|
Log-Analyse und Auswertung: Virus Bundesministerium für Internetsicherheit - Zahlung von...Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
29.07.2013, 18:45 | #1 |
| Virus Bundesministerium für Internetsicherheit - Zahlung von... Einen wunderschönen Guten Abend in die Runde. Mich hat es erwischt!! Gestern Abend erschien plötzlich beim Stream schauen mit meiner Holden ein Brief, welcher mich auffordert den Betrag von 100 Euro per Paypal zu zahlen, weil ich angeblich nicht Jugendfreies Material im Web geschaut habe. Dann auch noch vom Bundesministerium!! Aber, als ich dann las, dass Artikel... war klar; FAKE/VIRUS - Artikel gibt es nur im Grundgesetz oder in EU-Drucksachen!! Naja, es war dann auch schon recht spät und ich konnte mich heute früh erstmal der Sache widmen. Per Google habe ich einen Fred hier im Forum gefunden, gestartet von User Mintaka mit eine sehr tollen Unterstützung von t'john. Die ersten Schritte Malwarebytes Anti-Rootkt und den Systemscan mit OTL habe ich gemacht. Hier der Malwarebytes Log 1. Ergebnis Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.06.0.1004 www.malwarebytes.org Database version: v2013.07.29.04 Windows Vista Service Pack 2 x86 FAT32 (Safe Mode) Internet Explorer 9.0.8112.16421 weinboerg :: WEINBOERG-PC [administrator] 29.07.2013 18:25:13 mbar-log-2013-07-29 (18-25-13).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P Scan options disabled: PUP Objects scanned: 217415 Time elapsed: 11 minute(s), 22 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 16 HKCU\SOFTWARE\CLASSES\CLSID\{44101423-0900-2897-4698-446497410995} (Trojan.Agent.ED) -> Delete on reboot. HKCU\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\{44101423-0900-2897-4698-446497410995} (Trojan.Agent.ED) -> Delete on reboot. HKCU\SOFTWARE\CLASSES\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\EhStorShell.IconOverlayHandler (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\EhStorShell.IconOverlayHandler.1 (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\CLSID\{2854F705-3548-414C-A113-93E27C808C85} (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\TYPELIB\{B3A00612-1423-4072-A4F9-DE2ADCAA7F3C} (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\EhStorShell.ContextMenuHandler.1 (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\EhStorShell.ContextMenuHandler (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\CLSID\{36F54939-CD3B-4C73-92D5-F9A389ED631C} (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\EhStorShell.AutoplayHandler.1 (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\EhStorShell.AutoplayHandler (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\CLSID\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7} (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\EhStorShell.EhStorFolder.1 (Trojan.Agent.ED) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\EhStorShell.EnhancedStorageFolder (Trojan.Agent.ED) -> Delete on reboot. Registry Values Detected: 2 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|qcgce2mrvjq91kk1e7pnbb19m52fx (Trojan.Agent.ED) -> Data: C:\Users\WEINBO~1\AppData\Local\Temp\kyknynxsjtyyodbky.exe -> Delete on reboot. HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELL EXTENSIONS\APPROVED|{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7} (Trojan.Agent.ED) -> Data: Enhanced Storage Data Source -> Delete on reboot. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 8 c:\Users\weinboerg\AppData\Local\Temp\kyknynxsjtyyodbky.exe (Trojan.Agent.ED) -> Delete on reboot. c:\Users\weinboerg\AppData\Local\Temp\kyknynxsjtyyodbky.dll (Trojan.Agent.ED) -> Delete on reboot. c:\Windows\System32\ehstorshell.dll (Trojan.Agent.ED) -> Delete on reboot. c:\Users\weinboerg\AppData\Roaming\Adobe\shed\thr1.chm (Malware.Trace) -> Delete on reboot. c:\Users\weinboerg\AppData\Roaming\Adobe\plugs\mmc219.exe (Trojan.Agent.Gen) -> Delete on reboot. c:\ProgramData\2433f433 (Trojan.Agent.TPL) -> Delete on reboot. c:\Users\weinboerg\AppData\Roaming\2433f433 (Trojan.Agent.TPL) -> Delete on reboot. c:\Users\weinboerg\AppData\Local\2433f433 (Trojan.Agent.TPL) -> Delete on reboot. Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.06.0.1004 www.malwarebytes.org Database version: v2013.07.29.05 Windows Vista Service Pack 2 x86 FAT32 Internet Explorer 9.0.8112.16421 weinboerg :: WEINBOERG-PC [administrator] 29.07.2013 18:53:02 mbar-log-2013-07-29 (18-53-02).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P Scan options disabled: PUP Objects scanned: 221006 Time elapsed: 22 minute(s), 14 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Jetzt kommen die 2 OTL Logs OTL Code:
ATTFilter OTL logfile created on: 29.07.2013 19:18:29 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = J:\ Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,99 Gb Total Physical Memory | 0,92 Gb Available Physical Memory | 46,04% Memory free 4,21 Gb Paging File | 2,94 Gb Available in Paging File | 69,77% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 40,31 Gb Total Space | 2,78 Gb Free Space | 6,89% Space Free | Partition Type: NTFS Drive D: | 9,93 Gb Total Space | 7,52 Gb Free Space | 75,79% Space Free | Partition Type: NTFS Drive E: | 30,22 Gb Total Space | 8,68 Gb Free Space | 28,71% Space Free | Partition Type: NTFS Drive F: | 29,33 Gb Total Space | 8,22 Gb Free Space | 28,02% Space Free | Partition Type: NTFS Drive G: | 47,00 Gb Total Space | 11,45 Gb Free Space | 24,36% Space Free | Partition Type: NTFS Drive I: | 13,85 Gb Total Space | 5,08 Gb Free Space | 36,65% Space Free | Partition Type: NTFS Drive J: | 7,89 Gb Total Space | 5,31 Gb Free Space | 67,35% Space Free | Partition Type: FAT32 Computer Name: WEINBOERG-PC | User Name: weinboerg | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - J:\OTL.exe (OldTimer Tools) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Programme\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) PRC - C:\Programme\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) PRC - C:\Programme\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) PRC - C:\Programme\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.) PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) PRC - C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.) PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics) PRC - C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.) PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) PRC - C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) PRC - C:\Programme\Intel\Intel Media Share Software\Viivmonitor.exe (Intel(R) Corporation) PRC - C:\Programme\Intel\Intel Media Share Software\IMSSync.exe (Intel® Corporation) PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems) PRC - C:\Programme\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) ========== Modules (No Company Name) ========== MOD - C:\Programme\DivX\DivX Update\DivXUpdateCheck.dll () MOD - C:\Programme\DivX\DivX Update\DivXUpdate.exe () MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll () MOD - C:\Programme\Samsung\EBM\ChkSec.dll () MOD - C:\Programme\Samsung\Easy Display Manager\WinMove.dll () MOD - C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll () MOD - C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll () MOD - C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll () ========== Services (SafeList) ========== SRV - (MBAMService) -- I:\Malwarebytes' Anti-Malware\mbamservice.exe File not found SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies) SRV - (ServiceLayer) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia) SRV - (fsssvc) -- C:\Programme\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation) SRV - (wlidsvc) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) SRV - (IMSSync) -- C:\Programme\Intel\Intel Media Share Software\IMSSync.exe (Intel® Corporation) SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation) SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation) SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems) SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (MDM) -- C:\Programme\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (RimUsb) -- System32\Drivers\RimUsb.sys File not found DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found DRV - (mbamswissarmy) -- File not found DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found DRV - (9ef44980) -- C:\Windows\TEMP\88BB.tmp File not found DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia) DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia) DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia) DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia) DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia) DRV - (epmntdrv) -- C:\Windows\System32\epmntdrv.sys () DRV - (EuGdiDrv) -- C:\Windows\System32\EuGdiDrv.sys () DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation) DRV - (VMC302) -- C:\Windows\System32\drivers\vmc302.sys (Vimicro Corporation) DRV - (NETw4v32) -- C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation) DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC) DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC) DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC) DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems) DRV - (KMDFMEMIO) -- C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.) DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (NETw2v32) -- C:\Windows\System32\drivers\NETw2v32.sys (Intel® Corporation) DRV - (RTL8023xp) -- C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation ) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/ IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GZAZ_de IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@innoplus.de/ino3DViewer: D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: D:\VLC\npvlc.dll (VideoLAN) FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.08.13 17:34:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.02.24 22:14:55 | 000,000,000 | ---D | M] [2013.04.03 15:31:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\weinboerg\AppData\Roaming\mozilla\Firefox\Profiles\extensions [2012.08.05 21:09:47 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\weinboerg\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com [2012.07.11 23:44:50 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR - homepage: CHR - plugin: Shockwave Flash (Enabled) = C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: Move Media Player 7 (Enabled) = C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll CHR - plugin: VLC Web Plugin (Enabled) = D:\VLC\npvlc.dll CHR - plugin: iTunes Application Detector (Enabled) = D:\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: InoViewer Plugin (Enabled) = D:\npIno3DViewer.dll CHR - Extension: Codec-C = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhcekcffkpnaednoeoegnmnjdlnjjmg\1.0_0\ CHR - Extension: YouTube = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: Google-Suche = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: MonsterDivx = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkinfljboeildloankgjmljfibngeefa\0.95_0\ CHR - Extension: Cuevana Stream = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfdckejfnkaemompfjhecfmhjgnchmjg\5.2.1_0\ CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\ CHR - Extension: Google Mail = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ CHR - Extension: OneClickDownload = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco\1.3_0\ O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Codec-C Class) - {0D56E386-F8C6-4FBC-9A7E-E8DA50072D26} - C:\ProgramData\Codec-C\bhoclass.dll File not found O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Programme\FlashFXP\IEFlash.dll (IniCom Networks, Inc.) O3 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O3 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\Toolbar\WebBrowser: (no name) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No CLSID value found. O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe () O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] "I:\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray File not found O4 - HKLM..\Run: [Play AVStation TV Scheduler] C:\Programme\Samsung\Play AVStation\TvScheduler.exe (SAMSUNG ELECTRONICS CO., LTD.) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [ViivMonitor] C:\Programme\Intel\Intel Media Share Software\Viivmonitor.exe (Intel(R) Corporation) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [] File not found O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [ApplePhotoStreams] C:\Programme\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [iCloudServices] C:\Programme\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe File not found O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.1; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"hxxp://t4u.strongfire.net/goserv/www/delivery/afr.php?refresh=90&zoneid=1&source=TarifeAusland&target=_blank&loc=http%3A%2F%2Fwww.tarif4you.de%2Ftarife%2F0052.html" File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoHotStart = 0 O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D65BECAB-C710-43D5-BE15-D7A5039D8805}: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe () O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2009.03.10 17:27:40 | 001,007,616 | ---- | M] (RapidSolution Software AG) - D:\autotag.dll -- [ NTFS ] O33 - MountPoints2\{2ded0685-cd93-11e1-9921-0013775d3a92}\Shell - "" = AutoRun O33 - MountPoints2\{2ded0685-cd93-11e1-9921-0013775d3a92}\Shell\AutoRun\command - "" = J:\SafeStick.exe O33 - MountPoints2\{49895bc0-4788-11e1-87d3-0013775d3a92}\Shell - "" = AutoRun O33 - MountPoints2\{49895bc0-4788-11e1-87d3-0013775d3a92}\Shell\AutoRun\command - "" = I:\SafeStick.exe O33 - MountPoints2\{bc62e7b1-07f3-11e0-bb70-0013775d3a92}\Shell - "" = AutoRun O33 - MountPoints2\{bc62e7b1-07f3-11e0-bb70-0013775d3a92}\Shell\AutoRun\command - "" = I:\AutoRun.exe O33 - MountPoints2\{bc62e7c8-07f3-11e0-bb70-0013775d3a92}\Shell - "" = AutoRun O33 - MountPoints2\{bc62e7c8-07f3-11e0-bb70-0013775d3a92}\Shell\AutoRun\command - "" = I:\AutoRun.exe O33 - MountPoints2\{c1dff1c6-b9b2-11e2-9fd5-0013775d3a92}\Shell - "" = AutoRun O33 - MountPoints2\{c1dff1c6-b9b2-11e2-9fd5-0013775d3a92}\Shell\AutoRun\command - "" = K:\SafeStick.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2013.07.29 18:51:43 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{1FCADF76-D3CA-4C7D-B341-CBBF64E55327} [2013.07.29 18:25:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable) [2013.07.29 18:23:31 | 000,192,512 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxres.dll [2013.07.29 18:13:26 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2013.07.29 18:05:58 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{C83FFB65-2A2A-4F3B-9CF5-89951CDE188E} [2013.07.28 14:51:03 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{F5DF0651-2E2E-40B1-9A99-6D38B8A37D64} [2013.07.27 13:34:26 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{18E7F753-468C-440B-8B1C-C5B02EA03181} [2013.07.26 14:54:06 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{412A4A17-6CFB-4E58-B6E1-EB8FBF2F2DC1} [2013.07.25 22:13:33 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{D809B1C7-DBCE-42DE-ADD1-6431C7B89E31} [2013.07.24 13:34:27 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{0B191973-39A1-4052-BD89-FFC90D24DA0E} [2013.07.23 14:38:59 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{4CD2DF11-B5C4-4C2E-AB44-10DA2761172F} [2013.07.22 16:16:55 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{835AE2B4-683B-42EB-AF79-5D37B000D33A} [2013.07.21 23:16:12 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{6D49ACA4-0030-4298-8FFA-A6AD5BF4E8F8} [2013.07.21 11:15:54 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{5257980B-7969-47E1-8BAC-457EA18319C5} [2013.07.20 19:33:46 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{F7DC282A-9B28-415C-B4CC-E930186D3117} [2013.07.19 21:00:36 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{7D565F96-C83A-4E4B-9FF6-25917A3F7E4A} [2013.07.18 21:09:06 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{BA79A5EA-3C9B-4071-93AF-016F05C5A1A8} [2013.07.17 20:37:08 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{69CCEE85-19B0-4987-B444-189E8D7B50F8} [2013.07.16 21:01:38 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{19CAE532-FFBD-44DD-AC9D-1EA3BCF31BDC} [2013.07.15 21:24:27 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{2DB47F16-3118-44EB-8DD5-B79DD24CEFD5} [2013.07.14 22:21:27 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{5EDD6E88-E11E-4F8A-8BE8-7755CBF2FB18} [2013.07.13 23:06:39 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{8367EDC9-341A-4CBA-B602-097576277A3B} [2013.07.12 23:35:54 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{F4E63A7F-5A03-4D0C-8873-5513F3F6D5E3} [2013.07.11 23:41:43 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{6B9ECCFE-B5D4-4FA8-9A76-91A91547CD31} [2013.07.11 02:59:06 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2013.07.11 02:59:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2013.07.11 02:59:04 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2013.07.11 02:59:04 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2013.07.11 02:59:04 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2013.07.11 02:59:03 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2013.07.11 02:59:02 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2013.07.11 02:59:01 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2013.07.11 01:03:22 | 002,049,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2013.07.11 01:02:44 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2013.07.11 01:02:44 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll [2013.07.11 01:02:44 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll [2013.07.11 01:02:44 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll [2013.07.11 01:02:44 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll [2013.07.11 01:02:43 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll [2013.07.11 01:02:43 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll [2013.07.11 01:02:43 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll [2013.07.11 01:02:42 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll [2013.07.11 01:02:39 | 001,548,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL [2013.07.10 23:20:15 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{02202EA8-754C-41E5-9F34-42AD4B345C3F} [2013.07.10 11:19:58 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{0321EEA5-E980-4223-8ADA-9BBEF88D81C3} [2013.07.09 21:26:36 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{3FF890DB-2265-4164-BA74-9CB81296D7FF} [2013.07.08 22:13:07 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{D3E71BE4-0B6D-4490-ACDD-21A241966764} [2013.07.07 22:21:08 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{115E61A3-F743-4404-BE16-379335CFF0E5} [2013.07.06 22:12:28 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{DC0008B7-026E-49AB-BDA1-A4A8F367AA19} [2013.07.05 23:17:10 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{FA2EDF0D-CD84-4BBF-9E95-5E6A518B1829} [2013.07.03 19:52:01 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{C15EC694-05B2-4EDA-93BA-83BD7E9A1C1D} [2013.07.02 21:57:49 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{711428AC-F683-4E0A-812C-4128E97D83C7} [2013.07.01 21:33:15 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{EE87E53D-7737-4071-98AC-F6CA07ABFEC6} [2013.06.30 21:13:08 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{1ABB056C-8AAC-4772-A190-1EDF453E6B25} [2013.06.30 00:15:25 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{E1BB8F90-6097-4260-A68B-378B9450CA9B} [1 C:\Users\weinboerg\AppData\Roaming\*.tmp files -> C:\Users\weinboerg\AppData\Roaming\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.07.29 18:56:29 | 000,628,992 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.07.29 18:56:29 | 000,596,246 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.07.29 18:56:29 | 000,126,510 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.07.29 18:56:29 | 000,104,320 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.07.29 18:53:03 | 000,001,136 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job [2013.07.29 18:49:23 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.07.29 18:49:20 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2013.07.29 18:49:16 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2013.07.29 18:48:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.07.29 18:48:28 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys [2013.07.29 18:16:30 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2013.07.28 22:48:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.07.28 22:34:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.07.26 23:53:02 | 000,001,084 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job [2013.07.19 21:25:13 | 000,050,176 | ---- | M] () -- C:\Users\weinboerg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013.07.13 23:58:36 | 000,002,062 | ---- | M] () -- C:\Users\weinboerg\Desktop\Google Chrome.lnk [2013.07.11 23:44:14 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2013.07.11 23:44:13 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2013.07.11 23:34:47 | 000,380,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [1 C:\Users\weinboerg\AppData\Roaming\*.tmp files -> C:\Users\weinboerg\AppData\Roaming\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.07.29 18:48:28 | 2137,448,448 | -HS- | C] () -- C:\hiberfil.sys [2013.05.08 18:02:15 | 000,240,224 | ---- | C] () -- C:\Users\weinboerg\AppData\Roaming\AcroIEHelpe005270.dll [2013.04.19 16:21:41 | 000,216,160 | ---- | C] () -- C:\Users\weinboerg\AppData\Roaming\AcroIEHelpe005264.dll [2013.04.18 19:05:02 | 000,000,000 | ---- | C] () -- C:\ProgramData\xbr6x2Snc.dat [2013.04.18 19:04:47 | 000,000,001 | ---- | C] () -- C:\ProgramData\I0R26DN0.exe_.b [2013.04.18 19:04:47 | 000,000,001 | ---- | C] () -- C:\ProgramData\I0R26DN0.exe.b [2013.04.03 15:35:29 | 000,000,869 | ---- | C] () -- C:\Users\weinboerg\AppData\Roaming\rost.dat [2012.10.11 18:30:18 | 000,004,980 | ---- | C] () -- C:\Users\weinboerg\AppData\Local\soulseek-client.dat [2012.07.13 00:50:12 | 002,469,760 | ---- | C] () -- C:\Windows\System32\BootMan.exe [2012.07.13 00:50:12 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll [2012.07.13 00:50:11 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe [2012.07.13 00:50:11 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys [2012.07.13 00:50:11 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys [2012.07.12 23:10:29 | 000,000,393 | ---- | C] () -- C:\Users\weinboerg\AppData\Local\HamsterVideoConverterSettings.cfg [2011.10.05 21:11:26 | 000,001,200 | ---- | C] () -- C:\Users\weinboerg\AppData\Roaming\b333_logs [2010.08.12 22:50:00 | 000,118,784 | ---- | C] () -- C:\Users\weinboerg\JavaLoader.exe [2008.10.30 10:49:34 | 000,000,022 | ---- | C] () -- C:\ProgramData\8f01a90e-7eb3-48d3-93b1-50d88fd146fb [2008.01.26 13:15:07 | 000,050,176 | ---- | C] () -- C:\Users\weinboerg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2010.08.25 21:04:52 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Ashampoo [2011.04.17 18:55:24 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Caches [2011.10.29 10:39:23 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Canneverbe Limited [2013.04.03 15:31:09 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\ckoock [2011.12.29 21:12:22 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Deyqa [2012.10.11 17:44:14 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\elsterformular [2011.10.19 11:48:41 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Etsewe [2011.07.04 13:20:28 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Gokyma [2012.10.12 20:22:53 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\HandBrake [2011.12.29 11:53:59 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Ibawyq [2012.12.31 16:22:38 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\JAM Software [2011.07.16 13:44:19 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Mealmo [2012.08.09 22:06:32 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Nokia [2012.08.09 22:03:11 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Nokia Suite [2009.02.02 20:33:45 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\PC Suite [2009.03.23 21:53:16 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\RapidSolution [2012.01.25 21:54:16 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\SafeStick [2013.04.17 12:08:02 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\UsAgt [2012.08.28 20:30:28 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\WindSolutions [2013.05.13 11:18:05 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\xmldm [2013.04.13 13:29:13 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Ycve ========== Purity Check ========== < End of report > Code:
ATTFilter OTL Extras logfile created on: 29.07.2013 19:18:29 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = J:\ Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1,99 Gb Total Physical Memory | 0,92 Gb Available Physical Memory | 46,04% Memory free 4,21 Gb Paging File | 2,94 Gb Available in Paging File | 69,77% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 40,31 Gb Total Space | 2,78 Gb Free Space | 6,89% Space Free | Partition Type: NTFS Drive D: | 9,93 Gb Total Space | 7,52 Gb Free Space | 75,79% Space Free | Partition Type: NTFS Drive E: | 30,22 Gb Total Space | 8,68 Gb Free Space | 28,71% Space Free | Partition Type: NTFS Drive F: | 29,33 Gb Total Space | 8,22 Gb Free Space | 28,02% Space Free | Partition Type: NTFS Drive G: | 47,00 Gb Total Space | 11,45 Gb Free Space | 24,36% Space Free | Partition Type: NTFS Drive I: | 13,85 Gb Total Space | 5,08 Gb Free Space | 36,65% Space Free | Partition Type: NTFS Drive J: | 7,89 Gb Total Space | 5,31 Gb Free Space | 67,35% Space Free | Partition Type: FAT32 Computer Name: WEINBOERG-PC | User Name: weinboerg | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "D:\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "D:\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [Browse with &IrfanView] -- "G:\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00B9D4DC-587A-4929-9D27-58C25C2345B1}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | "{01E69000-F82A-449A-9F75-A739D3A9630A}" = lport=1034 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4003 | "{03518A9B-B383-4D9E-AB5E-60AE43BC8A31}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4006 | "{068AFEC0-46C9-40A2-85FE-642F3C5490C5}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4006 | "{2A4B6C2B-B8AB-4546-96B1-6D754DB64407}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | "{38A06FF6-79E7-4707-8EE0-4D6F856F4A99}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4006 | "{3AF1E3F5-8D7D-4981-80F0-21FBA29E433D}" = lport=1034 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4003 | "{3D6C867C-14CF-440B-B697-D8867483D0FC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{401B0B30-9924-47D1-A960-E6978184DB0E}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{4C84AB64-45E1-4BDF-B092-6827F6AB09F4}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{4DAB36A5-1062-41AC-A088-967EBB46981D}" = lport=5721 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4002 | "{4F211999-1D76-4F7F-9171-DE89160F3E9B}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | "{5C028561-4B9A-46AD-BF7B-B74C65DF3E19}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | "{5CFC2558-5E55-40AF-8705-FECD1A048A48}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | "{5D48FAB5-548F-4DF3-9A74-37D1EA65CE17}" = lport=1034 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4003 | "{6CE298D3-702F-4BFF-BFF4-DA07ACEC390C}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{7253C7E6-18C3-4F9A-A0D5-F5C91395D088}" = lport=2869 | protocol=6 | dir=in | app=system | "{769DD005-7991-44D2-8E7C-AF4DF40062B0}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{7A9B027E-7203-411D-A4E9-A0A50C167E96}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{7CC69E46-1EE5-44B5-9B68-8E1D126DDCEF}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{85C5C735-B87E-4182-B90B-59790A868714}" = lport=5721 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4002 | "{91C82D4C-2271-4BEA-B0A5-0A46524B3769}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | "{9384CECE-8693-41F5-B571-FCA0A7BD515F}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{9663D8C7-862A-425B-A541-50674297F7F9}" = lport=5721 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4002 | "{B6304DD4-FB01-44F1-9D9B-2EC6E6245D68}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{D5DD7262-4BCA-427F-BA61-E6CE26B1F5A0}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{F239C074-ADA5-45EC-8F27-61867EA867E8}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{06B7200B-017D-457B-8C25-C5D5D6AADA85}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{22938D25-E6ED-466D-AF6C-4590E573FC1A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{2E0A82CC-072D-4522-8CDF-652DBB497A67}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{3CF411DA-0402-4ED2-8F87-3E27A676754F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{59F3D07D-6D49-480E-9C6B-241FFE5C8895}" = protocol=17 | dir=in | app=c:\program files\intel\intel media share software\imss.exe | "{7D8BB780-74F5-4ECF-B36F-973B7CB3FC28}" = protocol=17 | dir=in | app=c:\program files\intel\intel media share software\imssync.exe | "{89119B85-06AD-4883-9742-57A8A989C6B5}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | "{8F084066-36B1-4E85-82B8-1C908E8A31A2}" = dir=in | app=d:\itunes\itunes.exe | "{9EF46C1A-052E-443B-8CC8-32E12A6472B8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{C06B5F35-1368-4DD5-A674-8CBE8F70D5A8}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "{C3567176-EB9C-4027-B58C-E9378C83BDB8}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{D0851CAE-E892-47F7-A8BF-F522B8BFB213}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{EAFCA84A-FB73-46EC-AD97-25EB4899E699}" = protocol=6 | dir=in | app=c:\program files\intel\intel media share software\imss.exe | "{F5B9013E-6F61-4C58-91FE-A04BD043AA71}" = protocol=6 | dir=in | app=c:\program files\intel\intel media share software\imssync.exe | "{F5D65820-A1DC-4033-9863-EBD437D4FCAF}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "{FC5B85F4-FF0F-4AE9-A5C2-EAFEEE7D7594}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "TCP Query User{133D293E-DCC4-4626-9DE6-00269A05145E}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{1A4C52D0-4EA0-4232-A8CC-6D6EBB66A1D8}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe | "TCP Query User{647E1D11-3C98-4AC3-9170-47D0892EC66F}C:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "TCP Query User{8D01E047-4B96-4ADD-A299-F2B66A97E0D1}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\german\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\german\setup.exe | "TCP Query User{9DD063F7-927E-48DF-AA72-2129DBA18160}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | "TCP Query User{AFD244CB-BB8F-4321-B278-15C1CCAB8890}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe | "TCP Query User{B04C6214-EEFE-4E61-B658-033272FFF0B0}C:\program files\intel\intel media share software\imss.exe" = protocol=6 | dir=in | app=c:\program files\intel\intel media share software\imss.exe | "TCP Query User{BF94D882-76D1-4FD6-9C3F-1CD309212C5D}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | "TCP Query User{CADBBF8B-451C-4F0D-B6AC-2FF3797EF558}G:\soulseekqt\soulseekqt.exe" = protocol=6 | dir=in | app=g:\soulseekqt\soulseekqt.exe | "UDP Query User{117851BB-1B1D-4A07-828C-60B5A02B9FD1}C:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | "UDP Query User{41C641AD-48C8-4F67-9410-49347CABA600}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{5D096D03-1C0B-4C49-8BBC-A037B7E60E04}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\german\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\german\setup.exe | "UDP Query User{68773E4B-D809-4640-948B-4BFB93D6371D}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | "UDP Query User{7B738C4C-0FBC-4E46-98D8-DD2738B3495D}G:\soulseekqt\soulseekqt.exe" = protocol=17 | dir=in | app=g:\soulseekqt\soulseekqt.exe | "UDP Query User{7DEC8A4D-47FB-49DA-A200-D75B2388A0EE}C:\program files\intel\intel media share software\imss.exe" = protocol=17 | dir=in | app=c:\program files\intel\intel media share software\imss.exe | "UDP Query User{8603F251-9787-4A2F-863D-C2C00FE37AB0}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe | "UDP Query User{CEA31998-3DC7-45C8-9BB3-EB5931029AC6}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe | "UDP Query User{F24DBA50-4F5F-4BBA-831E-BA751A7B50BB}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution II "{1686816B-367A-4EA6-9C20-F694A5511C13}" = AS Lernen "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1B6C0E95-182C-48E0-9C4B-4F916308249C}" = iTunes "{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F2A5DF9-40E1-4644-ADBD-D80F347BA6C8}" = Windows Mobile-Gerätecenter "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86 "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 22 "{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety "{2EF17083-57D4-4D64-AE4F-55F32A2C4571}" = Codec-C "{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2 "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite "{459699C3-9430-4381-964B-4248D87B49F9}" = Apple Mobile Device Support "{478CAA24-5DA4-48F5-A237-734EC3B41DF5}" = Windows Live Family Safety "{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3 "{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0 "{54E1342C-1FDF-4F2A-98AB-4E82A5616FC8}" = PixiePack Codec Pack "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6CC53910-973E-4DD4-AC3D-E2A3E5439346}" = Intel® Media-Share-Software "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager "{710BF966-43C8-4216-A8EC-BC4E169FF7C1}" = MobileMe Control Panel "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7964AE02-9127-42C0-A917-2CE4CD4EFE3B}" = Nokia Suite "{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{804F1285-8CBF-408D-8CDC-D4D40003B2E4}" = PlayCamera "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr "{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp "{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger "{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{95140000-007A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook Connector "{95140000-007A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook Connector "{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation "{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver "{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}" = WIDCOMM Bluetooth Software "{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common "{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A945BD16-4774-4A1F-96A7-118BEC004881}" = mCorev32.ism_new "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AC76BA86-7AD7-1031-7B44-A70800000002}" = Adobe Reader 7.0.8 - Deutsch "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86 "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter "{B066064E-8BB9-4BB6-88A1-62522FD34EB3}" = Radiotracker "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 "{B96DB037-DBEA-4186-9081-9CBD537F82E8}" = 3D-Viewer-innoPlus "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant "{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari "{CB8CA439-DA83-419C-A4CF-5A0A50025144}" = Windows Mobile-Gerätecenter: Treiberupdate "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! 1.0 "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D6B3114F-945B-4980-BF7A-AF12E9161A0F}" = iCloud "{DA5B2BDC-F654-4A88-A669-4D34BC7846A1}" = PC Connectivity Solution "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86 "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources "{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live "{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F32ED8B1-2442-4B0E-8DEC-3F3BFC1C2B7F}" = mCPlug "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{F5A4F780-DF0C-444F-BA82-637CCF5C8052}" = Windows Live Family Safety "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FD53302C-8E7B-4730-8AD8-86A889BDBFAB}" = AVStation Now "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "1ClickDownload" = 1ClickDownloader "504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) "7-Zip" = 7-Zip 9.20 "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 11 "Agere Systems Soft Modem" = Agere Systems HDA Modem "Avira AntiVir Desktop" = Avira Free Antivirus "CCleaner" = CCleaner "CleanUp!" = CleanUp! "DivX Setup" = DivX-Setup "EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 9.1.1 Home Edition "ElsterFormular" = ElsterFormular "HandBrake" = HandBrake 0.9.8 "HDMI" = Intel(R) Graphics Media Accelerator Driver "iLivid" = iLivid "InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0 "InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation "InstallShield_{FD53302C-8E7B-4730-8AD8-86A889BDBFAB}" = AVStation Now "IrfanView" = IrfanView (remove only) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.0.1200 "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Nokia PC Suite" = Nokia PC Suite "Nokia Suite" = Nokia Suite "ProInst" = Intel(R) PROSet/Wireless Software "SoulseekQt" = SoulseekQt "SynTPDeinstKey" = Synaptics Pointing Device Driver "VLC media player" = VLC media player 2.0.0 "Windows Mobile Device Handbook" = Windows Mobile®-Gerätehandbuch "WinLiveSuite" = Windows Live Essentials ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "Move Media Player" = Move Media Player ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 29.07.2013 12:50:37 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:37 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:38 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:38 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:39 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:39 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:39 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:39 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:40 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = Error - 29.07.2013 12:50:40 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013 Description = [ System Events ] Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001 Description = Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001 Description = Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001 Description = Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7026 Description = Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001 Description = Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001 Description = Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001 Description = Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001 Description = Error - 29.07.2013 12:49:20 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7000 Description = Error - 29.07.2013 12:51:41 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7000 Description = < End of report > Ist nun alles fertig oder muss ich noch etwas machen?? Vorab möchte ich mich schon mal für die Hilfe bedanken!! Gruß weinboerg Geändert von weinboerg (29.07.2013 um 18:54 Uhr) |
29.07.2013, 18:54 | #2 |
/// the machine /// TB-Ausbilder | Virus Bundesministerium für Internetsicherheit - Zahlung von... hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
29.07.2013, 19:09 | #3 |
| Virus Bundesministerium für Internetsicherheit - Zahlung von... Schon umgewandelt!! Sorry
__________________ |
29.07.2013, 20:11 | #4 |
/// the machine /// TB-Ausbilder | Virus Bundesministerium für Internetsicherheit - Zahlung von... hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.07.2013, 20:28 | #5 |
| Virus Bundesministerium für Internetsicherheit - Zahlung von... FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 01 Ran by weinboerg (administrator) on 29-07-2013 21:25:08 Running from C:\Users\weinboerg\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Agere Systems) C:\Windows\system32\agrsmsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Intel® Corporation) C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Intel(R) Corporation) C:\Program Files\Intel\Intel Media Share Software\Viivmonitor.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) D:\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4399104 2007-03-15] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [839680 2007-02-07] (Synaptics, Inc.) HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [56928 2006-11-23] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [54832 2006-12-05] () HKLM\...\Run: [Play AVStation TV Scheduler] - C:\Program Files\Samsung\Play AVStation\TvScheduler.exe [73728 2007-01-09] (SAMSUNG ELECTRONICS CO., LTD.) HKLM\...\Run: [ViivMonitor] - C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe [69632 2007-03-10] (Intel(R) Corporation) HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1822720 2007-03-14] (Realtek Semiconductor Corp.) HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.) HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdc.exe [563080 2007-01-24] (Microsoft Corporation) HKLM\...\Run: [Malwarebytes' Anti-Malware] - "I:\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [x] HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - D:\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [MsnMsgr] - C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [4280184 2012-03-08] (Microsoft Corporation) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-10-22] (Google Inc.) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [MobileDocuments] - C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [x] HKCU\...\Run: [] - [x] HKCU\...\Run: [Google Update] - C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-12-01] (Google Inc.) HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59280 2012-11-28] (Apple Inc.) HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59280 2012-11-28] (Apple Inc.) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.) HKCU\...\Runonce: [Shockwave Updater] - C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.1; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"hxxp://t4u.strongfire.net/goserv/www/delivery/afr.php?refresh=90&zoneid=1&source=TarifeAusland&target=_blank&loc=http%3A%2F%2Fwww.tarif4you.de%2Ftarife%2F0052.html" [x] HKCU\...\Command Processor: "C:\Users\WEINBO~1\AppData\Local\Temp\kyknynxsjtyyodbky.exe" <======= ATTENTION MountPoints2: {2ded0685-cd93-11e1-9921-0013775d3a92} - J:\SafeStick.exe MountPoints2: {49895bc0-4788-11e1-87d3-0013775d3a92} - I:\SafeStick.exe MountPoints2: {bc62e7b1-07f3-11e0-bb70-0013775d3a92} - I:\AutoRun.exe MountPoints2: {bc62e7c8-07f3-11e0-bb70-0013775d3a92} - I:\AutoRun.exe MountPoints2: {c1dff1c6-b9b2-11e2-9fd5-0013775d3a92} - K:\SafeStick.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: Codec-C Class - {0D56E386-F8C6-4FBC-9A7E-E8DA50072D26} - C:\ProgramData\Codec-C\bhoclass.dll No File BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (IniCom Networks, Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -No Name - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: msdaipp - No CLSID Value - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - D:\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @innoplus.de/ino3DViewer - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.0 - D:\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Extension: OneClickDownloader - C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\profiles\extensions\OneClickDownload@OneClickDownload.com FF Extension: No Name - C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= CHR RestoreOnStartup: "hxxp://search.iminent.com/SearchTheWeb/v4/1031/homepage/Default.aspx" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Skype Toolbars) - C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Move Media Player 7) - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (VLC Web Plugin) - D:\VLC\npvlc.dll (VideoLAN) CHR Plugin: (iTunes Application Detector) - D:\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (InoViewer Plugin) - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) CHR Extension: (Codec-C) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhcekcffkpnaednoeoegnmnjdlnjjmg\1.0_0 CHR Extension: (YouTube) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (MonsterDivx) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkinfljboeildloankgjmljfibngeefa\0.95_0 CHR Extension: (Cuevana Stream) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfdckejfnkaemompfjhecfmhjgnchmjg\5.2.1_0 CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0 CHR Extension: (Gmail) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR Extension: (OneClickDownload) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco\1.3_0 CHR HKLM\...\Chrome\Extension: [ajhcekcffkpnaednoeoegnmnjdlnjjmg] - C:\ProgramData\Codec-C\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR HKLM\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files\1ClickDownload\oneclickdownloader10.crx CHR StartMenuInternet: Google Chrome - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG) R2 IMSSync; C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe [368640 2007-03-10] (Intel® Corporation) R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [167936 2005-08-08] () S2 MBAMService; "I:\Malwarebytes' Anti-Malware\mbamservice.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-03-21] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-03-21] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-21] (Avira Operations GmbH & Co. KG) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2011-07-29] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2011-07-29] () R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22712 2011-05-29] (Malwarebytes Corporation) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-15] (Avira GmbH) R3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [243840 2009-01-23] (Vimicro Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 RimUsb; System32\Drivers\RimUsb.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe 2013-07-29 21:20 - 2013-07-29 21:20 - 01221282 _____ (Farbar) C:\Users\weinboerg\Desktop\FRST.exe 2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip 2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt 2013-07-29 18:51 - 2013-07-29 18:51 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{1FCADF76-D3CA-4C7D-B341-CBBF64E55327} 2013-07-29 18:25 - 2013-07-29 19:15 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-07-29 18:23 - 2008-01-02 17:37 - 00192512 _____ (Intel Corporation) C:\Windows\system32\igfxres.dll 2013-07-29 18:05 - 2013-07-29 18:05 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{C83FFB65-2A2A-4F3B-9CF5-89951CDE188E} 2013-07-28 14:51 - 2013-07-28 14:51 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F5DF0651-2E2E-40B1-9A99-6D38B8A37D64} 2013-07-27 13:48 - 2013-07-27 15:08 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls 2013-07-27 13:34 - 2013-07-27 13:34 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{18E7F753-468C-440B-8B1C-C5B02EA03181} 2013-07-26 14:54 - 2013-07-26 14:54 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{412A4A17-6CFB-4E58-B6E1-EB8FBF2F2DC1} 2013-07-25 22:13 - 2013-07-25 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{D809B1C7-DBCE-42DE-ADD1-6431C7B89E31} 2013-07-24 13:34 - 2013-07-24 13:34 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{0B191973-39A1-4052-BD89-FFC90D24DA0E} 2013-07-23 14:38 - 2013-07-23 14:39 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{4CD2DF11-B5C4-4C2E-AB44-10DA2761172F} 2013-07-22 16:16 - 2013-07-22 16:16 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{835AE2B4-683B-42EB-AF79-5D37B000D33A} 2013-07-21 23:16 - 2013-07-21 23:16 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{6D49ACA4-0030-4298-8FFA-A6AD5BF4E8F8} 2013-07-21 11:15 - 2013-07-21 11:15 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{5257980B-7969-47E1-8BAC-457EA18319C5} 2013-07-20 19:33 - 2013-07-20 19:33 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F7DC282A-9B28-415C-B4CC-E930186D3117} 2013-07-19 21:00 - 2013-07-19 21:00 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{7D565F96-C83A-4E4B-9FF6-25917A3F7E4A} 2013-07-18 21:09 - 2013-07-18 21:09 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{BA79A5EA-3C9B-4071-93AF-016F05C5A1A8} 2013-07-17 20:37 - 2013-07-17 20:37 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{69CCEE85-19B0-4987-B444-189E8D7B50F8} 2013-07-16 21:01 - 2013-07-16 21:01 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{19CAE532-FFBD-44DD-AC9D-1EA3BCF31BDC} 2013-07-15 21:24 - 2013-07-15 21:24 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{2DB47F16-3118-44EB-8DD5-B79DD24CEFD5} 2013-07-14 22:21 - 2013-07-14 22:21 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{5EDD6E88-E11E-4F8A-8BE8-7755CBF2FB18} 2013-07-13 23:06 - 2013-07-13 23:06 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{8367EDC9-341A-4CBA-B602-097576277A3B} 2013-07-12 23:35 - 2013-07-12 23:35 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F4E63A7F-5A03-4D0C-8873-5513F3F6D5E3} 2013-07-11 23:41 - 2013-07-11 23:41 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{6B9ECCFE-B5D4-4FA8-9A76-91A91547CD31} 2013-07-11 02:59 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-11 02:59 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-11 02:59 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-11 02:59 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-11 02:59 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-11 02:59 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-11 02:59 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-11 02:59 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-11 02:59 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-11 02:59 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-11 02:59 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-11 02:59 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-11 02:59 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-11 02:59 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-11 02:59 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-11 02:58 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-11 01:03 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-11 01:02 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-11 01:02 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-11 01:02 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-11 01:02 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-11 01:02 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-11 01:02 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-11 01:02 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-11 01:02 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-10 23:20 - 2013-07-10 23:20 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{02202EA8-754C-41E5-9F34-42AD4B345C3F} 2013-07-10 11:19 - 2013-07-10 11:19 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{0321EEA5-E980-4223-8ADA-9BBEF88D81C3} 2013-07-09 21:26 - 2013-07-09 21:26 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{3FF890DB-2265-4164-BA74-9CB81296D7FF} 2013-07-08 22:13 - 2013-07-08 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{D3E71BE4-0B6D-4490-ACDD-21A241966764} 2013-07-07 22:21 - 2013-07-07 22:21 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{115E61A3-F743-4404-BE16-379335CFF0E5} 2013-07-06 22:12 - 2013-07-06 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{DC0008B7-026E-49AB-BDA1-A4A8F367AA19} 2013-07-05 23:17 - 2013-07-05 23:17 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{FA2EDF0D-CD84-4BBF-9E95-5E6A518B1829} 2013-07-03 19:52 - 2013-07-03 19:52 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{C15EC694-05B2-4EDA-93BA-83BD7E9A1C1D} 2013-07-02 21:57 - 2013-07-02 21:57 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{711428AC-F683-4E0A-812C-4128E97D83C7} 2013-07-01 21:33 - 2013-07-01 21:33 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{EE87E53D-7737-4071-98AC-F6CA07ABFEC6} 2013-06-30 21:13 - 2013-06-30 21:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{1ABB056C-8AAC-4772-A190-1EDF453E6B25} 2013-06-30 00:15 - 2013-06-30 00:15 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{E1BB8F90-6097-4260-A68B-378B9450CA9B} ==================== One Month Modified Files and Folders ======= 2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe 2013-07-29 21:20 - 2013-07-29 21:20 - 01221282 _____ (Farbar) C:\Users\weinboerg\Desktop\FRST.exe 2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST 2013-07-29 20:53 - 2012-12-01 01:23 - 00001136 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job 2013-07-29 20:48 - 2012-04-03 09:36 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-29 20:48 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-29 20:48 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-29 20:34 - 2010-02-06 12:45 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-29 20:34 - 2007-10-31 02:55 - 01114645 _____ C:\Windows\WindowsUpdate.log 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip 2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt 2013-07-29 19:15 - 2013-07-29 18:25 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-07-29 18:56 - 2006-11-02 12:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-29 18:51 - 2013-07-29 18:51 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{1FCADF76-D3CA-4C7D-B341-CBBF64E55327} 2013-07-29 18:51 - 2009-03-21 23:16 - 00000000 ____D C:\Users\weinboerg\Tracing 2013-07-29 18:49 - 2010-02-06 12:45 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-29 18:49 - 2008-01-26 13:15 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2013-07-29 18:48 - 2013-05-17 23:21 - 00003816 _____ C:\Windows\PFRO.log 2013-07-29 18:48 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-29 18:16 - 2007-09-27 06:30 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-07-29 18:16 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-29 18:05 - 2013-07-29 18:05 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{C83FFB65-2A2A-4F3B-9CF5-89951CDE188E} 2013-07-28 14:51 - 2013-07-28 14:51 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F5DF0651-2E2E-40B1-9A99-6D38B8A37D64} 2013-07-27 15:08 - 2013-07-27 13:48 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls 2013-07-27 14:39 - 2011-12-04 16:57 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Skype 2013-07-27 13:34 - 2013-07-27 13:34 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{18E7F753-468C-440B-8B1C-C5B02EA03181} 2013-07-26 23:53 - 2012-12-01 01:23 - 00001084 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job 2013-07-26 14:54 - 2013-07-26 14:54 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{412A4A17-6CFB-4E58-B6E1-EB8FBF2F2DC1} 2013-07-25 22:13 - 2013-07-25 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{D809B1C7-DBCE-42DE-ADD1-6431C7B89E31} 2013-07-24 13:34 - 2013-07-24 13:34 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{0B191973-39A1-4052-BD89-FFC90D24DA0E} 2013-07-23 14:39 - 2013-07-23 14:38 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{4CD2DF11-B5C4-4C2E-AB44-10DA2761172F} 2013-07-22 16:16 - 2013-07-22 16:16 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{835AE2B4-683B-42EB-AF79-5D37B000D33A} 2013-07-21 23:16 - 2013-07-21 23:16 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{6D49ACA4-0030-4298-8FFA-A6AD5BF4E8F8} 2013-07-21 11:15 - 2013-07-21 11:15 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{5257980B-7969-47E1-8BAC-457EA18319C5} 2013-07-20 19:33 - 2013-07-20 19:33 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F7DC282A-9B28-415C-B4CC-E930186D3117} 2013-07-19 23:06 - 2012-03-03 21:43 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\vlc 2013-07-19 21:25 - 2008-01-26 13:15 - 00050176 _____ C:\Users\WEINBO~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-07-19 21:00 - 2013-07-19 21:00 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{7D565F96-C83A-4E4B-9FF6-25917A3F7E4A} 2013-07-18 21:09 - 2013-07-18 21:09 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{BA79A5EA-3C9B-4071-93AF-016F05C5A1A8} 2013-07-17 20:37 - 2013-07-17 20:37 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{69CCEE85-19B0-4987-B444-189E8D7B50F8} 2013-07-16 21:01 - 2013-07-16 21:01 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{19CAE532-FFBD-44DD-AC9D-1EA3BCF31BDC} 2013-07-15 21:24 - 2013-07-15 21:24 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{2DB47F16-3118-44EB-8DD5-B79DD24CEFD5} 2013-07-14 22:21 - 2013-07-14 22:21 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{5EDD6E88-E11E-4F8A-8BE8-7755CBF2FB18} 2013-07-13 23:58 - 2012-02-28 22:24 - 00002062 _____ C:\Users\weinboerg\Desktop\Google Chrome.lnk 2013-07-13 23:06 - 2013-07-13 23:06 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{8367EDC9-341A-4CBA-B602-097576277A3B} 2013-07-12 23:35 - 2013-07-12 23:35 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F4E63A7F-5A03-4D0C-8873-5513F3F6D5E3} 2013-07-12 00:06 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-11 23:44 - 2012-04-03 09:36 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-11 23:44 - 2011-05-17 06:58 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-11 23:44 - 2008-03-04 22:39 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\Adobe 2013-07-11 23:41 - 2013-07-11 23:41 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{6B9ECCFE-B5D4-4FA8-9A76-91A91547CD31} 2013-07-11 23:34 - 2006-11-02 14:47 - 00380216 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-11 23:32 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-11 23:31 - 2010-06-03 19:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-11 03:16 - 2006-11-02 12:23 - 00000240 _____ C:\Windows\win.ini 2013-07-11 03:03 - 2006-11-02 12:24 - 75699896 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-07-11 02:49 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 23:20 - 2013-07-10 23:20 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{02202EA8-754C-41E5-9F34-42AD4B345C3F} 2013-07-10 11:19 - 2013-07-10 11:19 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{0321EEA5-E980-4223-8ADA-9BBEF88D81C3} 2013-07-09 21:26 - 2013-07-09 21:26 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{3FF890DB-2265-4164-BA74-9CB81296D7FF} 2013-07-08 22:13 - 2013-07-08 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{D3E71BE4-0B6D-4490-ACDD-21A241966764} 2013-07-07 22:21 - 2013-07-07 22:21 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{115E61A3-F743-4404-BE16-379335CFF0E5} 2013-07-06 22:13 - 2013-07-06 22:12 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{DC0008B7-026E-49AB-BDA1-A4A8F367AA19} 2013-07-05 23:17 - 2013-07-05 23:17 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{FA2EDF0D-CD84-4BBF-9E95-5E6A518B1829} 2013-07-03 19:52 - 2013-07-03 19:52 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{C15EC694-05B2-4EDA-93BA-83BD7E9A1C1D} 2013-07-02 21:57 - 2013-07-02 21:57 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{711428AC-F683-4E0A-812C-4128E97D83C7} 2013-07-01 21:33 - 2013-07-01 21:33 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{EE87E53D-7737-4071-98AC-F6CA07ABFEC6} 2013-06-30 21:13 - 2013-06-30 21:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{1ABB056C-8AAC-4772-A190-1EDF453E6B25} 2013-06-30 00:15 - 2013-06-30 00:15 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{E1BB8F90-6097-4260-A68B-378B9450CA9B} Files to move or delete: ==================== C:\ProgramData\xbr6x2Snc.dat C:\Users\weinboerg\JavaLoader.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-29 19:10 ==================== End Of Log ============================ Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 30-07-2013 01 Ran by weinboerg at 2013-07-29 21:25:51 Running from C:\Users\weinboerg\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 1ClickDownloader (Version: 2.7 Build 26473) 3D-Viewer-innoPlus (Version: 10.00.0119) 7-Zip 9.20 Activation Assistant for the 2007 Microsoft Office suites Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0) Adobe Flash Player 11 ActiveX (Version: 11.8.800.94) Adobe Reader 7.0.8 - Deutsch (Version: 7.0.8) Adobe Shockwave Player 11 (Version: 11) Agere Systems HDA Modem Apple Application Support (Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Apple Software Update (Version: 2.1.3.127) AS Lernen (Version: 2.5.00) Avira Free Antivirus (Version: 13.0.0.3884) AVStation Now (Version: 4.0.10.6) Bonjour (Version: 3.0.0.10) CCleaner (Version: 3.11) CDBurnerXP (Version: 4.4.1.3341) CleanUp! Codec-C (Version: ) Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000) D3DX10 (Version: 15.4.2368.0902) DivX-Setup (Version: 2.6.1.9) DVD Suite EASEUS Partition Master 9.1.1 Home Edition Easy Battery Manager (Version: 3.2.1.1) Easy Display Manager (Version: 2.0.0.0) Easy Network Manager 3.0 (Version: 3.0.0.0) Easy SpeedUp Manager (Version: 2.0.0.10) ElsterFormular (Version: 13.3.0.9066) FlashFXP v3 (Version: 3.4.0.1145) Galería fotográfica de Windows Live (Version: 15.4.3502.0922) Google Chrome (HKCU Version: 28.0.1500.72) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.5.4209.2358) Google Update Helper (Version: 1.3.21.153) HandBrake 0.9.8 (Version: 0.9.8) iCloud (Version: 2.1.0.39) iLivid (Version: 1.92.0.118480) imagine digital freedom - Samsung (Version: 1.0.2.0) Intel(R) Graphics Media Accelerator Driver Intel(R) PROSet/Wireless Software (Version: 11.5.0000) Intel® Media-Share-Software (Version: 1.01.207) IrfanView (remove only) iTunes (Version: 11.0.0.163) Java Auto Updater (Version: 2.0.2.4) Java(TM) 6 Update 22 (Version: 6.0.220) Junk Mail filter update (Version: 15.4.3502.0922) Malwarebytes' Anti-Malware Version 1.51.0.1200 (Version: 1.51.0.1200) mCorev32.ism_new (Version: 11.03.0000) mCPlug (Version: 11.03.0000) mDriver (Version: 11.03.0000) mHelp (Version: 11.03.0000) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Outlook Connector (Version: 14.0.5118.5000) Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SOAP Toolkit 2.0 SP2 (Version: 623.1) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft_VC100_CRT_SP1_x86 (Version: 10.0.40219.1) mMHouse (Version: 11.03.0000) MobileMe Control Panel (Version: 3.1.8.0) Move Media Player mPfMgr (Version: 11.03.0000) MSVC80_x86 (Version: 1.0.1.0) MSVC80_x86_v2 (Version: 1.0.3.0) MSVC90_x86 (Version: 1.0.1.2) MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MSXML 4.0 SP2 Parser and SDK (Version: 4.20.9818.0) Nokia Connectivity Cable Driver (Version: 7.1.78.0) Nokia PC Suite (Version: 7.1.30.9) Nokia Suite (Version: 3.4.49.0) OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0) PC Connectivity Solution (Version: 12.0.17.0) PhotoNow! 1.0 PixiePack Codec Pack (Version: 1.1.300.0) Play AVStation (Version: 4.1.20.43) PlayCamera (Version: 1.00.32) PowerDVD (Version: 7.0.2414.0) QuickTime (Version: 7.73.80.64) Radiotracker (Version: 5.0.23040.4000) Realtek High Definition Audio Driver (Version: 6.0.1.5386) Safari (Version: 5.34.57.2) Samsung Magic Doctor (Version: 5.00) Samsung Recovery Solution II (Version: 2.0) Segoe UI (Version: 15.4.2271.0615) Skype™ 6.3 (Version: 6.3.107) SoulseekQt Synaptics Pointing Device Driver (Version: 9.1.15.0) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0) Vimicro UVC Camera (Version: 1.00.0000) VLC media player 2.0.0 (Version: 2.0.0) WIDCOMM Bluetooth Software (Version: 6.0.1.3700) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3555.0308) Windows Live Family Safety (Version: 15.4.3555.0308) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Mail (Version: 15.4.3502.0922) Windows Live Messenger (Version: 15.4.3538.0513) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live Sync (Version: 14.0.8117.416) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) Windows Mobile®-Gerätehandbuch (Version: 1.0) Windows Mobile-Gerätecenter (Version: 6.0.6783.0) Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.0.6783.0) Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) (Version: 08/22/2008 7.0.0.0) ==================== Restore Points ========================= 29-07-2013 18:36:13 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0F4B75A2-3821-4725-AE1D-CE4848403BD7} - System32\Tasks\SamsungMagicDoctor => C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe [2007-03-15] (Samsung Electronics Co., Ltd.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {27E767E7-77D6-4213-A51D-96B9F591F157} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2007-03-14] (Samsung Electronics Co., Ltd.) Task: {2D7B6E4D-1E15-420B-8D11-54A669397DB3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-11] (Adobe Systems Incorporated) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {444C9EE8-E38B-424A-88F4-8DDAF6556913} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core => C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-01] (Google Inc.) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {650738A3-CFE3-4929-A892-0E916CC16DCE} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation) Task: {6DCA8D12-FB32-40BA-B00C-984A11F1E648} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {73FF2179-C101-4D0A-82B8-44021D0DD0E2} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-19] (Microsoft Corp.) Task: {7F511AE9-D63C-4582-B890-CD2596E1EE3B} - System32\Tasks\RunAsStdUser Task => C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe No File Task: {7F9ADCAB-3CEE-4180-A518-831D7EF0ADCD} - System32\Tasks\WPD\SqmUpload_S-1-5-21-2152196072-760242556-3123413665-1003 => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation) Task: {8ECA359F-1132-4D9F-B406-29DEC0101550} - System32\Tasks\Microsoft\Office Genuine Advantage\OGALogon => C:\Windows\system32\OGAExec.exe [2009-08-03] () Task: {9BD56E96-1C03-491C-B4A9-DFD23F8EE347} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2007-04-09] (SAMSUNG Electronics) Task: {A299D5B4-C95A-4ECB-A75D-4476F9A4B5BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-06] (Google Inc.) Task: {A38CD883-2039-443D-B28D-74B3AE0E629E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA => C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-01] (Google Inc.) Task: {A3DCED7F-2BD8-4848-BDB1-31A3CF72373C} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [2007-04-12] (SAMSUNG Electronics co., LTD.) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation) Task: {B5A84497-751B-4B65-8039-426E86277063} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {C1A941FE-3863-4EE2-B20F-B914533FAAF2} - System32\Tasks\12ba7400 => C:\Users\WEINBO~1\AppData\Local\Temp\\setup2703038464.exe No File Task: {C5C78233-DD72-44C6-8175-3631ED3E1942} - System32\Tasks\e101f000 => C:\Users\WEINBO~1\AppData\Local\Temp\\setup2430360576.exe No File Task: {C963C549-F280-495D-A1D7-513B71F5D639} - System32\Tasks\Microsoft\Windows\RestartManager\{6E26A865-0E96-46fe-902C-73A33533B409} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {D15B4AE5-EAB9-406C-95F7-E55A9B382975} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-06] (Google Inc.) Task: {D2AE00E5-ACC0-4FB4-A1CD-FB08A7587789} - System32\Tasks\a5aa4e00 => C:\Users\WEINBO~1\AppData\Local\Temp\\setup167809024.exe No File Task: {D652B309-8764-43A1-8817-AB298D544BF5} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation) Task: {E0916ACC-2592-4781-9FC6-40CE4F0328AC} - System32\Tasks\17d73600 => C:\Users\WEINBO~1\AppData\Local\Temp\\setup316023808.exe No File Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: {ED04124B-5B7A-48D5-AD81-96C7568F9FCB} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {F502C4E7-EEBA-45C9-8087-E7F606A68CB8} - System32\Tasks\Microsoft\Windows\RestartManager\{018BCD93-37A0-4f76-8095-9F65CDBBD51F} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job => C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job => C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/29/2013 06:50:40 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\README.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:40 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\README.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD-HILFE.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD-HILFE.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD DEINSTALLIEREN.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD DEINSTALLIEREN.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:38 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\ONLINE-REGISTRIERUNG.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:38 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\ONLINE-REGISTRIERUNG.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:37 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\CYBERLINK POWERDVD.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 06:50:37 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\CYBERLINK POWERDVD.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) System errors: ============= Error: (07/29/2013 06:51:41 PM) (Source: Service Control Manager) (User: ) Description: MBAMService%%3 Error: (07/29/2013 06:49:20 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: ) Description: AFD avipbb avkmgr DfsC NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr ssmdrv tdx Wanarpv6 Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: ) Description: NLA (Network Location Awareness)Netzwerkspeicher-Schnittstellendienst%%1068 Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: ) Description: IP-HilfsdienstNetzwerkspeicher-Schnittstellendienst%%1068 Microsoft Office Sessions: ========================= Error: (07/29/2013 06:50:40 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\README.LNK Error: (07/29/2013 06:50:40 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\README.LNK Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD-HILFE.LNK Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD-HILFE.LNK Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD DEINSTALLIEREN.LNK Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD DEINSTALLIEREN.LNK Error: (07/29/2013 06:50:38 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\ONLINE-REGISTRIERUNG.LNK Error: (07/29/2013 06:50:38 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\ONLINE-REGISTRIERUNG.LNK Error: (07/29/2013 06:50:37 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\CYBERLINK POWERDVD.LNK Error: (07/29/2013 06:50:37 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\CYBERLINK POWERDVD.LNK CodeIntegrity Errors: =================================== Date: 2013-07-29 19:02:44.531 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-29 19:02:44.110 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-29 19:02:43.751 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-29 19:02:43.408 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-29 18:58:37.370 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-29 18:58:37.010 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-29 18:58:36.630 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-29 18:58:36.228 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-07-14 11:24:19.341 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-07-14 11:24:19.072 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 71% Total physical RAM: 2037.69 MB Available physical RAM: 570.75 MB Total Pagefile: 4312.64 MB Available Pagefile: 2396.68 MB Total Virtual: 2047.88 MB Available Virtual: 1909.36 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:40.31 GB) (Free:2.7 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Programme) (Fixed) (Total:9.93 GB) (Free:7.52 GB) NTFS Drive e: (Musik) (Fixed) (Total:30.22 GB) (Free:8.68 GB) NTFS Drive f: (Bilder) (Fixed) (Total:29.33 GB) (Free:8.22 GB) NTFS Drive g: (sonstiges) (Fixed) (Total:47 GB) (Free:11.45 GB) NTFS Drive i: (Family Holidays) (Fixed) (Total:13.85 GB) (Free:5.08 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 186 GB) (Disk ID: D168249C) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=40 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=136 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
30.07.2013, 07:07 | #6 | |
/// the machine /// TB-Ausbilder | Virus Bundesministerium für Internetsicherheit - Zahlung von...Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ --> Virus Bundesministerium für Internetsicherheit - Zahlung von... |
30.07.2013, 18:08 | #7 |
| Virus Bundesministerium für Internetsicherheit - Zahlung von...Code:
ATTFilter ComboFix 13-07-30.03 - weinboerg 30.07.2013 18:26:13.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.2038.351 [GMT 2:00] ausgeführt von:: c:\users\weinboerg\Desktop\Combofix\ComboFix.exe SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\8f01a90e-7eb3-48d3-93b1-50d88fd146fb c:\programdata\Codec-C c:\programdata\Codec-C\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx c:\programdata\Codec-C\background.html c:\programdata\Codec-C\content.js c:\programdata\Codec-C\data\content.js c:\programdata\Codec-C\data\jsondb.js c:\programdata\Codec-C\settings.ini c:\programdata\Codec-C\uninstall.exe c:\programdata\I0R26DN0.exe.b c:\programdata\I0R26DN0.exe_.b c:\programdata\Roaming c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini c:\users\weinboerg\AppData\Local\.# c:\users\weinboerg\AppData\Local\.#\MBX@16E8@1C91D08.### c:\users\weinboerg\AppData\Local\.#\MBX@16E8@1C91D18.### c:\users\weinboerg\AppData\Local\.#\MBX@16EC@BB1D08.### c:\users\weinboerg\AppData\Local\.#\MBX@16EC@BB1D18.### c:\users\weinboerg\AppData\Roaming\AcroIEHelpe.txt c:\users\weinboerg\AppData\Roaming\AcroIEHelpe005264.dll c:\users\weinboerg\AppData\Roaming\AcroIEHelpe005270.dll c:\users\weinboerg\AppData\Roaming\Adobe\plugs c:\users\weinboerg\AppData\Roaming\Adobe\shed c:\users\weinboerg\AppData\Roaming\srvblck5.tmp c:\users\weinboerg\JavaLoader.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-06-28 bis 2013-07-30 )))))))))))))))))))))))))))))) . . 2013-07-30 16:35 . 2013-07-30 16:35 -------- d-----w- c:\users\weinboerg\AppData\Local\temp 2013-07-30 16:35 . 2013-07-30 16:35 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-07-30 16:12 . 2013-07-30 16:13 -------- d-----w- C:\setup 2013-07-30 15:47 . 2013-07-30 16:15 -------- d-----w- c:\program files\MyPC Backup 2013-07-30 15:46 . 2013-07-30 15:47 -------- d-----w- c:\users\weinboerg\AppData\Local\VisualBeeClient 2013-07-30 15:46 . 2013-07-30 15:47 -------- d-----w- c:\program files\Plus-HD-2.5 2013-07-30 15:46 . 2013-07-30 15:46 -------- d-----w- c:\users\weinboerg\AppData\Local\VisualBeeExe 2013-07-30 15:46 . 2013-07-30 15:46 -------- d-----w- c:\programdata\VisualBee 2013-07-30 15:46 . 2013-07-30 15:46 -------- d-----w- c:\users\weinboerg\AppData\Local\emaze 2013-07-30 15:45 . 2013-07-30 15:45 -------- d-----w- c:\users\weinboerg\AppData\Local\Wajam 2013-07-30 15:45 . 2013-07-30 15:46 -------- d-----w- c:\program files\Wajam 2013-07-30 15:44 . 2013-07-30 15:45 -------- d-----w- c:\users\weinboerg\AppData\Local\Smartbar 2013-07-29 19:20 . 2013-07-29 19:20 -------- d-----w- C:\FRST 2013-07-29 16:23 . 2008-01-02 15:37 192512 ----a-w- c:\windows\system32\igfxres.dll 2013-07-10 23:03 . 2013-06-04 01:50 2049024 ----a-w- c:\windows\system32\win32k.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-11 21:44 . 2012-04-03 07:36 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-07-11 21:44 . 2011-05-17 04:58 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-05-08 04:37 . 2013-06-12 19:48 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-02 22:03 . 2013-06-12 19:48 3603832 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-05-02 22:03 . 2013-06-12 19:48 3551096 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-05-02 08:25 . 2012-07-11 21:31 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-02 04:04 . 2013-06-12 19:48 443904 ----a-w- c:\windows\system32\win32spl.dll 2013-05-02 04:03 . 2013-06-12 19:48 37376 ----a-w- c:\windows\system32\printcom.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-22 39408] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] "iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-11-28 59280] "ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-11-28 59280] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-04-19 18678376] "Browser Infrastructure Helper"="c:\users\weinboerg\AppData\Local\Smartbar\Application\Smartbar.exe" [2013-07-09 20992] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RtHDVCpl.exe" [2007-03-14 4399104] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-07 839680] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928] "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832] "Play AVStation TV Scheduler"="c:\program files\Samsung\Play AVStation\TvScheduler.exe" [2007-01-09 73728] "ViivMonitor"="c:\program files\Intel\Intel Media Share Software\ViivMonitor.exe" [2007-03-10 69632] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656] "Skytel"="Skytel.exe" [2007-03-14 1822720] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdc.exe" [2007-01-24 563080] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="d:\itunes\iTunesHelper.exe" [2012-11-28 151952] . c:\users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ MyPC Backup.lnk - c:\program files\MyPC Backup\MyPC Backup.exe [2013-7-1 1945128] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "NoHotStart"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{54E1342C-1FDF-4F2A-98AB-4E82A5616FC8}] 2009-03-02 11:49 8192 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe . Inhalt des "geplante Tasks" Ordners . 2013-07-30 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 21:44] . 2013-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 10:45] . 2013-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 10:45] . 2013-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job - c:\users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-30 23:23] . 2013-07-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job - c:\users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-30 23:23] . 2013-07-30 c:\windows\Tasks\Plus-HD-2.5-chromeinstaller.job - c:\program files\Plus-HD-2.5\Plus-HD-2.5-chromeinstaller.exe [2013-07-30 15:46] . 2013-07-30 c:\windows\Tasks\Plus-HD-2.5-codedownloader.job - c:\program files\Plus-HD-2.5\Plus-HD-2.5-codedownloader.exe [2013-07-30 15:47] . 2013-07-30 c:\windows\Tasks\Plus-HD-2.5-enabler.job - c:\program files\Plus-HD-2.5\Plus-HD-2.5-enabler.exe [2013-07-30 15:47] . 2013-07-30 c:\windows\Tasks\Plus-HD-2.5-firefoxinstaller.job - c:\program files\Plus-HD-2.5\Plus-HD-2.5-firefoxinstaller.exe [2013-07-30 15:47] . 2013-07-30 c:\windows\Tasks\Plus-HD-2.5-updater.job - c:\program files\Plus-HD-2.5\Plus-HD-2.5-updater.exe [2013-07-30 15:47] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=hp&installDate=30/07/2013 uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{0D56E386-F8C6-4FBC-9A7E-E8DA50072D26} - c:\programdata\Codec-C\bhoclass.dll WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file) HKCU-Run-MobileDocuments - c:\program files\Common Files\Apple\Internet Services\ubd.exe HKLM-Run-Malwarebytes' Anti-Malware - i:\malwarebytes' anti-malware\mbamgui.exe SafeBoot-WudfPf SafeBoot-WudfRd AddRemove-Malwarebytes' Anti-Malware_is1 - i:\malwarebytes' anti-malware\unins000.exe AddRemove-{2EF17083-57D4-4D64-AE4F-55F32A2C4571} - c:\programdata\Codec-C\uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2013-07-30 18:35 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\9ef44980] "imagepath"="\??\c:\windows\TEMP\88BB.tmp" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Zeit der Fertigstellung: 2013-07-30 18:39:00 ComboFix-quarantined-files.txt 2013-07-30 16:38 . Vor Suchlauf: 2.367.422.464 Bytes frei Nach Suchlauf: 2.498.179.072 Bytes frei . - - End Of File - - 1A95794241B2D8D2222C0DD22882592A 61A349592C4728853F4A90FF78F7628E Kurze Info; Es gab keine Fehlermeldung!! |
31.07.2013, 08:14 | #8 |
/// the machine /// TB-Ausbilder | Virus Bundesministerium für Internetsicherheit - Zahlung von... Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.07.2013, 17:30 | #9 |
| Virus Bundesministerium für Internetsicherheit - Zahlung von... Hier der LOG von Malewarebytes Anti Malware Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.07.31.05 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 weinboerg :: WEINBOERG-PC [Administrator] Schutz: Deaktiviert 31.07.2013 18:14:51 mbam-log-2013-07-31 (18-14-51).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 225095 Laufzeit: 12 Minute(n), 2 Sekunde(n) Infizierte Speicherprozesse: 1 C:\Program Files\Wajam\Updater\WajamUpdater.exe (PUP.Optional.Wajam) -> 2412 -> Löschen bei Neustart. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 10 HKCR\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\wajam.WajamBHO.1 (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\wajam.WajamBHO (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SYSTEM\CurrentControlSet\Services\WajamUpdater (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Program Files\Wajam\IE\priam_bho.dll (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\weinboerg\Downloads\setup.exe (PUP.Optional.Ibryte) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files\Wajam\Updater\WajamUpdater.exe (PUP.Optional.Wajam) -> Löschen bei Neustart. (Ende) Code:
ATTFilter # AdwCleaner v2.306 - Datei am 31/07/2013 um 18:36:52 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzer : weinboerg - WEINBOERG-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\weinboerg\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\user.js Ordner Gelöscht : C:\Program Files\1ClickDownload Ordner Gelöscht : C:\Program Files\Ilivid Ordner Gelöscht : C:\Program Files\Wajam Ordner Gelöscht : C:\ProgramData\{B49A644A-1076-4A3D-B124-DAA7862F2318} Ordner Gelöscht : C:\ProgramData\Premium Ordner Gelöscht : C:\ProgramData\visualbee Ordner Gelöscht : C:\Users\WEINBO~1\AppData\Local\Temp\Smartbar Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Ilivid Player Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Smartbar Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\visualbeeexe Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Wajam Ordner Gelöscht : C:\Users\weinboerg\AppData\LocalLow\boost_interprocess Ordner Gelöscht : C:\Users\weinboerg\AppData\LocalLow\Smartbar Ordner Gelöscht : C:\Users\weinboerg\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\weinboerg\AppData\LocalLow\Toolbar4 Ordner Gelöscht : C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Ordner Gelöscht : C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\1ClickDownload Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider Schlüssel Gelöscht : HKCU\Software\ilivid Schlüssel Gelöscht : HKCU\Software\Iminent Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2EF17083-57D4-4D64-AE4F-55F32A2C4571} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKCU\Software\SmartBar Schlüssel Gelöscht : HKCU\Software\SmartbarBackup Schlüssel Gelöscht : HKCU\Software\SmartbarLog Schlüssel Gelöscht : HKCU\Software\Wajam Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\1ClicktorrentFile Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\1ClicktorrentFile1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033438.BHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033438.Sandbox Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033438.Sandbox.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.BHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ilivid Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\2B1E51D87B2D71A44BB42DDD5E894160 Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BBA74401-6D6F-4BBD-9F65-E8623814F3BB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2F39980-399F-492E-8D88-5FF7CCB3B47F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\oneclick Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\oneclickmg Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2CF0D01-7657-48AA-98C9-AE5E64757FCC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco Schlüssel Gelöscht : HKLM\Software\ilivid Schlüssel Gelöscht : HKLM\Software\Iminent Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\817FDB46B46DE8B4AAD499F1DAFF341D Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5A9327D31011C244A196F700637C701 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6B84CEB2810F104BA0E5FC5C8EACD7E Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2B1E51D87B2D71A44BB42DDD5E894160 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4BD8E034-E0F4-4509-A753-467A8E854CD8} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam Schlüssel Gelöscht : HKLM\SOFTWARE\Software Schlüssel Gelöscht : HKLM\Software\Wajam Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper] Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16496 Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 --> hxxp://www.google.com Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 --> hxxp://www.google.com Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 --> hxxp://www.google.com Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 --> hxxp://www.google.com -\\ Mozilla Firefox v [Version kann nicht ermittelt werden] Datei : C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v28.0.1500.72 Datei : C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.26] : keyword = "search.snap.do", Gelöscht [l.30] : search_url = "hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=[...] ************************* AdwCleaner[S1].txt - [15487 octets] - [31/07/2013 18:36:52] ########## EOF - C:\AdwCleaner[S1].txt - [15548 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.2.9 (07.30.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by weinboerg on 31.07.2013 at 18:56:58,64 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully stopped: [Service] backupstack Successfully deleted: [Service] backupstack ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\visualbee Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\visualbee Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322342238} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550355345538} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366346638} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355345538} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366346638} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\weinboerg\appdata\local\visualbeeclient" Successfully deleted: [Folder] "C:\Users\weinboerg\appdata\locallow\codec-c" Failed to delete: [Folder] "C:\Program Files\mypc backup" Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0042C984-ACED-49D6-A88B-9B259E20C97D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{00C35C93-764C-4403-9D3F-71F1CD71C1AE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{00FCD90A-D3C1-4D86-8534-CD76425E3138} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{01B2D8FC-F912-4547-978D-BC79AA9B5E15} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{02202EA8-754C-41E5-9F34-42AD4B345C3F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0321EEA5-E980-4223-8ADA-9BBEF88D81C3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0366F02B-157F-4B41-92F3-7A47DCBE6925} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{03C7C968-B55F-43FE-B008-132BEB2F7BF9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{03F5AF8E-42BA-4A73-A9FB-49F0F02FA094} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{043E277F-CFC1-4CFF-989D-5EA259441107} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{04E9D79F-AD0E-4EAF-BAB6-FC55C9C9055E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{065B5F3F-6F7B-4C97-8597-F4A956350932} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{067E0499-402A-49D2-A4FB-A985316359AB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{06B9372A-C02D-4ABE-A4D6-71BF0BCC4567} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{088EEBBE-BE43-4E69-960F-B105DF560209} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{08AE343F-BC20-43DB-BB69-29A9D5DBC404} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{093C441F-484D-47E9-B010-2B3D4E81D4F1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0B191973-39A1-4052-BD89-FFC90D24DA0E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0B76A24D-A18A-45CE-8318-00A8F5C61A83} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0B89CD60-6E32-4CCE-BBD9-C44D13A078C2} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0C2D9ADD-6F15-4FAB-A26E-E77A8CF87240} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0C986F78-4C8F-4A47-BA3B-E308FD06F1E7} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0C9F3176-2632-4B12-9049-3AD7355ED209} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0CE6AC60-6137-4121-BB8B-B9747D419D72} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0DA4775E-A600-432A-8374-74DFFE7A5B72} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0E152A4B-EBEF-4691-9877-936FD708C9D5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0E46166F-1B03-4EF1-94B6-AF2D3118F91C} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0EC5CEF1-A299-482E-9543-93E1C7A6A9D1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{10392798-0BC6-4848-AA35-4BDA38A9C364} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{10925373-7875-4E05-958A-C4933703A51A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{115E61A3-F743-4404-BE16-379335CFF0E5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{12E01FE3-4607-490E-8266-7B2A844777A8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{14AAA05F-91A9-4AD9-A2BC-056455F63507} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{155F5FAB-9F94-453E-92AC-9A7EBDE460D7} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{183DB6A0-E6CC-4A24-A7F6-280144BCFEBD} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{18E7F753-468C-440B-8B1C-C5B02EA03181} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{196766BE-6DD6-44AB-9266-DFAE77570C9B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1981921A-98EB-40DB-8E2A-1B0ABFF2CBF9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{19CAE532-FFBD-44DD-AC9D-1EA3BCF31BDC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1ABB056C-8AAC-4772-A190-1EDF453E6B25} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1BC83E5F-64A3-4B8C-8E94-B1C349BA46E3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1C4B509A-5AB8-443C-99CD-5DEA5DE6D5F6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1C9E6330-4310-46B2-A906-3BD215CD4473} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1CEBC406-FB90-4427-8A50-B7489D4E2A28} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1D3AF3CB-4453-415D-90C3-A8D4503D1AD9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1E667D0B-C98A-4FFE-A298-9EF595EBA4D8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1E7D5E19-AD5E-4103-B216-B8DAE5BD8D80} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1EB0D0A0-3429-4E83-B6D6-049F67E6D0D9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1F4C0682-2F05-4233-8951-19BA63DC5FFB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1F6EF83A-FA0D-481B-971A-F84FD304E691} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1F878F8F-599A-4787-A71A-5E3C07755F51} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1FAD9CCA-1233-401F-BF07-7953CD1EB59A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1FCADF76-D3CA-4C7D-B341-CBBF64E55327} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1FE0FBA5-3C95-44A9-AFCE-4554DB69F0E9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{211F7F50-F3FB-46EF-A2E3-E53B836B7A3B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{21410747-2B0E-4254-8094-E57BDF10CB9B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{21CBF85A-E1CB-41DE-A180-AACA7CFADE7C} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{22A597E7-90D7-434B-A0A6-FE766362BA04} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{24475C3C-4351-4CBB-83B0-15A0CB4B95D0} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{24F72209-E94A-457D-95EB-1DDA955713E5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{259B7BB6-C40E-44D4-85DE-AF53919E2EE6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2659AEBB-9100-4A8F-8BFE-66A8FCBAE2F3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{26D700F9-5403-4C77-9628-35E12826D4AB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{270507F9-C4ED-4714-AA43-C44615B2D60A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{27FB5604-BBB2-4653-813D-3551AA29D3C8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{291929F9-3E9A-4EDE-9C75-100BCF1ABC49} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2AA81C7D-47D7-43E9-B349-6ADF1FF98B30} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2AA8DA0A-8D4D-4F8B-AC24-BCEC32B51919} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2AE35B52-A33F-4F6E-ABA4-B4021AB4420C} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2C1CCA18-2B0C-4269-83BD-ABD53F0F32AF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2D49AE29-84C2-448A-88D4-8ED8CCB3BCB6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2DB47F16-3118-44EB-8DD5-B79DD24CEFD5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2EAE47C0-4C2A-4F56-9A12-9BE79C2E95B8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2ED01AA6-2676-4F40-8A20-D571C55CDB9E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2F2F016B-8E31-4E4C-A57D-98575077E1A4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2F85E16E-0E6F-4DEE-A778-725BE5A26C94} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2FF52965-952C-45E7-9F90-B649198E95D3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2FFF92BB-26C2-40E7-9A10-B8AE14DE8CFF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{308BF049-F9CB-463A-A2F1-1CF5B9213534} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{30F1C9D6-5034-408F-B8A7-0C1886059D5D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{31A39B38-0599-4EFD-95B8-5756803D750C} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{31CDC924-CBAE-453D-9263-B7BAF990185E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{32408C75-3E3D-48AE-B721-510985CE8A5E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3337B9D8-B9A8-4E46-A59B-EEA9AD00F198} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{33A969E3-1AE4-4A86-BD25-1B536D54A02D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{34147F8D-47A6-4C10-931B-A7AFE20BC3A5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{34A46D83-E9DE-4280-8050-5CD83BAB60C0} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{34A908D9-C22C-477E-9187-E8154E44637F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{352B23EA-3558-4C24-871F-9E0CC925D8E4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{35FBEBDD-63FB-4E87-A8BC-6107E41EECC2} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3602CBDE-1939-4FFC-AED2-A5B8E5AFEDAB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{36F4C078-4C45-4FF8-828C-6355B488F115} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{37330B98-E209-43D0-9894-D0810D09B7F4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{377D8874-0750-4032-9289-D86D93DA9531} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3823F32A-F258-4085-92C0-46692EB8BC11} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{382D85ED-EC24-45E8-B207-BDE3970B5694} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3851BCFC-DA38-4F4E-AD83-635E180881FD} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{38F41AAA-98D7-4E41-BE5C-674AF261F5E1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3B45D076-DCF4-491A-BCAB-96670E7DFC87} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3BC1848A-2CA8-482E-9284-58571A8569D4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3BD0AFFD-76BC-4480-8A6F-EE406D0234A2} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3BDB7FCD-3AF5-4CF6-A3E3-196C26A49DB1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3D8BC93F-ACA1-4E32-8590-8D8BCA8310A3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3E138183-91B7-4266-8E85-86F0DD5C3B94} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3E432AF5-BC8B-40CA-B710-6B8A5A0036F6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3F817716-6DAE-4EA1-9C15-80E604202ABC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3FEA1DCD-C2E4-46EF-AADE-57DB4DF83A98} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3FF890DB-2265-4164-BA74-9CB81296D7FF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{40246073-D22F-4871-9214-7A08DB73A49D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{40646555-ABCD-4170-8BDE-E3108337A911} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{412A4A17-6CFB-4E58-B6E1-EB8FBF2F2DC1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{41FC8921-F9DB-4D91-88A9-8657B3C2812D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{42CC2448-6A7C-4BAF-B390-798FCE364127} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4410C1F2-7D83-4D31-AB60-09542C155055} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{444A8E82-03DE-48D5-A00E-3C2E4F7CC2A1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{449248B2-2390-4EF4-A365-61782A466102} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{44C8CAEF-C829-4E5C-B373-61DDFC2612EB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{44D17189-5DCB-4235-BB24-F271B9E4E0E6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{45892BC5-FEDC-4DE4-BF96-1C769118668F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{460747F9-4160-4C4C-9DA1-FE04A4479D33} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4690CB19-D305-4A4F-B3EB-17DE84675CD2} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{46E22705-94EE-4DA6-8E6C-2502809A0C40} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{47830DD4-A64F-4D81-824D-725ADCAB0684} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4786C238-C80E-4546-A134-430279A2C3CC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{488C2B92-D478-4F7E-AF5E-FCCAC4A56E99} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{48A381CD-6C1D-4512-BC31-C3ACB60CCC64} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4938CB98-D0C8-4295-90AB-E1913CF79B10} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{49B3E043-E82E-426D-B356-F225175EEDBC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4AA05E04-54FA-436E-8594-201BF35397CA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4BADDF41-6B41-4D9D-BCD0-4CDF4757E4F0} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4BB4DFEA-59DF-4F7B-B0EB-6E675C2DFE16} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4C1928F7-D01D-4E6C-A52E-45C59BE2D333} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4C42A391-92A8-418F-887B-98E656841FAB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4CB4D907-FBFB-40E9-AE14-EC1D3328F184} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4CC53112-99DF-4188-B640-9757D1B3D858} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4CD2DF11-B5C4-4C2E-AB44-10DA2761172F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4DE4BA56-5E86-4526-8757-6A9C823DE30F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4E29102C-4CF5-4B74-A4EA-18CC00AD475B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4E61C03F-20CE-4F72-8830-C2C39B5A9DEF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4F5C4216-66B9-4E56-A5B4-A5AA0401A609} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{50C498AB-0CD0-4925-927D-0C0C3E95326A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{50D9DDE6-E4C7-4D2D-85C8-7083B583E49B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{51AA408C-8C79-4007-B2BC-064BA0057AA5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{51FC2214-678B-4903-97C8-61B21416A283} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5257980B-7969-47E1-8BAC-457EA18319C5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{52C7E434-C45A-4EF5-A7AC-DEE393F84CCD} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{52FF1D2F-6B18-4377-B860-777263C1CA65} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5329446C-245B-4598-AEDC-54BDAC4CA6D3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{532FA649-7C77-4CBB-AB92-7A85F8C4337D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{543D0B29-7103-4F87-8D9E-F3E6D51FA5A4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{54DE1D2B-86CB-4AAF-BFAC-1F325C61AF9A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{54F12861-1482-4417-B40F-7AE9693AF9EA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{54F4E9EA-376E-4CAD-9962-7FCC6F5C9F8A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5616ADCB-2347-4F63-A155-28615ABDBCF9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{575AB408-53AC-4B4E-B6AE-A56A3031A1ED} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{581114C9-542A-46F1-8A2C-C2C27E26F034} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{58D49B5B-4B23-437B-996B-0235FAB9D429} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{58FCCDAA-6FB8-4FA3-BD0B-49A1E3EAE3EC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5907959E-95C7-4DF0-AE87-96ED30FB1BEC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{59FED3A2-5D2B-4F7D-B821-8C5C8ABE0CDA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5A3AFFF0-C787-404A-9D54-BF87CEBA734C} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5A57DCC5-DD28-4120-8C12-A5A2027F75BB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5A9525D3-F10F-45A9-BA15-C22783C0AC21} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5B7E50E4-5FB0-4D30-9ECA-7F7C477156D5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5BEFDA32-B563-4A4A-B14A-1DE81DB79385} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5D5A63C7-C083-4447-AA25-40C67B3FC400} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5DA8582B-BDA3-41C7-8831-88FDB4EA3A5E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5DC8C9B2-4D1D-4282-A025-5C8543F6976A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5E2F0129-6636-469F-819E-FBAAE59860E9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5ED0A1BB-9B00-4406-9D5B-A683E7FC38E4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5EDD6E88-E11E-4F8A-8BE8-7755CBF2FB18} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5F9F127D-F1D5-4CEE-B1A2-ED4B93BD486F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6002A7C0-4F89-4397-964A-A73F4CF716E6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{61206AA2-6F00-4C83-8793-E6E1E8547741} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6138F2EF-232C-45AD-B511-EB48274A17C4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{626B1C67-D720-4D11-9F63-3C3E42007C73} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{628F5020-1498-41C1-B3E8-14D3D1775A92} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{64A78480-96DD-4D87-AF62-246CD3F98721} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{65AB96CD-6682-4D61-81D6-925A9C5925D5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6919C84B-1664-4873-ABE0-E766FFD8CD0C} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{69CCEE85-19B0-4987-B444-189E8D7B50F8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{69FE1DDE-3F44-4360-8F60-F997EEB0F745} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6A645924-439E-43D2-A92B-A0F03A6E0418} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6B2E1584-6F48-4574-A776-2B917222CF07} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6B750117-D9C2-4AF9-A08F-43674519EFEE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6B9ECCFE-B5D4-4FA8-9A76-91A91547CD31} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6D49ACA4-0030-4298-8FFA-A6AD5BF4E8F8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6DA678AE-303D-40B5-9835-EE3D0DE349B3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6DE955D3-49A2-42D8-9BB3-5995246B86FF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6E73AA62-32A6-4B38-9AB9-A62ED451776F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6EE90BC0-A936-432A-9790-254B76F4DB1A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6F2D1121-C88F-4B55-8FD7-35D1EA3FB737} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{708F73B5-AE2B-487E-9BFD-46162EE9040F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{711428AC-F683-4E0A-812C-4128E97D83C7} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7156E135-E34D-4EF6-9DE2-B7CA4C419813} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{72D98DEA-CD75-421B-B465-EFA128774356} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{73DAACA1-2442-44AF-971E-E7525CC52F0F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{756E9E38-E51B-4EB7-B82D-E97FAE5477B8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{75B489C9-719E-4DBD-BA10-5C1A3C607899} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{75B5308C-D004-4D5C-8CFA-BD8EC7654204} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{75E5E5A2-AF6A-4147-AB8B-AB62A02DE27F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{76550045-48ED-4403-892D-39DD2B9A75DE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7790BE18-FFBC-461E-8EBC-4C0C137DFF20} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{77AA2DAF-81BA-4B41-8F4A-F73D8E57A034} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7868658D-D5AA-4CD5-AE9D-2F27D5229A34} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{79D66341-699E-4D61-BC44-BE5C34B2D8AA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7A596325-08BE-43ED-8A04-84F4692334B7} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7A83B5F4-8B51-410F-8A5D-6E990856FBF1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7ADBBA3B-7B55-4ACB-9732-7B101BC09119} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7BC7128A-A613-4AA6-BDAE-EF5DC72B75A6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7C6F063B-C7A1-4845-B031-85210C5CF9C1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7CDB9372-2194-4690-9671-4EAEA5B6A071} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7D0625F1-EDEB-49A9-B120-E34C436986B7} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7D565F96-C83A-4E4B-9FF6-25917A3F7E4A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7E5B3592-23F7-49EE-85C9-E98F10414E31} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8078598C-2E24-4805-B6C0-338B18898B5E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{80A7C49C-9424-42D2-9905-625A7518F467} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{80CA5C65-7270-4F51-ADCF-71B4C139EE93} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8102D84B-9598-4DDB-9668-5C1244BCDCA1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{813960E8-A06E-4778-A490-9E683D53C8F2} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{81F556A8-03CA-4F53-8929-11BC5DCA3A1D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{82992F07-0C3E-421F-A13D-A82454B39696} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8301B233-E533-4814-B21B-F20CFB13FC59} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{835AE2B4-683B-42EB-AF79-5D37B000D33A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8367EDC9-341A-4CBA-B602-097576277A3B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{837BB3FD-FB68-4FD8-9526-60D35A48FE7A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{83991402-1469-465E-A13B-83F1047B2B71} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{841C8774-0DC3-4484-A279-13DFA0AA265D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{85333D89-B951-42AE-BCF9-C4F694D977DC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{85B1C22B-31C5-406F-8E83-4018B6B6E980} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{860CDE5F-528C-4BA3-8229-6F09A70F976B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{88C36A5C-C3C4-4DD8-9CE4-0209186BA969} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{89B96DF3-60AF-4CCD-956D-6BB45A868CF4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8A01B334-5A25-41D4-8357-7CE49F5CCC8F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8A761960-CEA1-4703-8D88-78F0F6D09307} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8AC5C3F5-3D77-4C5D-A00C-FD66C8282653} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8B323017-0EAA-44CB-AE33-5C413DAEDD13} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8BEF9EB7-C787-443C-8C8D-622E156A1F68} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8C25491F-D7D7-46D9-BBCC-0E4C6B34CBA2} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8C2F612C-90A0-478F-B4D2-108F240F94BB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8CF8C3FB-20E6-477A-B1CD-D7AA8395DA65} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8D9EAE20-1BBF-406E-A7BB-1A8B9A77D4DD} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8DA2FE81-393E-4DB7-BA48-986EAC587B48} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8E6EAA1A-AFA4-40FE-BAB0-770A150D1A1B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8EE6ABB1-CEE2-48CB-A9C5-1BE7D231E2CB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8EF38603-1BE0-4B73-A429-AC0B454D2AC9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{90073CCA-25DA-40F0-B498-4B88C6B32D0A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{902CEBC7-D27E-4B79-8233-9E0A3384DB50} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{905E0BBD-5064-4FDF-BC1A-5009CDF92316} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9097D048-6D27-4C81-83AE-619E866AD89F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{91653C37-D931-40D3-9920-8716135BD861} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{91CF9961-A49C-4346-9157-A1173CB1751A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{91D07CF3-5CD3-467B-86A2-184ED6084933} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{92B64C56-E5B9-46D7-9452-B8A681709367} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{95FF93FB-5B0A-4208-AD7A-13DF8F23B562} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{961B5C0B-A945-4E8E-B993-CD963894EA14} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{972DCE75-8743-48BC-8CD9-B0C6301754D6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{973EC03B-4FE7-4931-99E1-5E6DBE96A86F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{99E656E2-AA46-4CF2-8FD5-9724D99E98FA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9A487EC5-94D7-4D6B-B9FA-CC3CDEE51D60} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9C676D81-F234-49DD-8B1F-0F8260D7E94C} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9CDD9B6F-5164-4C94-A673-0517914FBC9E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9D70A1E5-06C6-4DB0-A23F-2EBE4C658BD7} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9DFB60E0-B34D-424D-94DC-9700CB065963} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9F3C1ABB-75CA-4C1B-868A-08EB68E2C8CD} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9FE44A48-E2D4-4325-A698-20D617A10297} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A0282F8D-D972-44B9-85FC-517769ABC29E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A0448946-B1DA-47E3-9DF6-9F11BDB23435} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A05B8D37-BEE6-4E80-86DD-200BE51F632F} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A1125DED-1738-4D12-95CC-DEBE061B31A7} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A206F98E-5D94-4860-9403-CACFAEDB12EB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A49A79A1-9475-4B29-97DD-7D33837D17B2} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A545CBB5-761C-4662-BEEE-C9DA50408479} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A59E4BE5-0F0D-4262-9E3C-24BD78BF8080} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A6279BA0-D2DC-415E-9DC6-B1D2CC0E5036} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A6C20B57-C40F-41AD-A1B4-B710470B89B2} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A6F77335-D450-4405-9B50-F8D1BE173D67} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A8F806DF-81D6-4592-AFE5-DB8138888DBE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A9ABFD58-0A6A-4C41-9AB5-F89C596BDCE5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AA87A7F6-4273-4FE7-8B2C-D425C34822FF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AAD4B493-8220-4BF8-B316-396435B5C424} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{ABF7E1CF-1667-4EF6-97A0-E4864418936D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AC1A6DDF-CF2F-4C56-BB99-06F285CE251E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AC53FAEB-60C5-45CC-A711-F3F7CA0278A9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AD602622-4713-4A92-9711-89A5F06B71C5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{ADB761F2-7E4E-43BA-B5B5-CC5592DA61DB} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AE621C9A-0415-4176-B5C7-6924F8476238} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AE73966A-2EAF-4864-AAB7-7C861F4BA9D1} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AE8F003B-7FAA-43F1-B242-EDEA6ACA32B3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AE981044-6820-4D67-9B38-6ECEAE9E3BBA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B07C4AE3-2517-41AD-A733-02903D6A9FAF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B11BB211-53C2-4A4C-A3BD-C8A42582CA14} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B1442DF0-73ED-467A-A04B-C8A47B4ABCA9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B1A9AF8D-9F21-4BE6-8106-88F0EC5ADE37} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B2B13453-7D6F-4409-81B8-0A2EB361A313} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B3616B93-8D9E-4E82-A098-9EA15934E038} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B3A029E1-B283-442D-B379-22844DF61B22} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B44E8CF0-DAE4-4003-B14B-92E6EA9A3142} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B474E805-152E-4728-878E-4BDAE5C931FE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B5F8EFE6-EEDC-4420-A2B3-ABFC6D528B38} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B637687F-B93E-49B3-85C6-5C843791FFD8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B7EE30BA-6107-4FF2-B769-7327414CA9EF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B906BA16-D390-4CDB-BC84-6B61883727DA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B908EBDB-3753-431A-BB7F-527DF1B4F32E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BA79A5EA-3C9B-4071-93AF-016F05C5A1A8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BABFF9D2-AE3A-4726-A43F-BA722CEA4F5B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BAFC1669-2DDE-43EE-8C89-134D05106FAC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BB49CA81-AE50-49C1-9BCD-CB25401E3AE0} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BBD7A80E-9DBC-4213-98E9-71F1C28209DD} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BCEC224D-7102-45FA-AC98-8333D9ADAD79} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BD42EF2D-9DD0-4F93-B176-E7D3EF8FD5B9} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BDB6701F-338D-45BD-9994-DB501A0135FF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BDDBAC9A-D6E9-4A15-9703-DCB2E83A2ADE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BDFEA299-68CF-4CB3-A539-81E36CB35CE8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BE784E85-53CF-4AFE-A9F3-34E7BB49017B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C13C65F5-D131-4D2E-AB7E-F3EA5C7752D0} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C15EC694-05B2-4EDA-93BA-83BD7E9A1C1D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C300BF15-30B1-4478-AA9A-E42561996A1B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C346ABEF-3366-4A67-B90F-60C967546B86} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C4E9796E-C42C-4747-AABB-BEDE89FAD5FA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C55252E2-F75A-4497-B830-01172FDA29BC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C5B16E28-D6BB-47CF-9C6A-9B94FBCA1ACC} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C71D959C-07A1-4A20-B751-AC004E4F33F4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C83FFB65-2A2A-4F3B-9CF5-89951CDE188E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CC722136-D99C-4DE2-BA30-27677D62B639} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CCE3D820-421A-4381-8A56-1817E1E0B16B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CDE65A7B-22EE-4B96-9439-E9AC93590E97} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CE11049D-0DA3-4345-AC54-1772722A8CCF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CE2E92E2-7011-428A-83C3-7D1F7EC904C7} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CE8A6C3E-1C19-46E6-ABFD-3B0D7F4C2BCE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D02F298B-B995-4915-8C14-C13FC0A68F8B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D26CEF07-B324-4332-9082-4B5621D266C4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D366FA38-E67E-48FF-82A9-1EC7EB8617FE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D3E71BE4-0B6D-4490-ACDD-21A241966764} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D47B48C3-34DD-49BD-A49B-0106FFB95DAF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D50E78B7-A8E9-4875-98FE-E2CB916BE9E4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D5598389-6D6C-45DA-850F-3A49CD3DBA08} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D5901E26-0167-423A-9207-422DE34462C5} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D5905E94-43F1-4E75-A567-3D7D28E6FCBA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D685850A-3ED0-4F93-8A34-ECDA2A3CA9A8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D809B1C7-DBCE-42DE-ADD1-6431C7B89E31} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D86761FB-8F7A-415D-9D29-8DBC045C9E14} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D8C56337-AA02-4AB7-8F6D-1E84F2F8B59E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D8D6F484-9661-408D-8691-A7FB55208302} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D947A19F-489C-48D1-9F0D-3BC77F4114EA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D97540DF-4330-4456-959A-7BB28462897E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DAEB2809-AB09-4C08-B002-3E8BAD24C6D3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DC0008B7-026E-49AB-BDA1-A4A8F367AA19} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DCA6E3AB-D19A-4F97-99A4-7444B03705ED} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DDFED81B-5228-4700-8791-6F1177119CDF} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DEFD7900-1D28-4596-BC30-884891B8D9AA} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DF163BE0-6DEA-4515-9BC2-297ABE497BD3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DFC0FB7A-3868-4728-8FEE-F672E1B97799} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E08E57E9-4898-4CED-9050-E9CD2E62AB8D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E16309B1-4851-4485-86EE-4DDA481EC693} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E183D86A-ABE6-45F4-9DE4-6A20E1C1D820} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E1BB8F90-6097-4260-A68B-378B9450CA9B} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E29B1EFD-E5E2-4917-9700-0774DAE2EC7D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E311C97F-97F2-416E-958D-448B2171F192} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E45AE2FB-FCBF-45EA-BF3B-F3740237A060} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E754DC43-35AC-4BD8-B39E-BA28E3111EA0} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E82DB110-331C-4177-A569-A45F17C66EB4} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E83DEE25-AB68-4552-9CC3-610E46AA75E3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E85F50C9-97E2-4D63-BE29-8B6E16888452} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E872CE91-A103-45B8-95CB-F8D70D1B2722} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{EBA7EE98-E95A-4D52-91D9-A1F960B91A24} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{EC02D17A-78BD-407A-B168-860788E9826A} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{EE87E53D-7737-4071-98AC-F6CA07ABFEC6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F07D8B23-59A3-4AEC-8D25-E97044D21B1E} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F1046C2A-3D00-42C5-90FE-C16A5030E181} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F4E63A7F-5A03-4D0C-8873-5513F3F6D5E3} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F58E2212-F15A-4337-84CF-40FC5892C700} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F5B7BD6C-CF45-4A0A-A6CC-0EF890331BE0} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F5DF0651-2E2E-40B1-9A99-6D38B8A37D64} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F6A304C3-781B-4A1A-8232-3360413CFBA8} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F6A7B506-DC85-490A-9B6F-109F2BD6CAE6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F778FC8F-56C7-4391-BA33-DED8DBF48506} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F7DC282A-9B28-415C-B4CC-E930186D3117} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F833171C-A4F9-437A-9270-F8C3220D081D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F8F08927-846F-4C7F-BAFC-74F2AD8D60DD} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F91A3405-ED65-4F16-AECE-4EC619078D65} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F9494F4A-A45A-41C4-99AD-9D2DD7EBF457} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FA2EDF0D-CD84-4BBF-9E95-5E6A518B1829} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FB3620E5-2637-4FD6-B94A-B88429FFC88C} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FC4DF8C6-E158-4C09-AA07-A5B92FF07730} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FD0B60DD-DD3D-4E62-8A71-D3F4ECD3D718} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FD25BC60-03A6-462A-8041-0F0B824F9BA6} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FD59ACF9-CDB7-404E-A065-A32E38AF5EBD} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FE2914C7-5D30-4388-B0CE-80A1921EF70D} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FE8DE347-1CDE-4B28-9A10-A8FAD67970BE} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FF699B0E-395C-4B77-A56E-016778584586} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FF964C4A-D922-458A-ABDA-FF298CA54E77} Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FFC4787C-62C2-4A9D-A373-3AE9610A3845} ~~~ Chrome Successfully deleted: [Folder] C:\Users\weinboerg\appdata\local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Successfully deleted: [Folder] C:\Users\weinboerg\appdata\local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 31.07.2013 at 18:59:28,45 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 04 Ran by weinboerg (administrator) on 31-07-2013 19:06:59 Running from C:\Users\weinboerg\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Agere Systems) C:\Windows\system32\agrsmsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel® Corporation) C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Intel(R) Corporation) C:\Program Files\Intel\Intel Media Share Software\Viivmonitor.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) D:\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (MyPCBackup.com) C:\Program Files\MyPC Backup\MyPC Backup.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4399104 2007-03-15] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [839680 2007-02-07] (Synaptics, Inc.) HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [56928 2006-11-23] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [54832 2006-12-05] () HKLM\...\Run: [Play AVStation TV Scheduler] - C:\Program Files\Samsung\Play AVStation\TvScheduler.exe [73728 2007-01-09] (SAMSUNG ELECTRONICS CO., LTD.) HKLM\...\Run: [ViivMonitor] - C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe [69632 2007-03-10] (Intel(R) Corporation) HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1822720 2007-03-14] (Realtek Semiconductor Corp.) HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.) HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdc.exe [563080 2007-01-24] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - D:\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-30] (Avira Operations GmbH & Co. KG) HKLM\...\InprocServer32: [Default-cscui] <==== ATTENTION! HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-10-22] (Google Inc.) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59280 2012-11-28] (Apple Inc.) HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59280 2012-11-28] (Apple Inc.) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) Startup: C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (IniCom Networks, Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: msdaipp - No CLSID Value - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 38 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - D:\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @innoplus.de/ino3DViewer - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.0 - D:\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Extension: No Name - C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= CHR DefaultSearchURL: (Web) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Move Media Player 7) - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (VLC Web Plugin) - D:\VLC\npvlc.dll (VideoLAN) CHR Plugin: (iTunes Application Detector) - D:\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (InoViewer Plugin) - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0 CHR HKLM\...\Chrome\Extension: [ajhcekcffkpnaednoeoegnmnjdlnjjmg] - C:\ProgramData\Codec-C\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR StartMenuInternet: Google Chrome - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-30] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-30] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-30] (Avira Operations GmbH & Co. KG) R2 IMSSync; C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe [368640 2007-03-10] (Intel® Corporation) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [167936 2005-08-08] () S2 MBAMService; "I:\Malwarebytes' Anti-Malware\mbamservice.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-30] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-30] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-30] (Avira Operations GmbH & Co. KG) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2011-07-29] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2011-07-29] () R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-30] (Avira GmbH) R3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [243840 2009-01-23] (Vimicro Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 catchme; \??\C:\Users\WEINBO~1\AppData\Local\Temp\catchme.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 RimUsb; System32\Drivers\RimUsb.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-31 19:06 - 2013-07-31 19:06 - 01222064 _____ (Farbar) C:\Users\weinboerg\Desktop\FRST.exe 2013-07-31 18:59 - 2013-07-31 18:59 - 00045343 _____ C:\Users\weinboerg\Desktop\JRT.txt 2013-07-31 18:56 - 2013-07-31 18:56 - 00562430 _____ (Oleg N. Scherbakov) C:\Users\weinboerg\Desktop\JRT.exe 2013-07-31 18:56 - 2013-07-31 18:56 - 00000000 ____D C:\Windows\ERUNT 2013-07-31 18:36 - 2013-07-31 18:46 - 00015618 _____ C:\AdwCleaner[S1].txt 2013-07-31 18:30 - 2013-07-31 18:30 - 00666633 _____ C:\Users\weinboerg\Desktop\adwcleaner.exe 2013-07-31 18:12 - 2013-07-31 18:12 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-31 18:12 - 2013-07-31 18:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-31 18:11 - 2013-07-31 18:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\weinboerg\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-30 19:29 - 2013-07-30 19:29 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (2).zip 2013-07-30 19:10 - 2013-07-30 19:10 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Avira 2013-07-30 19:04 - 2013-07-30 19:04 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-30 19:04 - 2013-07-30 19:03 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-30 19:04 - 2013-07-30 19:03 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-30 19:04 - 2013-07-30 19:03 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-30 19:04 - 2013-07-30 19:03 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-30 19:03 - 2013-07-30 19:04 - 00000000 ____D C:\ProgramData\Avira 2013-07-30 19:03 - 2013-07-30 19:03 - 00000000 ____D C:\Program Files\Avira 2013-07-30 18:39 - 2013-07-30 18:39 - 00011618 _____ C:\ComboFix.txt 2013-07-30 18:23 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-30 18:23 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-30 18:23 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-30 18:22 - 2013-07-30 18:39 - 00000000 ____D C:\ComboFix 2013-07-30 18:20 - 2013-07-30 18:42 - 00000000 ____D C:\Users\weinboerg\Desktop\Combofix 2013-07-30 17:51 - 2013-07-30 18:39 - 00000000 ____D C:\Qoobox 2013-07-30 17:47 - 2013-07-31 18:57 - 00000000 ____D C:\Program Files\MyPC Backup 2013-07-30 17:47 - 2013-07-31 18:49 - 00001814 _____ C:\Windows\Tasks\Plus-HD-2.5-firefoxinstaller.job 2013-07-30 17:47 - 2013-07-31 18:49 - 00001194 _____ C:\Windows\Tasks\Plus-HD-2.5-codedownloader.job 2013-07-30 17:47 - 2013-07-31 18:49 - 00001190 _____ C:\Windows\Tasks\Plus-HD-2.5-updater.job 2013-07-30 17:47 - 2013-07-31 18:49 - 00001094 _____ C:\Windows\Tasks\Plus-HD-2.5-enabler.job 2013-07-30 17:47 - 2013-07-30 18:37 - 00000000 ____D C:\Windows\erdnt 2013-07-30 17:47 - 2013-07-30 17:47 - 00000884 _____ C:\Users\weinboerg\Desktop\MyPC Backup.lnk 2013-07-30 17:47 - 2013-07-30 17:47 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2013-07-30 17:46 - 2013-07-30 17:47 - 00000000 ____D C:\Program Files\Plus-HD-2.5 2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\Desktop\Create Amazing Presentations.lnk 2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk 2013-07-30 17:46 - 2013-07-30 17:46 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\emaze 2013-07-30 17:45 - 2013-07-30 17:45 - 00002149 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2013-07-30 17:45 - 2013-07-30 17:45 - 00002119 _____ C:\Users\weinboerg\Desktop\Search.lnk 2013-07-29 21:25 - 2013-07-29 21:26 - 00026448 _____ C:\Users\weinboerg\Desktop\Addition.txt 2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe 2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip 2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt 2013-07-29 18:23 - 2008-01-02 17:37 - 00192512 _____ (Intel Corporation) C:\Windows\system32\igfxres.dll 2013-07-27 13:48 - 2013-07-30 11:50 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls 2013-07-11 02:59 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-11 02:59 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-11 02:59 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-11 02:59 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-11 02:59 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-11 02:59 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-11 02:59 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-11 02:59 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-11 02:59 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-11 02:59 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-11 02:59 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-11 02:59 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-11 02:59 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-11 02:59 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-11 02:59 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-11 02:58 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-11 01:03 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-11 01:02 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-11 01:02 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-11 01:02 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-11 01:02 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-11 01:02 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-11 01:02 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-11 01:02 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-11 01:02 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll ==================== One Month Modified Files and Folders ======= 2013-07-31 19:06 - 2013-07-31 19:06 - 01222064 _____ (Farbar) C:\Users\weinboerg\Desktop\FRST.exe 2013-07-31 18:59 - 2013-07-31 18:59 - 00045343 _____ C:\Users\weinboerg\Desktop\JRT.txt 2013-07-31 18:57 - 2013-07-30 17:47 - 00000000 ____D C:\Program Files\MyPC Backup 2013-07-31 18:56 - 2013-07-31 18:56 - 00562430 _____ (Oleg N. Scherbakov) C:\Users\weinboerg\Desktop\JRT.exe 2013-07-31 18:56 - 2013-07-31 18:56 - 00000000 ____D C:\Windows\ERUNT 2013-07-31 18:56 - 2006-11-02 12:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-31 18:55 - 2007-10-31 02:55 - 01268625 _____ C:\Windows\WindowsUpdate.log 2013-07-31 18:53 - 2012-12-01 01:23 - 00001136 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job 2013-07-31 18:49 - 2013-07-30 17:47 - 00001814 _____ C:\Windows\Tasks\Plus-HD-2.5-firefoxinstaller.job 2013-07-31 18:49 - 2013-07-30 17:47 - 00001194 _____ C:\Windows\Tasks\Plus-HD-2.5-codedownloader.job 2013-07-31 18:49 - 2013-07-30 17:47 - 00001190 _____ C:\Windows\Tasks\Plus-HD-2.5-updater.job 2013-07-31 18:49 - 2013-07-30 17:47 - 00001094 _____ C:\Windows\Tasks\Plus-HD-2.5-enabler.job 2013-07-31 18:49 - 2010-02-06 12:45 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-31 18:49 - 2008-01-26 13:15 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2013-07-31 18:49 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-31 18:49 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-31 18:49 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-31 18:47 - 2007-09-27 06:30 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-07-31 18:47 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-31 18:46 - 2013-07-31 18:36 - 00015618 _____ C:\AdwCleaner[S1].txt 2013-07-31 18:34 - 2010-02-06 12:45 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-31 18:32 - 2013-05-17 23:21 - 00006630 _____ C:\Windows\PFRO.log 2013-07-31 18:30 - 2013-07-31 18:30 - 00666633 _____ C:\Users\weinboerg\Desktop\adwcleaner.exe 2013-07-31 18:27 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\schemas 2013-07-31 18:12 - 2013-07-31 18:12 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-31 18:12 - 2013-07-31 18:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-31 18:11 - 2013-07-31 18:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\weinboerg\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-31 15:48 - 2012-04-03 09:36 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-30 19:29 - 2013-07-30 19:29 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (2).zip 2013-07-30 19:10 - 2013-07-30 19:10 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Avira 2013-07-30 19:04 - 2013-07-30 19:04 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-30 19:04 - 2013-07-30 19:03 - 00000000 ____D C:\ProgramData\Avira 2013-07-30 19:03 - 2013-07-30 19:04 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-30 19:03 - 2013-07-30 19:04 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-30 19:03 - 2013-07-30 19:04 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-30 19:03 - 2013-07-30 19:04 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-30 19:03 - 2013-07-30 19:03 - 00000000 ____D C:\Program Files\Avira 2013-07-30 18:42 - 2013-07-30 18:20 - 00000000 ____D C:\Users\weinboerg\Desktop\Combofix 2013-07-30 18:39 - 2013-07-30 18:39 - 00011618 _____ C:\ComboFix.txt 2013-07-30 18:39 - 2013-07-30 18:22 - 00000000 ____D C:\ComboFix 2013-07-30 18:39 - 2013-07-30 17:51 - 00000000 ____D C:\Qoobox 2013-07-30 18:39 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-07-30 18:39 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-07-30 18:37 - 2013-07-30 17:47 - 00000000 ____D C:\Windows\erdnt 2013-07-30 18:36 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-07-30 18:34 - 2008-03-04 22:39 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Adobe 2013-07-30 18:34 - 2008-01-26 13:12 - 00000000 ____D C:\Users\weinboerg 2013-07-30 18:16 - 2009-03-21 23:16 - 00000000 ____D C:\Users\weinboerg\Tracing 2013-07-30 17:47 - 2013-07-30 17:47 - 00000884 _____ C:\Users\weinboerg\Desktop\MyPC Backup.lnk 2013-07-30 17:47 - 2013-07-30 17:47 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2013-07-30 17:47 - 2013-07-30 17:46 - 00000000 ____D C:\Program Files\Plus-HD-2.5 2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\Desktop\Create Amazing Presentations.lnk 2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk 2013-07-30 17:46 - 2013-07-30 17:46 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\emaze 2013-07-30 17:45 - 2013-07-30 17:45 - 00002149 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2013-07-30 17:45 - 2013-07-30 17:45 - 00002119 _____ C:\Users\weinboerg\Desktop\Search.lnk 2013-07-30 11:50 - 2013-07-27 13:48 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls 2013-07-29 21:26 - 2013-07-29 21:25 - 00026448 _____ C:\Users\weinboerg\Desktop\Addition.txt 2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe 2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip 2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt 2013-07-27 14:39 - 2011-12-04 16:57 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Skype 2013-07-26 23:53 - 2012-12-01 01:23 - 00001084 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job 2013-07-19 23:06 - 2012-03-03 21:43 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\vlc 2013-07-19 21:25 - 2008-01-26 13:15 - 00050176 _____ C:\Users\WEINBO~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-07-13 23:58 - 2012-02-28 22:24 - 00002062 _____ C:\Users\weinboerg\Desktop\Google Chrome.lnk 2013-07-12 00:06 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-11 23:44 - 2012-04-03 09:36 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-11 23:44 - 2011-05-17 06:58 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-11 23:44 - 2008-03-04 22:39 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\Adobe 2013-07-11 23:34 - 2006-11-02 14:47 - 00380216 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-11 23:32 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-11 23:31 - 2010-06-03 19:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-11 03:16 - 2006-11-02 12:23 - 00000240 _____ C:\Windows\win.ini 2013-07-11 03:03 - 2006-11-02 12:24 - 75699896 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-07-11 02:49 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal Files to move or delete: ==================== C:\ProgramData\xbr6x2Snc.dat ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-31 18:58 ==================== End Of Log ============================ Geändert von weinboerg (31.07.2013 um 18:10 Uhr) |
31.07.2013, 19:51 | #10 |
/// the machine /// TB-Ausbilder | Virus Bundesministerium für Internetsicherheit - Zahlung von... Fast Fertig ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.08.2013, 05:42 | #11 |
| Virus Bundesministerium für Internetsicherheit - Zahlung von... Einen wunderschönen Guten Morgen, ESET hat, nachdem er die ganze Nachtr gescannt hat 3 Sachen gefunden, hier der LOG: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=488c7927f1255442a9c5fa1d5dea6feb # engine=14605 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-31 09:44:09 # local_time=2013-07-31 11:44:09 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1799 16775165 100 95 8816 103353 1573 0 # compatibility_mode=5892 16776574 100 100 11932731 212839777 0 0 # scanned=183237 # found=3 # cleaned=0 # scan_time=8238 sh=DFAD8339A55F72A1354F76959337CAA0956B8C03 ft=1 fh=2d4df1f9f1c82730 vn="a variant of Win32/Spy.Banker.ZJN trojan" ac=I fn="C:\Qoobox\Quarantine\C\Users\weinboerg\AppData\Roaming\AcroIEHelpe005264.dll.vir" sh=D1988EE0ED8F3DEED5DD1FC370EF64D0CF79ACF4 ft=1 fh=c73162a413d63a3e vn="a variant of Win32/Spy.Banker.ZQA trojan" ac=I fn="C:\Qoobox\Quarantine\C\Users\weinboerg\AppData\Roaming\AcroIEHelpe005270.dll.vir" sh=3F1EDA047C56CDC4EE518FD161F9B80CEDB6937F ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\weinboerg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\10684096-51fec1c7" Code:
ATTFilter Results of screen317's Security Check version 0.99.71 Windows Vista Service Pack 2 x86 Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java(TM) 6 Update 22 Java version out of Date! Adobe Reader 7 Adobe Reader out of Date! Google Chrome 28.0.1500.72 Google Chrome 28.0.1500.95 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 04 Ran by weinboerg (administrator) on 01-08-2013 07:02:53 Running from C:\Users\weinboerg\Desktop\VIREN-Malware Software Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Agere Systems) C:\Windows\system32\agrsmsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel® Corporation) C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Intel(R) Corporation) C:\Program Files\Intel\Intel Media Share Software\Viivmonitor.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) D:\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (MyPCBackup.com) C:\Program Files\MyPC Backup\MyPC Backup.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4399104 2007-03-15] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [839680 2007-02-07] (Synaptics, Inc.) HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [56928 2006-11-23] (Cyberlink Corp.) HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [54832 2006-12-05] () HKLM\...\Run: [Play AVStation TV Scheduler] - C:\Program Files\Samsung\Play AVStation\TvScheduler.exe [73728 2007-01-09] (SAMSUNG ELECTRONICS CO., LTD.) HKLM\...\Run: [ViivMonitor] - C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe [69632 2007-03-10] (Intel(R) Corporation) HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1822720 2007-03-14] (Realtek Semiconductor Corp.) HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.) HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdc.exe [563080 2007-01-24] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] () HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - D:\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-30] (Avira Operations GmbH & Co. KG) HKLM\...\InprocServer32: [Default-cscui] <==== ATTENTION! HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-10-22] (Google Inc.) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59280 2012-11-28] (Apple Inc.) HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59280 2012-11-28] (Apple Inc.) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) Startup: C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (IniCom Networks, Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: msdaipp - No CLSID Value - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 38 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - D:\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @innoplus.de/ino3DViewer - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.0 - D:\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Extension: No Name - C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 Chrome: ======= CHR DefaultSearchURL: (Web) - hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Move Media Player 7) - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (VLC Web Plugin) - D:\VLC\npvlc.dll (VideoLAN) CHR Plugin: (iTunes Application Detector) - D:\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (InoViewer Plugin) - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden) CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0 CHR HKLM\...\Chrome\Extension: [ajhcekcffkpnaednoeoegnmnjdlnjjmg] - C:\ProgramData\Codec-C\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx CHR StartMenuInternet: Google Chrome - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-30] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-30] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-30] (Avira Operations GmbH & Co. KG) R2 IMSSync; C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe [368640 2007-03-10] (Intel® Corporation) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [167936 2005-08-08] () S2 MBAMService; "I:\Malwarebytes' Anti-Malware\mbamservice.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-30] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-30] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-30] (Avira Operations GmbH & Co. KG) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2011-07-29] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2011-07-29] () R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-30] (Avira GmbH) R3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [243840 2009-01-23] (Vimicro Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 catchme; \??\C:\Users\WEINBO~1\AppData\Local\Temp\catchme.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 RimUsb; System32\Drivers\RimUsb.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-31 21:24 - 2013-07-31 21:24 - 02347384 _____ (ESET) C:\Users\weinboerg\Downloads\esetsmartinstaller_enu.exe 2013-07-31 19:10 - 2013-08-01 07:02 - 00000000 ____D C:\Users\weinboerg\Desktop\VIREN-Malware Software 2013-07-31 18:56 - 2013-07-31 18:56 - 00000000 ____D C:\Windows\ERUNT 2013-07-31 18:36 - 2013-07-31 18:46 - 00015618 _____ C:\AdwCleaner[S1].txt 2013-07-31 18:12 - 2013-07-31 18:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-31 18:11 - 2013-07-31 18:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\weinboerg\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-30 19:29 - 2013-07-30 19:29 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (2).zip 2013-07-30 19:10 - 2013-07-30 19:10 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Avira 2013-07-30 19:04 - 2013-07-30 19:04 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-30 19:04 - 2013-07-30 19:03 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-30 19:04 - 2013-07-30 19:03 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-30 19:04 - 2013-07-30 19:03 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-30 19:04 - 2013-07-30 19:03 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-30 19:03 - 2013-07-30 19:04 - 00000000 ____D C:\ProgramData\Avira 2013-07-30 19:03 - 2013-07-30 19:03 - 00000000 ____D C:\Program Files\Avira 2013-07-30 18:39 - 2013-07-30 18:39 - 00011618 _____ C:\ComboFix.txt 2013-07-30 18:23 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-30 18:23 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-30 18:23 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-30 18:23 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-30 18:22 - 2013-07-30 18:39 - 00000000 ____D C:\ComboFix 2013-07-30 17:51 - 2013-07-30 18:39 - 00000000 ____D C:\Qoobox 2013-07-30 17:47 - 2013-08-01 05:47 - 00001814 _____ C:\Windows\Tasks\Plus-HD-2.5-firefoxinstaller.job 2013-07-30 17:47 - 2013-08-01 05:47 - 00001194 _____ C:\Windows\Tasks\Plus-HD-2.5-codedownloader.job 2013-07-30 17:47 - 2013-08-01 05:47 - 00001190 _____ C:\Windows\Tasks\Plus-HD-2.5-updater.job 2013-07-30 17:47 - 2013-08-01 05:47 - 00001094 _____ C:\Windows\Tasks\Plus-HD-2.5-enabler.job 2013-07-30 17:47 - 2013-07-31 21:15 - 00000000 ____D C:\Program Files\MyPC Backup 2013-07-30 17:47 - 2013-07-30 18:37 - 00000000 ____D C:\Windows\erdnt 2013-07-30 17:47 - 2013-07-30 17:47 - 00000884 _____ C:\Users\weinboerg\Desktop\MyPC Backup.lnk 2013-07-30 17:47 - 2013-07-30 17:47 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2013-07-30 17:46 - 2013-07-30 17:47 - 00000000 ____D C:\Program Files\Plus-HD-2.5 2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\Desktop\Create Amazing Presentations.lnk 2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk 2013-07-30 17:46 - 2013-07-30 17:46 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\emaze 2013-07-30 17:45 - 2013-07-30 17:45 - 00002149 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2013-07-30 17:45 - 2013-07-30 17:45 - 00002119 _____ C:\Users\weinboerg\Desktop\Search.lnk 2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe 2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip 2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt 2013-07-29 18:23 - 2008-01-02 17:37 - 00192512 _____ (Intel Corporation) C:\Windows\system32\igfxres.dll 2013-07-27 13:48 - 2013-07-30 11:50 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls 2013-07-11 02:59 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-11 02:59 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-11 02:59 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-11 02:59 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-11 02:59 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-11 02:59 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-11 02:59 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-11 02:59 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-11 02:59 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-11 02:59 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-11 02:59 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-11 02:59 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-11 02:59 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-11 02:59 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-11 02:59 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-11 02:58 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-11 01:03 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-11 01:02 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-11 01:02 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-11 01:02 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-11 01:02 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-11 01:02 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-11 01:02 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-11 01:02 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-11 01:02 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-11 01:02 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll ==================== One Month Modified Files and Folders ======= 2013-08-01 07:02 - 2013-07-31 19:10 - 00000000 ____D C:\Users\weinboerg\Desktop\VIREN-Malware Software 2013-08-01 06:53 - 2012-12-01 01:23 - 00001136 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job 2013-08-01 06:48 - 2012-04-03 09:36 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-01 06:48 - 2007-10-31 02:55 - 01306270 _____ C:\Windows\WindowsUpdate.log 2013-08-01 06:34 - 2010-02-06 12:45 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-01 05:47 - 2013-07-30 17:47 - 00001814 _____ C:\Windows\Tasks\Plus-HD-2.5-firefoxinstaller.job 2013-08-01 05:47 - 2013-07-30 17:47 - 00001194 _____ C:\Windows\Tasks\Plus-HD-2.5-codedownloader.job 2013-08-01 05:47 - 2013-07-30 17:47 - 00001190 _____ C:\Windows\Tasks\Plus-HD-2.5-updater.job 2013-08-01 05:47 - 2013-07-30 17:47 - 00001094 _____ C:\Windows\Tasks\Plus-HD-2.5-enabler.job 2013-08-01 05:12 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-01 05:12 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-01 00:34 - 2010-02-06 12:45 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-31 23:53 - 2012-12-01 01:23 - 00001084 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job 2013-07-31 22:00 - 2012-02-28 22:24 - 00002062 _____ C:\Users\weinboerg\Desktop\Google Chrome.lnk 2013-07-31 21:24 - 2013-07-31 21:24 - 02347384 _____ (ESET) C:\Users\weinboerg\Downloads\esetsmartinstaller_enu.exe 2013-07-31 21:16 - 2006-11-02 12:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-31 21:15 - 2013-07-30 17:47 - 00000000 ____D C:\Program Files\MyPC Backup 2013-07-31 21:11 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-31 19:12 - 2007-09-27 06:30 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-07-31 19:12 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-31 18:56 - 2013-07-31 18:56 - 00000000 ____D C:\Windows\ERUNT 2013-07-31 18:49 - 2008-01-26 13:15 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2013-07-31 18:46 - 2013-07-31 18:36 - 00015618 _____ C:\AdwCleaner[S1].txt 2013-07-31 18:32 - 2013-05-17 23:21 - 00006630 _____ C:\Windows\PFRO.log 2013-07-31 18:32 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\schemas 2013-07-31 18:12 - 2013-07-31 18:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-31 18:11 - 2013-07-31 18:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\weinboerg\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-30 19:29 - 2013-07-30 19:29 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (2).zip 2013-07-30 19:10 - 2013-07-30 19:10 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Avira 2013-07-30 19:04 - 2013-07-30 19:04 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-30 19:04 - 2013-07-30 19:03 - 00000000 ____D C:\ProgramData\Avira 2013-07-30 19:03 - 2013-07-30 19:04 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-30 19:03 - 2013-07-30 19:04 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-30 19:03 - 2013-07-30 19:04 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-30 19:03 - 2013-07-30 19:04 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-30 19:03 - 2013-07-30 19:03 - 00000000 ____D C:\Program Files\Avira 2013-07-30 18:39 - 2013-07-30 18:39 - 00011618 _____ C:\ComboFix.txt 2013-07-30 18:39 - 2013-07-30 18:22 - 00000000 ____D C:\ComboFix 2013-07-30 18:39 - 2013-07-30 17:51 - 00000000 ____D C:\Qoobox 2013-07-30 18:39 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-07-30 18:39 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-07-30 18:37 - 2013-07-30 17:47 - 00000000 ____D C:\Windows\erdnt 2013-07-30 18:36 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-07-30 18:34 - 2008-03-04 22:39 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Adobe 2013-07-30 18:34 - 2008-01-26 13:12 - 00000000 ____D C:\Users\weinboerg 2013-07-30 18:16 - 2009-03-21 23:16 - 00000000 ____D C:\Users\weinboerg\Tracing 2013-07-30 17:47 - 2013-07-30 17:47 - 00000884 _____ C:\Users\weinboerg\Desktop\MyPC Backup.lnk 2013-07-30 17:47 - 2013-07-30 17:47 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2013-07-30 17:47 - 2013-07-30 17:46 - 00000000 ____D C:\Program Files\Plus-HD-2.5 2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\Desktop\Create Amazing Presentations.lnk 2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk 2013-07-30 17:46 - 2013-07-30 17:46 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\emaze 2013-07-30 17:45 - 2013-07-30 17:45 - 00002149 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2013-07-30 17:45 - 2013-07-30 17:45 - 00002119 _____ C:\Users\weinboerg\Desktop\Search.lnk 2013-07-30 11:50 - 2013-07-27 13:48 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls 2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe 2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip 2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip 2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt 2013-07-27 14:39 - 2011-12-04 16:57 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Skype 2013-07-19 23:06 - 2012-03-03 21:43 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\vlc 2013-07-19 21:25 - 2008-01-26 13:15 - 00050176 _____ C:\Users\WEINBO~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-07-12 00:06 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-11 23:44 - 2012-04-03 09:36 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-11 23:44 - 2011-05-17 06:58 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-11 23:44 - 2008-03-04 22:39 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\Adobe 2013-07-11 23:34 - 2006-11-02 14:47 - 00380216 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-11 23:32 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-11 23:31 - 2010-06-03 19:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-11 03:16 - 2006-11-02 12:23 - 00000240 _____ C:\Windows\win.ini 2013-07-11 03:03 - 2006-11-02 12:24 - 75699896 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-07-11 02:49 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal Files to move or delete: ==================== C:\ProgramData\xbr6x2Snc.dat ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-31 21:18 ==================== End Of Log ============================ Laufen tut alles, bzw. ich kann keinen Unterschied erkennen zum Stand vor dem Virus/Trojaner Ist denn der Rechner nun sauber?? Geändert von weinboerg (01.08.2013 um 06:07 Uhr) |
01.08.2013, 09:31 | #12 |
/// the machine /// TB-Ausbilder | Virus Bundesministerium für Internetsicherheit - Zahlung von... Java und Adobe updaten. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.08.2013, 19:59 | #13 |
| Virus Bundesministerium für Internetsicherheit - Zahlung von... Schrauber, herzlichen Dank für deine Hilfe!! Ist echt spitze und alles läuft ohne Probleme. Eine Frage habe ich aber noch; bei einer Installation wurde das Programm "My PCBackup" mit installiert. Dieses war nach der letzten Aktion mit dem DelFix noch vorhanden. Jetzt wollte ich es manuell mit der Funktion deinstallieren vom Rechner schmeißen, da sagt er mir, das Programm ist nicht mehr vorhanden. Ich sehe aber noch den kompletten Ordner mit seinem Inhalt. Kann ich diesen Ordner ebenfalls bedenkenlos löschen?? Dankeschön |
02.08.2013, 10:54 | #14 |
/// the machine /// TB-Ausbilder | Virus Bundesministerium für Internetsicherheit - Zahlung von... Ja lösch den einfach
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Virus Bundesministerium für Internetsicherheit - Zahlung von... |
7-zip, abend, angeblich, bedanken, brief, erwischt, forum, gestartet, gestern, google, heute, install.exe, interne, konnte, malware.trace, malwarebytes, nichts, paypal, plug-in, plötzlich, pup.optional.ibryte, pup.optional.wajam, refresh, sicherheit, trojan.agent.ed, trojan.agent.ge, trojan.agent.gen, trojan.agent.tpl, unterstützung, virus, zahlen, zahlung |