Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Virus Bundesministerium für Internetsicherheit - Zahlung von...

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 29.07.2013, 18:45   #1
weinboerg
 
Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Einen wunderschönen Guten Abend in die Runde.

Mich hat es erwischt!! Gestern Abend erschien plötzlich beim Stream schauen mit meiner Holden ein Brief, welcher mich auffordert den Betrag von 100 Euro per Paypal zu zahlen, weil ich angeblich nicht Jugendfreies Material im Web geschaut habe. Dann auch noch vom Bundesministerium!! Aber, als ich dann las, dass Artikel... war klar; FAKE/VIRUS - Artikel gibt es nur im Grundgesetz oder in EU-Drucksachen!!

Naja, es war dann auch schon recht spät und ich konnte mich heute früh erstmal der Sache widmen. Per Google habe ich einen Fred hier im Forum gefunden, gestartet von User Mintaka mit eine sehr tollen Unterstützung von t'john.

Die ersten Schritte Malwarebytes Anti-Rootkt und den Systemscan mit OTL habe ich gemacht.

Hier der Malwarebytes Log

1. Ergebnis
Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org

Database version: v2013.07.29.04

Windows Vista Service Pack 2 x86 FAT32 (Safe Mode)
Internet Explorer 9.0.8112.16421
weinboerg :: WEINBOERG-PC [administrator]

29.07.2013 18:25:13
mbar-log-2013-07-29 (18-25-13).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 217415
Time elapsed: 11 minute(s), 22 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 16
HKCU\SOFTWARE\CLASSES\CLSID\{44101423-0900-2897-4698-446497410995} (Trojan.Agent.ED) -> Delete on reboot.
HKCU\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\{44101423-0900-2897-4698-446497410995} (Trojan.Agent.ED) -> Delete on reboot.
HKCU\SOFTWARE\CLASSES\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\EhStorShell.IconOverlayHandler (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\EhStorShell.IconOverlayHandler.1 (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{2854F705-3548-414C-A113-93E27C808C85} (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\TYPELIB\{B3A00612-1423-4072-A4F9-DE2ADCAA7F3C} (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\EhStorShell.ContextMenuHandler.1 (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\EhStorShell.ContextMenuHandler (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{36F54939-CD3B-4C73-92D5-F9A389ED631C} (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\EhStorShell.AutoplayHandler.1 (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\EhStorShell.AutoplayHandler (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\CLSID\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7} (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\EhStorShell.EhStorFolder.1 (Trojan.Agent.ED) -> Delete on reboot.
HKLM\SOFTWARE\CLASSES\EhStorShell.EnhancedStorageFolder (Trojan.Agent.ED) -> Delete on reboot.

Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|qcgce2mrvjq91kk1e7pnbb19m52fx (Trojan.Agent.ED) -> Data: C:\Users\WEINBO~1\AppData\Local\Temp\kyknynxsjtyyodbky.exe -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELL EXTENSIONS\APPROVED|{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7} (Trojan.Agent.ED) -> Data: Enhanced Storage Data Source -> Delete on reboot.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 8
c:\Users\weinboerg\AppData\Local\Temp\kyknynxsjtyyodbky.exe (Trojan.Agent.ED) -> Delete on reboot.
c:\Users\weinboerg\AppData\Local\Temp\kyknynxsjtyyodbky.dll (Trojan.Agent.ED) -> Delete on reboot.
c:\Windows\System32\ehstorshell.dll (Trojan.Agent.ED) -> Delete on reboot.
c:\Users\weinboerg\AppData\Roaming\Adobe\shed\thr1.chm (Malware.Trace) -> Delete on reboot.
c:\Users\weinboerg\AppData\Roaming\Adobe\plugs\mmc219.exe (Trojan.Agent.Gen) -> Delete on reboot.
c:\ProgramData\2433f433 (Trojan.Agent.TPL) -> Delete on reboot.
c:\Users\weinboerg\AppData\Roaming\2433f433 (Trojan.Agent.TPL) -> Delete on reboot.
c:\Users\weinboerg\AppData\Local\2433f433 (Trojan.Agent.TPL) -> Delete on reboot.

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         
2. Ergebnis
Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org

Database version: v2013.07.29.05

Windows Vista Service Pack 2 x86 FAT32
Internet Explorer 9.0.8112.16421
weinboerg :: WEINBOERG-PC [administrator]

29.07.2013 18:53:02
mbar-log-2013-07-29 (18-53-02).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 221006
Time elapsed: 22 minute(s), 14 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         
Gut, schon mal nichts mehr gefunden im 2. Lauf

Jetzt kommen die 2 OTL Logs

OTL
Code:
ATTFilter
OTL logfile created on: 29.07.2013 19:18:29 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = J:\
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 0,92 Gb Available Physical Memory | 46,04% Memory free
4,21 Gb Paging File | 2,94 Gb Available in Paging File | 69,77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 40,31 Gb Total Space | 2,78 Gb Free Space | 6,89% Space Free | Partition Type: NTFS
Drive D: | 9,93 Gb Total Space | 7,52 Gb Free Space | 75,79% Space Free | Partition Type: NTFS
Drive E: | 30,22 Gb Total Space | 8,68 Gb Free Space | 28,71% Space Free | Partition Type: NTFS
Drive F: | 29,33 Gb Total Space | 8,22 Gb Free Space | 28,02% Space Free | Partition Type: NTFS
Drive G: | 47,00 Gb Total Space | 11,45 Gb Free Space | 24,36% Space Free | Partition Type: NTFS
Drive I: | 13,85 Gb Total Space | 5,08 Gb Free Space | 36,65% Space Free | Partition Type: NTFS
Drive J: | 7,89 Gb Total Space | 5,31 Gb Free Space | 67,35% Space Free | Partition Type: FAT32
 
Computer Name: WEINBOERG-PC | User Name: weinboerg | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - J:\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
PRC - C:\Programme\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Programme\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Programme\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.)
PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Intel\Intel Media Share Software\Viivmonitor.exe (Intel(R) Corporation)
PRC - C:\Programme\Intel\Intel Media Share Software\IMSSync.exe (Intel® Corporation)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Programme\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Programme\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Programme\Samsung\EBM\ChkSec.dll ()
MOD - C:\Programme\Samsung\Easy Display Manager\WinMove.dll ()
MOD - C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll ()
MOD - C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll ()
MOD - C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll ()
 
 
========== Services (SafeList) ==========
 
SRV - (MBAMService) -- I:\Malwarebytes' Anti-Malware\mbamservice.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ServiceLayer) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (fsssvc) -- C:\Programme\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (IMSSync) -- C:\Programme\Intel\Intel Media Share Software\IMSSync.exe (Intel® Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) -- C:\Programme\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (RimUsb) -- System32\Drivers\RimUsb.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (mbamswissarmy) --  File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (9ef44980) -- C:\Windows\TEMP\88BB.tmp File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (nmwcdc) -- C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (UsbserFilt) -- C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (epmntdrv) -- C:\Windows\System32\epmntdrv.sys ()
DRV - (EuGdiDrv) -- C:\Windows\System32\EuGdiDrv.sys ()
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (VMC302) -- C:\Windows\System32\drivers\vmc302.sys (Vimicro Corporation)
DRV - (NETw4v32) -- C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (KMDFMEMIO) -- C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NETw2v32) -- C:\Windows\System32\drivers\NETw2v32.sys (Intel® Corporation)
DRV - (RTL8023xp) -- C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation                           )
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GZAZ_de
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@innoplus.de/ino3DViewer: D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: D:\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.08.13 17:34:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.02.24 22:14:55 | 000,000,000 | ---D | M]
 
[2013.04.03 15:31:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\weinboerg\AppData\Roaming\mozilla\Firefox\Profiles\extensions
[2012.08.05 21:09:47 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\weinboerg\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com
[2012.07.11 23:44:50 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: 
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Move Media Player 7 (Enabled) = C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: VLC Web Plugin (Enabled) = D:\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: InoViewer Plugin (Enabled) = D:\npIno3DViewer.dll
CHR - Extension: Codec-C = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhcekcffkpnaednoeoegnmnjdlnjjmg\1.0_0\
CHR - Extension: YouTube = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: MonsterDivx = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkinfljboeildloankgjmljfibngeefa\0.95_0\
CHR - Extension: Cuevana Stream = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfdckejfnkaemompfjhecfmhjgnchmjg\5.2.1_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: OneClickDownload = C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco\1.3_0\
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1             localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Codec-C Class) - {0D56E386-F8C6-4FBC-9A7E-E8DA50072D26} - C:\ProgramData\Codec-C\bhoclass.dll File not found
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Programme\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O3 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003\..\Toolbar\WebBrowser: (no name) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] "I:\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray File not found
O4 - HKLM..\Run: [Play AVStation TV Scheduler] C:\Programme\Samsung\Play AVStation\TvScheduler.exe (SAMSUNG ELECTRONICS CO., LTD.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ViivMonitor] C:\Programme\Intel\Intel Media Share Software\Viivmonitor.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: []  File not found
O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [ApplePhotoStreams] C:\Programme\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [iCloudServices] C:\Programme\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe File not found
O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2152196072-760242556-3123413665-1003..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.1; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"hxxp://t4u.strongfire.net/goserv/www/delivery/afr.php?refresh=90&zoneid=1&source=TarifeAusland&target=_blank&loc=http%3A%2F%2Fwww.tarif4you.de%2Ftarife%2F0052.html" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoHotStart = 0
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D65BECAB-C710-43D5-BE15-D7A5039D8805}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe ()
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.03.10 17:27:40 | 001,007,616 | ---- | M] (RapidSolution Software AG) - D:\autotag.dll -- [ NTFS ]
O33 - MountPoints2\{2ded0685-cd93-11e1-9921-0013775d3a92}\Shell - "" = AutoRun
O33 - MountPoints2\{2ded0685-cd93-11e1-9921-0013775d3a92}\Shell\AutoRun\command - "" = J:\SafeStick.exe
O33 - MountPoints2\{49895bc0-4788-11e1-87d3-0013775d3a92}\Shell - "" = AutoRun
O33 - MountPoints2\{49895bc0-4788-11e1-87d3-0013775d3a92}\Shell\AutoRun\command - "" = I:\SafeStick.exe
O33 - MountPoints2\{bc62e7b1-07f3-11e0-bb70-0013775d3a92}\Shell - "" = AutoRun
O33 - MountPoints2\{bc62e7b1-07f3-11e0-bb70-0013775d3a92}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{bc62e7c8-07f3-11e0-bb70-0013775d3a92}\Shell - "" = AutoRun
O33 - MountPoints2\{bc62e7c8-07f3-11e0-bb70-0013775d3a92}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{c1dff1c6-b9b2-11e2-9fd5-0013775d3a92}\Shell - "" = AutoRun
O33 - MountPoints2\{c1dff1c6-b9b2-11e2-9fd5-0013775d3a92}\Shell\AutoRun\command - "" = K:\SafeStick.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.07.29 18:51:43 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{1FCADF76-D3CA-4C7D-B341-CBBF64E55327}
[2013.07.29 18:25:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013.07.29 18:23:31 | 000,192,512 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxres.dll
[2013.07.29 18:13:26 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013.07.29 18:05:58 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{C83FFB65-2A2A-4F3B-9CF5-89951CDE188E}
[2013.07.28 14:51:03 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{F5DF0651-2E2E-40B1-9A99-6D38B8A37D64}
[2013.07.27 13:34:26 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{18E7F753-468C-440B-8B1C-C5B02EA03181}
[2013.07.26 14:54:06 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{412A4A17-6CFB-4E58-B6E1-EB8FBF2F2DC1}
[2013.07.25 22:13:33 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{D809B1C7-DBCE-42DE-ADD1-6431C7B89E31}
[2013.07.24 13:34:27 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{0B191973-39A1-4052-BD89-FFC90D24DA0E}
[2013.07.23 14:38:59 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{4CD2DF11-B5C4-4C2E-AB44-10DA2761172F}
[2013.07.22 16:16:55 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{835AE2B4-683B-42EB-AF79-5D37B000D33A}
[2013.07.21 23:16:12 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{6D49ACA4-0030-4298-8FFA-A6AD5BF4E8F8}
[2013.07.21 11:15:54 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{5257980B-7969-47E1-8BAC-457EA18319C5}
[2013.07.20 19:33:46 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{F7DC282A-9B28-415C-B4CC-E930186D3117}
[2013.07.19 21:00:36 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{7D565F96-C83A-4E4B-9FF6-25917A3F7E4A}
[2013.07.18 21:09:06 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{BA79A5EA-3C9B-4071-93AF-016F05C5A1A8}
[2013.07.17 20:37:08 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{69CCEE85-19B0-4987-B444-189E8D7B50F8}
[2013.07.16 21:01:38 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{19CAE532-FFBD-44DD-AC9D-1EA3BCF31BDC}
[2013.07.15 21:24:27 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{2DB47F16-3118-44EB-8DD5-B79DD24CEFD5}
[2013.07.14 22:21:27 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{5EDD6E88-E11E-4F8A-8BE8-7755CBF2FB18}
[2013.07.13 23:06:39 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{8367EDC9-341A-4CBA-B602-097576277A3B}
[2013.07.12 23:35:54 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{F4E63A7F-5A03-4D0C-8873-5513F3F6D5E3}
[2013.07.11 23:41:43 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{6B9ECCFE-B5D4-4FA8-9A76-91A91547CD31}
[2013.07.11 02:59:06 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.07.11 02:59:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.07.11 02:59:04 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.07.11 02:59:04 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.07.11 02:59:04 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.07.11 02:59:03 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.07.11 02:59:02 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.07.11 02:59:01 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.07.11 01:03:22 | 002,049,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013.07.11 01:02:44 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2013.07.11 01:02:44 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2013.07.11 01:02:44 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2013.07.11 01:02:44 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2013.07.11 01:02:44 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2013.07.11 01:02:43 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2013.07.11 01:02:43 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2013.07.11 01:02:43 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2013.07.11 01:02:42 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
[2013.07.11 01:02:39 | 001,548,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2013.07.10 23:20:15 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{02202EA8-754C-41E5-9F34-42AD4B345C3F}
[2013.07.10 11:19:58 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{0321EEA5-E980-4223-8ADA-9BBEF88D81C3}
[2013.07.09 21:26:36 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{3FF890DB-2265-4164-BA74-9CB81296D7FF}
[2013.07.08 22:13:07 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{D3E71BE4-0B6D-4490-ACDD-21A241966764}
[2013.07.07 22:21:08 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{115E61A3-F743-4404-BE16-379335CFF0E5}
[2013.07.06 22:12:28 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{DC0008B7-026E-49AB-BDA1-A4A8F367AA19}
[2013.07.05 23:17:10 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{FA2EDF0D-CD84-4BBF-9E95-5E6A518B1829}
[2013.07.03 19:52:01 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{C15EC694-05B2-4EDA-93BA-83BD7E9A1C1D}
[2013.07.02 21:57:49 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{711428AC-F683-4E0A-812C-4128E97D83C7}
[2013.07.01 21:33:15 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{EE87E53D-7737-4071-98AC-F6CA07ABFEC6}
[2013.06.30 21:13:08 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{1ABB056C-8AAC-4772-A190-1EDF453E6B25}
[2013.06.30 00:15:25 | 000,000,000 | ---D | C] -- C:\Users\weinboerg\AppData\Local\{E1BB8F90-6097-4260-A68B-378B9450CA9B}
[1 C:\Users\weinboerg\AppData\Roaming\*.tmp files -> C:\Users\weinboerg\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.07.29 18:56:29 | 000,628,992 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.07.29 18:56:29 | 000,596,246 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.07.29 18:56:29 | 000,126,510 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.07.29 18:56:29 | 000,104,320 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.07.29 18:53:03 | 000,001,136 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job
[2013.07.29 18:49:23 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.07.29 18:49:20 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.29 18:49:16 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.29 18:48:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.29 18:48:28 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.29 18:16:30 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013.07.28 22:48:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.07.28 22:34:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.07.26 23:53:02 | 000,001,084 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job
[2013.07.19 21:25:13 | 000,050,176 | ---- | M] () -- C:\Users\weinboerg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.07.13 23:58:36 | 000,002,062 | ---- | M] () -- C:\Users\weinboerg\Desktop\Google Chrome.lnk
[2013.07.11 23:44:14 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.07.11 23:44:13 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.07.11 23:34:47 | 000,380,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Users\weinboerg\AppData\Roaming\*.tmp files -> C:\Users\weinboerg\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.07.29 18:48:28 | 2137,448,448 | -HS- | C] () -- C:\hiberfil.sys
[2013.05.08 18:02:15 | 000,240,224 | ---- | C] () -- C:\Users\weinboerg\AppData\Roaming\AcroIEHelpe005270.dll
[2013.04.19 16:21:41 | 000,216,160 | ---- | C] () -- C:\Users\weinboerg\AppData\Roaming\AcroIEHelpe005264.dll
[2013.04.18 19:05:02 | 000,000,000 | ---- | C] () -- C:\ProgramData\xbr6x2Snc.dat
[2013.04.18 19:04:47 | 000,000,001 | ---- | C] () -- C:\ProgramData\I0R26DN0.exe_.b
[2013.04.18 19:04:47 | 000,000,001 | ---- | C] () -- C:\ProgramData\I0R26DN0.exe.b
[2013.04.03 15:35:29 | 000,000,869 | ---- | C] () -- C:\Users\weinboerg\AppData\Roaming\rost.dat
[2012.10.11 18:30:18 | 000,004,980 | ---- | C] () -- C:\Users\weinboerg\AppData\Local\soulseek-client.dat
[2012.07.13 00:50:12 | 002,469,760 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2012.07.13 00:50:12 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2012.07.13 00:50:11 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2012.07.13 00:50:11 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2012.07.13 00:50:11 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2012.07.12 23:10:29 | 000,000,393 | ---- | C] () -- C:\Users\weinboerg\AppData\Local\HamsterVideoConverterSettings.cfg
[2011.10.05 21:11:26 | 000,001,200 | ---- | C] () -- C:\Users\weinboerg\AppData\Roaming\b333_logs
[2010.08.12 22:50:00 | 000,118,784 | ---- | C] () -- C:\Users\weinboerg\JavaLoader.exe
[2008.10.30 10:49:34 | 000,000,022 | ---- | C] () -- C:\ProgramData\8f01a90e-7eb3-48d3-93b1-50d88fd146fb
[2008.01.26 13:15:07 | 000,050,176 | ---- | C] () -- C:\Users\weinboerg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2010.08.25 21:04:52 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Ashampoo
[2011.04.17 18:55:24 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Caches
[2011.10.29 10:39:23 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Canneverbe Limited
[2013.04.03 15:31:09 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\ckoock
[2011.12.29 21:12:22 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Deyqa
[2012.10.11 17:44:14 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\elsterformular
[2011.10.19 11:48:41 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Etsewe
[2011.07.04 13:20:28 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Gokyma
[2012.10.12 20:22:53 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\HandBrake
[2011.12.29 11:53:59 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Ibawyq
[2012.12.31 16:22:38 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\JAM Software
[2011.07.16 13:44:19 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Mealmo
[2012.08.09 22:06:32 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Nokia
[2012.08.09 22:03:11 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Nokia Suite
[2009.02.02 20:33:45 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\PC Suite
[2009.03.23 21:53:16 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\RapidSolution
[2012.01.25 21:54:16 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\SafeStick
[2013.04.17 12:08:02 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\UsAgt
[2012.08.28 20:30:28 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\WindSolutions
[2013.05.13 11:18:05 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\xmldm
[2013.04.13 13:29:13 | 000,000,000 | ---D | M] -- C:\Users\weinboerg\AppData\Roaming\Ycve
 
========== Purity Check ==========
 
 

< End of report >
         
Extras
Code:
ATTFilter
OTL Extras logfile created on: 29.07.2013 19:18:29 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = J:\
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 0,92 Gb Available Physical Memory | 46,04% Memory free
4,21 Gb Paging File | 2,94 Gb Available in Paging File | 69,77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 40,31 Gb Total Space | 2,78 Gb Free Space | 6,89% Space Free | Partition Type: NTFS
Drive D: | 9,93 Gb Total Space | 7,52 Gb Free Space | 75,79% Space Free | Partition Type: NTFS
Drive E: | 30,22 Gb Total Space | 8,68 Gb Free Space | 28,71% Space Free | Partition Type: NTFS
Drive F: | 29,33 Gb Total Space | 8,22 Gb Free Space | 28,02% Space Free | Partition Type: NTFS
Drive G: | 47,00 Gb Total Space | 11,45 Gb Free Space | 24,36% Space Free | Partition Type: NTFS
Drive I: | 13,85 Gb Total Space | 5,08 Gb Free Space | 36,65% Space Free | Partition Type: NTFS
Drive J: | 7,89 Gb Total Space | 5,31 Gb Free Space | 67,35% Space Free | Partition Type: FAT32
 
Computer Name: WEINBOERG-PC | User Name: weinboerg | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "D:\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "G:\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.)
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00B9D4DC-587A-4929-9D27-58C25C2345B1}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{01E69000-F82A-449A-9F75-A739D3A9630A}" = lport=1034 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4003 | 
"{03518A9B-B383-4D9E-AB5E-60AE43BC8A31}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4006 | 
"{068AFEC0-46C9-40A2-85FE-642F3C5490C5}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4006 | 
"{2A4B6C2B-B8AB-4546-96B1-6D754DB64407}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{38A06FF6-79E7-4707-8EE0-4D6F856F4A99}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4006 | 
"{3AF1E3F5-8D7D-4981-80F0-21FBA29E433D}" = lport=1034 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4003 | 
"{3D6C867C-14CF-440B-B697-D8867483D0FC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{401B0B30-9924-47D1-A960-E6978184DB0E}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{4C84AB64-45E1-4BDF-B092-6827F6AB09F4}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{4DAB36A5-1062-41AC-A088-967EBB46981D}" = lport=5721 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4002 | 
"{4F211999-1D76-4F7F-9171-DE89160F3E9B}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{5C028561-4B9A-46AD-BF7B-B74C65DF3E19}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{5CFC2558-5E55-40AF-8705-FECD1A048A48}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{5D48FAB5-548F-4DF3-9A74-37D1EA65CE17}" = lport=1034 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4003 | 
"{6CE298D3-702F-4BFF-BFF4-DA07ACEC390C}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{7253C7E6-18C3-4F9A-A0D5-F5C91395D088}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{769DD005-7991-44D2-8E7C-AF4DF40062B0}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{7A9B027E-7203-411D-A4E9-A0A50C167E96}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{7CC69E46-1EE5-44B5-9B68-8E1D126DDCEF}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{85C5C735-B87E-4182-B90B-59790A868714}" = lport=5721 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4002 | 
"{91C82D4C-2271-4BEA-B0A5-0A46524B3769}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{9384CECE-8693-41F5-B571-FCA0A7BD515F}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{9663D8C7-862A-425B-A541-50674297F7F9}" = lport=5721 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdc.exe,-4002 | 
"{B6304DD4-FB01-44F1-9D9B-2EC6E6245D68}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{D5DD7262-4BCA-427F-BA61-E6CE26B1F5A0}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{F239C074-ADA5-45EC-8F27-61867EA867E8}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06B7200B-017D-457B-8C25-C5D5D6AADA85}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | 
"{22938D25-E6ED-466D-AF6C-4590E573FC1A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | 
"{2E0A82CC-072D-4522-8CDF-652DBB497A67}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{3CF411DA-0402-4ED2-8F87-3E27A676754F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{59F3D07D-6D49-480E-9C6B-241FFE5C8895}" = protocol=17 | dir=in | app=c:\program files\intel\intel media share software\imss.exe | 
"{7D8BB780-74F5-4ECF-B36F-973B7CB3FC28}" = protocol=17 | dir=in | app=c:\program files\intel\intel media share software\imssync.exe | 
"{89119B85-06AD-4883-9742-57A8A989C6B5}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | 
"{8F084066-36B1-4E85-82B8-1C908E8A31A2}" = dir=in | app=d:\itunes\itunes.exe | 
"{9EF46C1A-052E-443B-8CC8-32E12A6472B8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{C06B5F35-1368-4DD5-A674-8CBE8F70D5A8}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | 
"{C3567176-EB9C-4027-B58C-E9378C83BDB8}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{D0851CAE-E892-47F7-A8BF-F522B8BFB213}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{EAFCA84A-FB73-46EC-AD97-25EB4899E699}" = protocol=6 | dir=in | app=c:\program files\intel\intel media share software\imss.exe | 
"{F5B9013E-6F61-4C58-91FE-A04BD043AA71}" = protocol=6 | dir=in | app=c:\program files\intel\intel media share software\imssync.exe | 
"{F5D65820-A1DC-4033-9863-EBD437D4FCAF}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"{FC5B85F4-FF0F-4AE9-A5C2-EAFEEE7D7594}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | 
"TCP Query User{133D293E-DCC4-4626-9DE6-00269A05145E}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | 
"TCP Query User{1A4C52D0-4EA0-4232-A8CC-6D6EBB66A1D8}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe | 
"TCP Query User{647E1D11-3C98-4AC3-9170-47D0892EC66F}C:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | 
"TCP Query User{8D01E047-4B96-4ADD-A299-F2B66A97E0D1}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\german\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\german\setup.exe | 
"TCP Query User{9DD063F7-927E-48DF-AA72-2129DBA18160}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | 
"TCP Query User{AFD244CB-BB8F-4321-B278-15C1CCAB8890}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe | 
"TCP Query User{B04C6214-EEFE-4E61-B658-033272FFF0B0}C:\program files\intel\intel media share software\imss.exe" = protocol=6 | dir=in | app=c:\program files\intel\intel media share software\imss.exe | 
"TCP Query User{BF94D882-76D1-4FD6-9C3F-1CD309212C5D}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | 
"TCP Query User{CADBBF8B-451C-4F0D-B6AC-2FF3797EF558}G:\soulseekqt\soulseekqt.exe" = protocol=6 | dir=in | app=g:\soulseekqt\soulseekqt.exe | 
"UDP Query User{117851BB-1B1D-4A07-828C-60B5A02B9FD1}C:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe | 
"UDP Query User{41C641AD-48C8-4F67-9410-49347CABA600}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | 
"UDP Query User{5D096D03-1C0B-4C49-8BBC-A037B7E60E04}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\german\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\german\setup.exe | 
"UDP Query User{68773E4B-D809-4640-948B-4BFB93D6371D}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | 
"UDP Query User{7B738C4C-0FBC-4E46-98D8-DD2738B3495D}G:\soulseekqt\soulseekqt.exe" = protocol=17 | dir=in | app=g:\soulseekqt\soulseekqt.exe | 
"UDP Query User{7DEC8A4D-47FB-49DA-A200-D75B2388A0EE}C:\program files\intel\intel media share software\imss.exe" = protocol=17 | dir=in | app=c:\program files\intel\intel media share software\imss.exe | 
"UDP Query User{8603F251-9787-4A2F-863D-C2C00FE37AB0}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe | 
"UDP Query User{CEA31998-3DC7-45C8-9BB3-EB5931029AC6}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe | 
"UDP Query User{F24DBA50-4F5F-4BBA-831E-BA751A7B50BB}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution II
"{1686816B-367A-4EA6-9C20-F694A5511C13}" = AS Lernen
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B6C0E95-182C-48E0-9C4B-4F916308249C}" = iTunes
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F2A5DF9-40E1-4644-ADBD-D80F347BA6C8}" = Windows Mobile-Gerätecenter
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 22
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{2EF17083-57D4-4D64-AE4F-55F32A2C4571}" = Codec-C
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite
"{459699C3-9430-4381-964B-4248D87B49F9}" = Apple Mobile Device Support
"{478CAA24-5DA4-48F5-A237-734EC3B41DF5}" = Windows Live Family Safety
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"{54E1342C-1FDF-4F2A-98AB-4E82A5616FC8}" = PixiePack Codec Pack
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6CC53910-973E-4DD4-AC3D-E2A3E5439346}" = Intel® Media-Share-Software
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager
"{710BF966-43C8-4216-A8EC-BC4E169FF7C1}" = MobileMe Control Panel
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7964AE02-9127-42C0-A917-2CE4CD4EFE3B}" = Nokia Suite
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{804F1285-8CBF-408D-8CDC-D4D40003B2E4}" = PlayCamera
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}" = WIDCOMM Bluetooth Software
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A945BD16-4774-4A1F-96A7-118BEC004881}" = mCorev32.ism_new
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-A70800000002}" = Adobe Reader 7.0.8 - Deutsch
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B066064E-8BB9-4BB6-88A1-62522FD34EB3}" = Radiotracker
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B96DB037-DBEA-4186-9081-9CBD537F82E8}" = 3D-Viewer-innoPlus
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{CB8CA439-DA83-419C-A4CF-5A0A50025144}" = Windows Mobile-Gerätecenter: Treiberupdate
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! 1.0
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6B3114F-945B-4980-BF7A-AF12E9161A0F}" = iCloud
"{DA5B2BDC-F654-4A88-A669-4D34BC7846A1}" = PC Connectivity Solution
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F32ED8B1-2442-4B0E-8DEC-3F3BFC1C2B7F}" = mCPlug
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F5A4F780-DF0C-444F-BA82-637CCF5C8052}" = Windows Live Family Safety
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FD53302C-8E7B-4730-8AD8-86A889BDBFAB}" = AVStation Now
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"1ClickDownload" = 1ClickDownloader
"504244733D18C8F63FF584AEB290E3904E791693" = Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"7-Zip" = 7-Zip 9.20
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"DivX Setup" = DivX-Setup
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 9.1.1 Home Edition
"ElsterFormular" = ElsterFormular
"HandBrake" = HandBrake 0.9.8
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"iLivid" = iLivid
"InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"InstallShield_{FD53302C-8E7B-4730-8AD8-86A889BDBFAB}" = AVStation Now
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.0.1200
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Nokia PC Suite" = Nokia PC Suite
"Nokia Suite" = Nokia Suite
"ProInst" = Intel(R) PROSet/Wireless Software
"SoulseekQt" = SoulseekQt
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 2.0.0
"Windows Mobile Device Handbook" = Windows Mobile®-Gerätehandbuch
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-2152196072-760242556-3123413665-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 29.07.2013 12:50:37 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:37 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:38 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:38 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:39 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:39 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:39 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:39 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:40 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 29.07.2013 12:50:40 | Computer Name = weinboerg-PC | Source = Windows Search Service | ID = 3013
Description = 
 
[ System Events ]
Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7026
Description = 
 
Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 29.07.2013 12:23:55 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 29.07.2013 12:49:20 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 29.07.2013 12:51:41 | Computer Name = weinboerg-PC | Source = Service Control Manager | ID = 7000
Description = 
 
 
< End of report >
         
So, bis dahin bin ich schon mal alleine gekommen.
Ist nun alles fertig oder muss ich noch etwas machen??

Vorab möchte ich mich schon mal für die Hilfe bedanken!!

Gruß
weinboerg

Geändert von weinboerg (29.07.2013 um 18:54 Uhr)

Alt 29.07.2013, 18:54   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



hi,

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 29.07.2013, 19:09   #3
weinboerg
 
Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Schon umgewandelt!! Sorry
__________________

Alt 29.07.2013, 20:11   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 29.07.2013, 20:28   #5
weinboerg
 
Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



FRST

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 01
Ran by weinboerg (administrator) on 29-07-2013 21:25:08
Running from C:\Users\weinboerg\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
(Intel® Corporation) C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(Intel(R) Corporation) C:\Program Files\Intel\Intel Media Share Software\Viivmonitor.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Apple Inc.) D:\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4399104 2007-03-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [839680 2007-02-07] (Synaptics, Inc.)
HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [56928 2006-11-23] (Cyberlink Corp.)
HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [54832 2006-12-05] ()
HKLM\...\Run: [Play AVStation TV Scheduler] - C:\Program Files\Samsung\Play AVStation\TvScheduler.exe [73728 2007-01-09] (SAMSUNG ELECTRONICS CO., LTD.)
HKLM\...\Run: [ViivMonitor] - C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe [69632 2007-03-10] (Intel(R) Corporation)
HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1822720 2007-03-14] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdc.exe [563080 2007-01-24] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes' Anti-Malware] - "I:\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [x]
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] ()
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - D:\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [MsnMsgr] - C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [4280184 2012-03-08] (Microsoft Corporation)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-10-22] (Google Inc.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [MobileDocuments] - C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [x]
HKCU\...\Run: [] -  [x]
HKCU\...\Run: [Google Update] - C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-12-01] (Google Inc.)
HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59280 2012-11-28] (Apple Inc.)
HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59280 2012-11-28] (Apple Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
HKCU\...\Runonce: [Shockwave Updater] - C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.1; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"hxxp://t4u.strongfire.net/goserv/www/delivery/afr.php?refresh=90&zoneid=1&source=TarifeAusland&target=_blank&loc=http%3A%2F%2Fwww.tarif4you.de%2Ftarife%2F0052.html" [x]
HKCU\...\Command Processor: "C:\Users\WEINBO~1\AppData\Local\Temp\kyknynxsjtyyodbky.exe" <======= ATTENTION
MountPoints2: {2ded0685-cd93-11e1-9921-0013775d3a92} - J:\SafeStick.exe
MountPoints2: {49895bc0-4788-11e1-87d3-0013775d3a92} - I:\SafeStick.exe
MountPoints2: {bc62e7b1-07f3-11e0-bb70-0013775d3a92} - I:\AutoRun.exe
MountPoints2: {bc62e7c8-07f3-11e0-bb70-0013775d3a92} - I:\AutoRun.exe
MountPoints2: {c1dff1c6-b9b2-11e2-9fd5-0013775d3a92} - K:\SafeStick.exe
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Codec-C Class - {0D56E386-F8C6-4FBC-9A7E-E8DA50072D26} - C:\ProgramData\Codec-C\bhoclass.dll No File
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -No Name - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} -  No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: msdaipp - No CLSID Value - 
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - D:\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @innoplus.de/ino3DViewer - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.0 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: OneClickDownloader - C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\profiles\extensions\OneClickDownload@OneClickDownload.com
FF Extension: No Name - C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5

Chrome: 
=======
CHR RestoreOnStartup: "hxxp://search.iminent.com/SearchTheWeb/v4/1031/homepage/Default.aspx"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Skype Toolbars) - C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Move Media Player 7) - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (VLC Web Plugin) - D:\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - D:\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (InoViewer Plugin) - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
CHR Extension: (Codec-C) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhcekcffkpnaednoeoegnmnjdlnjjmg\1.0_0
CHR Extension: (YouTube) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (MonsterDivx) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkinfljboeildloankgjmljfibngeefa\0.95_0
CHR Extension: (Cuevana Stream) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfdckejfnkaemompfjhecfmhjgnchmjg\5.2.1_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0
CHR Extension: (Gmail) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR Extension: (OneClickDownload) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco\1.3_0
CHR HKLM\...\Chrome\Extension: [ajhcekcffkpnaednoeoegnmnjdlnjjmg] - C:\ProgramData\Codec-C\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR HKLM\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files\1ClickDownload\oneclickdownloader10.crx
CHR StartMenuInternet: Google Chrome - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 IMSSync; C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe [368640 2007-03-10] (Intel® Corporation)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [167936 2005-08-08] ()
S2 MBAMService; "I:\Malwarebytes' Anti-Malware\mbamservice.exe" [x]

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-03-21] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-03-21] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-21] (Avira Operations GmbH & Co. KG)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2011-07-29] ()
R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22712 2011-05-29] (Malwarebytes Corporation)
S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-15] (Avira GmbH)
R3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [243840 2009-01-23] (Vimicro Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe
2013-07-29 21:20 - 2013-07-29 21:20 - 01221282 _____ (Farbar) C:\Users\weinboerg\Desktop\FRST.exe
2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip
2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt
2013-07-29 18:51 - 2013-07-29 18:51 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{1FCADF76-D3CA-4C7D-B341-CBBF64E55327}
2013-07-29 18:25 - 2013-07-29 19:15 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-29 18:23 - 2008-01-02 17:37 - 00192512 _____ (Intel Corporation) C:\Windows\system32\igfxres.dll
2013-07-29 18:05 - 2013-07-29 18:05 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{C83FFB65-2A2A-4F3B-9CF5-89951CDE188E}
2013-07-28 14:51 - 2013-07-28 14:51 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F5DF0651-2E2E-40B1-9A99-6D38B8A37D64}
2013-07-27 13:48 - 2013-07-27 15:08 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls
2013-07-27 13:34 - 2013-07-27 13:34 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{18E7F753-468C-440B-8B1C-C5B02EA03181}
2013-07-26 14:54 - 2013-07-26 14:54 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{412A4A17-6CFB-4E58-B6E1-EB8FBF2F2DC1}
2013-07-25 22:13 - 2013-07-25 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{D809B1C7-DBCE-42DE-ADD1-6431C7B89E31}
2013-07-24 13:34 - 2013-07-24 13:34 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{0B191973-39A1-4052-BD89-FFC90D24DA0E}
2013-07-23 14:38 - 2013-07-23 14:39 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{4CD2DF11-B5C4-4C2E-AB44-10DA2761172F}
2013-07-22 16:16 - 2013-07-22 16:16 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{835AE2B4-683B-42EB-AF79-5D37B000D33A}
2013-07-21 23:16 - 2013-07-21 23:16 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{6D49ACA4-0030-4298-8FFA-A6AD5BF4E8F8}
2013-07-21 11:15 - 2013-07-21 11:15 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{5257980B-7969-47E1-8BAC-457EA18319C5}
2013-07-20 19:33 - 2013-07-20 19:33 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F7DC282A-9B28-415C-B4CC-E930186D3117}
2013-07-19 21:00 - 2013-07-19 21:00 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{7D565F96-C83A-4E4B-9FF6-25917A3F7E4A}
2013-07-18 21:09 - 2013-07-18 21:09 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{BA79A5EA-3C9B-4071-93AF-016F05C5A1A8}
2013-07-17 20:37 - 2013-07-17 20:37 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{69CCEE85-19B0-4987-B444-189E8D7B50F8}
2013-07-16 21:01 - 2013-07-16 21:01 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{19CAE532-FFBD-44DD-AC9D-1EA3BCF31BDC}
2013-07-15 21:24 - 2013-07-15 21:24 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{2DB47F16-3118-44EB-8DD5-B79DD24CEFD5}
2013-07-14 22:21 - 2013-07-14 22:21 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{5EDD6E88-E11E-4F8A-8BE8-7755CBF2FB18}
2013-07-13 23:06 - 2013-07-13 23:06 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{8367EDC9-341A-4CBA-B602-097576277A3B}
2013-07-12 23:35 - 2013-07-12 23:35 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F4E63A7F-5A03-4D0C-8873-5513F3F6D5E3}
2013-07-11 23:41 - 2013-07-11 23:41 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{6B9ECCFE-B5D4-4FA8-9A76-91A91547CD31}
2013-07-11 02:59 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 02:59 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 02:59 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-11 02:59 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 02:59 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 02:59 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-11 02:59 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 02:59 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-11 02:59 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-11 02:59 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 02:59 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 02:59 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 02:59 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 02:59 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-11 02:59 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 02:58 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 01:03 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 01:02 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 01:02 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 01:02 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-11 01:02 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-11 01:02 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-11 01:02 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-11 01:02 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-11 01:02 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-07-10 23:20 - 2013-07-10 23:20 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{02202EA8-754C-41E5-9F34-42AD4B345C3F}
2013-07-10 11:19 - 2013-07-10 11:19 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{0321EEA5-E980-4223-8ADA-9BBEF88D81C3}
2013-07-09 21:26 - 2013-07-09 21:26 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{3FF890DB-2265-4164-BA74-9CB81296D7FF}
2013-07-08 22:13 - 2013-07-08 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{D3E71BE4-0B6D-4490-ACDD-21A241966764}
2013-07-07 22:21 - 2013-07-07 22:21 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{115E61A3-F743-4404-BE16-379335CFF0E5}
2013-07-06 22:12 - 2013-07-06 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{DC0008B7-026E-49AB-BDA1-A4A8F367AA19}
2013-07-05 23:17 - 2013-07-05 23:17 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{FA2EDF0D-CD84-4BBF-9E95-5E6A518B1829}
2013-07-03 19:52 - 2013-07-03 19:52 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{C15EC694-05B2-4EDA-93BA-83BD7E9A1C1D}
2013-07-02 21:57 - 2013-07-02 21:57 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{711428AC-F683-4E0A-812C-4128E97D83C7}
2013-07-01 21:33 - 2013-07-01 21:33 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{EE87E53D-7737-4071-98AC-F6CA07ABFEC6}
2013-06-30 21:13 - 2013-06-30 21:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{1ABB056C-8AAC-4772-A190-1EDF453E6B25}
2013-06-30 00:15 - 2013-06-30 00:15 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{E1BB8F90-6097-4260-A68B-378B9450CA9B}

==================== One Month Modified Files and Folders =======

2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe
2013-07-29 21:20 - 2013-07-29 21:20 - 01221282 _____ (Farbar) C:\Users\weinboerg\Desktop\FRST.exe
2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST
2013-07-29 20:53 - 2012-12-01 01:23 - 00001136 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job
2013-07-29 20:48 - 2012-04-03 09:36 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-29 20:48 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-29 20:48 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-29 20:34 - 2010-02-06 12:45 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-29 20:34 - 2007-10-31 02:55 - 01114645 _____ C:\Windows\WindowsUpdate.log
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip
2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt
2013-07-29 19:15 - 2013-07-29 18:25 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-07-29 18:56 - 2006-11-02 12:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-29 18:51 - 2013-07-29 18:51 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{1FCADF76-D3CA-4C7D-B341-CBBF64E55327}
2013-07-29 18:51 - 2009-03-21 23:16 - 00000000 ____D C:\Users\weinboerg\Tracing
2013-07-29 18:49 - 2010-02-06 12:45 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-29 18:49 - 2008-01-26 13:15 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2013-07-29 18:48 - 2013-05-17 23:21 - 00003816 _____ C:\Windows\PFRO.log
2013-07-29 18:48 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-29 18:16 - 2007-09-27 06:30 - 00000012 _____ C:\Windows\bthservsdp.dat
2013-07-29 18:16 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-29 18:05 - 2013-07-29 18:05 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{C83FFB65-2A2A-4F3B-9CF5-89951CDE188E}
2013-07-28 14:51 - 2013-07-28 14:51 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F5DF0651-2E2E-40B1-9A99-6D38B8A37D64}
2013-07-27 15:08 - 2013-07-27 13:48 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls
2013-07-27 14:39 - 2011-12-04 16:57 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Skype
2013-07-27 13:34 - 2013-07-27 13:34 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{18E7F753-468C-440B-8B1C-C5B02EA03181}
2013-07-26 23:53 - 2012-12-01 01:23 - 00001084 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job
2013-07-26 14:54 - 2013-07-26 14:54 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{412A4A17-6CFB-4E58-B6E1-EB8FBF2F2DC1}
2013-07-25 22:13 - 2013-07-25 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{D809B1C7-DBCE-42DE-ADD1-6431C7B89E31}
2013-07-24 13:34 - 2013-07-24 13:34 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{0B191973-39A1-4052-BD89-FFC90D24DA0E}
2013-07-23 14:39 - 2013-07-23 14:38 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{4CD2DF11-B5C4-4C2E-AB44-10DA2761172F}
2013-07-22 16:16 - 2013-07-22 16:16 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{835AE2B4-683B-42EB-AF79-5D37B000D33A}
2013-07-21 23:16 - 2013-07-21 23:16 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{6D49ACA4-0030-4298-8FFA-A6AD5BF4E8F8}
2013-07-21 11:15 - 2013-07-21 11:15 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{5257980B-7969-47E1-8BAC-457EA18319C5}
2013-07-20 19:33 - 2013-07-20 19:33 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F7DC282A-9B28-415C-B4CC-E930186D3117}
2013-07-19 23:06 - 2012-03-03 21:43 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\vlc
2013-07-19 21:25 - 2008-01-26 13:15 - 00050176 _____ C:\Users\WEINBO~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-07-19 21:00 - 2013-07-19 21:00 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{7D565F96-C83A-4E4B-9FF6-25917A3F7E4A}
2013-07-18 21:09 - 2013-07-18 21:09 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{BA79A5EA-3C9B-4071-93AF-016F05C5A1A8}
2013-07-17 20:37 - 2013-07-17 20:37 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{69CCEE85-19B0-4987-B444-189E8D7B50F8}
2013-07-16 21:01 - 2013-07-16 21:01 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{19CAE532-FFBD-44DD-AC9D-1EA3BCF31BDC}
2013-07-15 21:24 - 2013-07-15 21:24 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{2DB47F16-3118-44EB-8DD5-B79DD24CEFD5}
2013-07-14 22:21 - 2013-07-14 22:21 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{5EDD6E88-E11E-4F8A-8BE8-7755CBF2FB18}
2013-07-13 23:58 - 2012-02-28 22:24 - 00002062 _____ C:\Users\weinboerg\Desktop\Google Chrome.lnk
2013-07-13 23:06 - 2013-07-13 23:06 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{8367EDC9-341A-4CBA-B602-097576277A3B}
2013-07-12 23:35 - 2013-07-12 23:35 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{F4E63A7F-5A03-4D0C-8873-5513F3F6D5E3}
2013-07-12 00:06 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-11 23:44 - 2012-04-03 09:36 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-11 23:44 - 2011-05-17 06:58 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-11 23:44 - 2008-03-04 22:39 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\Adobe
2013-07-11 23:41 - 2013-07-11 23:41 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{6B9ECCFE-B5D4-4FA8-9A76-91A91547CD31}
2013-07-11 23:34 - 2006-11-02 14:47 - 00380216 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 23:32 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-07-11 23:31 - 2010-06-03 19:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 03:16 - 2006-11-02 12:23 - 00000240 _____ C:\Windows\win.ini
2013-07-11 03:03 - 2006-11-02 12:24 - 75699896 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-07-11 02:49 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-10 23:20 - 2013-07-10 23:20 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{02202EA8-754C-41E5-9F34-42AD4B345C3F}
2013-07-10 11:19 - 2013-07-10 11:19 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{0321EEA5-E980-4223-8ADA-9BBEF88D81C3}
2013-07-09 21:26 - 2013-07-09 21:26 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{3FF890DB-2265-4164-BA74-9CB81296D7FF}
2013-07-08 22:13 - 2013-07-08 22:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{D3E71BE4-0B6D-4490-ACDD-21A241966764}
2013-07-07 22:21 - 2013-07-07 22:21 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{115E61A3-F743-4404-BE16-379335CFF0E5}
2013-07-06 22:13 - 2013-07-06 22:12 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{DC0008B7-026E-49AB-BDA1-A4A8F367AA19}
2013-07-05 23:17 - 2013-07-05 23:17 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{FA2EDF0D-CD84-4BBF-9E95-5E6A518B1829}
2013-07-03 19:52 - 2013-07-03 19:52 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{C15EC694-05B2-4EDA-93BA-83BD7E9A1C1D}
2013-07-02 21:57 - 2013-07-02 21:57 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{711428AC-F683-4E0A-812C-4128E97D83C7}
2013-07-01 21:33 - 2013-07-01 21:33 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{EE87E53D-7737-4071-98AC-F6CA07ABFEC6}
2013-06-30 21:13 - 2013-06-30 21:13 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{1ABB056C-8AAC-4772-A190-1EDF453E6B25}
2013-06-30 00:15 - 2013-06-30 00:15 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\{E1BB8F90-6097-4260-A68B-378B9450CA9B}

Files to move or delete:
====================
C:\ProgramData\xbr6x2Snc.dat
C:\Users\weinboerg\JavaLoader.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-29 19:10

==================== End Of Log ============================
         
--- --- ---


Addition
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 30-07-2013 01
Ran by weinboerg at 2013-07-29 21:25:51
Running from C:\Users\weinboerg\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

1ClickDownloader (Version: 2.7 Build 26473)
3D-Viewer-innoPlus (Version: 10.00.0119)
7-Zip 9.20
Activation Assistant for the 2007 Microsoft Office suites
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0)
Adobe Flash Player 11 ActiveX (Version: 11.8.800.94)
Adobe Reader 7.0.8 - Deutsch (Version: 7.0.8)
Adobe Shockwave Player 11 (Version: 11)
Agere Systems HDA Modem
Apple Application Support (Version: 2.3.2)
Apple Mobile Device Support (Version: 6.0.1.3)
Apple Software Update (Version: 2.1.3.127)
AS Lernen (Version: 2.5.00)
Avira Free Antivirus (Version: 13.0.0.3884)
AVStation Now (Version: 4.0.10.6)
Bonjour (Version: 3.0.0.10)
CCleaner (Version: 3.11)
CDBurnerXP (Version: 4.4.1.3341)
CleanUp!
Codec-C (Version: )
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
D3DX10 (Version: 15.4.2368.0902)
DivX-Setup (Version: 2.6.1.9)
DVD Suite
EASEUS Partition Master 9.1.1 Home Edition
Easy Battery Manager (Version: 3.2.1.1)
Easy Display Manager (Version: 2.0.0.0)
Easy Network Manager 3.0 (Version: 3.0.0.0)
Easy SpeedUp Manager (Version: 2.0.0.10)
ElsterFormular (Version: 13.3.0.9066)
FlashFXP v3 (Version: 3.4.0.1145)
Galería fotográfica de Windows Live (Version: 15.4.3502.0922)
Google Chrome (HKCU Version: 28.0.1500.72)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4209.2358)
Google Update Helper (Version: 1.3.21.153)
HandBrake 0.9.8 (Version: 0.9.8)
iCloud (Version: 2.1.0.39)
iLivid (Version: 1.92.0.118480)
imagine digital freedom - Samsung (Version: 1.0.2.0)
Intel(R) Graphics Media Accelerator Driver
Intel(R) PROSet/Wireless Software (Version: 11.5.0000)
Intel® Media-Share-Software (Version: 1.01.207)
IrfanView (remove only)
iTunes (Version: 11.0.0.163)
Java Auto Updater (Version: 2.0.2.4)
Java(TM) 6 Update 22 (Version: 6.0.220)
Junk Mail filter update (Version: 15.4.3502.0922)
Malwarebytes' Anti-Malware Version 1.51.0.1200 (Version: 1.51.0.1200)
mCorev32.ism_new (Version: 11.03.0000)
mCPlug (Version: 11.03.0000)
mDriver (Version: 11.03.0000)
mHelp (Version: 11.03.0000)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office Outlook Connector (Version: 14.0.5118.5000)
Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SOAP Toolkit 2.0 SP2 (Version: 623.1)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft_VC100_CRT_SP1_x86 (Version: 10.0.40219.1)
mMHouse (Version: 11.03.0000)
MobileMe Control Panel (Version: 3.1.8.0)
Move Media Player
mPfMgr (Version: 11.03.0000)
MSVC80_x86 (Version: 1.0.1.0)
MSVC80_x86_v2 (Version: 1.0.3.0)
MSVC90_x86 (Version: 1.0.1.2)
MSVCRT (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0)
MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP2 Parser and SDK (Version: 4.20.9818.0)
Nokia Connectivity Cable Driver (Version: 7.1.78.0)
Nokia PC Suite (Version: 7.1.30.9)
Nokia Suite (Version: 3.4.49.0)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0)
PC Connectivity Solution (Version: 12.0.17.0)
PhotoNow! 1.0
PixiePack Codec Pack (Version: 1.1.300.0)
Play AVStation (Version: 4.1.20.43)
PlayCamera (Version: 1.00.32)
PowerDVD (Version: 7.0.2414.0)
QuickTime (Version: 7.73.80.64)
Radiotracker (Version: 5.0.23040.4000)
Realtek High Definition Audio Driver (Version: 6.0.1.5386)
Safari (Version: 5.34.57.2)
Samsung Magic Doctor (Version: 5.00)
Samsung Recovery Solution II (Version: 2.0)
Segoe UI (Version: 15.4.2271.0615)
Skype™ 6.3 (Version: 6.3.107)
SoulseekQt
Synaptics Pointing Device Driver (Version: 9.1.15.0)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
Vimicro UVC Camera (Version: 1.00.0000)
VLC media player 2.0.0 (Version: 2.0.0)
WIDCOMM Bluetooth Software (Version: 6.0.1.3700)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live Sync (Version: 14.0.8117.416)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Mobile®-Gerätehandbuch (Version: 1.0)
Windows Mobile-Gerätecenter (Version: 6.0.6783.0)
Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.0.6783.0)
Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0) (Version: 08/22/2008 7.0.0.0)
 

==================== Restore Points  =========================

29-07-2013 18:36:13 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0F4B75A2-3821-4725-AE1D-CE4848403BD7} - System32\Tasks\SamsungMagicDoctor => C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe [2007-03-15] (Samsung Electronics Co., Ltd.)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {27E767E7-77D6-4213-A51D-96B9F591F157} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2007-03-14] (Samsung Electronics Co., Ltd.)
Task: {2D7B6E4D-1E15-420B-8D11-54A669397DB3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-11] (Adobe Systems Incorporated)
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {444C9EE8-E38B-424A-88F4-8DDAF6556913} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core => C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-01] (Google Inc.)
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation)
Task: {650738A3-CFE3-4929-A892-0E916CC16DCE} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-12] (Microsoft Corporation)
Task: {6DCA8D12-FB32-40BA-B00C-984A11F1E648} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {73FF2179-C101-4D0A-82B8-44021D0DD0E2} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-19] (Microsoft Corp.)
Task: {7F511AE9-D63C-4582-B890-CD2596E1EE3B} - System32\Tasks\RunAsStdUser Task => C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe No File
Task: {7F9ADCAB-3CEE-4180-A518-831D7EF0ADCD} - System32\Tasks\WPD\SqmUpload_S-1-5-21-2152196072-760242556-3123413665-1003 => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation)
Task: {8ECA359F-1132-4D9F-B406-29DEC0101550} - System32\Tasks\Microsoft\Office Genuine Advantage\OGALogon => C:\Windows\system32\OGAExec.exe [2009-08-03] ()
Task: {9BD56E96-1C03-491C-B4A9-DFD23F8EE347} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2007-04-09] (SAMSUNG Electronics)
Task: {A299D5B4-C95A-4ECB-A75D-4476F9A4B5BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-06] (Google Inc.)
Task: {A38CD883-2039-443D-B28D-74B3AE0E629E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA => C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-01] (Google Inc.)
Task: {A3DCED7F-2BD8-4848-BDB1-31A3CF72373C} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [2007-04-12] (SAMSUNG Electronics co., LTD.)
Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation)
Task: {B5A84497-751B-4B65-8039-426E86277063} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {C1A941FE-3863-4EE2-B20F-B914533FAAF2} - System32\Tasks\12ba7400 => C:\Users\WEINBO~1\AppData\Local\Temp\\setup2703038464.exe No File
Task: {C5C78233-DD72-44C6-8175-3631ED3E1942} - System32\Tasks\e101f000 => C:\Users\WEINBO~1\AppData\Local\Temp\\setup2430360576.exe No File
Task: {C963C549-F280-495D-A1D7-513B71F5D639} - System32\Tasks\Microsoft\Windows\RestartManager\{6E26A865-0E96-46fe-902C-73A33533B409} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: {D15B4AE5-EAB9-406C-95F7-E55A9B382975} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-06] (Google Inc.)
Task: {D2AE00E5-ACC0-4FB4-A1CD-FB08A7587789} - System32\Tasks\a5aa4e00 => C:\Users\WEINBO~1\AppData\Local\Temp\\setup167809024.exe No File
Task: {D652B309-8764-43A1-8817-AB298D544BF5} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation)
Task: {E0916ACC-2592-4781-9FC6-40CE4F0328AC} - System32\Tasks\17d73600 => C:\Users\WEINBO~1\AppData\Local\Temp\\setup316023808.exe No File
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] ()
Task: {ED04124B-5B7A-48D5-AD81-96C7568F9FCB} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {F502C4E7-EEBA-45C9-8087-E7F606A68CB8} - System32\Tasks\Microsoft\Windows\RestartManager\{018BCD93-37A0-4f76-8095-9F65CDBBD51F} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job => C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job => C:\Users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/29/2013 06:50:40 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\README.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:40 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\README.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD-HILFE.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD-HILFE.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD DEINSTALLIEREN.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD DEINSTALLIEREN.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:38 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\ONLINE-REGISTRIERUNG.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:38 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\ONLINE-REGISTRIERUNG.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:37 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\CYBERLINK POWERDVD.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (07/29/2013 06:50:37 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\CYBERLINK POWERDVD.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)


System errors:
=============
Error: (07/29/2013 06:51:41 PM) (Source: Service Control Manager) (User: )
Description: MBAMService%%3

Error: (07/29/2013 06:49:20 PM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058

Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: )
Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068

Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: )
Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068

Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: )
Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068

Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: )
Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068

Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: )
Description: AFD
avipbb
avkmgr
DfsC
NetBIOS
netbt
nsiproxy
PSched
RasAcd
rdbss
Smb
spldr
ssmdrv
tdx
Wanarpv6

Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: )
Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068

Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: )
Description: NLA (Network Location Awareness)Netzwerkspeicher-Schnittstellendienst%%1068

Error: (07/29/2013 06:23:55 PM) (Source: Service Control Manager) (User: )
Description: IP-HilfsdienstNetzwerkspeicher-Schnittstellendienst%%1068


Microsoft Office Sessions:
=========================
Error: (07/29/2013 06:50:40 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\README.LNK

Error: (07/29/2013 06:50:40 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\README.LNK

Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD-HILFE.LNK

Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD-HILFE.LNK

Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD DEINSTALLIEREN.LNK

Error: (07/29/2013 06:50:39 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\POWERDVD DEINSTALLIEREN.LNK

Error: (07/29/2013 06:50:38 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\ONLINE-REGISTRIERUNG.LNK

Error: (07/29/2013 06:50:38 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\ONLINE-REGISTRIERUNG.LNK

Error: (07/29/2013 06:50:37 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\CYBERLINK POWERDVD.LNK

Error: (07/29/2013 06:50:37 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\WEINBOERG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK DVD SUITE\POWERDVD\CYBERLINK POWERDVD.LNK


CodeIntegrity Errors:
===================================
  Date: 2013-07-29 19:02:44.531
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-07-29 19:02:44.110
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-07-29 19:02:43.751
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-07-29 19:02:43.408
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-07-29 18:58:37.370
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-07-29 18:58:37.010
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-07-29 18:58:36.630
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-07-29 18:58:36.228
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-07-14 11:24:19.341
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-07-14 11:24:19.072
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Percentage of memory in use: 71%
Total physical RAM: 2037.69 MB
Available physical RAM: 570.75 MB
Total Pagefile: 4312.64 MB
Available Pagefile: 2396.68 MB
Total Virtual: 2047.88 MB
Available Virtual: 1909.36 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:40.31 GB) (Free:2.7 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Programme) (Fixed) (Total:9.93 GB) (Free:7.52 GB) NTFS
Drive e: (Musik) (Fixed) (Total:30.22 GB) (Free:8.68 GB) NTFS
Drive f: (Bilder) (Fixed) (Total:29.33 GB) (Free:8.22 GB) NTFS
Drive g: (sonstiges) (Fixed) (Total:47 GB) (Free:11.45 GB) NTFS
Drive i: (Family Holidays) (Fixed) (Total:13.85 GB) (Free:5.08 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 186 GB) (Disk ID: D168249C)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=40 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=136 GB) - (Type=OF Extended)

==================== End Of Log ============================
         
Dankeschön


Alt 30.07.2013, 07:07   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
--> Virus Bundesministerium für Internetsicherheit - Zahlung von...

Alt 30.07.2013, 18:08   #7
weinboerg
 
Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Code:
ATTFilter
ComboFix 13-07-30.03 - weinboerg 30.07.2013  18:26:13.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.49.1031.18.2038.351 [GMT 2:00]
ausgeführt von:: c:\users\weinboerg\Desktop\Combofix\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\8f01a90e-7eb3-48d3-93b1-50d88fd146fb
c:\programdata\Codec-C
c:\programdata\Codec-C\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx
c:\programdata\Codec-C\background.html
c:\programdata\Codec-C\content.js
c:\programdata\Codec-C\data\content.js
c:\programdata\Codec-C\data\jsondb.js
c:\programdata\Codec-C\settings.ini
c:\programdata\Codec-C\uninstall.exe
c:\programdata\I0R26DN0.exe.b
c:\programdata\I0R26DN0.exe_.b
c:\programdata\Roaming
c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini
c:\users\weinboerg\AppData\Local\.#
c:\users\weinboerg\AppData\Local\.#\MBX@16E8@1C91D08.###
c:\users\weinboerg\AppData\Local\.#\MBX@16E8@1C91D18.###
c:\users\weinboerg\AppData\Local\.#\MBX@16EC@BB1D08.###
c:\users\weinboerg\AppData\Local\.#\MBX@16EC@BB1D18.###
c:\users\weinboerg\AppData\Roaming\AcroIEHelpe.txt
c:\users\weinboerg\AppData\Roaming\AcroIEHelpe005264.dll
c:\users\weinboerg\AppData\Roaming\AcroIEHelpe005270.dll
c:\users\weinboerg\AppData\Roaming\Adobe\plugs
c:\users\weinboerg\AppData\Roaming\Adobe\shed
c:\users\weinboerg\AppData\Roaming\srvblck5.tmp
c:\users\weinboerg\JavaLoader.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-06-28 bis 2013-07-30  ))))))))))))))))))))))))))))))
.
.
2013-07-30 16:35 . 2013-07-30 16:35	--------	d-----w-	c:\users\weinboerg\AppData\Local\temp
2013-07-30 16:35 . 2013-07-30 16:35	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-07-30 16:12 . 2013-07-30 16:13	--------	d-----w-	C:\setup
2013-07-30 15:47 . 2013-07-30 16:15	--------	d-----w-	c:\program files\MyPC Backup
2013-07-30 15:46 . 2013-07-30 15:47	--------	d-----w-	c:\users\weinboerg\AppData\Local\VisualBeeClient
2013-07-30 15:46 . 2013-07-30 15:47	--------	d-----w-	c:\program files\Plus-HD-2.5
2013-07-30 15:46 . 2013-07-30 15:46	--------	d-----w-	c:\users\weinboerg\AppData\Local\VisualBeeExe
2013-07-30 15:46 . 2013-07-30 15:46	--------	d-----w-	c:\programdata\VisualBee
2013-07-30 15:46 . 2013-07-30 15:46	--------	d-----w-	c:\users\weinboerg\AppData\Local\emaze
2013-07-30 15:45 . 2013-07-30 15:45	--------	d-----w-	c:\users\weinboerg\AppData\Local\Wajam
2013-07-30 15:45 . 2013-07-30 15:46	--------	d-----w-	c:\program files\Wajam
2013-07-30 15:44 . 2013-07-30 15:45	--------	d-----w-	c:\users\weinboerg\AppData\Local\Smartbar
2013-07-29 19:20 . 2013-07-29 19:20	--------	d-----w-	C:\FRST
2013-07-29 16:23 . 2008-01-02 15:37	192512	----a-w-	c:\windows\system32\igfxres.dll
2013-07-10 23:03 . 2013-06-04 01:50	2049024	----a-w-	c:\windows\system32\win32k.sys
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-11 21:44 . 2012-04-03 07:36	692104	----a-w-	c:\windows\system32\FlashPlayerApp.exe
2013-07-11 21:44 . 2011-05-17 04:58	71048	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-08 04:37 . 2013-06-12 19:48	905576	----a-w-	c:\windows\system32\drivers\tcpip.sys
2013-05-02 22:03 . 2013-06-12 19:48	3603832	----a-w-	c:\windows\system32\ntkrnlpa.exe
2013-05-02 22:03 . 2013-06-12 19:48	3551096	----a-w-	c:\windows\system32\ntoskrnl.exe
2013-05-02 08:25 . 2012-07-11 21:31	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-02 04:04 . 2013-06-12 19:48	443904	----a-w-	c:\windows\system32\win32spl.dll
2013-05-02 04:03 . 2013-06-12 19:48	37376	----a-w-	c:\windows\system32\printcom.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-22 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-11-28 59280]
"ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-11-28 59280]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-04-19 18678376]
"Browser Infrastructure Helper"="c:\users\weinboerg\AppData\Local\Smartbar\Application\Smartbar.exe" [2013-07-09 20992]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-14 4399104]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-07 839680]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"Play AVStation TV Scheduler"="c:\program files\Samsung\Play AVStation\TvScheduler.exe" [2007-01-09 73728]
"ViivMonitor"="c:\program files\Intel\Intel Media Share Software\ViivMonitor.exe" [2007-03-10 69632]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
"Skytel"="Skytel.exe" [2007-03-14 1822720]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdc.exe" [2007-01-24 563080]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2012-11-28 151952]
.
c:\users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MyPC Backup.lnk - c:\program files\MyPC Backup\MyPC Backup.exe [2013-7-1 1945128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"NoHotStart"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs	REG_MULTI_SZ   	BthServ
WindowsMobile	REG_MULTI_SZ   	wcescomm rapimgr
LocalServiceRestricted	REG_MULTI_SZ   	WcesComm RapiMgr
LocalServiceAndNoImpersonation	REG_MULTI_SZ   	FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{54E1342C-1FDF-4F2A-98AB-4E82A5616FC8}]
2009-03-02 11:49	8192	----a-w-	c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-07-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 21:44]
.
2013-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 10:45]
.
2013-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 10:45]
.
2013-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job
- c:\users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-30 23:23]
.
2013-07-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job
- c:\users\weinboerg\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-30 23:23]
.
2013-07-30 c:\windows\Tasks\Plus-HD-2.5-chromeinstaller.job
- c:\program files\Plus-HD-2.5\Plus-HD-2.5-chromeinstaller.exe [2013-07-30 15:46]
.
2013-07-30 c:\windows\Tasks\Plus-HD-2.5-codedownloader.job
- c:\program files\Plus-HD-2.5\Plus-HD-2.5-codedownloader.exe [2013-07-30 15:47]
.
2013-07-30 c:\windows\Tasks\Plus-HD-2.5-enabler.job
- c:\program files\Plus-HD-2.5\Plus-HD-2.5-enabler.exe [2013-07-30 15:47]
.
2013-07-30 c:\windows\Tasks\Plus-HD-2.5-firefoxinstaller.job
- c:\program files\Plus-HD-2.5\Plus-HD-2.5-firefoxinstaller.exe [2013-07-30 15:47]
.
2013-07-30 c:\windows\Tasks\Plus-HD-2.5-updater.job
- c:\program files\Plus-HD-2.5\Plus-HD-2.5-updater.exe [2013-07-30 15:47]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=hp&installDate=30/07/2013
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{0D56E386-F8C6-4FBC-9A7E-E8DA50072D26} - c:\programdata\Codec-C\bhoclass.dll
WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
HKCU-Run-MobileDocuments - c:\program files\Common Files\Apple\Internet Services\ubd.exe
HKLM-Run-Malwarebytes' Anti-Malware - i:\malwarebytes' anti-malware\mbamgui.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Malwarebytes' Anti-Malware_is1 - i:\malwarebytes' anti-malware\unins000.exe
AddRemove-{2EF17083-57D4-4D64-AE4F-55F32A2C4571} - c:\programdata\Codec-C\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-07-30 18:35
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse... 
.
Scanne versteckte Autostarteinträge... 
.
Scanne versteckte Dateien... 
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\9ef44980]
"imagepath"="\??\c:\windows\TEMP\88BB.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2013-07-30  18:39:00
ComboFix-quarantined-files.txt  2013-07-30 16:38
.
Vor Suchlauf: 2.367.422.464 Bytes frei
Nach Suchlauf: 2.498.179.072 Bytes frei
.
- - End Of File - - 1A95794241B2D8D2222C0DD22882592A
61A349592C4728853F4A90FF78F7628E
         
So, ich starte jetzt neu!!

Kurze Info;

Es gab keine Fehlermeldung!!

Alt 31.07.2013, 08:14   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 31.07.2013, 17:30   #9
weinboerg
 
Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Hier der LOG von Malewarebytes Anti Malware
Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.07.31.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
weinboerg :: WEINBOERG-PC [Administrator]

Schutz: Deaktiviert

31.07.2013 18:14:51
mbam-log-2013-07-31 (18-14-51).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 225095
Laufzeit: 12 Minute(n), 2 Sekunde(n)

Infizierte Speicherprozesse: 1
C:\Program Files\Wajam\Updater\WajamUpdater.exe (PUP.Optional.Wajam) -> 2412 -> Löschen bei Neustart.

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 10
HKCR\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\wajam.WajamBHO.1 (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\wajam.WajamBHO (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SYSTEM\CurrentControlSet\Services\WajamUpdater (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 3
C:\Program Files\Wajam\IE\priam_bho.dll (PUP.Optional.Wajam) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\weinboerg\Downloads\setup.exe (PUP.Optional.Ibryte) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\Wajam\Updater\WajamUpdater.exe (PUP.Optional.Wajam) -> Löschen bei Neustart.

(Ende)
         
Adwcleaner
Code:
ATTFilter
# AdwCleaner v2.306 - Datei am 31/07/2013 um 18:36:52 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : weinboerg - WEINBOERG-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\weinboerg\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\user.js
Ordner Gelöscht : C:\Program Files\1ClickDownload
Ordner Gelöscht : C:\Program Files\Ilivid
Ordner Gelöscht : C:\Program Files\Wajam
Ordner Gelöscht : C:\ProgramData\{B49A644A-1076-4A3D-B124-DAA7862F2318}
Ordner Gelöscht : C:\ProgramData\Premium
Ordner Gelöscht : C:\ProgramData\visualbee
Ordner Gelöscht : C:\Users\WEINBO~1\AppData\Local\Temp\Smartbar
Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco
Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Smartbar
Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\visualbeeexe
Ordner Gelöscht : C:\Users\weinboerg\AppData\Local\Wajam
Ordner Gelöscht : C:\Users\weinboerg\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\weinboerg\AppData\LocalLow\Smartbar
Ordner Gelöscht : C:\Users\weinboerg\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\weinboerg\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
Ordner Gelöscht : C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\1ClickDownload
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\ilivid
Schlüssel Gelöscht : HKCU\Software\Iminent
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2EF17083-57D4-4D64-AE4F-55F32A2C4571}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\SmartbarBackup
Schlüssel Gelöscht : HKCU\Software\SmartbarLog
Schlüssel Gelöscht : HKCU\Software\Wajam
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\1ClicktorrentFile
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\1ClicktorrentFile1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033438.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033438.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033438.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ilivid
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\2B1E51D87B2D71A44BB42DDD5E894160
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\2B1E51D87B2D71A44BB42DDD5E894160
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BBA74401-6D6F-4BBD-9F65-E8623814F3BB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\oneclick
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\oneclickmg
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2CF0D01-7657-48AA-98C9-AE5E64757FCC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco
Schlüssel Gelöscht : HKLM\Software\ilivid
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\817FDB46B46DE8B4AAD499F1DAFF341D
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5A9327D31011C244A196F700637C701
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6B84CEB2810F104BA0E5FC5C8EACD7E
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2B1E51D87B2D71A44BB42DDD5E894160
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4BD8E034-E0F4-4509-A753-467A8E854CD8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Schlüssel Gelöscht : HKLM\SOFTWARE\Software
Schlüssel Gelöscht : HKLM\Software\Wajam
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16496

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013 --> hxxp://www.google.com

-\\ Mozilla Firefox v [Version kann nicht ermittelt werden]

Datei : C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js

[OK] Die Datei ist sauber.

-\\ Google Chrome v28.0.1500.72

Datei : C:\Users\weinboerg\AppData\Local\Google\Chrome\User Data\Default\Preferences

Gelöscht [l.26] : keyword = "search.snap.do",
Gelöscht [l.30] : search_url = "hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=[...]

*************************

AdwCleaner[S1].txt - [15487 octets] - [31/07/2013 18:36:52]

########## EOF - C:\AdwCleaner[S1].txt - [15548 octets] ##########
         
Hier kommt das JRT Log
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.9 (07.30.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by weinboerg on 31.07.2013 at 18:56:58,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Successfully stopped: [Service] backupstack 
Successfully deleted: [Service] backupstack 



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\visualbee
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\visualbee
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322342238}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550355345538}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366346638}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355345538}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366346638}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\weinboerg\appdata\local\visualbeeclient"
Successfully deleted: [Folder] "C:\Users\weinboerg\appdata\locallow\codec-c"
Failed to delete: [Folder] "C:\Program Files\mypc backup"
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0042C984-ACED-49D6-A88B-9B259E20C97D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{00C35C93-764C-4403-9D3F-71F1CD71C1AE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{00FCD90A-D3C1-4D86-8534-CD76425E3138}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{01B2D8FC-F912-4547-978D-BC79AA9B5E15}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{02202EA8-754C-41E5-9F34-42AD4B345C3F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0321EEA5-E980-4223-8ADA-9BBEF88D81C3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0366F02B-157F-4B41-92F3-7A47DCBE6925}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{03C7C968-B55F-43FE-B008-132BEB2F7BF9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{03F5AF8E-42BA-4A73-A9FB-49F0F02FA094}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{043E277F-CFC1-4CFF-989D-5EA259441107}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{04E9D79F-AD0E-4EAF-BAB6-FC55C9C9055E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{065B5F3F-6F7B-4C97-8597-F4A956350932}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{067E0499-402A-49D2-A4FB-A985316359AB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{06B9372A-C02D-4ABE-A4D6-71BF0BCC4567}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{088EEBBE-BE43-4E69-960F-B105DF560209}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{08AE343F-BC20-43DB-BB69-29A9D5DBC404}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{093C441F-484D-47E9-B010-2B3D4E81D4F1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0B191973-39A1-4052-BD89-FFC90D24DA0E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0B76A24D-A18A-45CE-8318-00A8F5C61A83}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0B89CD60-6E32-4CCE-BBD9-C44D13A078C2}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0C2D9ADD-6F15-4FAB-A26E-E77A8CF87240}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0C986F78-4C8F-4A47-BA3B-E308FD06F1E7}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0C9F3176-2632-4B12-9049-3AD7355ED209}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0CE6AC60-6137-4121-BB8B-B9747D419D72}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0DA4775E-A600-432A-8374-74DFFE7A5B72}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0E152A4B-EBEF-4691-9877-936FD708C9D5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0E46166F-1B03-4EF1-94B6-AF2D3118F91C}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{0EC5CEF1-A299-482E-9543-93E1C7A6A9D1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{10392798-0BC6-4848-AA35-4BDA38A9C364}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{10925373-7875-4E05-958A-C4933703A51A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{115E61A3-F743-4404-BE16-379335CFF0E5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{12E01FE3-4607-490E-8266-7B2A844777A8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{14AAA05F-91A9-4AD9-A2BC-056455F63507}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{155F5FAB-9F94-453E-92AC-9A7EBDE460D7}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{183DB6A0-E6CC-4A24-A7F6-280144BCFEBD}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{18E7F753-468C-440B-8B1C-C5B02EA03181}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{196766BE-6DD6-44AB-9266-DFAE77570C9B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1981921A-98EB-40DB-8E2A-1B0ABFF2CBF9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{19CAE532-FFBD-44DD-AC9D-1EA3BCF31BDC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1ABB056C-8AAC-4772-A190-1EDF453E6B25}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1BC83E5F-64A3-4B8C-8E94-B1C349BA46E3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1C4B509A-5AB8-443C-99CD-5DEA5DE6D5F6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1C9E6330-4310-46B2-A906-3BD215CD4473}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1CEBC406-FB90-4427-8A50-B7489D4E2A28}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1D3AF3CB-4453-415D-90C3-A8D4503D1AD9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1E667D0B-C98A-4FFE-A298-9EF595EBA4D8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1E7D5E19-AD5E-4103-B216-B8DAE5BD8D80}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1EB0D0A0-3429-4E83-B6D6-049F67E6D0D9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1F4C0682-2F05-4233-8951-19BA63DC5FFB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1F6EF83A-FA0D-481B-971A-F84FD304E691}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1F878F8F-599A-4787-A71A-5E3C07755F51}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1FAD9CCA-1233-401F-BF07-7953CD1EB59A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1FCADF76-D3CA-4C7D-B341-CBBF64E55327}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{1FE0FBA5-3C95-44A9-AFCE-4554DB69F0E9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{211F7F50-F3FB-46EF-A2E3-E53B836B7A3B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{21410747-2B0E-4254-8094-E57BDF10CB9B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{21CBF85A-E1CB-41DE-A180-AACA7CFADE7C}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{22A597E7-90D7-434B-A0A6-FE766362BA04}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{24475C3C-4351-4CBB-83B0-15A0CB4B95D0}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{24F72209-E94A-457D-95EB-1DDA955713E5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{259B7BB6-C40E-44D4-85DE-AF53919E2EE6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2659AEBB-9100-4A8F-8BFE-66A8FCBAE2F3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{26D700F9-5403-4C77-9628-35E12826D4AB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{270507F9-C4ED-4714-AA43-C44615B2D60A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{27FB5604-BBB2-4653-813D-3551AA29D3C8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{291929F9-3E9A-4EDE-9C75-100BCF1ABC49}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2AA81C7D-47D7-43E9-B349-6ADF1FF98B30}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2AA8DA0A-8D4D-4F8B-AC24-BCEC32B51919}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2AE35B52-A33F-4F6E-ABA4-B4021AB4420C}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2C1CCA18-2B0C-4269-83BD-ABD53F0F32AF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2D49AE29-84C2-448A-88D4-8ED8CCB3BCB6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2DB47F16-3118-44EB-8DD5-B79DD24CEFD5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2EAE47C0-4C2A-4F56-9A12-9BE79C2E95B8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2ED01AA6-2676-4F40-8A20-D571C55CDB9E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2F2F016B-8E31-4E4C-A57D-98575077E1A4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2F85E16E-0E6F-4DEE-A778-725BE5A26C94}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2FF52965-952C-45E7-9F90-B649198E95D3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{2FFF92BB-26C2-40E7-9A10-B8AE14DE8CFF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{308BF049-F9CB-463A-A2F1-1CF5B9213534}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{30F1C9D6-5034-408F-B8A7-0C1886059D5D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{31A39B38-0599-4EFD-95B8-5756803D750C}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{31CDC924-CBAE-453D-9263-B7BAF990185E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{32408C75-3E3D-48AE-B721-510985CE8A5E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3337B9D8-B9A8-4E46-A59B-EEA9AD00F198}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{33A969E3-1AE4-4A86-BD25-1B536D54A02D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{34147F8D-47A6-4C10-931B-A7AFE20BC3A5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{34A46D83-E9DE-4280-8050-5CD83BAB60C0}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{34A908D9-C22C-477E-9187-E8154E44637F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{352B23EA-3558-4C24-871F-9E0CC925D8E4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{35FBEBDD-63FB-4E87-A8BC-6107E41EECC2}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3602CBDE-1939-4FFC-AED2-A5B8E5AFEDAB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{36F4C078-4C45-4FF8-828C-6355B488F115}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{37330B98-E209-43D0-9894-D0810D09B7F4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{377D8874-0750-4032-9289-D86D93DA9531}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3823F32A-F258-4085-92C0-46692EB8BC11}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{382D85ED-EC24-45E8-B207-BDE3970B5694}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3851BCFC-DA38-4F4E-AD83-635E180881FD}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{38F41AAA-98D7-4E41-BE5C-674AF261F5E1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3B45D076-DCF4-491A-BCAB-96670E7DFC87}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3BC1848A-2CA8-482E-9284-58571A8569D4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3BD0AFFD-76BC-4480-8A6F-EE406D0234A2}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3BDB7FCD-3AF5-4CF6-A3E3-196C26A49DB1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3D8BC93F-ACA1-4E32-8590-8D8BCA8310A3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3E138183-91B7-4266-8E85-86F0DD5C3B94}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3E432AF5-BC8B-40CA-B710-6B8A5A0036F6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3F817716-6DAE-4EA1-9C15-80E604202ABC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3FEA1DCD-C2E4-46EF-AADE-57DB4DF83A98}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{3FF890DB-2265-4164-BA74-9CB81296D7FF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{40246073-D22F-4871-9214-7A08DB73A49D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{40646555-ABCD-4170-8BDE-E3108337A911}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{412A4A17-6CFB-4E58-B6E1-EB8FBF2F2DC1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{41FC8921-F9DB-4D91-88A9-8657B3C2812D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{42CC2448-6A7C-4BAF-B390-798FCE364127}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4410C1F2-7D83-4D31-AB60-09542C155055}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{444A8E82-03DE-48D5-A00E-3C2E4F7CC2A1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{449248B2-2390-4EF4-A365-61782A466102}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{44C8CAEF-C829-4E5C-B373-61DDFC2612EB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{44D17189-5DCB-4235-BB24-F271B9E4E0E6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{45892BC5-FEDC-4DE4-BF96-1C769118668F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{460747F9-4160-4C4C-9DA1-FE04A4479D33}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4690CB19-D305-4A4F-B3EB-17DE84675CD2}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{46E22705-94EE-4DA6-8E6C-2502809A0C40}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{47830DD4-A64F-4D81-824D-725ADCAB0684}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4786C238-C80E-4546-A134-430279A2C3CC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{488C2B92-D478-4F7E-AF5E-FCCAC4A56E99}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{48A381CD-6C1D-4512-BC31-C3ACB60CCC64}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4938CB98-D0C8-4295-90AB-E1913CF79B10}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{49B3E043-E82E-426D-B356-F225175EEDBC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4AA05E04-54FA-436E-8594-201BF35397CA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4BADDF41-6B41-4D9D-BCD0-4CDF4757E4F0}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4BB4DFEA-59DF-4F7B-B0EB-6E675C2DFE16}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4C1928F7-D01D-4E6C-A52E-45C59BE2D333}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4C42A391-92A8-418F-887B-98E656841FAB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4CB4D907-FBFB-40E9-AE14-EC1D3328F184}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4CC53112-99DF-4188-B640-9757D1B3D858}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4CD2DF11-B5C4-4C2E-AB44-10DA2761172F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4DE4BA56-5E86-4526-8757-6A9C823DE30F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4E29102C-4CF5-4B74-A4EA-18CC00AD475B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4E61C03F-20CE-4F72-8830-C2C39B5A9DEF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{4F5C4216-66B9-4E56-A5B4-A5AA0401A609}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{50C498AB-0CD0-4925-927D-0C0C3E95326A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{50D9DDE6-E4C7-4D2D-85C8-7083B583E49B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{51AA408C-8C79-4007-B2BC-064BA0057AA5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{51FC2214-678B-4903-97C8-61B21416A283}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5257980B-7969-47E1-8BAC-457EA18319C5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{52C7E434-C45A-4EF5-A7AC-DEE393F84CCD}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{52FF1D2F-6B18-4377-B860-777263C1CA65}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5329446C-245B-4598-AEDC-54BDAC4CA6D3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{532FA649-7C77-4CBB-AB92-7A85F8C4337D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{543D0B29-7103-4F87-8D9E-F3E6D51FA5A4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{54DE1D2B-86CB-4AAF-BFAC-1F325C61AF9A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{54F12861-1482-4417-B40F-7AE9693AF9EA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{54F4E9EA-376E-4CAD-9962-7FCC6F5C9F8A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5616ADCB-2347-4F63-A155-28615ABDBCF9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{575AB408-53AC-4B4E-B6AE-A56A3031A1ED}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{581114C9-542A-46F1-8A2C-C2C27E26F034}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{58D49B5B-4B23-437B-996B-0235FAB9D429}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{58FCCDAA-6FB8-4FA3-BD0B-49A1E3EAE3EC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5907959E-95C7-4DF0-AE87-96ED30FB1BEC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{59FED3A2-5D2B-4F7D-B821-8C5C8ABE0CDA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5A3AFFF0-C787-404A-9D54-BF87CEBA734C}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5A57DCC5-DD28-4120-8C12-A5A2027F75BB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5A9525D3-F10F-45A9-BA15-C22783C0AC21}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5B7E50E4-5FB0-4D30-9ECA-7F7C477156D5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5BEFDA32-B563-4A4A-B14A-1DE81DB79385}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5D5A63C7-C083-4447-AA25-40C67B3FC400}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5DA8582B-BDA3-41C7-8831-88FDB4EA3A5E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5DC8C9B2-4D1D-4282-A025-5C8543F6976A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5E2F0129-6636-469F-819E-FBAAE59860E9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5ED0A1BB-9B00-4406-9D5B-A683E7FC38E4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5EDD6E88-E11E-4F8A-8BE8-7755CBF2FB18}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{5F9F127D-F1D5-4CEE-B1A2-ED4B93BD486F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6002A7C0-4F89-4397-964A-A73F4CF716E6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{61206AA2-6F00-4C83-8793-E6E1E8547741}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6138F2EF-232C-45AD-B511-EB48274A17C4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{626B1C67-D720-4D11-9F63-3C3E42007C73}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{628F5020-1498-41C1-B3E8-14D3D1775A92}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{64A78480-96DD-4D87-AF62-246CD3F98721}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{65AB96CD-6682-4D61-81D6-925A9C5925D5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6919C84B-1664-4873-ABE0-E766FFD8CD0C}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{69CCEE85-19B0-4987-B444-189E8D7B50F8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{69FE1DDE-3F44-4360-8F60-F997EEB0F745}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6A645924-439E-43D2-A92B-A0F03A6E0418}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6B2E1584-6F48-4574-A776-2B917222CF07}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6B750117-D9C2-4AF9-A08F-43674519EFEE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6B9ECCFE-B5D4-4FA8-9A76-91A91547CD31}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6D49ACA4-0030-4298-8FFA-A6AD5BF4E8F8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6DA678AE-303D-40B5-9835-EE3D0DE349B3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6DE955D3-49A2-42D8-9BB3-5995246B86FF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6E73AA62-32A6-4B38-9AB9-A62ED451776F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6EE90BC0-A936-432A-9790-254B76F4DB1A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{6F2D1121-C88F-4B55-8FD7-35D1EA3FB737}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{708F73B5-AE2B-487E-9BFD-46162EE9040F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{711428AC-F683-4E0A-812C-4128E97D83C7}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7156E135-E34D-4EF6-9DE2-B7CA4C419813}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{72D98DEA-CD75-421B-B465-EFA128774356}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{73DAACA1-2442-44AF-971E-E7525CC52F0F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{756E9E38-E51B-4EB7-B82D-E97FAE5477B8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{75B489C9-719E-4DBD-BA10-5C1A3C607899}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{75B5308C-D004-4D5C-8CFA-BD8EC7654204}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{75E5E5A2-AF6A-4147-AB8B-AB62A02DE27F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{76550045-48ED-4403-892D-39DD2B9A75DE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7790BE18-FFBC-461E-8EBC-4C0C137DFF20}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{77AA2DAF-81BA-4B41-8F4A-F73D8E57A034}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7868658D-D5AA-4CD5-AE9D-2F27D5229A34}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{79D66341-699E-4D61-BC44-BE5C34B2D8AA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7A596325-08BE-43ED-8A04-84F4692334B7}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7A83B5F4-8B51-410F-8A5D-6E990856FBF1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7ADBBA3B-7B55-4ACB-9732-7B101BC09119}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7BC7128A-A613-4AA6-BDAE-EF5DC72B75A6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7C6F063B-C7A1-4845-B031-85210C5CF9C1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7CDB9372-2194-4690-9671-4EAEA5B6A071}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7D0625F1-EDEB-49A9-B120-E34C436986B7}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7D565F96-C83A-4E4B-9FF6-25917A3F7E4A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{7E5B3592-23F7-49EE-85C9-E98F10414E31}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8078598C-2E24-4805-B6C0-338B18898B5E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{80A7C49C-9424-42D2-9905-625A7518F467}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{80CA5C65-7270-4F51-ADCF-71B4C139EE93}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8102D84B-9598-4DDB-9668-5C1244BCDCA1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{813960E8-A06E-4778-A490-9E683D53C8F2}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{81F556A8-03CA-4F53-8929-11BC5DCA3A1D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{82992F07-0C3E-421F-A13D-A82454B39696}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8301B233-E533-4814-B21B-F20CFB13FC59}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{835AE2B4-683B-42EB-AF79-5D37B000D33A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8367EDC9-341A-4CBA-B602-097576277A3B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{837BB3FD-FB68-4FD8-9526-60D35A48FE7A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{83991402-1469-465E-A13B-83F1047B2B71}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{841C8774-0DC3-4484-A279-13DFA0AA265D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{85333D89-B951-42AE-BCF9-C4F694D977DC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{85B1C22B-31C5-406F-8E83-4018B6B6E980}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{860CDE5F-528C-4BA3-8229-6F09A70F976B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{88C36A5C-C3C4-4DD8-9CE4-0209186BA969}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{89B96DF3-60AF-4CCD-956D-6BB45A868CF4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8A01B334-5A25-41D4-8357-7CE49F5CCC8F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8A761960-CEA1-4703-8D88-78F0F6D09307}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8AC5C3F5-3D77-4C5D-A00C-FD66C8282653}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8B323017-0EAA-44CB-AE33-5C413DAEDD13}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8BEF9EB7-C787-443C-8C8D-622E156A1F68}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8C25491F-D7D7-46D9-BBCC-0E4C6B34CBA2}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8C2F612C-90A0-478F-B4D2-108F240F94BB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8CF8C3FB-20E6-477A-B1CD-D7AA8395DA65}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8D9EAE20-1BBF-406E-A7BB-1A8B9A77D4DD}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8DA2FE81-393E-4DB7-BA48-986EAC587B48}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8E6EAA1A-AFA4-40FE-BAB0-770A150D1A1B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8EE6ABB1-CEE2-48CB-A9C5-1BE7D231E2CB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{8EF38603-1BE0-4B73-A429-AC0B454D2AC9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{90073CCA-25DA-40F0-B498-4B88C6B32D0A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{902CEBC7-D27E-4B79-8233-9E0A3384DB50}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{905E0BBD-5064-4FDF-BC1A-5009CDF92316}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9097D048-6D27-4C81-83AE-619E866AD89F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{91653C37-D931-40D3-9920-8716135BD861}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{91CF9961-A49C-4346-9157-A1173CB1751A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{91D07CF3-5CD3-467B-86A2-184ED6084933}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{92B64C56-E5B9-46D7-9452-B8A681709367}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{95FF93FB-5B0A-4208-AD7A-13DF8F23B562}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{961B5C0B-A945-4E8E-B993-CD963894EA14}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{972DCE75-8743-48BC-8CD9-B0C6301754D6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{973EC03B-4FE7-4931-99E1-5E6DBE96A86F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{99E656E2-AA46-4CF2-8FD5-9724D99E98FA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9A487EC5-94D7-4D6B-B9FA-CC3CDEE51D60}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9C676D81-F234-49DD-8B1F-0F8260D7E94C}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9CDD9B6F-5164-4C94-A673-0517914FBC9E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9D70A1E5-06C6-4DB0-A23F-2EBE4C658BD7}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9DFB60E0-B34D-424D-94DC-9700CB065963}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9F3C1ABB-75CA-4C1B-868A-08EB68E2C8CD}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{9FE44A48-E2D4-4325-A698-20D617A10297}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A0282F8D-D972-44B9-85FC-517769ABC29E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A0448946-B1DA-47E3-9DF6-9F11BDB23435}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A05B8D37-BEE6-4E80-86DD-200BE51F632F}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A1125DED-1738-4D12-95CC-DEBE061B31A7}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A206F98E-5D94-4860-9403-CACFAEDB12EB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A49A79A1-9475-4B29-97DD-7D33837D17B2}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A545CBB5-761C-4662-BEEE-C9DA50408479}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A59E4BE5-0F0D-4262-9E3C-24BD78BF8080}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A6279BA0-D2DC-415E-9DC6-B1D2CC0E5036}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A6C20B57-C40F-41AD-A1B4-B710470B89B2}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A6F77335-D450-4405-9B50-F8D1BE173D67}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A8F806DF-81D6-4592-AFE5-DB8138888DBE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{A9ABFD58-0A6A-4C41-9AB5-F89C596BDCE5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AA87A7F6-4273-4FE7-8B2C-D425C34822FF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AAD4B493-8220-4BF8-B316-396435B5C424}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{ABF7E1CF-1667-4EF6-97A0-E4864418936D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AC1A6DDF-CF2F-4C56-BB99-06F285CE251E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AC53FAEB-60C5-45CC-A711-F3F7CA0278A9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AD602622-4713-4A92-9711-89A5F06B71C5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{ADB761F2-7E4E-43BA-B5B5-CC5592DA61DB}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AE621C9A-0415-4176-B5C7-6924F8476238}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AE73966A-2EAF-4864-AAB7-7C861F4BA9D1}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AE8F003B-7FAA-43F1-B242-EDEA6ACA32B3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{AE981044-6820-4D67-9B38-6ECEAE9E3BBA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B07C4AE3-2517-41AD-A733-02903D6A9FAF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B11BB211-53C2-4A4C-A3BD-C8A42582CA14}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B1442DF0-73ED-467A-A04B-C8A47B4ABCA9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B1A9AF8D-9F21-4BE6-8106-88F0EC5ADE37}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B2B13453-7D6F-4409-81B8-0A2EB361A313}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B3616B93-8D9E-4E82-A098-9EA15934E038}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B3A029E1-B283-442D-B379-22844DF61B22}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B44E8CF0-DAE4-4003-B14B-92E6EA9A3142}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B474E805-152E-4728-878E-4BDAE5C931FE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B5F8EFE6-EEDC-4420-A2B3-ABFC6D528B38}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B637687F-B93E-49B3-85C6-5C843791FFD8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B7EE30BA-6107-4FF2-B769-7327414CA9EF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B906BA16-D390-4CDB-BC84-6B61883727DA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{B908EBDB-3753-431A-BB7F-527DF1B4F32E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BA79A5EA-3C9B-4071-93AF-016F05C5A1A8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BABFF9D2-AE3A-4726-A43F-BA722CEA4F5B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BAFC1669-2DDE-43EE-8C89-134D05106FAC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BB49CA81-AE50-49C1-9BCD-CB25401E3AE0}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BBD7A80E-9DBC-4213-98E9-71F1C28209DD}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BCEC224D-7102-45FA-AC98-8333D9ADAD79}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BD42EF2D-9DD0-4F93-B176-E7D3EF8FD5B9}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BDB6701F-338D-45BD-9994-DB501A0135FF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BDDBAC9A-D6E9-4A15-9703-DCB2E83A2ADE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BDFEA299-68CF-4CB3-A539-81E36CB35CE8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{BE784E85-53CF-4AFE-A9F3-34E7BB49017B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C13C65F5-D131-4D2E-AB7E-F3EA5C7752D0}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C15EC694-05B2-4EDA-93BA-83BD7E9A1C1D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C300BF15-30B1-4478-AA9A-E42561996A1B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C346ABEF-3366-4A67-B90F-60C967546B86}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C4E9796E-C42C-4747-AABB-BEDE89FAD5FA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C55252E2-F75A-4497-B830-01172FDA29BC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C5B16E28-D6BB-47CF-9C6A-9B94FBCA1ACC}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C71D959C-07A1-4A20-B751-AC004E4F33F4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{C83FFB65-2A2A-4F3B-9CF5-89951CDE188E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CC722136-D99C-4DE2-BA30-27677D62B639}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CCE3D820-421A-4381-8A56-1817E1E0B16B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CDE65A7B-22EE-4B96-9439-E9AC93590E97}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CE11049D-0DA3-4345-AC54-1772722A8CCF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CE2E92E2-7011-428A-83C3-7D1F7EC904C7}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{CE8A6C3E-1C19-46E6-ABFD-3B0D7F4C2BCE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D02F298B-B995-4915-8C14-C13FC0A68F8B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D26CEF07-B324-4332-9082-4B5621D266C4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D366FA38-E67E-48FF-82A9-1EC7EB8617FE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D3E71BE4-0B6D-4490-ACDD-21A241966764}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D47B48C3-34DD-49BD-A49B-0106FFB95DAF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D50E78B7-A8E9-4875-98FE-E2CB916BE9E4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D5598389-6D6C-45DA-850F-3A49CD3DBA08}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D5901E26-0167-423A-9207-422DE34462C5}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D5905E94-43F1-4E75-A567-3D7D28E6FCBA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D685850A-3ED0-4F93-8A34-ECDA2A3CA9A8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D809B1C7-DBCE-42DE-ADD1-6431C7B89E31}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D86761FB-8F7A-415D-9D29-8DBC045C9E14}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D8C56337-AA02-4AB7-8F6D-1E84F2F8B59E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D8D6F484-9661-408D-8691-A7FB55208302}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D947A19F-489C-48D1-9F0D-3BC77F4114EA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{D97540DF-4330-4456-959A-7BB28462897E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DAEB2809-AB09-4C08-B002-3E8BAD24C6D3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DC0008B7-026E-49AB-BDA1-A4A8F367AA19}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DCA6E3AB-D19A-4F97-99A4-7444B03705ED}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DDFED81B-5228-4700-8791-6F1177119CDF}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DEFD7900-1D28-4596-BC30-884891B8D9AA}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DF163BE0-6DEA-4515-9BC2-297ABE497BD3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{DFC0FB7A-3868-4728-8FEE-F672E1B97799}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E08E57E9-4898-4CED-9050-E9CD2E62AB8D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E16309B1-4851-4485-86EE-4DDA481EC693}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E183D86A-ABE6-45F4-9DE4-6A20E1C1D820}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E1BB8F90-6097-4260-A68B-378B9450CA9B}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E29B1EFD-E5E2-4917-9700-0774DAE2EC7D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E311C97F-97F2-416E-958D-448B2171F192}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E45AE2FB-FCBF-45EA-BF3B-F3740237A060}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E754DC43-35AC-4BD8-B39E-BA28E3111EA0}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E82DB110-331C-4177-A569-A45F17C66EB4}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E83DEE25-AB68-4552-9CC3-610E46AA75E3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E85F50C9-97E2-4D63-BE29-8B6E16888452}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{E872CE91-A103-45B8-95CB-F8D70D1B2722}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{EBA7EE98-E95A-4D52-91D9-A1F960B91A24}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{EC02D17A-78BD-407A-B168-860788E9826A}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{EE87E53D-7737-4071-98AC-F6CA07ABFEC6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F07D8B23-59A3-4AEC-8D25-E97044D21B1E}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F1046C2A-3D00-42C5-90FE-C16A5030E181}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F4E63A7F-5A03-4D0C-8873-5513F3F6D5E3}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F58E2212-F15A-4337-84CF-40FC5892C700}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F5B7BD6C-CF45-4A0A-A6CC-0EF890331BE0}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F5DF0651-2E2E-40B1-9A99-6D38B8A37D64}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F6A304C3-781B-4A1A-8232-3360413CFBA8}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F6A7B506-DC85-490A-9B6F-109F2BD6CAE6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F778FC8F-56C7-4391-BA33-DED8DBF48506}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F7DC282A-9B28-415C-B4CC-E930186D3117}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F833171C-A4F9-437A-9270-F8C3220D081D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F8F08927-846F-4C7F-BAFC-74F2AD8D60DD}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F91A3405-ED65-4F16-AECE-4EC619078D65}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{F9494F4A-A45A-41C4-99AD-9D2DD7EBF457}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FA2EDF0D-CD84-4BBF-9E95-5E6A518B1829}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FB3620E5-2637-4FD6-B94A-B88429FFC88C}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FC4DF8C6-E158-4C09-AA07-A5B92FF07730}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FD0B60DD-DD3D-4E62-8A71-D3F4ECD3D718}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FD25BC60-03A6-462A-8041-0F0B824F9BA6}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FD59ACF9-CDB7-404E-A065-A32E38AF5EBD}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FE2914C7-5D30-4388-B0CE-80A1921EF70D}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FE8DE347-1CDE-4B28-9A10-A8FAD67970BE}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FF699B0E-395C-4B77-A56E-016778584586}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FF964C4A-D922-458A-ABDA-FF298CA54E77}
Successfully deleted: [Empty Folder] C:\Users\weinboerg\appdata\local\{FFC4787C-62C2-4A9D-A373-3AE9610A3845}



~~~ Chrome

Successfully deleted: [Folder] C:\Users\weinboerg\appdata\local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Successfully deleted: [Folder] C:\Users\weinboerg\appdata\local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31.07.2013 at 18:59:28,45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
und hier das FRST Log

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 04
Ran by weinboerg (administrator) on 31-07-2013 19:06:59
Running from C:\Users\weinboerg\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
(Intel® Corporation) C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(Intel(R) Corporation) C:\Program Files\Intel\Intel Media Share Software\Viivmonitor.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Apple Inc.) D:\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(MyPCBackup.com) C:\Program Files\MyPC Backup\MyPC Backup.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4399104 2007-03-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [839680 2007-02-07] (Synaptics, Inc.)
HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [56928 2006-11-23] (Cyberlink Corp.)
HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [54832 2006-12-05] ()
HKLM\...\Run: [Play AVStation TV Scheduler] - C:\Program Files\Samsung\Play AVStation\TvScheduler.exe [73728 2007-01-09] (SAMSUNG ELECTRONICS CO., LTD.)
HKLM\...\Run: [ViivMonitor] - C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe [69632 2007-03-10] (Intel(R) Corporation)
HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1822720 2007-03-14] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdc.exe [563080 2007-01-24] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] ()
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - D:\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-30] (Avira Operations GmbH & Co. KG)
HKLM\...\InprocServer32: [Default-cscui]  <==== ATTENTION!
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-10-22] (Google Inc.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59280 2012-11-28] (Apple Inc.)
HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59280 2012-11-28] (Apple Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
Startup: C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: msdaipp - No CLSID Value - 
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 38 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - D:\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @innoplus.de/ino3DViewer - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.0 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5

Chrome: 
=======
CHR DefaultSearchURL: (Web) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Move Media Player 7) - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (VLC Web Plugin) - D:\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - D:\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (InoViewer Plugin) - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0
CHR HKLM\...\Chrome\Extension: [ajhcekcffkpnaednoeoegnmnjdlnjjmg] - C:\ProgramData\Codec-C\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR StartMenuInternet: Google Chrome - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-30] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-30] (Avira Operations GmbH & Co. KG)
R2 IMSSync; C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe [368640 2007-03-10] (Intel® Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [167936 2005-08-08] ()
S2 MBAMService; "I:\Malwarebytes' Anti-Malware\mbamservice.exe" [x]

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-30] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-30] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-30] (Avira Operations GmbH & Co. KG)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2011-07-29] ()
R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-30] (Avira GmbH)
R3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [243840 2009-01-23] (Vimicro Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 catchme; \??\C:\Users\WEINBO~1\AppData\Local\Temp\catchme.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-31 19:06 - 2013-07-31 19:06 - 01222064 _____ (Farbar) C:\Users\weinboerg\Desktop\FRST.exe
2013-07-31 18:59 - 2013-07-31 18:59 - 00045343 _____ C:\Users\weinboerg\Desktop\JRT.txt
2013-07-31 18:56 - 2013-07-31 18:56 - 00562430 _____ (Oleg N. Scherbakov) C:\Users\weinboerg\Desktop\JRT.exe
2013-07-31 18:56 - 2013-07-31 18:56 - 00000000 ____D C:\Windows\ERUNT
2013-07-31 18:36 - 2013-07-31 18:46 - 00015618 _____ C:\AdwCleaner[S1].txt
2013-07-31 18:30 - 2013-07-31 18:30 - 00666633 _____ C:\Users\weinboerg\Desktop\adwcleaner.exe
2013-07-31 18:12 - 2013-07-31 18:12 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-07-31 18:12 - 2013-07-31 18:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-31 18:11 - 2013-07-31 18:11 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\weinboerg\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-30 19:29 - 2013-07-30 19:29 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (2).zip
2013-07-30 19:10 - 2013-07-30 19:10 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Avira
2013-07-30 19:04 - 2013-07-30 19:04 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-07-30 19:04 - 2013-07-30 19:03 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-07-30 19:04 - 2013-07-30 19:03 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-07-30 19:04 - 2013-07-30 19:03 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-30 19:04 - 2013-07-30 19:03 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2013-07-30 19:03 - 2013-07-30 19:04 - 00000000 ____D C:\ProgramData\Avira
2013-07-30 19:03 - 2013-07-30 19:03 - 00000000 ____D C:\Program Files\Avira
2013-07-30 18:39 - 2013-07-30 18:39 - 00011618 _____ C:\ComboFix.txt
2013-07-30 18:23 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-07-30 18:23 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-07-30 18:23 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-07-30 18:22 - 2013-07-30 18:39 - 00000000 ____D C:\ComboFix
2013-07-30 18:20 - 2013-07-30 18:42 - 00000000 ____D C:\Users\weinboerg\Desktop\Combofix
2013-07-30 17:51 - 2013-07-30 18:39 - 00000000 ____D C:\Qoobox
2013-07-30 17:47 - 2013-07-31 18:57 - 00000000 ____D C:\Program Files\MyPC Backup
2013-07-30 17:47 - 2013-07-31 18:49 - 00001814 _____ C:\Windows\Tasks\Plus-HD-2.5-firefoxinstaller.job
2013-07-30 17:47 - 2013-07-31 18:49 - 00001194 _____ C:\Windows\Tasks\Plus-HD-2.5-codedownloader.job
2013-07-30 17:47 - 2013-07-31 18:49 - 00001190 _____ C:\Windows\Tasks\Plus-HD-2.5-updater.job
2013-07-30 17:47 - 2013-07-31 18:49 - 00001094 _____ C:\Windows\Tasks\Plus-HD-2.5-enabler.job
2013-07-30 17:47 - 2013-07-30 18:37 - 00000000 ____D C:\Windows\erdnt
2013-07-30 17:47 - 2013-07-30 17:47 - 00000884 _____ C:\Users\weinboerg\Desktop\MyPC Backup.lnk
2013-07-30 17:47 - 2013-07-30 17:47 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-07-30 17:46 - 2013-07-30 17:47 - 00000000 ____D C:\Program Files\Plus-HD-2.5
2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\Desktop\Create Amazing Presentations.lnk
2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk
2013-07-30 17:46 - 2013-07-30 17:46 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\emaze
2013-07-30 17:45 - 2013-07-30 17:45 - 00002149 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-07-30 17:45 - 2013-07-30 17:45 - 00002119 _____ C:\Users\weinboerg\Desktop\Search.lnk
2013-07-29 21:25 - 2013-07-29 21:26 - 00026448 _____ C:\Users\weinboerg\Desktop\Addition.txt
2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe
2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip
2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt
2013-07-29 18:23 - 2008-01-02 17:37 - 00192512 _____ (Intel Corporation) C:\Windows\system32\igfxres.dll
2013-07-27 13:48 - 2013-07-30 11:50 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls
2013-07-11 02:59 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 02:59 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 02:59 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-11 02:59 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 02:59 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 02:59 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-11 02:59 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 02:59 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-11 02:59 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-11 02:59 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 02:59 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 02:59 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 02:59 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 02:59 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-11 02:59 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 02:58 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 01:03 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 01:02 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 01:02 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 01:02 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-11 01:02 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-11 01:02 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-11 01:02 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-11 01:02 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-11 01:02 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll

==================== One Month Modified Files and Folders =======

2013-07-31 19:06 - 2013-07-31 19:06 - 01222064 _____ (Farbar) C:\Users\weinboerg\Desktop\FRST.exe
2013-07-31 18:59 - 2013-07-31 18:59 - 00045343 _____ C:\Users\weinboerg\Desktop\JRT.txt
2013-07-31 18:57 - 2013-07-30 17:47 - 00000000 ____D C:\Program Files\MyPC Backup
2013-07-31 18:56 - 2013-07-31 18:56 - 00562430 _____ (Oleg N. Scherbakov) C:\Users\weinboerg\Desktop\JRT.exe
2013-07-31 18:56 - 2013-07-31 18:56 - 00000000 ____D C:\Windows\ERUNT
2013-07-31 18:56 - 2006-11-02 12:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-31 18:55 - 2007-10-31 02:55 - 01268625 _____ C:\Windows\WindowsUpdate.log
2013-07-31 18:53 - 2012-12-01 01:23 - 00001136 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job
2013-07-31 18:49 - 2013-07-30 17:47 - 00001814 _____ C:\Windows\Tasks\Plus-HD-2.5-firefoxinstaller.job
2013-07-31 18:49 - 2013-07-30 17:47 - 00001194 _____ C:\Windows\Tasks\Plus-HD-2.5-codedownloader.job
2013-07-31 18:49 - 2013-07-30 17:47 - 00001190 _____ C:\Windows\Tasks\Plus-HD-2.5-updater.job
2013-07-31 18:49 - 2013-07-30 17:47 - 00001094 _____ C:\Windows\Tasks\Plus-HD-2.5-enabler.job
2013-07-31 18:49 - 2010-02-06 12:45 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-31 18:49 - 2008-01-26 13:15 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2013-07-31 18:49 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-31 18:49 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-31 18:49 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-31 18:47 - 2007-09-27 06:30 - 00000012 _____ C:\Windows\bthservsdp.dat
2013-07-31 18:47 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-31 18:46 - 2013-07-31 18:36 - 00015618 _____ C:\AdwCleaner[S1].txt
2013-07-31 18:34 - 2010-02-06 12:45 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-31 18:32 - 2013-05-17 23:21 - 00006630 _____ C:\Windows\PFRO.log
2013-07-31 18:30 - 2013-07-31 18:30 - 00666633 _____ C:\Users\weinboerg\Desktop\adwcleaner.exe
2013-07-31 18:27 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\schemas
2013-07-31 18:12 - 2013-07-31 18:12 - 00000906 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-07-31 18:12 - 2013-07-31 18:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-31 18:11 - 2013-07-31 18:11 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\weinboerg\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-31 15:48 - 2012-04-03 09:36 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-30 19:29 - 2013-07-30 19:29 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (2).zip
2013-07-30 19:10 - 2013-07-30 19:10 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Avira
2013-07-30 19:04 - 2013-07-30 19:04 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-07-30 19:04 - 2013-07-30 19:03 - 00000000 ____D C:\ProgramData\Avira
2013-07-30 19:03 - 2013-07-30 19:04 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-07-30 19:03 - 2013-07-30 19:04 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-07-30 19:03 - 2013-07-30 19:04 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-30 19:03 - 2013-07-30 19:04 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2013-07-30 19:03 - 2013-07-30 19:03 - 00000000 ____D C:\Program Files\Avira
2013-07-30 18:42 - 2013-07-30 18:20 - 00000000 ____D C:\Users\weinboerg\Desktop\Combofix
2013-07-30 18:39 - 2013-07-30 18:39 - 00011618 _____ C:\ComboFix.txt
2013-07-30 18:39 - 2013-07-30 18:22 - 00000000 ____D C:\ComboFix
2013-07-30 18:39 - 2013-07-30 17:51 - 00000000 ____D C:\Qoobox
2013-07-30 18:39 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2013-07-30 18:39 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-07-30 18:37 - 2013-07-30 17:47 - 00000000 ____D C:\Windows\erdnt
2013-07-30 18:36 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2013-07-30 18:34 - 2008-03-04 22:39 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Adobe
2013-07-30 18:34 - 2008-01-26 13:12 - 00000000 ____D C:\Users\weinboerg
2013-07-30 18:16 - 2009-03-21 23:16 - 00000000 ____D C:\Users\weinboerg\Tracing
2013-07-30 17:47 - 2013-07-30 17:47 - 00000884 _____ C:\Users\weinboerg\Desktop\MyPC Backup.lnk
2013-07-30 17:47 - 2013-07-30 17:47 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-07-30 17:47 - 2013-07-30 17:46 - 00000000 ____D C:\Program Files\Plus-HD-2.5
2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\Desktop\Create Amazing Presentations.lnk
2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk
2013-07-30 17:46 - 2013-07-30 17:46 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\emaze
2013-07-30 17:45 - 2013-07-30 17:45 - 00002149 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-07-30 17:45 - 2013-07-30 17:45 - 00002119 _____ C:\Users\weinboerg\Desktop\Search.lnk
2013-07-30 11:50 - 2013-07-27 13:48 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls
2013-07-29 21:26 - 2013-07-29 21:25 - 00026448 _____ C:\Users\weinboerg\Desktop\Addition.txt
2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe
2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip
2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt
2013-07-27 14:39 - 2011-12-04 16:57 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Skype
2013-07-26 23:53 - 2012-12-01 01:23 - 00001084 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job
2013-07-19 23:06 - 2012-03-03 21:43 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\vlc
2013-07-19 21:25 - 2008-01-26 13:15 - 00050176 _____ C:\Users\WEINBO~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-07-13 23:58 - 2012-02-28 22:24 - 00002062 _____ C:\Users\weinboerg\Desktop\Google Chrome.lnk
2013-07-12 00:06 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-11 23:44 - 2012-04-03 09:36 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-11 23:44 - 2011-05-17 06:58 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-11 23:44 - 2008-03-04 22:39 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\Adobe
2013-07-11 23:34 - 2006-11-02 14:47 - 00380216 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 23:32 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-07-11 23:31 - 2010-06-03 19:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 03:16 - 2006-11-02 12:23 - 00000240 _____ C:\Windows\win.ini
2013-07-11 03:03 - 2006-11-02 12:24 - 75699896 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-07-11 02:49 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal

Files to move or delete:
====================
C:\ProgramData\xbr6x2Snc.dat

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-31 18:58

==================== End Of Log ============================
         
--- --- ---

Geändert von weinboerg (31.07.2013 um 18:10 Uhr)

Alt 31.07.2013, 19:51   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Fast Fertig


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 01.08.2013, 05:42   #11
weinboerg
 
Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Einen wunderschönen Guten Morgen,

ESET hat, nachdem er die ganze Nachtr gescannt hat 3 Sachen gefunden, hier der LOG:

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=488c7927f1255442a9c5fa1d5dea6feb
# engine=14605
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-31 09:44:09
# local_time=2013-07-31 11:44:09 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1799 16775165 100 95 8816 103353 1573 0
# compatibility_mode=5892 16776574 100 100 11932731 212839777 0 0
# scanned=183237
# found=3
# cleaned=0
# scan_time=8238
sh=DFAD8339A55F72A1354F76959337CAA0956B8C03 ft=1 fh=2d4df1f9f1c82730 vn="a variant of Win32/Spy.Banker.ZJN trojan" ac=I fn="C:\Qoobox\Quarantine\C\Users\weinboerg\AppData\Roaming\AcroIEHelpe005264.dll.vir"
sh=D1988EE0ED8F3DEED5DD1FC370EF64D0CF79ACF4 ft=1 fh=c73162a413d63a3e vn="a variant of Win32/Spy.Banker.ZQA trojan" ac=I fn="C:\Qoobox\Quarantine\C\Users\weinboerg\AppData\Roaming\AcroIEHelpe005270.dll.vir"
sh=3F1EDA047C56CDC4EE518FD161F9B80CEDB6937F ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\weinboerg\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\10684096-51fec1c7"
         
Security Check sagt folgendes:
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.71  
 Windows Vista Service Pack 2 x86   
 Internet Explorer 9  
 Internet Explorer 8  
``````````````Antivirus/Firewall Check:`````````````` 
Avira Desktop   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Malwarebytes Anti-Malware Version 1.75.0.1300  
 CCleaner     
 Java(TM) 6 Update 22  
 Java version out of Date! 
 Adobe Reader 7 Adobe Reader out of Date! 
 Google Chrome 28.0.1500.72  
 Google Chrome 28.0.1500.95  
````````Process Check: objlist.exe by Laurent````````  
 Avira Antivir avgnt.exe 
 Avira Antivir avguard.exe 
 Malwarebytes' Anti-Malware mbamscheduler.exe   
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log``````````````````````
         
...und nun die frische FRST

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 04
Ran by weinboerg (administrator) on 01-08-2013 07:02:53
Running from C:\Users\weinboerg\Desktop\VIREN-Malware Software
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
(Intel® Corporation) C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(Intel(R) Corporation) C:\Program Files\Intel\Intel Media Share Software\Viivmonitor.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Apple Inc.) D:\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(MyPCBackup.com) C:\Program Files\MyPC Backup\MyPC Backup.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4399104 2007-03-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [839680 2007-02-07] (Synaptics, Inc.)
HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [56928 2006-11-23] (Cyberlink Corp.)
HKLM\...\Run: [LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [54832 2006-12-05] ()
HKLM\...\Run: [Play AVStation TV Scheduler] - C:\Program Files\Samsung\Play AVStation\TvScheduler.exe [73728 2007-01-09] (SAMSUNG ELECTRONICS CO., LTD.)
HKLM\...\Run: [ViivMonitor] - C:\Program Files\Intel\Intel Media Share Software\ViivMonitor.exe [69632 2007-03-10] (Intel(R) Corporation)
HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1822720 2007-03-14] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdc.exe [563080 2007-01-24] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] ()
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - D:\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-30] (Avira Operations GmbH & Co. KG)
HKLM\...\InprocServer32: [Default-cscui]  <==== ATTENTION!
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-10-22] (Google Inc.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59280 2012-11-28] (Apple Inc.)
HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59280 2012-11-28] (Apple Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
Startup: C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: msdaipp - No CLSID Value - 
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 38 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - D:\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @innoplus.de/ino3DViewer - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.0 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\weinboerg\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\weinboerg\AppData\Roaming\Mozilla\Firefox\profiles\extensions\prefs.js
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5

Chrome: 
=======
CHR DefaultSearchURL: (Web) - hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=8e5c6fac-7f6e-4ae6-8d6d-70606f5abbba&searchtype=ds&q={searchTerms}&installDate=30/07/2013
CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U22) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Move Media Player 7) - C:\Users\weinboerg\AppData\Roaming\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (VLC Web Plugin) - D:\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - D:\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (InoViewer Plugin) - D:\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\WEINBO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0
CHR HKLM\...\Chrome\Extension: [ajhcekcffkpnaednoeoegnmnjdlnjjmg] - C:\ProgramData\Codec-C\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR StartMenuInternet: Google Chrome - C:\Users\weinboerg\AppData\Local\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-30] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-30] (Avira Operations GmbH & Co. KG)
R2 IMSSync; C:\Program Files\Intel\Intel Media Share Software\IMSSync.exe [368640 2007-03-10] (Intel® Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [167936 2005-08-08] ()
S2 MBAMService; "I:\Malwarebytes' Anti-Malware\mbamservice.exe" [x]

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-30] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-30] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-30] (Avira Operations GmbH & Co. KG)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2011-07-29] ()
R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2589184 2006-11-02] (Intel® Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-30] (Avira GmbH)
R3 VMC302; C:\Windows\System32\Drivers\VMC302.sys [243840 2009-01-23] (Vimicro Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 catchme; \??\C:\Users\WEINBO~1\AppData\Local\Temp\catchme.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-31 21:24 - 2013-07-31 21:24 - 02347384 _____ (ESET) C:\Users\weinboerg\Downloads\esetsmartinstaller_enu.exe
2013-07-31 19:10 - 2013-08-01 07:02 - 00000000 ____D C:\Users\weinboerg\Desktop\VIREN-Malware Software
2013-07-31 18:56 - 2013-07-31 18:56 - 00000000 ____D C:\Windows\ERUNT
2013-07-31 18:36 - 2013-07-31 18:46 - 00015618 _____ C:\AdwCleaner[S1].txt
2013-07-31 18:12 - 2013-07-31 18:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-31 18:11 - 2013-07-31 18:11 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\weinboerg\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-30 19:29 - 2013-07-30 19:29 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (2).zip
2013-07-30 19:10 - 2013-07-30 19:10 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Avira
2013-07-30 19:04 - 2013-07-30 19:04 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-07-30 19:04 - 2013-07-30 19:03 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-07-30 19:04 - 2013-07-30 19:03 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-07-30 19:04 - 2013-07-30 19:03 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-30 19:04 - 2013-07-30 19:03 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2013-07-30 19:03 - 2013-07-30 19:04 - 00000000 ____D C:\ProgramData\Avira
2013-07-30 19:03 - 2013-07-30 19:03 - 00000000 ____D C:\Program Files\Avira
2013-07-30 18:39 - 2013-07-30 18:39 - 00011618 _____ C:\ComboFix.txt
2013-07-30 18:23 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-07-30 18:23 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-07-30 18:23 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-07-30 18:23 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-07-30 18:22 - 2013-07-30 18:39 - 00000000 ____D C:\ComboFix
2013-07-30 17:51 - 2013-07-30 18:39 - 00000000 ____D C:\Qoobox
2013-07-30 17:47 - 2013-08-01 05:47 - 00001814 _____ C:\Windows\Tasks\Plus-HD-2.5-firefoxinstaller.job
2013-07-30 17:47 - 2013-08-01 05:47 - 00001194 _____ C:\Windows\Tasks\Plus-HD-2.5-codedownloader.job
2013-07-30 17:47 - 2013-08-01 05:47 - 00001190 _____ C:\Windows\Tasks\Plus-HD-2.5-updater.job
2013-07-30 17:47 - 2013-08-01 05:47 - 00001094 _____ C:\Windows\Tasks\Plus-HD-2.5-enabler.job
2013-07-30 17:47 - 2013-07-31 21:15 - 00000000 ____D C:\Program Files\MyPC Backup
2013-07-30 17:47 - 2013-07-30 18:37 - 00000000 ____D C:\Windows\erdnt
2013-07-30 17:47 - 2013-07-30 17:47 - 00000884 _____ C:\Users\weinboerg\Desktop\MyPC Backup.lnk
2013-07-30 17:47 - 2013-07-30 17:47 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-07-30 17:46 - 2013-07-30 17:47 - 00000000 ____D C:\Program Files\Plus-HD-2.5
2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\Desktop\Create Amazing Presentations.lnk
2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk
2013-07-30 17:46 - 2013-07-30 17:46 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\emaze
2013-07-30 17:45 - 2013-07-30 17:45 - 00002149 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-07-30 17:45 - 2013-07-30 17:45 - 00002119 _____ C:\Users\weinboerg\Desktop\Search.lnk
2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe
2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip
2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt
2013-07-29 18:23 - 2008-01-02 17:37 - 00192512 _____ (Intel Corporation) C:\Windows\system32\igfxres.dll
2013-07-27 13:48 - 2013-07-30 11:50 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls
2013-07-11 02:59 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 02:59 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 02:59 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-11 02:59 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 02:59 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 02:59 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-11 02:59 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 02:59 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-11 02:59 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-11 02:59 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 02:59 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 02:59 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 02:59 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 02:59 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-11 02:59 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 02:58 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 01:03 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 01:02 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 01:02 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 01:02 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-11 01:02 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-11 01:02 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-11 01:02 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-11 01:02 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-11 01:02 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-11 01:02 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll

==================== One Month Modified Files and Folders =======

2013-08-01 07:02 - 2013-07-31 19:10 - 00000000 ____D C:\Users\weinboerg\Desktop\VIREN-Malware Software
2013-08-01 06:53 - 2012-12-01 01:23 - 00001136 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003UA.job
2013-08-01 06:48 - 2012-04-03 09:36 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-01 06:48 - 2007-10-31 02:55 - 01306270 _____ C:\Windows\WindowsUpdate.log
2013-08-01 06:34 - 2010-02-06 12:45 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-01 05:47 - 2013-07-30 17:47 - 00001814 _____ C:\Windows\Tasks\Plus-HD-2.5-firefoxinstaller.job
2013-08-01 05:47 - 2013-07-30 17:47 - 00001194 _____ C:\Windows\Tasks\Plus-HD-2.5-codedownloader.job
2013-08-01 05:47 - 2013-07-30 17:47 - 00001190 _____ C:\Windows\Tasks\Plus-HD-2.5-updater.job
2013-08-01 05:47 - 2013-07-30 17:47 - 00001094 _____ C:\Windows\Tasks\Plus-HD-2.5-enabler.job
2013-08-01 05:12 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-01 05:12 - 2006-11-02 14:47 - 00003296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-01 00:34 - 2010-02-06 12:45 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-31 23:53 - 2012-12-01 01:23 - 00001084 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2152196072-760242556-3123413665-1003Core.job
2013-07-31 22:00 - 2012-02-28 22:24 - 00002062 _____ C:\Users\weinboerg\Desktop\Google Chrome.lnk
2013-07-31 21:24 - 2013-07-31 21:24 - 02347384 _____ (ESET) C:\Users\weinboerg\Downloads\esetsmartinstaller_enu.exe
2013-07-31 21:16 - 2006-11-02 12:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-31 21:15 - 2013-07-30 17:47 - 00000000 ____D C:\Program Files\MyPC Backup
2013-07-31 21:11 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-31 19:12 - 2007-09-27 06:30 - 00000012 _____ C:\Windows\bthservsdp.dat
2013-07-31 19:12 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-31 18:56 - 2013-07-31 18:56 - 00000000 ____D C:\Windows\ERUNT
2013-07-31 18:49 - 2008-01-26 13:15 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2013-07-31 18:46 - 2013-07-31 18:36 - 00015618 _____ C:\AdwCleaner[S1].txt
2013-07-31 18:32 - 2013-05-17 23:21 - 00006630 _____ C:\Windows\PFRO.log
2013-07-31 18:32 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\schemas
2013-07-31 18:12 - 2013-07-31 18:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-31 18:11 - 2013-07-31 18:11 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\weinboerg\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-30 19:29 - 2013-07-30 19:29 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (2).zip
2013-07-30 19:10 - 2013-07-30 19:10 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Avira
2013-07-30 19:04 - 2013-07-30 19:04 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-07-30 19:04 - 2013-07-30 19:03 - 00000000 ____D C:\ProgramData\Avira
2013-07-30 19:03 - 2013-07-30 19:04 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-07-30 19:03 - 2013-07-30 19:04 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-07-30 19:03 - 2013-07-30 19:04 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-07-30 19:03 - 2013-07-30 19:04 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2013-07-30 19:03 - 2013-07-30 19:03 - 00000000 ____D C:\Program Files\Avira
2013-07-30 18:39 - 2013-07-30 18:39 - 00011618 _____ C:\ComboFix.txt
2013-07-30 18:39 - 2013-07-30 18:22 - 00000000 ____D C:\ComboFix
2013-07-30 18:39 - 2013-07-30 17:51 - 00000000 ____D C:\Qoobox
2013-07-30 18:39 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2013-07-30 18:39 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-07-30 18:37 - 2013-07-30 17:47 - 00000000 ____D C:\Windows\erdnt
2013-07-30 18:36 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2013-07-30 18:34 - 2008-03-04 22:39 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Adobe
2013-07-30 18:34 - 2008-01-26 13:12 - 00000000 ____D C:\Users\weinboerg
2013-07-30 18:16 - 2009-03-21 23:16 - 00000000 ____D C:\Users\weinboerg\Tracing
2013-07-30 17:47 - 2013-07-30 17:47 - 00000884 _____ C:\Users\weinboerg\Desktop\MyPC Backup.lnk
2013-07-30 17:47 - 2013-07-30 17:47 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-07-30 17:47 - 2013-07-30 17:46 - 00000000 ____D C:\Program Files\Plus-HD-2.5
2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\Desktop\Create Amazing Presentations.lnk
2013-07-30 17:46 - 2013-07-30 17:46 - 00001200 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk
2013-07-30 17:46 - 2013-07-30 17:46 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\emaze
2013-07-30 17:45 - 2013-07-30 17:45 - 00002149 _____ C:\Users\weinboerg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-07-30 17:45 - 2013-07-30 17:45 - 00002119 _____ C:\Users\weinboerg\Desktop\Search.lnk
2013-07-30 11:50 - 2013-07-27 13:48 - 00025088 _____ C:\Users\weinboerg\Desktop\Menu Fiesta Mexicana 2013.xls
2013-07-29 21:24 - 2013-07-29 21:24 - 01221282 _____ (Farbar) C:\Users\weinboerg\Downloads\FRST (1).exe
2013-07-29 21:20 - 2013-07-29 21:20 - 00000000 ____D C:\FRST
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3.zip
2013-07-29 19:49 - 2013-07-29 19:49 - 00586952 _____ C:\Users\weinboerg\Downloads\AntiBundestrojaner_Globell_V_1_3_3 (1).zip
2013-07-29 19:45 - 2013-07-29 19:45 - 00056538 _____ C:\Users\weinboerg\Downloads\Extras_29_07_2013.Txt
2013-07-27 14:39 - 2011-12-04 16:57 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\Skype
2013-07-19 23:06 - 2012-03-03 21:43 - 00000000 ____D C:\Users\weinboerg\AppData\Roaming\vlc
2013-07-19 21:25 - 2008-01-26 13:15 - 00050176 _____ C:\Users\WEINBO~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-07-12 00:06 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-11 23:44 - 2012-04-03 09:36 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-11 23:44 - 2011-05-17 06:58 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-11 23:44 - 2008-03-04 22:39 - 00000000 ____D C:\Users\WEINBO~1\AppData\Local\Adobe
2013-07-11 23:34 - 2006-11-02 14:47 - 00380216 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 23:32 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-07-11 23:31 - 2010-06-03 19:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 03:16 - 2006-11-02 12:23 - 00000240 _____ C:\Windows\win.ini
2013-07-11 03:03 - 2006-11-02 12:24 - 75699896 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-07-11 02:49 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal

Files to move or delete:
====================
C:\ProgramData\xbr6x2Snc.dat

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-31 21:18

==================== End Of Log ============================
         
--- --- ---


Laufen tut alles, bzw. ich kann keinen Unterschied erkennen zum Stand vor dem Virus/Trojaner

Ist denn der Rechner nun sauber??

Geändert von weinboerg (01.08.2013 um 06:07 Uhr)

Alt 01.08.2013, 09:31   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Java und Adobe updaten.

Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop.
Schließe nun alle offenen Programme und trenne Dich von dem Internet.
Doppelklick auf die TFC.exe und drücke auf Start.
Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen.

Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 01.08.2013, 19:59   #13
weinboerg
 
Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Schrauber,

herzlichen Dank für deine Hilfe!! Ist echt spitze und alles läuft ohne Probleme.

Eine Frage habe ich aber noch; bei einer Installation wurde das Programm "My PCBackup" mit installiert.

Dieses war nach der letzten Aktion mit dem DelFix noch vorhanden. Jetzt wollte ich es manuell mit der Funktion deinstallieren vom Rechner schmeißen, da sagt er mir, das Programm ist nicht mehr vorhanden.
Ich sehe aber noch den kompletten Ordner mit seinem Inhalt. Kann ich diesen Ordner ebenfalls bedenkenlos löschen??

Dankeschön

Alt 02.08.2013, 10:54   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Virus Bundesministerium für Internetsicherheit - Zahlung von... - Standard

Virus Bundesministerium für Internetsicherheit - Zahlung von...



Ja lösch den einfach
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Virus Bundesministerium für Internetsicherheit - Zahlung von...
7-zip, abend, angeblich, bedanken, brief, erwischt, forum, gestartet, gestern, google, heute, install.exe, interne, konnte, malware.trace, malwarebytes, nichts, paypal, plug-in, plötzlich, pup.optional.ibryte, pup.optional.wajam, refresh, sicherheit, trojan.agent.ed, trojan.agent.ge, trojan.agent.gen, trojan.agent.tpl, unterstützung, virus, zahlen, zahlung




Ähnliche Themen: Virus Bundesministerium für Internetsicherheit - Zahlung von...


  1. Virus Bundesministerium f. Internetsicherheit entfernen
    Plagegeister aller Art und deren Bekämpfung - 17.07.2014 (13)
  2. Bundesministerium für Internetsicherheit. Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 20.01.2014 (4)
  3. AKM Virus entfernen - Zahlung von 100,00 Euro zum entsperren
    Plagegeister aller Art und deren Bekämpfung - 13.01.2014 (21)
  4. Virus:Forderung der stornierten Zahlung Ihrer Bestellung 23.08.2013.com
    Plagegeister aller Art und deren Bekämpfung - 03.09.2013 (18)
  5. Bundesministerium für Internetsicherheit - Kompromitierter Rechner
    Log-Analyse und Auswertung - 12.05.2013 (34)
  6. PC gesperrt! Strafverfolgung mit 100€ Paypal zahlung entgehen(bka virus?)
    Log-Analyse und Auswertung - 21.04.2013 (11)
  7. Virus Bundesministerium f. Internetsicherheit...Zahlung von €100 per paypal
    Log-Analyse und Auswertung - 07.04.2013 (11)
  8. Virus über Kinox.to, Bundesministerium
    Log-Analyse und Auswertung - 28.12.2012 (1)
  9. GEMA-Virus aufgetreten, PC bis zur Zahlung von 100 Euro gesperrt
    Plagegeister aller Art und deren Bekämpfung - 11.05.2012 (15)
  10. Anitvir Virus? ; Aufforderung zur Zahlung von 50 €
    Plagegeister aller Art und deren Bekämpfung - 21.03.2012 (16)
  11. Aus Sicherheitsgründen wurde Ihr Windowssystem blockiert. 50€ Zahlung Virus
    Log-Analyse und Auswertung - 19.03.2012 (1)
  12. Virus Windows Security Center; Aufforderung zur Zahlung von 100 €
    Plagegeister aller Art und deren Bekämpfung - 17.03.2012 (11)
  13. Virus: 50€ Zahlung
    Log-Analyse und Auswertung - 24.01.2012 (13)
  14. Virus blockiert Windows - 50€ Zahlung verlang
    Plagegeister aller Art und deren Bekämpfung - 22.01.2012 (3)
  15. Virus: 50€ Zahlung
    Plagegeister aller Art und deren Bekämpfung - 22.01.2012 (4)
  16. PC durch Virus gesperrt. Zahlung von 50 Euro etc.
    Plagegeister aller Art und deren Bekämpfung - 19.01.2012 (3)
  17. Leptop gesperrt durch Virus. Zahlung von 50 Euro für ein Virenprogramm.
    Log-Analyse und Auswertung - 10.01.2012 (1)

Zum Thema Virus Bundesministerium für Internetsicherheit - Zahlung von... - Einen wunderschönen Guten Abend in die Runde. Mich hat es erwischt!! Gestern Abend erschien plötzlich beim Stream schauen mit meiner Holden ein Brief, welcher mich auffordert den Betrag von 100 - Virus Bundesministerium für Internetsicherheit - Zahlung von......
Archiv
Du betrachtest: Virus Bundesministerium für Internetsicherheit - Zahlung von... auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.