zu 1:
AdwCleaner Logfile: Code:
# AdwCleaner v3.011 - Bericht erstellt am 07/11/2013 um 21:37:17
# Updated 03/11/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Willi - WPC1-NEW
# Gestartet von : C:\Users\Willi\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16514
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\Willi\AppData\Roaming\Mozilla\Firefox\Profiles\ucju8jmy.default\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\Willi\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R6].txt - [921 octets] - [07/11/2013 21:36:23]
AdwCleaner[S6].txt - [843 octets] - [07/11/2013 21:37:17]
########## EOF - C:\AdwCleaner\AdwCleaner[S6].txt - [902 octets] ########## --- --- ---
[/CODE]
zu 2: hier bekomme ich das Tool nicht zum start. Bekomme immer wieder eine Fehlermeldung.
zu 3:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013
Ran by Willi (administrator) on WPC1-NEW on 07-11-2013 22:01:17
Running from C:\Users\Willi\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ArcadeDeluxeAgent] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [156968 2009-09-17] (CyberLink Corp.)
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [AmIcoSinglun] - C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [237568 2008-10-24] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6957600 2009-03-11] (Realtek Semiconductor)
HKLM\...\Run: [PLFSetI] - C:\Windows\PLFSetI.exe [200704 2009-07-25] ()
HKLM\...\Run: [VitaKeyPdtWzd] - C:\Program Files\Acer Bio Protection\PdtWzd.exe [3549696 2009-02-13] (Egis Technology Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1410344 2008-12-05] (Synaptics, Inc.)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [870920 2009-02-24] (Dritek System Inc.)
HKLM\...\Run: [BackupManagerTray] - C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [249600 2009-04-11] (NewTech Infosystems, Inc.)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [440864 2009-06-23] (Acer Incorporated)
HKLM\...\Run: [EgisTecLiveUpdate] - C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-05-13] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] - C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [345384 2009-05-14] (Egis Technology Inc.)
HKLM\...\Run: [PlayMovie] - C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [173288 2009-06-16] (Acer Corp.)
HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-08-11] (Google)
HKLM\...\Run: [LexwareInfoService] - C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe [339240 2008-11-03] (Lexware GmbH & Co. KG)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Reader Application Helper] - C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [898952 2012-11-08] (Sony Corporation)
HKLM\...\Run: [CLMLServer] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [206120 2009-07-02] (CyberLink)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SamsungSM PanelMgr] - C:\Windows\SamsungSM\PanelMgr\SSMMgr.exe [536576 2008-07-31] ()
HKLM\...\Run: [WHITNEY_S2P] - C:\Program Files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe [274432 2007-01-08] ()
HKLM\...\Run: [] - [x]
HKLM\...\Run: [ControlCenter4] - C:\Program Files\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] - C:\Program Files\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [IndexSearch] - C:\Program Files\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-08] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] - C:\Program Files\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-08] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort12reminder] - C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [135168 2008-11-17] (Acer)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [Google Update] - C:\Users\Willi\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2010-10-14] (Google Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
HKCU\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
MountPoints2: {119a9d0f-0b5d-11e0-af1c-001e655cf5c2} - E:\LaunchU3.exe -a
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
HKU\Default\...\Run: [ooVoo] - C\ooVoo.exe /minimized
HKU\Default\...\RunOnce: [ScrSav] - C:\Windows\Screensavers\logon\run_logon.exe
HKU\Gast\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Gast\...\Run: [ProductReg] - C:\Program Files\Acer\WR_PopUp\ProductReg.exe [ 2008-11-17] (Acer)
HKU\Gast\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [ 2008-01-21] (Microsoft Corporation)
HKU\Gast\...\Run: [Steam] - "C:\Program Files\Steam\Steam.exe" -silent
HKU\Gast\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [ 2012-03-08] (Microsoft Corporation)
HKU\Gast\...\Run: [cleansweep.exe] - C:\cleansweep.exe\cleansweep.exe
HKU\Gast\...\Run: [Google Update] - C:\Users\Willi\AppData\Local\Google\Update\GoogleUpdate.exe [ 2010-10-14] (Google Inc.)
HKU\Gast\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [ 2013-10-02] (Skype Technologies S.A.)
HKU\Gast\...\Run: [ooVoo.exe] - C:\Program Files\ooVoo\ooVoo.exe [ 2013-04-04] (ooVoo LLC)
HKU\Gast\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [ 2008-01-21] (Microsoft Corporation)
HKU\Gast\...\Run: [{42809868-7B10-DE59-9233-31BFA56F0CD5}] - C:\Users\Gast\AppData\Roaming\Duuxgym\ykywiq.exe
HKU\Gast\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [ 2009-05-05] (Acresso Corporation)
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [ 2010-08-11] (Google)
Lsa: [Notification Packages] c:\Program Files\Acer Bio Protection\PwdFilter
Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG)
Startup: C:\Users\Willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0709&m=aspire_7738
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0709&m=aspire_7738
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0709&m=aspire_7738
URLSearchHook: HKCU - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Willi\AppData\Roaming\Mozilla\Firefox\Profiles\ucju8jmy.default
FF DefaultSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Ask.com
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @sony.com/ReaderDesktop - C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Willi\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Willi\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Willi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Willi\AppData\Roaming\Mozilla\Firefox\Profiles\ucju8jmy.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Users\Willi\AppData\Roaming\Mozilla\Firefox\Profiles\ucju8jmy.default\Extensions\BackupManager.list
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - C:\Program Files\AVG\AVG10\Firefox4\
FF Extension: AVG Safe Search - C:\Program Files\AVG\AVG10\Firefox4\
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [finder@meingutscheincode.de] - C:\Program Files\Mein Gutscheincode Finder\Firefox
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: hxxp://web.de/
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Willi\AppData\Local\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Willi\AppData\Local\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Willi\AppData\Local\Google\Chrome\Application\30.0.1599.101\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Willi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
CHR Plugin: (Windows Genuine Advantage) - C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Reader Application Detector) - C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: () - C:\Users\Willi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3_0
CHR Extension: (Autodesk Homestyler) - C:\Users\Willi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb\2.6_0
CHR Extension: (Skype Click to Call) - C:\Users\Willi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0
CHR Extension: (Google Wallet) - C:\Users\Willi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR HKLM\...\Chrome\Extension: [aaaaoiagmlcohkmjodefppbmpjdiocmh] - C:\Users\Willi\AppData\Local\APN\GoogleCRXs\aaaaoiagmlcohkmjodefppbmpjdiocmh_7.15.4.0.crx
CHR HKLM\...\Chrome\Extension: [jgfpelakfkbbkkdchaaaknckhoadkcbo] - C:\Program Files\Mein Gutscheincode Finder\Chrome\chrome-extension.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\Willi\AppData\Local\Temp\tbch.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Willi\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.)
R2 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [75048 2009-05-20] ()
R2 CodeMeter.exe; C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe [2304400 2011-06-07] (WIBU-SYSTEMS AG)
R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [707104 2009-06-23] (Acer Incorporated)
R2 FirebirdGuardianDefaultInstance; C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe [81920 2007-03-02] (FirebirdSQL Project)
R3 FirebirdServerDefaultInstance; C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe [1994752 2007-03-02] (FirebirdSQL Project)
S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-08-11] (Google)
R2 IGBASVC; c:\Program Files\Acer Bio Protection\BASVC.exe [3440640 2009-02-13] (Egis Technology Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R3 MSSQL$MSSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL10.MSSMLBIZ\MSSQL\Binn\sqlservr.exe [43028328 2011-09-22] (Microsoft Corporation)
R2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-05-14] (Egis Technology Inc.)
R2 MySQL; c:\Program Files\MySQL\MySQL Server 5\my.ini [8916 2012-11-19] ()
R2 NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [61184 2009-04-11] (NewTech Infosystems, Inc.)
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144632 2008-09-23] (NewTech Infosystems, Inc.)
R2 PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-08] (Nuance Communications, Inc.)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [237568 2008-11-27] (Acer Incorporated)
S4 SQLAgent$MSSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL10.MSSMLBIZ\MSSQL\Binn\SQLAGENT.EXE [370024 2011-09-22] (Microsoft Corporation)
S2 Winmgmt; C:\Users\Willi\wgsdgsdgdsgsd.dll [x]
==================== Drivers (Whitelisted) ====================
R0 AlfaFF; C:\Windows\System32\drivers\AlfaFF.sys [42608 2009-02-13] (Alfa Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [41984 2007-01-08] (Samsung Electronics Co., Ltd.)
R2 FPSensor; C:\Windows\System32\Drivers\FPSensor.sys [26928 2008-12-24] (Egis)
R3 hidshim; C:\Windows\System32\DRIVERS\hidshim.sys [5632 2008-10-08] (Windows (R) Codename Longhorn DDK provider)
R2 int15; c:\Windows\system32\drivers\int15.sys [69632 2009-02-13] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [19504 2008-12-04] (Egis Incorporated.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2008-12-04] (Egis Incorporated.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [59952 2008-12-04] (Egis Incorporated.)
R3 nuvotonhidgeneric; C:\Windows\System32\DRIVERS\nuvotonhidgeneric.sys [22528 2008-10-08] (Nuvoton Technology Corporation)
S4 RsFx0105; C:\Windows\System32\DRIVERS\RsFx0105.sys [238696 2011-09-22] (Microsoft Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-10] (Avira GmbH)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2007-01-08] (Samsung Electronics)
S4 AVGIDSShim; system32\DRIVERS\AVGIDSShim.Sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-07 21:18 - 2013-11-07 21:18 - 01089445 _____ (Farbar) C:\Users\Willi\Desktop\FRST.exe
2013-11-07 21:17 - 2013-11-07 21:17 - 01034531 _____ (Thisisu) C:\Users\Willi\Desktop\JRT.exe
2013-11-06 22:59 - 2013-11-06 22:59 - 01073262 _____ C:\Users\Willi\Desktop\adwcleaner.exe
2013-11-05 22:35 - 2013-11-05 22:35 - 00000000 _____ C:\Users\Willi\defogger_reenable
2013-11-04 22:13 - 2013-11-04 22:15 - 00000000 ____D C:\Users\Willi\Documents\Trojaner Board
2013-11-01 13:13 - 2013-11-01 13:13 - 00001757 _____ C:\Users\Willi\Desktop\AFS_Kaufmann - Verknüpfung.lnk
2013-11-01 11:24 - 2013-11-01 11:24 - 00000000 _____ C:\Windows\setuperr.log
2013-11-01 11:24 - 2013-11-01 11:24 - 00000000 _____ C:\Windows\setupact.log
2013-10-31 22:09 - 2013-10-31 22:09 - 00000000 ____D C:\Windows\ERUNT
2013-10-30 15:39 - 2013-10-30 15:39 - 00009936 _____ C:\Users\Willi\Documents\cc_20131030_153902.reg
2013-10-29 23:04 - 2013-10-29 23:04 - 00002111 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-10-26 20:52 - 2013-10-26 20:52 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-10-26 10:08 - 2013-10-26 10:08 - 00000000 ____D C:\Users\Willi\AppData\Local\{40D5F337-CFB3-4522-B6B0-98E0E22EBD83}
2013-10-25 19:42 - 2013-10-25 19:42 - 00000000 ____D C:\ede1430a84bd433c4aec9928b772
2013-10-25 11:53 - 2013-10-25 11:55 - 00000000 ____D C:\Users\Willi\AppData\Local\datacrossmedia
2013-10-25 10:54 - 2013-10-25 10:54 - 00000000 ____D C:\Users\Willi\Documents\Visual Studio 2005
2013-10-25 10:52 - 2013-10-25 10:52 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8
2013-10-25 10:50 - 2013-10-25 10:50 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-10-25 10:47 - 2013-10-25 10:47 - 00001888 _____ C:\Users\Public\Desktop\datacrossmedia paula3.lnk
2013-10-25 10:47 - 2013-10-25 10:47 - 00000000 ____D C:\Users\Willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\datacrossmedia
2013-10-25 10:46 - 2013-10-25 10:47 - 00000000 ____D C:\Program Files\datacrossmedia
2013-10-20 13:32 - 2013-10-20 13:32 - 00000873 _____ C:\Users\Willi\Desktop\tiptoi.lnk
2013-10-17 19:48 - 2013-10-17 19:48 - 00000000 ____D C:\ProgramData\Oracle
2013-10-17 19:48 - 2013-10-17 19:48 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-17 19:48 - 2013-10-17 19:47 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-17 19:47 - 2013-10-17 19:47 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-17 19:47 - 2013-10-17 19:47 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-17 19:47 - 2013-10-17 19:47 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-17 19:46 - 2013-10-17 19:46 - 00000000 ____D C:\Program Files\Java
2013-10-16 17:53 - 2013-10-16 18:00 - 00000000 ____D C:\Users\Willi\Documents\Free Sound Recorder
2013-10-14 20:27 - 2013-10-14 20:27 - 00000000 ____D C:\FRST
2013-10-14 20:00 - 2013-11-07 21:42 - 00000000 ____D C:\AdwCleaner
2013-10-12 09:25 - 2013-10-12 09:25 - 00000000 ____D C:\Users\Willi\AppData\Local\WebPlayer
2013-10-11 12:16 - 2013-09-22 11:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-11 12:16 - 2013-09-22 11:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-11 12:16 - 2013-09-22 11:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-10-11 12:16 - 2013-09-22 11:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-11 12:16 - 2013-09-22 11:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-11 12:16 - 2013-09-22 11:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-11 12:16 - 2013-09-22 11:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-11 12:16 - 2013-09-22 11:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-10-11 12:16 - 2013-09-22 11:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-11 12:16 - 2013-09-22 11:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-10-11 12:16 - 2013-09-22 11:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-11 12:16 - 2013-09-22 11:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-11 12:16 - 2013-09-22 11:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-11 12:16 - 2013-09-22 11:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-11 12:16 - 2013-09-22 10:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-11 12:15 - 2013-09-22 11:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-11 10:28 - 2013-10-11 10:35 - 00000000 ____D C:\Users\Willi\AppData\Roaming\Free Sound Recorder
2013-10-11 09:22 - 2013-10-11 09:22 - 00000000 ____D C:\7fc475a7f13dd7e903fca8b987bb0033
2013-10-11 08:10 - 2013-10-11 08:10 - 00000000 ____D C:\4e485115cadf2d7977e0e2790ea047
2013-10-11 08:09 - 2013-11-07 19:26 - 00001650 _____ C:\Users\Willi\Desktop\Tages Bericht.txt
2013-10-11 07:49 - 2013-08-27 03:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-10-11 07:49 - 2013-08-27 03:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-10-11 07:49 - 2013-08-27 03:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-10-11 07:49 - 2013-08-27 03:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-10-11 07:49 - 2013-08-27 02:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-10-11 07:49 - 2013-08-27 02:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-10-11 07:49 - 2013-08-27 02:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-10-11 07:49 - 2013-08-27 02:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-10-11 07:49 - 2013-08-27 02:28 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-10-11 07:49 - 2013-08-01 04:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-11 07:49 - 2013-08-01 03:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-10-11 07:48 - 2013-08-29 08:36 - 02050048 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-11 07:48 - 2013-07-20 11:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 07:46 - 2013-07-12 10:04 - 00134272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-11 07:46 - 2013-06-29 03:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-11 07:46 - 2013-06-29 03:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-11 07:46 - 2013-06-29 03:07 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-11 07:46 - 2013-06-29 03:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-11 07:46 - 2011-05-05 14:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-11 07:46 - 2011-05-05 14:54 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-11 07:45 - 2013-06-27 00:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-11 07:44 - 2013-07-04 05:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-11 07:44 - 2013-07-03 03:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-11 07:44 - 2013-07-03 03:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-11 07:44 - 2013-06-04 05:16 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-11 07:44 - 2013-06-04 02:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
==================== One Month Modified Files and Folders =======
2013-11-07 21:44 - 2010-10-06 15:44 - 00000000 ____D C:\Users\Willi\AppData\Roaming\Skype
2013-11-07 21:42 - 2013-10-14 20:00 - 00000000 ____D C:\AdwCleaner
2013-11-07 21:40 - 2010-03-01 19:30 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-07 21:40 - 2009-07-25 13:15 - 00228864 _____ C:\ProgramData\nvModes.001
2013-11-07 21:40 - 2009-07-25 13:13 - 00228864 _____ C:\ProgramData\nvModes.dat
2013-11-07 21:40 - 2006-11-02 13:47 - 00003344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-07 21:40 - 2006-11-02 13:47 - 00003344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-07 21:39 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-07 21:38 - 2010-09-28 11:46 - 00000012 _____ C:\Windows\bthservsdp.dat
2013-11-07 21:38 - 2009-07-25 13:05 - 01471178 _____ C:\Windows\WindowsUpdate.log
2013-11-07 21:38 - 2006-11-02 14:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-07 21:20 - 2012-04-07 19:40 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-07 21:18 - 2013-11-07 21:18 - 01089445 _____ (Farbar) C:\Users\Willi\Desktop\FRST.exe
2013-11-07 21:17 - 2013-11-07 21:17 - 01034531 _____ (Thisisu) C:\Users\Willi\Desktop\JRT.exe
2013-11-07 21:17 - 2011-02-09 09:32 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4166261621-4185443696-1375803092-1000UA.job
2013-11-07 21:11 - 2010-03-01 19:30 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-07 19:26 - 2013-10-11 08:09 - 00001650 _____ C:\Users\Willi\Desktop\Tages Bericht.txt
2013-11-07 16:17 - 2011-02-09 09:32 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4166261621-4185443696-1375803092-1000Core.job
2013-11-07 10:36 - 2013-02-09 17:16 - 00000000 ____D C:\Remote Viewlog
2013-11-07 10:32 - 2011-01-20 19:52 - 00000000 ____D C:\Program Files\WIN-CASA2011
2013-11-06 23:07 - 2010-10-06 21:12 - 00000000 ____D C:\Users\Willi\Documents\Steuerfälle
2013-11-06 22:59 - 2013-11-06 22:59 - 01073262 _____ C:\Users\Willi\Desktop\adwcleaner.exe
2013-11-06 17:19 - 2013-07-19 08:45 - 00023817 _____ C:\Users\Willi\Desktop\ToDo-Liste_Tomurcu.xlsx
2013-11-05 22:35 - 2013-11-05 22:35 - 00000000 _____ C:\Users\Willi\defogger_reenable
2013-11-05 22:35 - 2010-01-03 20:02 - 00000000 ____D C:\Users\Willi
2013-11-04 22:15 - 2013-11-04 22:13 - 00000000 ____D C:\Users\Willi\Documents\Trojaner Board
2013-11-01 13:13 - 2013-11-01 13:13 - 00001757 _____ C:\Users\Willi\Desktop\AFS_Kaufmann - Verknüpfung.lnk
2013-11-01 11:24 - 2013-11-01 11:24 - 00000000 _____ C:\Windows\setuperr.log
2013-11-01 11:24 - 2013-11-01 11:24 - 00000000 _____ C:\Windows\setupact.log
2013-10-31 22:09 - 2013-10-31 22:09 - 00000000 ____D C:\Windows\ERUNT
2013-10-30 15:39 - 2013-10-30 15:39 - 00009936 _____ C:\Users\Willi\Documents\cc_20131030_153902.reg
2013-10-29 23:04 - 2013-10-29 23:04 - 00002111 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-10-29 23:04 - 2010-01-21 00:50 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-10-29 23:04 - 2010-01-21 00:50 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-10-29 23:03 - 2011-08-03 22:51 - 00000000 ____D C:\Users\Willi\AppData\Roaming\DVDVideoSoft
2013-10-29 10:40 - 2010-10-06 20:39 - 00000000 ____D C:\Users\Willi\Documents\Alpenberger & TFS
2013-10-27 17:09 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Speech
2013-10-26 20:52 - 2013-10-26 20:52 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-10-26 20:04 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-10-26 19:57 - 2006-11-02 11:33 - 01595334 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-26 19:48 - 2009-03-12 04:11 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-26 16:19 - 2013-05-16 11:31 - 00000000 ____D C:\Users\Willi\Documents\Firma Gebäudereinigung Hasan Birol
2013-10-26 16:19 - 2011-11-22 17:05 - 00000000 ____D C:\Users\Willi\Documents\Firma Gebäudereinigung Uzunov Nedzhat Ramisov
2013-10-26 10:08 - 2013-10-26 10:08 - 00000000 ____D C:\Users\Willi\AppData\Local\{40D5F337-CFB3-4522-B6B0-98E0E22EBD83}
2013-10-25 19:42 - 2013-10-25 19:42 - 00000000 ____D C:\ede1430a84bd433c4aec9928b772
2013-10-25 11:55 - 2013-10-25 11:53 - 00000000 ____D C:\Users\Willi\AppData\Local\datacrossmedia
2013-10-25 10:54 - 2013-10-25 10:54 - 00000000 ____D C:\Users\Willi\Documents\Visual Studio 2005
2013-10-25 10:52 - 2013-10-25 10:52 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8
2013-10-25 10:52 - 2009-03-12 04:11 - 00000000 ____D C:\Program Files\Microsoft Office
2013-10-25 10:52 - 2006-11-02 12:18 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-10-25 10:50 - 2013-10-25 10:50 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-10-25 10:50 - 2009-03-12 04:41 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-10-25 10:47 - 2013-10-25 10:47 - 00001888 _____ C:\Users\Public\Desktop\datacrossmedia paula3.lnk
2013-10-25 10:47 - 2013-10-25 10:47 - 00000000 ____D C:\Users\Willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\datacrossmedia
2013-10-25 10:47 - 2013-10-25 10:46 - 00000000 ____D C:\Program Files\datacrossmedia
2013-10-23 07:55 - 2010-10-06 15:44 - 00000000 ___RD C:\Program Files\Skype
2013-10-23 07:55 - 2010-10-06 15:44 - 00000000 ____D C:\ProgramData\Skype
2013-10-20 13:48 - 2012-06-04 16:36 - 00000000 ____D C:\Program Files\PDFCreator
2013-10-20 13:42 - 2013-01-01 13:43 - 00000808 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-10-20 13:42 - 2013-01-01 13:43 - 00000000 ____D C:\Program Files\CCleaner
2013-10-20 13:34 - 2013-08-24 20:58 - 00000000 ____D C:\Users\Willi\AppData\Roaming\RavensburgerTipToi
2013-10-20 13:32 - 2013-10-20 13:32 - 00000873 _____ C:\Users\Willi\Desktop\tiptoi.lnk
2013-10-20 13:30 - 2013-08-24 20:58 - 00000000 ____D C:\ProgramData\RavensburgerTipToi
2013-10-17 19:48 - 2013-10-17 19:48 - 00000000 ____D C:\ProgramData\Oracle
2013-10-17 19:48 - 2013-10-17 19:48 - 00000000 ____D C:\Program Files\Common Files\Java
2013-10-17 19:47 - 2013-10-17 19:48 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-17 19:47 - 2013-10-17 19:47 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-17 19:47 - 2013-10-17 19:47 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-17 19:47 - 2013-10-17 19:47 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-10-17 19:46 - 2013-10-17 19:46 - 00000000 ____D C:\Program Files\Java
2013-10-17 08:39 - 2010-01-24 19:31 - 00000000 ____D C:\Users\Willi\Documents\Eigene Scans
2013-10-16 18:00 - 2013-10-16 17:53 - 00000000 ____D C:\Users\Willi\Documents\Free Sound Recorder
2013-10-14 20:55 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\tracing
2013-10-14 20:27 - 2013-10-14 20:27 - 00000000 ____D C:\FRST
2013-10-12 09:25 - 2013-10-12 09:25 - 00000000 ____D C:\Users\Willi\AppData\Local\WebPlayer
2013-10-11 13:26 - 2013-07-25 15:20 - 00000000 ____D C:\Windows\system32\MRT
2013-10-11 13:22 - 2012-12-29 15:19 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-11 13:04 - 2006-11-02 13:47 - 00417840 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-11 12:48 - 2013-01-10 00:48 - 00000000 ____D C:\Users\Willi\AppData\Roaming\Duuxgym
2013-10-11 12:48 - 2010-02-28 20:14 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-11 12:21 - 2006-11-02 11:24 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-10-11 10:35 - 2013-10-11 10:28 - 00000000 ____D C:\Users\Willi\AppData\Roaming\Free Sound Recorder
2013-10-11 09:22 - 2013-10-11 09:22 - 00000000 ____D C:\7fc475a7f13dd7e903fca8b987bb0033
2013-10-11 08:10 - 2013-10-11 08:10 - 00000000 ____D C:\4e485115cadf2d7977e0e2790ea047
2013-10-09 16:20 - 2012-04-07 19:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-09 16:20 - 2011-05-12 22:12 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-09 10:57 - 2012-04-10 16:56 - 00000000 ____D C:\Users\Willi\AppData\Local\Windows Live
2013-10-09 10:29 - 2013-09-03 16:18 - 00000959 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
Some content of TEMP:
====================
C:\Users\Gast\AppData\Local\Temp\AskSLib.dll
C:\Users\Gast\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\Willi\AppData\Local\Temp\avgnt.exe
C:\Users\Willi\AppData\Local\Temp\paula3.exe
C:\Users\Willi\AppData\Local\Temp\Quarantine.exe
C:\Users\Willi\AppData\Local\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-07 21:47
==================== End Of Log ============================ --- --- ---
--- --- ---
[/CODE] |