:confused:
Hmm
kann auf die Downloads im Ordner Download nicht zugreifen?
meine Verknüpfungen zum explorer zeigen : explorer.exe
Schnittstelle nicht unterstützt
ahh sorry
kann rechte Maustaste Öffnen nutzen
geschafft
1)AdwCleaner Logfile: Code:
# AdwCleaner v3.212 - Bericht erstellt am 06/06/2014 um 18:52:14
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium (32 bits)
# Benutzername : georg - HOME-DESKTOP
# Gestartet von : C:\Users\georg\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\georg\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\georg\AppData\Roaming\Mozilla\Firefox\Profiles\ybstvj2w.default\Extensions\anttoolbar@ant.com
Ordner Gelöscht : C:\Users\renate\AppData\Roaming\Mozilla\Firefox\Profiles\esm2fv5k.default\Extensions\anttoolbar@ant.com
Ordner Gelöscht : C:\Users\testbrowser\AppData\Roaming\Mozilla\Firefox\Profiles\5wmk3vka.default\Extensions\anttoolbar@ant.com
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_freefilesync_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_freefilesync_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_pdfcreator_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_pdfcreator_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_treesize-professional_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_treesize-professional_RASMANCS
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7600.16700
-\\ Mozilla Firefox v29.0 (de)
[ Datei : C:\Users\anna\AppData\Roaming\Mozilla\Firefox\Profiles\80ecdxg1.default\prefs.js ]
[ Datei : C:\Users\eva\AppData\Roaming\Mozilla\Firefox\Profiles\6seqhgty.default\prefs.js ]
[ Datei : C:\Users\georg\AppData\Roaming\Mozilla\Firefox\Profiles\ybstvj2w.default\prefs.js ]
[ Datei : C:\Users\ghadmin\AppData\Roaming\Mozilla\Firefox\Profiles\60m798vi.default\prefs.js ]
[ Datei : C:\Users\jens\AppData\Roaming\Mozilla\Firefox\Profiles\8fnwvplv.default\prefs.js ]
[ Datei : C:\Users\renate\AppData\Roaming\Mozilla\Firefox\Profiles\esm2fv5k.default\prefs.js ]
[ Datei : C:\Users\testbrowser\AppData\Roaming\Mozilla\Firefox\Profiles\5wmk3vka.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2949 octets] - [06/06/2014 18:50:47]
AdwCleaner[S0].txt - [2874 octets] - [06/06/2014 18:52:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2934 octets] ########## --- --- ---
2) JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x86
Ran by georg on 06.06.2014 at 18:56:14,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{01CE2BE8-4C18-4990-96BF-81AC4BDC849E}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{03C833CF-6573-484D-A96E-F17FF0ED334E}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{05D4C364-A24F-497C-8064-5E44691922BC}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{065A3699-4DF9-43E9-92AC-6C3F95F15DB0}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{09CA61EB-5B37-4065-98E7-280ADBE55145}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{0F0481F9-C1C5-45BC-BBCE-28D0527775EF}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{0FD68F82-B638-4447-B225-21FA715B5BD5}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{10543A91-C116-4ACB-BE2E-6E74AC57AA13}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{1092E64B-A485-460B-B29B-072AC04CBDBE}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{11721FD2-9431-458E-8346-604833A7EF40}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{135B0967-F7ED-4C46-80B5-B410B7118F55}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{1393A9A3-88FF-499E-9640-7B2DFC49B4B2}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{139D0EA1-6DE9-41EC-B990-50905296E310}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{143B6561-9AEF-433A-A8E4-111EEC94C099}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{19716505-8625-4DDB-B967-0E6A20B50520}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{1B27EDB7-AE4A-4550-A52A-70D8576D8E4B}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{1FEE1667-5CB1-45BE-B490-2DCB9B862184}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{207026B6-6531-47EE-8EC7-3EECB5ED0C4F}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{22A7A18D-2C1A-41DD-B862-DDA243CAE441}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{23013793-4CA6-44B6-9E29-EB0C980113FB}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{265DA2CB-1335-4550-AE2C-9BE0218292B3}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{290AE1D6-4421-4C37-986F-3079D05F2A75}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{2917EC67-22FF-475A-9EC5-21714F413FBD}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{2AAD7648-F6C3-434C-8048-E64E8CDC826A}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{2BD6D305-FA8C-4067-8779-17B0E497BBF8}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{2C019A44-B892-4896-A1DC-E578CF91F0E8}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{2F0322F9-27BC-45B7-A09A-728737596483}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{2F54935B-245E-4FA8-8405-A269293BF0BC}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{303859B0-334E-4342-AD1B-41F1F99122E5}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{394DFB53-D6FC-41CA-B66E-5F4C9670D93D}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{3C5AE1CA-848E-44C0-A158-EC4CF4C141CF}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{3CABEC67-DBAF-44FC-94C1-BF54299798A5}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{3CB8C8FD-4C10-4610-B741-E98BE77D1295}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{3D5A114B-4D6D-40B5-9EC0-71D05A7A11DA}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{419A8F47-BB09-4DD7-8CC9-BFF3FF8D5023}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{42A14C64-31AE-4DE2-8AD4-12D92E0E0C42}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{42A9EB67-988E-4331-B370-74103C41CA72}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{42B4C95E-0ECA-4C7F-A4CD-9BA18D543DF4}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{435C98A9-E40F-4B9F-9BF1-693B132B6664}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{487AB872-4921-43FC-8D8A-BDA183A618EE}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{4DD5D7D6-6CC2-49EA-AB0D-B13A26DAD2FF}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{4E0C4945-6F25-451B-A918-F566A7458228}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{4F3848C2-A754-4B28-997B-1FABD28A45D8}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{53EDFA05-8420-4B48-89FA-01044C26370A}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{5481E701-B6C3-4FE0-8BC0-BEEFD41B5157}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{559BA738-17D3-4C4C-B67A-7F607EFD6F6F}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{56DFB304-1C84-4A41-8EC3-8B405360580B}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{57B54BC4-FBB0-40B5-8CB7-193E12F24077}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{5854E873-0D1C-487F-AEA0-4163524AB042}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{58DB92F4-B7F8-44F3-A500-9EEEF8D95ACA}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{5B92B1F0-1098-4AB6-A88F-EC6AA7175215}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{5D4DE5B4-9421-4537-8235-CB139C1123FC}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{5D5E8777-DFDA-4802-9526-8C8D2911AC96}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{5E923283-3D18-4C04-8825-262A5DCA9B39}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{61E6BFAF-5549-4092-A5A0-F9107338712F}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{66C3E805-D026-41D7-AC22-C45B197CCFCD}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{677B0C8B-A497-453F-8893-4D39C40227AF}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{69E203F7-7B15-49FB-B235-A866F90CEEB2}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{6A59DD87-31EB-457B-A141-42C666455EF3}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{6A735CA9-B12A-4974-BF28-B0C2FF9B62A3}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{6CFFF266-9CB1-434E-905E-DA065C48D813}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{6D49FA00-73E5-4066-B9D0-153118F361CE}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{70DEE717-AC9D-4CE2-A675-7FF4FE7CC096}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{71214CF0-5FF0-45E0-A4AB-53095F7EA7EB}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{745B8D72-10B1-4762-8378-ED517CD592F8}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{756D8B95-FE99-4622-A4B5-FDBF94CD412E}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{761DFD03-4C2F-46CD-A22E-F7AB5BC3F945}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{762EF63B-AC0E-48BA-A746-6487B4D7A333}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{78444615-3A1F-43C6-9CBA-B561BFA4802B}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{799E9558-2499-4DFC-ADFF-DFB44F80E695}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{7A0CE6C8-5CFC-49DB-9A66-0B4EBF5E6813}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{7A8F9AB8-0CE3-4534-BAFA-E35077B29280}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{7B578D7F-4171-4525-B098-C58134053150}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{7E577432-481E-436A-BA61-AB469371B978}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{7EFEF656-94AC-4DF2-838B-FB3225DC7267}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{8187511F-AA56-4F2B-9236-8F4AC35CE009}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{82835048-1CC6-4DC6-80C3-3FDB81E20716}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{833E7771-5E16-4E94-8085-F16371526F07}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{855241A7-F731-457D-8D34-0A6DDD74CEC2}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{85AE6975-8E0A-439B-809E-2116C8C857FB}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{866B1558-C65A-4E83-8450-D172F7B795E6}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{875C54ED-8550-4D7C-A507-5B0372A0FF33}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{89F9A70A-1CE7-488B-A2E6-6FF5E5964DE3}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{8CC0A86F-C9BA-4B6E-9336-1248C8F15313}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{8DCDEB24-6AC4-4966-81FD-3EFB73237B1E}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{938FA284-9175-4BB6-A655-4D87048602D1}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{93FF85E9-05B4-40C5-8343-08F4D24752F9}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{9701D445-9B19-4FB5-A41F-121D4B042BC3}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{978D0815-910A-4DD9-B89D-EE6AF64042C5}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{98C7086C-F426-4075-B4D7-2637BF473B13}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{9AAA718E-DD5E-4434-8457-640A13105253}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{9B50EF8C-1A2B-4954-B73C-B8AE5DD07568}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{9DF4D809-7F45-4DB1-B9A2-C8AE90BDF07B}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{A5365C55-A3DA-431D-9ECB-B50FBDA22240}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{A5F806C7-9BA5-44B8-BC2B-FB25B4677683}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{A89122B9-B1BC-4475-AA74-CDF95503255C}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{AAA1022F-0EED-4F39-9126-AA753D39EB38}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{ABD35AA8-7670-46A5-9681-07922697F7CE}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{AC94BFE1-B7F0-4F78-96C5-6BA239DF7A07}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{AD846DA0-96A7-430C-AC43-F75D1239E086}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{B4044FAE-FF92-499D-88A0-958C3CD035E9}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{B4AE6AD4-FEF9-4562-B317-68F4FEB10334}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{BBBD0A25-A8EA-403D-971F-DF95B5A2BCA9}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{BEAFBAB7-65E0-4E13-85E2-9B02A9D38D67}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{C0BFEFB8-97A1-4879-AE8D-5F0A28E38E30}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{C2232356-70B3-42FB-84DC-8BA06C896249}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{C34A966D-B807-4B30-8DC4-0DCFFED60DEB}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{C3AC1FB4-9909-4961-BED8-0976F47FB29D}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{C5E5AAFB-36D8-4C9A-98F9-F96705B6E9E3}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{CA911339-A2B3-47DC-B57D-92818EFFF06D}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{CAC533FB-6696-4777-A909-BAF6658C208D}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{CCFEF2EA-1FF6-4C7E-B3A5-B1273D26AEF9}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{CFA8270A-051C-4DC3-A484-B7D0D16AE3F5}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{D357AA1B-140A-4E68-8A41-0C80A5F582D4}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{D47EBD6F-43B9-49DA-BCC6-4B4A373ED051}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{DA6131EB-0907-40D2-BA1E-800C1BB4FA7C}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{DAAA69D1-566A-4BE8-8095-4FAD17F88897}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{DB77D662-69E1-42B3-8346-896FBDB6AAA6}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{DF1ABA0F-C673-4326-99CA-41D1A32E1373}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{DF97AD71-968C-4645-843B-87CE58B21609}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{E04F3D51-4C70-4155-8ABC-C26FE7974C1C}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{E151AA94-A67C-4F7F-85BF-AEDA1A229CEC}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{E411268E-223C-4352-9B68-E90690C59A01}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{E860F7F2-D6F6-416A-A542-AC6F0DF00A8C}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{F0108BC8-011B-4525-AD30-DC0480ABE7A1}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{F2642FD1-6D21-409E-9AB3-AB1860CCD70F}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{F2E768AA-05DE-447E-B60A-BB031A194F6C}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{F3A92350-B7E9-41C5-8704-CA926468A1DB}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{F704D2CC-9760-41B7-A718-E61974F0DD8C}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{FB55B3BE-EAD7-4FA3-BE8E-9252C090B925}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{FB725A65-D58D-4830-8121-52A98E426FC2}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{FE294B22-FDA7-426D-A78A-2CCE6498A868}
Successfully deleted: [Empty Folder] C:\Users\georg\appdata\local\{FE327498-3958-49DC-8186-EA6450E52EB3}
~~~ FireFox
Emptied folder: C:\Users\georg\AppData\Roaming\mozilla\firefox\profiles\ybstvj2w.default\minidumps [35 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.06.2014 at 18:58:47,51
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
3) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 06.06.2014 19:00:33, SYSTEM, HOME-DESKTOP, Manual, Rootkit Database, 2014.2.20.1, 2014.6.2.1,
Update, 06.06.2014 19:00:44, SYSTEM, HOME-DESKTOP, Manual, Malware Database, 2014.3.4.9, 2014.6.6.5,
Protection, 06.06.2014 19:19:22, SYSTEM, HOME-DESKTOP, Protection, Malware Protection, Starting,
Protection, 06.06.2014 19:19:22, SYSTEM, HOME-DESKTOP, Protection, Malware Protection, Started,
(end) Es gab einen Fund .
4)
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:06-06-2014
Ran by georg (administrator) on HOME-DESKTOP on 06-06-2014 19:23:40
Running from C:\Users\georg\Desktop
Platform: Microsoft Windows 7 Home Premium (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
(Acronis) C:\Program Files\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(cyberlink) C:\Program Files\CyberLink\Shared files\brs.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Acronis) C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM\...\Run: [CLMLServer] => C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-02] (CyberLink)
HKLM\...\Run: [BDRegion] => C:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-01-19] (cyberlink)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8555040 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [TrueImageMonitor.exe] => C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [5992064 2011-12-16] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [403616 2011-08-21] (Acronis)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [LifeCam] => C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-27] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKU\S-1-5-21-1378868678-2165211460-215521333-1003\...\Run: [HP Officejet 4620 series (NET)] => C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-1378868678-2165211460-215521333-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-1378868678-2165211460-215521333-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
GroupPolicyUsers\S-1-5-21-1378868678-2165211460-215521333-1010\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.medion.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {70A87C79-0E13-424C-915B-134E4825475C} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}
SearchScopes: HKCU - {D3CAC7D6-2B63-4F9D-AF10-63031BED7C67} URL = hxxp://www.google.de/search?q={searchTerms}
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File
Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - No File
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - No File
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - No File
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\georg\AppData\Roaming\Mozilla\Firefox\Profiles\ybstvj2w.default
FF DefaultSearchEngine: Yahoo
FF SelectedSearchEngine: Yahoo
FF Homepage: about:blank
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\georg\AppData\Roaming\Mozilla\Firefox\Profiles\ybstvj2w.default\Extensions\ich@maltegoetz.de [2014-04-30]
FF Extension: Screengrab - C:\Users\georg\AppData\Roaming\Mozilla\Firefox\Profiles\ybstvj2w.default\Extensions\{02450954-cdd9-410f-b1da-db804e18c671} [2011-01-14]
FF Extension: OptimizeGoogle - C:\Users\georg\AppData\Roaming\Mozilla\Firefox\Profiles\ybstvj2w.default\Extensions\optimizegoogle@optimizegoogle.com.xpi [2011-12-11]
FF Extension: Adblock Plus - C:\Users\georg\AppData\Roaming\Mozilla\Firefox\Profiles\ybstvj2w.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-12-11]
FF Extension: BetterPrivacy - C:\Users\georg\AppData\Roaming\Mozilla\Firefox\Profiles\ybstvj2w.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2012-08-11]
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-11-03]
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-11-03]
========================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [809224 2011-08-21] (Acronis)
R2 afcdpsrv; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [3483600 2012-04-22] (Acronis)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-05-27] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [247152 2009-04-17] ()
R2 syncagentsrv; C:\Program Files\Common Files\Acronis\SyncAgent\syncagentsrv.exe [5891048 2011-12-16] (Acronis)
R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
==================== Drivers (Whitelisted) ====================
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17408 2009-05-26] (ArcSoft, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-05] (Avira Operations GmbH & Co. KG)
R3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [219352 2009-06-05] (Intel Corporation)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2009-03-31] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-06-06] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-14] (Ralink Technology Corp.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [16472 2012-01-18] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [11104 2012-01-18] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-31] (Avira GmbH)
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [90112 2009-03-20] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14976 2009-03-20] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [121856 2009-03-20] (MCCI Corporation)
R0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [766496 2012-04-22] (Acronis)
S3 USBPNPA; C:\Windows\System32\drivers\CM108.sys [1310720 2007-06-28] (C-Media Inc)
R0 vididr; C:\Windows\System32\DRIVERS\vididr.sys [126144 2011-12-04] (Acronis)
R0 vidsflt61; C:\Windows\System32\DRIVERS\vsflt61.sys [84544 2012-04-22] (Acronis)
R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; C:\Program Files\CyberLink\PowerDVD9\000.fcl [87536 2010-01-20] (CyberLink Corp.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\georg\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-06 19:23 - 2014-06-06 19:24 - 00015376 _____ () C:\Users\georg\Desktop\FRST.txt
2014-06-06 19:23 - 2014-06-06 19:23 - 00000000 ____D () C:\Users\georg\Desktop\FRST-OlderVersion
2014-06-06 19:20 - 2014-06-06 19:20 - 00000464 _____ () C:\Users\georg\Desktop\mbam.txt
2014-06-06 19:00 - 2014-06-06 19:19 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-06 19:00 - 2014-06-06 19:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-06 19:00 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-06 19:00 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-06 18:58 - 2014-06-06 18:58 - 00014857 _____ () C:\Users\georg\Desktop\JRT.txt
2014-06-06 18:56 - 2014-06-06 18:56 - 00000000 ____D () C:\Windows\ERUNT
2014-06-06 18:49 - 2014-06-06 18:52 - 00000000 ____D () C:\AdwCleaner
2014-06-06 18:36 - 2014-06-06 18:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\georg\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-06 18:35 - 2014-06-06 18:35 - 01333465 _____ () C:\Users\georg\Desktop\adwcleaner_3.212.exe
2014-06-06 18:35 - 2014-06-06 18:35 - 01016261 _____ (Thisisu) C:\Users\georg\Desktop\JRT.exe
2014-06-06 18:18 - 2014-06-06 18:18 - 00010402 _____ () C:\Users\georg\Desktop\ghcombofixgh.txt
2014-06-06 18:12 - 2014-06-06 19:24 - 00000000 ____D () C:\Users\georg\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00010402 _____ () C:\ComboFix.txt
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\Testbrowser1\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\testbrowser\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\renate\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\jens\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\ghadmin\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\eva\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\anna\AppData\Local\temp
2014-06-06 18:00 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-06 18:00 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-06 18:00 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-06 18:00 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-06 18:00 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-06 18:00 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-06 18:00 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-06 18:00 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-06 17:59 - 2014-06-06 18:12 - 00000000 ____D () C:\Qoobox
2014-06-06 17:59 - 2014-06-06 18:11 - 00000000 ____D () C:\Windows\erdnt
2014-06-06 17:53 - 2014-06-06 17:53 - 05205146 ____R (Swearware) C:\Users\georg\Desktop\ComboFix.exe
2014-06-06 15:23 - 2014-06-06 15:23 - 00380416 _____ () C:\Users\georg\Downloads\Gmer-19357.exe
2014-06-06 12:02 - 2014-06-06 12:02 - 00027464 _____ () C:\Users\georg\Desktop\ghAddition.txt
2014-06-06 12:01 - 2014-06-06 19:23 - 00000000 ____D () C:\FRST
2014-06-06 12:01 - 2014-06-06 12:02 - 00023347 _____ () C:\Users\georg\Desktop\ghFRST.txt
2014-06-06 12:00 - 2014-06-06 19:23 - 01063424 _____ (Farbar) C:\Users\georg\Desktop\FRST.exe
2014-06-06 11:59 - 2014-06-06 11:59 - 00000472 _____ () C:\Users\georg\Desktop\ghdefogger_disable.log
2014-06-06 11:59 - 2014-06-06 11:59 - 00000000 _____ () C:\Users\georg\defogger_reenable
2014-06-06 11:58 - 2014-06-06 11:58 - 00050477 _____ () C:\Users\georg\Desktop\Defogger.exe
2014-06-05 20:56 - 2014-06-05 20:56 - 00000000 ____D () C:\Users\testbrowser\AppData\Local\Macromedia
2014-06-05 20:54 - 2014-06-05 20:54 - 00000000 ____D () C:\Users\testbrowser\Downloads\antvideo
2014-05-30 10:26 - 2014-05-31 20:01 - 00000000 ____D () C:\Users\georg\Documents\samsung s3 backup
==================== One Month Modified Files and Folders =======
2014-06-06 19:24 - 2014-06-06 19:23 - 00015376 _____ () C:\Users\georg\Desktop\FRST.txt
2014-06-06 19:24 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\georg\AppData\Local\temp
2014-06-06 19:23 - 2014-06-06 19:23 - 00000000 ____D () C:\Users\georg\Desktop\FRST-OlderVersion
2014-06-06 19:23 - 2014-06-06 12:01 - 00000000 ____D () C:\FRST
2014-06-06 19:23 - 2014-06-06 12:00 - 01063424 _____ (Farbar) C:\Users\georg\Desktop\FRST.exe
2014-06-06 19:20 - 2014-06-06 19:20 - 00000464 _____ () C:\Users\georg\Desktop\mbam.txt
2014-06-06 19:19 - 2014-06-06 19:00 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-06 19:16 - 2011-01-16 22:06 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-06 19:16 - 2010-07-07 20:31 - 00237928 _____ () C:\Windows\PFRO.log
2014-06-06 19:16 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-06 19:16 - 2009-07-14 06:39 - 00184351 _____ () C:\Windows\setupact.log
2014-06-06 19:15 - 2011-01-14 18:19 - 01581975 _____ () C:\Windows\WindowsUpdate.log
2014-06-06 19:02 - 2009-07-14 06:34 - 00009888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-06 19:02 - 2009-07-14 06:34 - 00009888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-06 19:00 - 2014-06-06 19:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-06 19:00 - 2012-01-12 21:24 - 00000000 ____D () C:\Users\georg\AppData\Roaming\Malwarebytes
2014-06-06 19:00 - 2012-01-12 21:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-06 19:00 - 2011-01-16 22:06 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-06 18:58 - 2014-06-06 18:58 - 00014857 _____ () C:\Users\georg\Desktop\JRT.txt
2014-06-06 18:56 - 2014-06-06 18:56 - 00000000 ____D () C:\Windows\ERUNT
2014-06-06 18:52 - 2014-06-06 18:49 - 00000000 ____D () C:\AdwCleaner
2014-06-06 18:36 - 2014-06-06 18:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\georg\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-06 18:35 - 2014-06-06 18:35 - 01333465 _____ () C:\Users\georg\Desktop\adwcleaner_3.212.exe
2014-06-06 18:35 - 2014-06-06 18:35 - 01016261 _____ (Thisisu) C:\Users\georg\Desktop\JRT.exe
2014-06-06 18:18 - 2014-06-06 18:18 - 00010402 _____ () C:\Users\georg\Desktop\ghcombofixgh.txt
2014-06-06 18:12 - 2014-06-06 18:12 - 00010402 _____ () C:\ComboFix.txt
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\Testbrowser1\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\testbrowser\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\renate\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\jens\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\ghadmin\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\eva\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 18:12 - 00000000 ____D () C:\Users\anna\AppData\Local\temp
2014-06-06 18:12 - 2014-06-06 17:59 - 00000000 ____D () C:\Qoobox
2014-06-06 18:12 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-06-06 18:11 - 2014-06-06 17:59 - 00000000 ____D () C:\Windows\erdnt
2014-06-06 18:11 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-06-06 17:53 - 2014-06-06 17:53 - 05205146 ____R (Swearware) C:\Users\georg\Desktop\ComboFix.exe
2014-06-06 15:23 - 2014-06-06 15:23 - 00380416 _____ () C:\Users\georg\Downloads\Gmer-19357.exe
2014-06-06 12:02 - 2014-06-06 12:02 - 00027464 _____ () C:\Users\georg\Desktop\ghAddition.txt
2014-06-06 12:02 - 2014-06-06 12:01 - 00023347 _____ () C:\Users\georg\Desktop\ghFRST.txt
2014-06-06 11:59 - 2014-06-06 11:59 - 00000472 _____ () C:\Users\georg\Desktop\ghdefogger_disable.log
2014-06-06 11:59 - 2014-06-06 11:59 - 00000000 _____ () C:\Users\georg\defogger_reenable
2014-06-06 11:59 - 2011-01-14 21:18 - 00000000 ____D () C:\Users\georg
2014-06-06 11:58 - 2014-06-06 11:58 - 00050477 _____ () C:\Users\georg\Desktop\Defogger.exe
2014-06-06 11:48 - 2011-10-09 09:29 - 00000000 ____D () C:\Users\renate\AppData\Roaming\Skype
2014-06-05 20:56 - 2014-06-05 20:56 - 00000000 ____D () C:\Users\testbrowser\AppData\Local\Macromedia
2014-06-05 20:56 - 2012-01-13 13:02 - 00000000 ____D () C:\Users\testbrowser
2014-06-05 20:54 - 2014-06-05 20:54 - 00000000 ____D () C:\Users\testbrowser\Downloads\antvideo
2014-06-05 20:54 - 2012-01-13 13:04 - 00000000 ____D () C:\Users\testbrowser\AppData\Roaming\Mozilla
2014-06-05 20:54 - 2012-01-13 13:04 - 00000000 ____D () C:\Users\testbrowser\AppData\Local\Mozilla
2014-06-05 20:37 - 2011-05-17 17:25 - 00000000 ____D () C:\Program Files\Akademische Arbeitsgemeinschaft
2014-06-05 17:03 - 2014-01-04 12:40 - 01767424 _____ () C:\Users\georg\Documents\Home-Bank.sub
2014-06-05 16:53 - 2014-01-04 14:25 - 00483328 _____ () C:\Users\georg\Documents\Lauftreff.sub
2014-06-05 16:45 - 2010-07-06 22:23 - 01498506 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-31 20:01 - 2014-05-30 10:26 - 00000000 ____D () C:\Users\georg\Documents\samsung s3 backup
2014-05-27 15:55 - 2013-09-01 09:45 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-27 15:55 - 2013-09-01 09:45 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-12 07:26 - 2014-06-06 19:00 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-06 19:00 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:25 - 2012-01-12 21:24 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-07 19:15 - 2012-01-13 13:02 - 00000000 ____D () C:\Users\testbrowser\AppData\Roaming\ArcSoft
Some content of TEMP:
====================
C:\Users\georg\AppData\Local\temp\avgnt.exe
C:\Users\georg\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-30 07:58
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:06-06-2014
Ran by georg at 2014-06-06 19:24:17
Running from C:\Users\georg\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Acrobat.com (HKLM\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Acronis*True*Image*Home 2012 (HKLM\...\{77DDEEB4-CBF4-4B4C-8366-07E8CC03692B}Visible) (Version: 15.0.6154 - Acronis)
Acronis*True*Image*Home 2012 (Version: 15.0.6154 - Acronis) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe AIR (Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden
Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.2.152.26 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Magic-i Visual Effects 2 (HKLM\...\{334713BA-B8E7-4A60-988C-4110753A191E}) (Version: 2.0.11.80 - ArcSoft)
ArcSoft WebCam Companion 3 (HKLM\...\{6D8EACA3-664E-4F83-8A84-BE3AE952DAB6}) (Version: 3.0.7.264 - ArcSoft)
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira)
Banking 4W (HKLM\...\TopBanking) (Version: - Subsembly GmbH)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2602 - CyberLink Corp.)
CyberLink LabelPrint (Version: 2.5.2602 - CyberLink Corp.) Hidden
CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.)
CyberLink Power2Go (Version: 6.1.3802 - CyberLink Corp.) Hidden
CyberLink PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2815 - CyberLink Corp.)
CyberLink PowerDirector (Version: 8.0.2815 - CyberLink Corp.) Hidden
CyberLink PowerDVD 9 (HKLM\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.2519.50 - CyberLink Corp.)
CyberLink PowerDVD 9 (Version: 9.0.2519.50 - CyberLink Corp.) Hidden
CyberLink PowerDVD Copy (HKLM\...\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.5.1306 - CyberLink Corp.)
CyberLink PowerDVD Copy (Version: 1.5.1306 - CyberLink Corp.) Hidden
CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0.2.2326 - CyberLink Corp.)
CyberLink PowerProducer (Version: 5.0.2.2326 - CyberLink Corp.) Hidden
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DC120 (HKLM\...\DC120) (Version: - )
Deluxe Snake version 3.8.1 (HKLM\...\Deluxe Snake_is1) (Version: 3.8.1 - Daniel Schlyder)
Geldtipps Homebanking 2011 1und1 (HKLM\...\{BE618A02-45E7-4456-8277-D05BE76B9E1A}) (Version: 3.27 - Akademische Arbeitsgemeinschaft)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
HP Button Manager (HKLM\...\{7390FC95-D842-448A-A3A2-C8DC89AEB83A}) (Version: 1.6.0.0 - Hewlett-Packard)
HP Officejet 4620 series - Grundlegende Software für das Gerät (HKLM\...\{717130C7-FEA7-4D63-AEE3-00EF2F41ACDD}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 4620 series Hilfe (HKLM\...\{72EDA2AC-2908-4BB3-97E5-4F9DDEBF9731}) (Version: 6.0.0 - Hewlett Packard)
HP WebCam Benutzerhandbuch (HKLM\...\{D31612BB-C6D7-4142-96AE-16DB062354CF}) (Version: - Hewlett-Packard)
I.R.I.S. OCR (HKLM\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Intel(R) Control Center (HKLM\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 14.3 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.28 - Irfan Skiljan)
iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Logitech Harmony Remote Software 7 (HKLM\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech)
Logitech Harmony Remote Software 7 (Version: 7.7.0.0 - Logitech) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Medion Home Cinema (HKLM\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.1517 - CyberLink Corp.)
Medion Home Cinema (Version: 8.0.1517 - CyberLink Corp.) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Corporation (Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft LifeCam (HKLM\...\{BD71B413-9FEE-49BB-A6D1-2C0BFB99BDFE}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MindManager 2002 (HKLM\...\MindManager 2002) (Version: 4.6.171 - Mindjet LLC)
MiniTool Partition Wizard Home Edition 7.1 (HKLM\...\{34A153FE-6926-4C14-B48A-B71E68C672A8}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 29.0 (x86 de) (HKLM\...\Mozilla Firefox 29.0 (x86 de)) (Version: 29.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5721 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.61.39 - NVIDIA Corporation)
NVIDIA PhysX (HKLM\...\{DEA314C4-0929-4250-BC92-98E4C105F28D}) (Version: 9.10.0129 - NVIDIA Corporation)
PC Connectivity Solution (HKLM\...\{AC599724-5755-48C1-ABE7-ABB857652930}) (Version: 8.15.0.0 - Nokia)
PDF Architect (HKLM\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.1 - pdfforge)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6083 - Realtek Semiconductor Corp.)
Remote Control USB Driver (HKLM\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - )
SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version: - )
Samsung Mobile Modem Device Software (HKLM\...\Samsung Mobile Modem Device) (Version: - )
SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - )
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - )
SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - )
Samsung New PC Studio (HKLM\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
Samsung New PC Studio USB Driver Installer (HKLM\...\InstallShield_{AF7E85DC-317C-47F5-810E-B82EE093A612}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio USB Driver Installer (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Mobile Device Software (HKLM\...\SAMSUNG USB Mobile Device) (Version: - )
SamsungConnectivityCableDriver (HKLM\...\{7E84FAC8-C518-40F9-9807-7455301D6D25}) (Version: 6.83.6.2.1 - Samsung)
Skype™ 6.3 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.107 - Skype Technologies S.A.)
SourceGear DiffMerge 3.3.2.1139 (x86) (HKLM\...\{88C1A719-C868-4FD1-8F95-8E5AEA5BF206}) (Version: 3.3.2.1139 - SourceGear, LLC)
TreeSize Professional 5.3.3 (HKLM\...\TreeSize Professional_is1) (Version: 5.3.3 - JAM Software)
VLC media player 2.1.0 (HKLM\...\VLC media player) (Version: 2.1.0 - VideoLAN)
Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows-Treiberpaket - Nokia pccsmcfd (10/12/2007 6.85.4.0) (HKLM\...\3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F) (Version: 10/12/2007 6.85.4.0 - Nokia)
==================== Restore Points =========================
11-05-2014 10:41:11 Geplanter Prüfpunkt
20-05-2014 11:08:04 Geplanter Prüfpunkt
30-05-2014 06:05:39 Geplanter Prüfpunkt
05-06-2014 18:23:08 Removed AAVUpdateManager.
05-06-2014 18:36:31 Removed AAVUpdateManager.
==================== Hosts content: ==========================
2009-07-14 04:04 - 2014-06-06 18:10 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {68FA8388-9837-4DA4-A802-613212D76604} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-16] (Google Inc.)
Task: {F3D6A448-EB36-40EA-80D9-4F4D4719BA09} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-16] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 21:58 - 2014-02-12 21:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2010-07-08 22:55 - 2009-04-17 18:01 - 00247152 ____N () C:\Program Files\CyberLink\Shared files\RichVideo.exe
2012-06-28 17:58 - 2011-12-16 14:02 - 00435552 _____ () C:\Program Files\Acronis\TrueImageHome\Common\ulxmlrpcpp.dll
2012-06-28 21:46 - 2011-12-16 17:51 - 13923280 _____ () C:\Program Files\Acronis\TrueImageHome\Common\ti_managers.dll
2011-01-15 14:46 - 2011-01-15 14:46 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\be6fde9e4dbe4483b2d9882741988b89\IsdiInterop.ni.dll
2010-07-08 01:41 - 2010-03-04 05:08 - 00058880 _____ () C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\georg\Documents\ltgrill2010.jpg.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\georg\Documents\ltgrill2010.jpg.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
MSCONFIG\Services: iPod Service => 3
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Error: (06/06/2014 07:20:00 PM) (Source: WMPNetworkSvc) (EventID: 14324) (User: )
Description: WMPNetworkSvc0x80004002
Error: (06/06/2014 07:18:08 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Heimnetzgruppen-Listener" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147467262.
Error: (06/06/2014 07:18:03 PM) (Source: WMPNetworkSvc) (EventID: 14324) (User: )
Description: WMPNetworkSvc0x80004002
Error: (06/06/2014 07:17:53 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "MSCamSvc" wurde nicht richtig gestartet.
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2014-06-05 20:16:36.432
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Malwarebytes' Anti-Malware\mbampt.exe" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 34%
Total physical RAM: 3326.18 MB
Available physical RAM: 2186.05 MB
Total Pagefile: 6650.63 MB
Available Pagefile: 5290.27 MB
Total Virtual: 2047.88 MB
Available Virtual: 1906.11 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:900.41 GB) (Free:696.81 GB) NTFS
Drive d: (Recover) (Fixed) (Total:30 GB) (Free:9.98 GB) NTFS
Drive f: (zweite-300-platte) (Fixed) (Total:279.48 GB) (Free:45.14 GB) NTFS
Drive k: (GEORG-V2) (Removable) (Total:1.86 GB) (Free:1.48 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 168AF31D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=900 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=30 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
========================================================
Disk: 1 (Size: 279 GB) (Disk ID: 837B837B)
Partition 1: (Active) - (Size=279 GB) - (Type=07 NTFS)
========================================================
Disk: 5 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: 30A1FECE)
Partition 1: (Active) - (Size=2 GB) - (Type=0B)
==================== End Of Log ============================ --- --- --- |