012.10.28 19:11:46 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Samsung
[2012.10.28 19:11:18 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Downloaded Installations
[2012.10.28 19:09:39 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Macromedia
[2012.10.28 19:09:39 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Macromedia
[2012.10.28 19:00:20 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Opera
[2012.10.28 19:00:20 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Opera
[2012.10.28 19:00:15 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Opera
[2012.10.28 18:58:14 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.10.28 18:58:12 | 000,000,000 | ---D | C] -- F:\Program Files\7-Zip
[2012.10.28 18:55:51 | 000,000,000 | ---D | C] -- F:\ProgramData\HP
[2012.10.28 18:51:23 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2012.10.28 18:51:22 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012.10.28 18:50:25 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Microsoft Synchronization Services
[2012.10.28 18:50:24 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Common Files\DESIGNER
[2012.10.28 18:50:01 | 000,000,000 | ---D | C] -- F:\WINDOWS\PCHEALTH
[2012.10.28 18:50:01 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Microsoft Sync Framework
[2012.10.28 18:50:01 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2012.10.28 18:47:27 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Microsoft Visual Studio 8
[2012.10.28 18:46:30 | 000,000,000 | ---D | C] -- F:\Program Files\Microsoft Office
[2012.10.28 18:46:13 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Microsoft Analysis Services
[2012.10.28 18:45:58 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Microsoft Help
[2012.10.28 18:45:55 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Microsoft Office
[2012.10.28 18:45:55 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft Help
[2012.10.28 18:45:43 | 000,000,000 | RH-D | C] -- F:\MSOCache
[2012.10.28 16:36:10 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2012.10.28 16:21:09 | 000,000,000 | ---D | C] -- F:\ProgramData\McAfee Security Scan
[2012.10.28 16:21:06 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\McAfee Security Scan
[2012.10.28 16:21:06 | 000,000,000 | ---D | C] -- F:\ProgramData\McAfee
[2012.10.28 16:20:47 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Common Files\Adobe
[2012.10.28 16:20:47 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Adobe
[2012.10.28 16:20:01 | 000,000,000 | ---D | C] -- F:\ProgramData\Adobe
[2012.10.28 13:47:15 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO Steuer-Sparbuch 2012
[2012.10.28 13:46:46 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
[2012.10.28 13:45:58 | 000,000,000 | -H-D | C] -- F:\Program Files (x86)\InstallShield Installation Information
[2012.10.28 13:45:58 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\WISO
[2012.10.28 13:42:49 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Buhl Data Service
[2012.10.28 13:42:44 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Buhl Data Service
[2012.10.28 13:42:43 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Buhl Data Service GmbH
[2012.10.28 13:40:24 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO Mein Geld 2013
[2012.10.28 13:40:05 | 000,000,000 | ---D | C] -- F:\ProgramData\Buhl Data Service GmbH
[2012.10.28 13:39:55 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Buhl
[2012.10.28 12:14:48 | 000,000,000 | --SD | C] -- F:\Users\***\Google Drive
[2012.10.28 12:14:07 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2012.10.27 22:16:14 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\LibreOffice
[2012.10.27 22:13:33 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 3.6
[2012.10.27 22:12:08 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\LibreOffice 3.6
[2012.10.27 22:09:26 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Mozilla
[2012.10.27 22:07:42 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Thunderbird
[2012.10.27 22:07:42 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Thunderbird
[2012.10.27 22:07:42 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Mozilla
[2012.10.27 22:07:22 | 000,000,000 | ---D | C] -- F:\ProgramData\Sun
[2012.10.27 22:07:09 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Java
[2012.10.27 22:01:40 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Mozilla Maintenance Service
[2012.10.27 22:01:40 | 000,000,000 | ---D | C] -- F:\ProgramData\Mozilla
[2012.10.27 22:01:30 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Mozilla Firefox
[2012.10.27 21:57:40 | 000,000,000 | ---D | C] -- F:\Users\***\.VirtualBox
[2012.10.27 21:56:54 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
[2012.10.27 21:56:50 | 000,000,000 | ---D | C] -- F:\WINDOWS\SysNative\DRVSTORE
[2012.10.27 21:56:46 | 000,000,000 | ---D | C] -- F:\Program Files\Oracle
[2012.10.27 21:55:11 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\MSXML 4.0
[2012.10.27 21:52:41 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012.10.27 21:52:24 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Microsoft Silverlight
[2012.10.27 21:50:08 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Secunia PSI
[2012.10.27 21:50:02 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Secunia
[2012.10.27 21:42:27 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\FileHippo.com
[2012.10.27 21:39:47 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Reference Assemblies
[2012.10.27 21:39:47 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\MSBuild
[2012.10.27 21:39:11 | 000,000,000 | ---D | C] -- F:\WINDOWS\SysWow64\XPSViewer
[2012.10.27 21:39:06 | 000,000,000 | ---D | C] -- F:\Program Files\Reference Assemblies
[2012.10.27 21:39:06 | 000,000,000 | ---D | C] -- F:\Program Files\MSBuild
[2012.10.27 21:37:14 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
[2012.10.27 21:37:14 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
[2012.10.27 21:37:12 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Notepad++
[2012.10.27 21:37:12 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Notepad++
[2012.10.27 21:36:32 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64
[2012.10.27 21:36:27 | 000,000,000 | ---D | C] -- F:\Program Files\K-Lite Codec Pack x64
[2012.10.27 21:30:44 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.10.27 21:30:42 | 000,000,000 | ---D | C] -- F:\Program Files\CCleaner
[2012.10.27 21:22:01 | 000,000,000 | R--D | C] -- F:\WINDOWS\BrowserChoice
[2012.10.27 21:01:39 | 000,000,000 | ---D | C] -- F:\Windows.old
[2012.10.27 20:56:22 | 000,000,000 | ---D | C] -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
[2012.10.27 20:55:53 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Emsisoft Anti-Malware
[2012.10.27 20:55:53 | 000,000,000 | ---D | C] -- F:\Users\***\Documents\Anti-Malware
[2012.10.27 20:43:40 | 000,000,000 | ---D | C] -- F:\Program Files\ATI Technologies
[2012.10.27 20:43:38 | 000,000,000 | ---D | C] -- F:\Program Files\ATI
[2012.10.27 20:43:02 | 000,000,000 | ---D | C] -- F:\AMD
[2012.10.27 20:23:17 | 000,000,000 | ---D | C] -- F:\Program Files (x86)\Google
[2012.10.27 20:23:14 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Google
[2012.10.27 20:15:15 | 000,000,000 | R--D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.10.27 20:15:15 | 000,000,000 | R--D | C] -- F:\Users\***\Searches
[2012.10.27 20:15:15 | 000,000,000 | R--D | C] -- F:\Users\***\Contacts
[2012.10.27 20:15:15 | 000,000,000 | R--D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.10.27 20:15:13 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Adobe
[2012.10.27 20:14:45 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\VirtualStore
[2012.10.27 20:14:38 | 000,000,000 | ---D | C] -- F:\ProgramData\PRICache
[2012.10.27 20:14:38 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Packages
[2012.10.27 20:14:10 | 000,000,000 | --SD | C] -- F:\Users\***\AppData\Roaming\Microsoft
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Videos
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Saved Games
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Pictures
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Music
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Links
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Favorites
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Downloads
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Documents
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\Desktop
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.10.27 20:14:10 | 000,000,000 | R--D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Vorlagen
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\AppData\Local\Verlauf
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\AppData\Local\Temporary Internet Files
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Startmenü
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\SendTo
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Recent
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Netzwerkumgebung
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Lokale Einstellungen
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Documents\Eigene Videos
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Documents\Eigene Musik
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Eigene Dateien
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Documents\Eigene Bilder
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Druckumgebung
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Cookies
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\AppData\Local\Anwendungsdaten
[2012.10.27 20:14:10 | 000,000,000 | -HSD | C] -- F:\Users\***\Anwendungsdaten
[2012.10.27 20:14:10 | 000,000,000 | -H-D | C] -- F:\Users\***\AppData
[2012.10.27 20:14:10 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Temp
[2012.10.27 20:14:10 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Local\Microsoft
[2012.10.27 20:14:10 | 000,000,000 | ---D | C] -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.10.27 20:13:32 | 000,000,000 | ---D | C] -- F:\WINDOWS\CSC
[2012.10.27 20:08:26 | 000,000,000 | -HSD | C] -- F:\Program Files\Gemeinsame Dateien
[2012.10.27 20:08:26 | 000,000,000 | -HSD | C] -- F:\Users\Public\Documents\Eigene Videos
[2012.10.27 20:08:26 | 000,000,000 | -HSD | C] -- F:\Users\Public\Documents\Eigene Musik
[2012.10.27 20:08:26 | 000,000,000 | -HSD | C] -- F:\Users\Public\Documents\Eigene Bilder
[2012.10.27 20:08:25 | 000,000,000 | -HSD | C] -- F:\ProgramData\Vorlagen
[2012.10.27 20:08:25 | 000,000,000 | -HSD | C] -- F:\ProgramData\Startmenü
[2012.10.27 20:08:25 | 000,000,000 | -HSD | C] -- F:\ProgramData\Dokumente
[2012.10.27 20:08:25 | 000,000,000 | -HSD | C] -- F:\ProgramData\Anwendungsdaten
[2012.10.27 20:07:36 | 000,000,000 | ---D | C] -- F:\WINDOWS\SoftwareDistribution
[2012.10.27 20:03:44 | 000,000,000 | ---D | C] -- F:\WINDOWS\Prefetch
[2012.10.27 19:49:28 | 000,000,000 | ---D | C] -- F:\WINDOWS\Panther
[2012.10.27 15:54:00 | 000,000,000 | RH-D | C] -- F:\ESD
[2012.10.27 14:21:40 | 000,000,000 | ---D | C] -- F:\Intel
[2012.10.27 13:57:27 | 000,000,000 | -HSD | C] -- F:\Recovery
[2012.10.27 13:57:27 | 000,000,000 | -HSD | C] -- F:\Programme
[2012.10.27 13:57:27 | 000,000,000 | -HSD | C] -- F:\Dokumente und Einstellungen
========== Files - Modified Within 30 Days ==========
[2012.11.11 10:08:38 | 000,000,000 | ---- | M] () -- F:\Users\***\defogger_reenable
[2012.11.11 09:28:01 | 000,001,130 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.11.11 09:22:03 | 000,000,884 | ---- | M] () -- F:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.11.11 09:15:27 | 000,067,584 | --S- | M] () -- F:\WINDOWS\bootstat.dat
[2012.11.10 21:56:12 | 000,001,972 | ---- | M] () -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Photosmart Plus B210 series.lnk
[2012.11.10 21:56:05 | 000,001,126 | ---- | M] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.11.07 21:43:07 | 000,223,477 | ---- | M] () -- F:\Users\***\Documents\Scan0001.pdf
[2012.11.07 21:16:14 | 001,724,222 | ---- | M] () -- F:\Users\***\Documents\***.zip
[2012.11.07 21:03:05 | 268,435,456 | -HS- | M] () -- F:\swapfile.sys
[2012.11.05 20:47:00 | 001,745,416 | ---- | M] () -- F:\WINDOWS\SysNative\PerfStringBackup.INI
[2012.11.05 20:47:00 | 000,751,892 | ---- | M] () -- F:\WINDOWS\SysNative\perfh007.dat
[2012.11.05 20:47:00 | 000,710,046 | ---- | M] () -- F:\WINDOWS\SysNative\perfh009.dat
[2012.11.05 20:47:00 | 000,155,620 | ---- | M] () -- F:\WINDOWS\SysNative\perfc007.dat
[2012.11.05 20:47:00 | 000,132,416 | ---- | M] () -- F:\WINDOWS\SysNative\perfc009.dat
[2012.11.05 20:42:03 | 2557,579,263 | -HS- | M] () -- F:\hiberfil.sys
[2012.11.05 20:00:08 | 000,399,302 | ---- | M] () -- F:\Users\***\Documents\Scan0005.jpg
[2012.11.05 19:59:15 | 000,452,199 | ---- | M] () -- F:\Users\***\Documents\Scan0004.jpg
[2012.11.05 19:58:33 | 000,424,520 | ---- | M] () -- F:\Users\***\Documents\Scan0003.jpg
[2012.11.05 19:56:29 | 000,378,680 | ---- | M] () -- F:\Users\***\Documents\Scan0002.jpg
[2012.11.05 18:14:20 | 000,002,247 | ---- | M] () -- F:\Users\***\Desktop\Google Chrome.lnk
[2012.11.03 21:30:53 | 000,120,535 | ---- | M] () -- F:\Users\***\Documents\Apfel auf grobem Papier - 118.jpg
[2012.11.03 21:27:05 | 000,647,131 | ---- | M] () -- F:\Users\***\Documents\Apfel auf grobem Papier.jpg
[2012.11.03 21:23:37 | 000,031,465 | ---- | M] () -- F:\Users\***\AppData\Local\funmoods.crx
[2012.11.03 21:23:31 | 000,001,890 | ---- | M] () -- F:\Users\Public\Desktop\IrfanView Thumbnails.lnk
[2012.11.03 21:23:31 | 000,001,002 | ---- | M] () -- F:\Users\Public\Desktop\IrfanView.lnk
[2012.11.03 21:22:39 | 001,725,680 | ---- | M] (Setup © ) -- F:\Users\***\Desktop\FunmoodsSetup.exe
[2012.11.03 21:22:35 | 001,820,672 | ---- | M] (Irfan Skiljan) -- F:\Users\***\Desktop\iview433g_setup.exe
[2012.11.03 21:18:04 | 000,000,476 | -H-- | M] () -- F:\Users\***\Documents\.picasa.ini
[2012.11.03 21:11:48 | 000,750,250 | ---- | M] () -- F:\Users\***\Documents\Scan0001-001.jpg
[2012.11.03 21:04:01 | 000,333,125 | ---- | M] () -- F:\Users\***\Documents\Scan0001.jpg
[2012.11.03 21:01:11 | 000,001,991 | ---- | M] () -- F:\Users\Public\Desktop\HP Photo Creations.lnk
[2012.11.03 21:00:59 | 000,002,308 | ---- | M] () -- F:\Users\Public\Desktop\HP Photosmart Plus B210 series.lnk
[2012.11.03 21:00:59 | 000,001,215 | ---- | M] () -- F:\Users\Public\Desktop\Shop für Zubehör - HP Photosmart Plus B210 series.lnk
[2012.11.03 21:00:41 | 000,000,057 | ---- | M] () -- F:\ProgramData\Ament.ini
[2012.10.31 18:27:13 | 000,011,034 | ---- | M] () -- F:\Users\***\Documents\Was du machst.rar
[2012.10.31 18:21:51 | 000,002,517 | ---- | M] () -- F:\Users\Public\Desktop\Skype.lnk
[2012.10.30 18:43:39 | 000,467,184 | ---- | M] () -- F:\WINDOWS\SysNative\FNTCACHE.DAT
[2012.10.29 21:33:20 | 000,000,979 | ---- | M] () -- F:\Users\Public\Desktop\Winamp.lnk
[2012.10.29 20:37:36 | 000,001,066 | ---- | M] () -- F:\Users\Public\Desktop\VLC media player.lnk
[2012.10.28 19:44:28 | 000,001,239 | ---- | M] () -- F:\Users\***\Desktop\DVDVideoSoft Free Studio.lnk
[2012.10.28 19:29:25 | 000,001,992 | ---- | M] () -- F:\Users\Public\Desktop\Samsung Kies.lnk
[2012.10.28 19:26:35 | 000,001,398 | ---- | M] () -- F:\Users\***\Desktop\Free YouTube to MP3 Converter.lnk
[2012.10.28 19:21:25 | 000,000,646 | ---- | M] () -- F:\Users\***\Desktop\Total Commander 64 bit.lnk
[2012.10.28 18:55:54 | 000,000,000 | -H-- | M] () -- F:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2012.10.28 16:36:10 | 000,002,046 | ---- | M] () -- F:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2012.10.28 16:36:10 | 000,002,046 | ---- | M] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2012.10.28 16:20:52 | 000,002,019 | ---- | M] () -- F:\Users\Public\Desktop\Adobe Reader XI.lnk
[2012.10.28 13:53:07 | 000,002,127 | ---- | M] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
[2012.10.28 13:53:07 | 000,002,095 | ---- | M] () -- F:\Users\Public\Desktop\WISO Steuer-Sparbuch 2012.lnk
[2012.10.28 13:46:50 | 000,001,106 | ---- | M] () -- F:\Users\Public\Desktop\Picasa 3.lnk
[2012.10.28 13:40:25 | 000,001,206 | ---- | M] () -- F:\Users\Public\Desktop\WISO Mein Geld 2013.lnk
[2012.10.28 12:14:48 | 000,001,715 | ---- | M] () -- F:\Users\***\Desktop\Google Drive.lnk
[2012.10.28 11:32:20 | 000,000,000 | -H-- | M] () -- F:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2012.10.27 22:13:33 | 000,001,126 | ---- | M] () -- F:\Users\Public\Desktop\LibreOffice 3.6.lnk
[2012.10.27 22:05:21 | 000,002,086 | ---- | M] () -- F:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2012.10.27 22:01:41 | 000,001,147 | ---- | M] () -- F:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.10.27 21:56:55 | 000,001,076 | ---- | M] () -- F:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
[2012.10.27 21:50:03 | 000,001,106 | ---- | M] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012.10.27 21:43:23 | 000,000,822 | ---- | M] () -- F:\Users\Public\Desktop\CCleaner.lnk
[2012.10.27 21:42:27 | 000,001,969 | ---- | M] () -- F:\Users\***\Desktop\Update Checker.lnk
[2012.10.27 21:07:54 | 000,007,605 | ---- | M] () -- F:\Users\***\AppData\Local\Resmon.ResmonCfg
[2012.10.27 20:58:43 | 000,000,116 | ---- | M] () -- F:\Users\***\Desktop\listen1.asx
[2012.10.27 20:56:22 | 000,001,091 | ---- | M] () -- F:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
[2012.10.27 20:04:00 | 000,000,000 | ---- | M] () -- F:\WINDOWS\ativpsrm.bin
[2012.10.27 20:04:00 | 000,000,000 | ---- | M] () -- F:\WINDOWS\SysNative\atiicdxx.dat
========== Files Created - No Company Name ==========
[2012.11.11 10:08:38 | 000,000,000 | ---- | C] () -- F:\Users\***\defogger_reenable
[2012.11.07 21:43:07 | 000,223,477 | ---- | C] () -- F:\Users\***\Documents\Scan0001.pdf
[2012.11.07 21:16:11 | 001,724,222 | ---- | C] () -- F:\Users\***\Documents\***.zip
[2012.11.05 20:00:07 | 000,399,302 | ---- | C] () -- F:\Users\***\Documents\Scan0005.jpg
[2012.11.05 19:59:15 | 000,452,199 | ---- | C] () -- F:\Users\***\Documents\Scan0004.jpg
[2012.11.05 19:58:33 | 000,424,520 | ---- | C] () -- F:\Users\***\Documents\Scan0003.jpg
[2012.11.05 19:56:29 | 000,378,680 | ---- | C] () -- F:\Users\***\Documents\Scan0002.jpg
[2012.11.03 21:30:53 | 000,120,535 | ---- | C] () -- F:\Users\***\Documents\Apfel auf grobem Papier - 118.jpg
[2012.11.03 21:27:05 | 000,647,131 | ---- | C] () -- F:\Users\***\Documents\Apfel auf grobem Papier.jpg
[2012.11.03 21:23:38 | 000,031,465 | ---- | C] () -- F:\Users\***\AppData\Local\funmoods.crx
[2012.11.03 21:23:31 | 000,001,890 | ---- | C] () -- F:\Users\Public\Desktop\IrfanView Thumbnails.lnk
[2012.11.03 21:23:31 | 000,001,002 | ---- | C] () -- F:\Users\Public\Desktop\IrfanView.lnk
[2012.11.03 21:11:48 | 000,750,250 | ---- | C] () -- F:\Users\***\Documents\Scan0001-001.jpg
[2012.11.03 21:05:06 | 000,000,476 | -H-- | C] () -- F:\Users\***\Documents\.picasa.ini
[2012.11.03 21:04:01 | 000,333,125 | ---- | C] () -- F:\Users\***\Documents\Scan0001.jpg
[2012.11.03 21:01:51 | 000,001,972 | ---- | C] () -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Photosmart Plus B210 series.lnk
[2012.11.03 21:01:11 | 000,001,991 | ---- | C] () -- F:\Users\Public\Desktop\HP Photo Creations.lnk
[2012.11.03 21:01:06 | 000,000,968 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR-Registrierung.lnk
[2012.11.03 21:00:59 | 000,002,308 | ---- | C] () -- F:\Users\Public\Desktop\HP Photosmart Plus B210 series.lnk
[2012.11.03 21:00:59 | 000,001,215 | ---- | C] () -- F:\Users\Public\Desktop\Shop für Zubehör - HP Photosmart Plus B210 series.lnk
[2012.11.03 21:00:41 | 000,000,057 | ---- | C] () -- F:\ProgramData\Ament.ini
[2012.11.02 20:24:22 | 000,002,247 | ---- | C] () -- F:\Users\***\Desktop\Google Chrome.lnk
[2012.10.31 18:27:12 | 000,011,034 | ---- | C] () -- F:\Users\***\Documents\Was du machst.rar
[2012.10.31 18:21:51 | 000,002,517 | ---- | C] () -- F:\Users\Public\Desktop\Skype.lnk
[2012.10.30 18:38:42 | 000,031,841 | ---- | C] () -- F:\WINDOWS\ProfessionalWMC.xml
[2012.10.29 21:33:20 | 000,000,979 | ---- | C] () -- F:\Users\Public\Desktop\Winamp.lnk
[2012.10.29 20:37:36 | 000,001,066 | ---- | C] () -- F:\Users\Public\Desktop\VLC media player.lnk
[2012.10.28 19:29:25 | 000,001,992 | ---- | C] () -- F:\Users\Public\Desktop\Samsung Kies.lnk
[2012.10.28 19:26:35 | 000,001,398 | ---- | C] () -- F:\Users\***\Desktop\Free YouTube to MP3 Converter.lnk
[2012.10.28 19:26:35 | 000,001,239 | ---- | C] () -- F:\Users\***\Desktop\DVDVideoSoft Free Studio.lnk
[2012.10.28 19:21:25 | 000,000,646 | ---- | C] () -- F:\Users\***\Desktop\Total Commander 64 bit.lnk
[2012.10.28 19:00:19 | 000,001,841 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.10.28 18:55:54 | 000,000,000 | -H-- | C] () -- F:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2012.10.28 16:36:41 | 000,000,884 | ---- | C] () -- F:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.10.28 16:21:06 | 000,002,046 | ---- | C] () -- F:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2012.10.28 16:21:06 | 000,002,046 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2012.10.28 16:20:52 | 000,002,019 | ---- | C] () -- F:\Users\Public\Desktop\Adobe Reader XI.lnk
[2012.10.28 16:20:51 | 000,002,441 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2012.10.28 14:35:33 | 000,467,184 | ---- | C] () -- F:\WINDOWS\SysNative\FNTCACHE.DAT
[2012.10.28 13:53:07 | 000,002,127 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
[2012.10.28 13:53:07 | 000,002,095 | ---- | C] () -- F:\Users\Public\Desktop\WISO Steuer-Sparbuch 2012.lnk
[2012.10.28 13:46:50 | 000,001,106 | ---- | C] () -- F:\Users\Public\Desktop\Picasa 3.lnk
[2012.10.28 13:40:25 | 000,001,206 | ---- | C] () -- F:\Users\Public\Desktop\WISO Mein Geld 2013.lnk
[2012.10.28 12:14:48 | 000,001,715 | ---- | C] () -- F:\Users\***\Desktop\Google Drive.lnk
[2012.10.28 11:32:20 | 000,000,000 | -H-- | C] () -- F:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2012.10.27 22:13:33 | 000,001,126 | ---- | C] () -- F:\Users\Public\Desktop\LibreOffice 3.6.lnk
[2012.10.27 22:05:21 | 000,002,098 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2012.10.27 22:05:21 | 000,002,086 | ---- | C] () -- F:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2012.10.27 22:01:41 | 000,001,159 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.10.27 22:01:41 | 000,001,147 | ---- | C] () -- F:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.10.27 21:56:55 | 000,001,076 | ---- | C] () -- F:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
[2012.10.27 21:50:03 | 000,001,106 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012.10.27 21:50:03 | 000,001,069 | ---- | C] () -- F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012.10.27 21:42:27 | 000,001,999 | ---- | C] () -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk
[2012.10.27 21:42:27 | 000,001,969 | ---- | C] () -- F:\Users\***\Desktop\Update Checker.lnk
[2012.10.27 21:36:32 | 000,148,992 | ---- | C] ( ) -- F:\WINDOWS\SysNative\lagarith.dll
[2012.10.27 21:36:31 | 000,206,336 | ---- | C] () -- F:\WINDOWS\SysNative\unrar.dll
[2012.10.27 21:36:29 | 000,092,160 | ---- | C] () -- F:\WINDOWS\SysNative\ff_vfw.dll
[2012.10.27 21:30:44 | 000,000,822 | ---- | C] () -- F:\Users\Public\Desktop\CCleaner.lnk
[2012.10.27 21:07:54 | 000,007,605 | ---- | C] () -- F:\Users\***\AppData\Local\Resmon.ResmonCfg
[2012.10.27 21:02:00 | 000,000,116 | ---- | C] () -- F:\Users\***\Desktop\listen1.asx
[2012.10.27 20:56:22 | 000,001,091 | ---- | C] () -- F:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
[2012.10.27 20:37:32 | 000,361,934 | ---- | C] () -- F:\WINDOWS\SysNative\ApnDatabase.xml
[2012.10.27 20:37:21 | 000,110,592 | ---- | C] () -- F:\WINDOWS\SysNative\OEMLicense.dll
[2012.10.27 20:37:21 | 000,083,968 | ---- | C] () -- F:\WINDOWS\SysWow64\OEMLicense.dll
[2012.10.27 20:23:18 | 000,001,130 | ---- | C] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.27 20:23:17 | 000,001,126 | ---- | C] () -- F:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.27 20:15:13 | 000,001,438 | ---- | C] () -- F:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.10.27 20:04:00 | 000,000,000 | ---- | C] () -- F:\WINDOWS\ativpsrm.bin
[2012.10.27 20:04:00 | 000,000,000 | ---- | C] () -- F:\WINDOWS\SysNative\atiicdxx.dat
[2012.10.27 20:02:58 | 268,435,456 | -HS- | C] () -- F:\swapfile.sys
[2012.10.27 14:04:38 | 000,007,233 | ---- | C] () -- F:\pdiports.cat
[2012.10.27 14:04:38 | 000,002,853 | ---- | C] () -- F:\pdiports64.inf
[2012.10.27 13:43:24 | 2557,579,263 | -HS- | C] () -- F:\hiberfil.sys
[2012.09.26 20:57:16 | 000,030,568 | ---- | C] () -- F:\WINDOWS\MusiccityDownload.exe
[2012.09.26 20:57:14 | 000,974,848 | ---- | C] () -- F:\WINDOWS\SysWow64\cis-2.4.dll
[2012.09.26 20:57:14 | 000,081,920 | ---- | C] () -- F:\WINDOWS\SysWow64\issacapi_bs-2.3.dll
[2012.09.26 20:57:14 | 000,065,536 | ---- | C] () -- F:\WINDOWS\SysWow64\issacapi_pe-2.3.dll
[2012.09.26 20:57:14 | 000,057,344 | ---- | C] () -- F:\WINDOWS\SysWow64\issacapi_se-2.3.dll
[2012.07.26 09:13:10 | 000,215,943 | ---- | C] () -- F:\WINDOWS\SysWow64\dssec.dat
[2012.07.26 09:13:09 | 000,000,741 | ---- | C] () -- F:\WINDOWS\SysWow64\NOISE.DAT
[2012.07.26 08:21:26 | 000,067,584 | --S- | C] () -- F:\WINDOWS\bootstat.dat
[2012.07.26 02:17:42 | 000,043,520 | ---- | C] () -- F:\WINDOWS\SysWow64\BWContextHandler.dll
[2012.07.25 21:37:29 | 000,043,131 | ---- | C] () -- F:\WINDOWS\mib.bin
[2012.07.25 21:28:31 | 000,364,544 | ---- | C] () -- F:\WINDOWS\SysWow64\msjetoledb40.dll
[2012.06.02 15:31:19 | 000,673,088 | ---- | C] () -- F:\WINDOWS\SysWow64\mlang.dat
========== ZeroAccess Check ==========
[2012.11.02 20:24:08 | 000,000,227 | RHS- | M] () -- F:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = F:\Windows\SysNative\shell32.dll -- [2012.10.11 06:45:39 | 019,789,824 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.10.11 06:07:29 | 017,560,576 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = F:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 04:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 04:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = F:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 04:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.10.28 13:42:49 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\Buhl Data Service
[2012.10.30 20:24:53 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\Buhl Data Service GmbH
[2012.10.28 19:45:23 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\DVDVideoSoft
[2012.10.28 19:44:29 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.10.28 19:20:42 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\GHISLER
[2012.11.03 21:23:31 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\IrfanView
[2012.10.27 22:16:14 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\LibreOffice
[2012.10.28 18:52:20 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\Notepad++
[2012.10.28 19:00:20 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\Opera
[2012.10.28 19:29:27 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\Samsung
[2012.10.27 22:07:42 | 000,000,000 | ---D | M] -- F:\Users\***\AppData\Roaming\Thunderbird
========== Purity Check ==========
< End of report > ScanErgenis Emsisoft: Code:
Emsisoft Anti-Malware - Version 7.0
Letztes Update: 10.11.2012 20:46:20
Scan Einstellungen:
Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\, E:\, F:\, Z:\
Riskware-Erkennung: Aus
Archiv Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus
Scan Beginn: 10.11.2012 22:32:47
C:\Users\Ghost\Desktop\2011file.exe.dat gefunden: Trojan.Generic.KDV.182338 (B)
Gescannt 874317
Gefunden 1
Scan Ende: 11.11.2012 10:00:15
Scan Zeit: 11:27:28
C:\Users\Ghost\Desktop\2011file.exe.dat Quarantäne Trojan.Generic.KDV.182338 (B)
Quarantäne 1
Nun bitte ich um Hilfe bei der weiteren Vorgehensweise. Den Rechner nutze ich auch fürs OnlineBanking. Das Internet läuft heute Vormittag schnell und problemlos wie gewohnt.
Grüsse
verrant
Edith: asvMBR.exe versucht. AVAST-VirenlistenDownload erlaubt. Sowohl Scan als auch QuickScan brechen mit einer Windows-Fehlermeldung ab (*... funktioniert nicht mehr.) . War ein Versuch, es gab keinen bestimmten Anlass. Info als Info dazu gestellt. /Edith aus. |