Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Getwindowinfo entfernen

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 16.09.2013, 11:45   #11
Nadine333
 
Getwindowinfo entfernen - Standard

Getwindowinfo entfernen



Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-09-2013
Ran by Nadine333 at 2013-09-15 19:39:09 Run:2
Running from C:\Users\Nadine333\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Task: {F597493C-D90D-4CAA-ADD2-7D680504E8D3} - \DealPly No Task File
Task: {EB336648-3122-4A20-9C52-6FCD34A4BF0C} - \Browser Updater\Browser Updater No Task File
2013-09-13 12:02 - 2013-09-13 12:02 - 00000000 ____D C:\Windows\System32\Tasks\ProtectedSearch
FF Extension: pricealarm - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
FF Extension: HomeTab - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947}
FF Extension: FoxyDeal - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D}
FF Extension: No Name - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\complitly_0.sqlite
FF Extension: No Name - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\WTB_GLOBAL.sqlite
FF HKLM-x32\...\Firefox\Extensions: [{52b0f3db-f988-4788-b9dc-861d016f4487}] - C:\Program Files (x86)\Web Check\WebCheck.xpi
FF Extension: No Name - C:\Program Files (x86)\Web Check\WebCheck.xpi
BHO-x32: Web Check - {E155F23C-9931-47c6-A619-20E6FCA86D75} - C:\Program Files (x86)\Web Check\WebCheck.dll (Web Check)
SearchScopes: HKLM-x32 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://search.certified-toolbar.com?si=99&st=bs&tid=0&q={searchTerms}
2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____D C:\Program Files (x86)\Web Check
FF Homepage: hxxp://startsear.ch/?hp=df

*****************

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F597493C-D90D-4CAA-ADD2-7D680504E8D3} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F597493C-D90D-4CAA-ADD2-7D680504E8D3} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EB336648-3122-4A20-9C52-6FCD34A4BF0C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB336648-3122-4A20-9C52-6FCD34A4BF0C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater\Browser Updater => Key deleted successfully.
C:\Windows\System32\Tasks\ProtectedSearch => Moved successfully.
C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM => Moved successfully.
C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} => Moved successfully.
C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} => Moved successfully.
C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\complitly_0.sqlite => Moved successfully.
C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\WTB_GLOBAL.sqlite => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{52b0f3db-f988-4788-b9dc-861d016f4487} => Value deleted successfully.
C:\Program Files (x86)\Web Check\WebCheck.xpi => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E155F23C-9931-47c6-A619-20E6FCA86D75} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{E155F23C-9931-47c6-A619-20E6FCA86D75} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
C:\Program Files (x86)\Web Check => Moved successfully.
Firefox homepage deleted successfully.

==== End of Fixlog ====

Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.09.15.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
Nadine333 :: KATERLIE [Administrator]

Schutz: Aktiviert

15.09.2013 19:43:20
mbam-log-2013-09-15 (19-43-20).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 251852
Laufzeit: 11 Minute(n),

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 1
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {EF7FA7BA-FAA1-11E1-8C77-78843C300ED2} -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 13
C:\Users\Nadine333\AppData\Local\Temp\dealply.exe (PUP.Optional.Dealply) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\mgsqlite3.dll (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\Shortcut_bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\toolbar_vit_sweetim.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\CAB784BF-BAB0-7891-924C-6C0B87DA31B8\MyBabylonTB.exe (PUP.Optional.BabylonToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\CAB784BF-BAB0-7891-924C-6C0B87DA31B8\Latest\MyBabylonTB.exe (PUP.Optional.BabylonToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\CAB784BF-BAB0-7891-924C-6C0B87DA31B8\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\F395AD3D-BAB0-7891-A3D7-2C8784BFAA2D\MyBabylonTB.exe (PUP.Optional.BabylonToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\OfferID4\simupdater.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\OfferID5\simboapp.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\OfferID9000\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\OfferID9001\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Nadine333\AppData\Local\Temp\OfferID9999\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

...wie deaktiviere ich AntiVirus und Firewall?

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=72fffd0211f1a84e9df04e23611b8df3
# engine=15144
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-09-16 09:44:25
# local_time=2013-09-16 11:44:25 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 96 60033 244747955 4148 0
# compatibility_mode=5893 16776573 100 94 234968 130954515 0 0
# scanned=300248
# found=4
# cleaned=0
# scan_time=10955
sh=A086FBA81BEB72CFDE335142C74445E273DFC8E5 ft=0 fh=0000000000000000 vn="JS/Iframe.BS trojan" ac=I fn="C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\mt5iozsx.default\Cache\2\B1\2FA56d01"
sh=754828410EF42ED8CBE1EAB0AE120C7E2B7434CC ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2012-0507.FA trojan" ac=I fn="C:\Users\Gast\AppData\Local\Temp\jar_cache4744379021573566519.tmp"
sh=87EFD62268087AD5F0849F987C426B39706112EB ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Gast\AppData\Local\Temp\jar_cache7874357938633299538.tmp"
sh=1B6959B40AFFDDB38A72F170EC0CF2F25AE1606B ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NAY trojan" ac=I fn="C:\Users\Nadine333\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\6fd48510-12648619"


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-09-2013
Ran by Nadine333 (administrator) on KATERLIE on 16-09-2013 12:44:26
Running from C:\Users\Nadine333\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Users\Nadine333\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10134560 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [226160 2010-07-30] (Alps Electric Co., Ltd.)
HKCU\...\Run: [iPhone PC Suite] - C:\Program Files (x86)\NetDragon\91 Mobile\iPhone\iPhone PC Suite.exe /start
HKCU\...\Run: [SkyDrive] - C:\Users\Nadine333\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257136 2013-09-15] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-03] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] - C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe [538472 2009-06-17] (Symantec Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [597792 2010-01-21] (Sony Corporation)
HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-03-22] (Nullsoft, Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKU\Gast\...\Run: [msnmsgr] - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVED&bmod=EU01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {A16712E9-48DE-43B2-AC61-48E3896C0296} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKCU - {A6E824C5-A7AC-46F9-AA13-A8DCA465AA82} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-0/4?satitle={searchTerms}
SearchScopes: HKCU - {F0F15ED0-8B4E-4D3B-951A-50761BF672F8} URL = hxxp://de.shopping.com/?linkin_id=8056363
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -  No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU -  No Name - {56CF4856-ECB4-4E46-A897-A378821F97B9} -  No File
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} -  No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default
FF NewTab: about:home
FF Homepage: hxxp://www.hintertuxergletscher.at/uploads/tx_coodata/ml_panorama_extrem_snow.jpg
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Nadine333\AppData\Roaming\Mozilla\Firefox\Profiles\pnr75tgy.default\Extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

Chrome: 
=======
CHR Extension: () - C:\Users\NADINE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html
CHR HKLM-x32\...\Chrome\Extension: [bddpogknpjlgfpbboediomaiiaecfajn] - C:\Program Files (x86)\HomeTab\chrome\HomeTab.crx
CHR HKLM-x32\...\Chrome\Extension: [dacechnliklhcacondhhkkfobapdopee] - C:\Program Files (x86)\Web Check\WebCheck.crx

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-11-25] (Sonic Solutions)
S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-11-25] (Sonic Solutions)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
S3 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-13] (soft Xpansion)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [74496 2010-09-27] (Sony Corporation)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1368624 2013-08-01] (Sony Corporation)

==================== Drivers (Whitelisted) ====================

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-06] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-27] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-16 10:21 - 2013-09-16 10:25 - 00000000 ____D C:\Users\Nadine333\Downloads\sortieren
2013-09-16 10:13 - 2013-09-16 10:14 - 00000000 ____D C:\Users\Nadine333\Desktop\Fotos entwickeln
2013-09-16 08:38 - 2013-09-16 08:38 - 02347384 _____ (ESET) C:\Users\Nadine333\Downloads\esetsmartinstaller_enu.exe
2013-09-15 20:56 - 2013-09-15 20:56 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-09-15 20:56 - 2013-09-15 20:56 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-09-15 20:22 - 2013-09-16 08:06 - 00000000 ___RD C:\Users\Nadine333\SkyDrive
2013-09-15 20:22 - 2013-09-15 20:22 - 00002188 _____ C:\Users\Nadine333\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2013-09-15 20:22 - 2013-09-15 20:22 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2013-09-15 20:22 - 2013-09-15 20:21 - 06040688 _____ (Microsoft Corporation) C:\Users\Nadine333\Downloads\SkyDriveSetup.exe
2013-09-15 20:21 - 2013-09-15 20:21 - 00000000 ____D C:\ProgramData\Microsoft SkyDrive
2013-09-15 19:41 - 2013-09-15 19:41 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-09-15 19:41 - 2013-09-15 19:41 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\Malwarebytes
2013-09-15 19:41 - 2013-09-15 19:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-15 19:41 - 2013-09-15 19:41 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-15 19:41 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-15 19:40 - 2013-09-15 19:40 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Nadine333\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-15 19:16 - 2013-09-15 19:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-09-13 20:08 - 2013-09-13 20:24 - 00000000 ____D C:\AdwCleaner
2013-09-13 20:08 - 2013-09-13 20:09 - 01037278 _____ C:\Users\Nadine333\Downloads\adwcleaner.exe
2013-09-13 18:52 - 2013-09-13 22:41 - 00048451 _____ C:\Users\Nadine333\Downloads\Addition.txt
2013-09-13 18:50 - 2013-09-13 18:50 - 00000000 ____D C:\FRST
2013-09-13 18:49 - 2013-09-13 18:49 - 01949572 _____ (Farbar) C:\Users\Nadine333\Downloads\FRST64.exe
2013-09-13 12:11 - 2013-09-13 12:11 - 00010464 _____ C:\Windows\SysWOW64\sx_p2d.tlb
2013-09-13 12:10 - 2013-09-13 12:26 - 00000000 ____D C:\ProgramData\Freemium
2013-09-13 12:09 - 2013-09-13 12:09 - 00000000 ____D C:\Users\Nadine333\Downloads\freepdf
2013-09-13 12:02 - 2013-09-13 22:37 - 00000000 ____D C:\SoloApp
2013-09-13 12:02 - 2013-09-13 20:24 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-09-13 12:02 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe
2013-09-13 11:56 - 2013-09-13 11:56 - 00444400 _____ C:\Users\Nadine333\Downloads\DLG_free-pdf-perfect_chip_de-DE10.exe
2013-09-12 23:21 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-12 23:21 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-12 23:21 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-12 23:21 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-12 23:21 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-12 23:21 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-12 23:21 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-12 23:21 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-12 23:21 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-12 23:21 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-12 23:21 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-12 23:21 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-12 23:21 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-12 23:21 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-12 23:21 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-12 23:21 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-12 23:21 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-12 23:21 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-12 23:21 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-12 23:21 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-12 23:21 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-12 21:31 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 21:31 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-12 21:31 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-12 21:31 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-12 21:31 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-12 21:31 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-12 21:31 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-12 21:31 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-12 21:31 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-12 21:31 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-12 21:31 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-12 21:31 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-12 21:31 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-12 21:31 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-12 21:31 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-12 21:31 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-12 21:31 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-12 21:31 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-12 21:31 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-12 21:31 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-12 21:31 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-12 21:31 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 21:31 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-12 21:31 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-12 21:31 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-12 21:31 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-12 21:31 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-12 20:44 - 2013-09-16 10:23 - 00000000 ____D C:\Users\Nadine333\Documents\Gutachten - Befundaufnahme
2013-09-10 11:30 - 2013-09-10 11:32 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-08-24 21:56 - 2013-09-16 10:23 - 00000000 ___RD C:\Users\Nadine333\Desktop\Studium
2013-08-19 11:54 - 2013-08-19 11:54 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-08-19 11:53 - 2013-08-19 11:54 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-19 11:53 - 2013-08-19 11:54 - 00000000 ____D C:\Program Files\iTunes
2013-08-19 11:53 - 2013-08-19 11:54 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-08-19 11:53 - 2013-08-19 11:53 - 00000000 ____D C:\Program Files\iPod
2013-08-19 11:41 - 2013-09-13 12:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== One Month Modified Files and Folders =======

2013-09-16 12:42 - 2010-12-07 05:34 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-16 12:04 - 2012-04-18 21:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-16 11:05 - 2011-04-19 16:05 - 01980515 _____ C:\Windows\WindowsUpdate.log
2013-09-16 10:31 - 2011-04-22 18:39 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\SoftGrid Client
2013-09-16 10:25 - 2013-09-16 10:21 - 00000000 ____D C:\Users\Nadine333\Downloads\sortieren
2013-09-16 10:23 - 2013-09-12 20:44 - 00000000 ____D C:\Users\Nadine333\Documents\Gutachten - Befundaufnahme
2013-09-16 10:23 - 2013-08-24 21:56 - 00000000 ___RD C:\Users\Nadine333\Desktop\Studium
2013-09-16 10:14 - 2013-09-16 10:13 - 00000000 ____D C:\Users\Nadine333\Desktop\Fotos entwickeln
2013-09-16 09:44 - 2011-04-19 23:33 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\Winamp
2013-09-16 08:38 - 2013-09-16 08:38 - 02347384 _____ (ESET) C:\Users\Nadine333\Downloads\esetsmartinstaller_enu.exe
2013-09-16 08:09 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-16 08:09 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-16 08:06 - 2013-09-15 20:22 - 00000000 ___RD C:\Users\Nadine333\SkyDrive
2013-09-16 08:01 - 2010-12-07 05:34 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-16 07:58 - 2010-12-07 06:04 - 00160252 _____ C:\Windows\PFRO.log
2013-09-16 07:58 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-16 07:58 - 2009-07-14 06:51 - 00144471 _____ C:\Windows\setupact.log
2013-09-15 21:01 - 2011-11-20 22:09 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-15 21:00 - 2009-07-14 04:34 - 00000478 _____ C:\Windows\win.ini
2013-09-15 20:56 - 2013-09-15 20:56 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-09-15 20:56 - 2013-09-15 20:56 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-09-15 20:22 - 2013-09-15 20:22 - 00002188 _____ C:\Users\Nadine333\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2013-09-15 20:22 - 2013-09-15 20:22 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2013-09-15 20:22 - 2011-04-19 16:05 - 00000000 ____D C:\Users\Nadine333
2013-09-15 20:21 - 2013-09-15 20:22 - 06040688 _____ (Microsoft Corporation) C:\Users\Nadine333\Downloads\SkyDriveSetup.exe
2013-09-15 20:21 - 2013-09-15 20:21 - 00000000 ____D C:\ProgramData\Microsoft SkyDrive
2013-09-15 20:03 - 2011-04-19 16:06 - 00117384 _____ C:\Users\Nadine333\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-15 19:59 - 2009-07-14 06:45 - 00437176 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-15 19:41 - 2013-09-15 19:41 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-09-15 19:41 - 2013-09-15 19:41 - 00000000 ____D C:\Users\Nadine333\AppData\Roaming\Malwarebytes
2013-09-15 19:41 - 2013-09-15 19:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-15 19:41 - 2013-09-15 19:41 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-15 19:40 - 2013-09-15 19:40 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Nadine333\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-15 19:25 - 2010-12-07 05:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-09-15 19:21 - 2009-07-14 09:45 - 00000000 ____D C:\Windows\ShellNew
2013-09-15 19:18 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-09-15 19:16 - 2013-09-15 19:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-09-15 12:55 - 2011-04-19 16:09 - 00003946 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{02601A2E-B72F-4DB2-9ECC-7A01B39F69F6}
2013-09-13 22:41 - 2013-09-13 18:52 - 00048451 _____ C:\Users\Nadine333\Downloads\Addition.txt
2013-09-13 22:37 - 2013-09-13 12:02 - 00000000 ____D C:\SoloApp
2013-09-13 21:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-13 20:24 - 2013-09-13 20:08 - 00000000 ____D C:\AdwCleaner
2013-09-13 20:24 - 2013-09-13 12:02 - 00000000 ____D C:\Windows\System32\Tasks\Browser Updater
2013-09-13 20:24 - 2011-04-19 16:09 - 00000000 ___RD C:\Users\Nadine333\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-13 20:09 - 2013-09-13 20:08 - 01037278 _____ C:\Users\Nadine333\Downloads\adwcleaner.exe
2013-09-13 18:50 - 2013-09-13 18:50 - 00000000 ____D C:\FRST
2013-09-13 18:49 - 2013-09-13 18:49 - 01949572 _____ (Farbar) C:\Users\Nadine333\Downloads\FRST64.exe
2013-09-13 12:26 - 2013-09-13 12:10 - 00000000 ____D C:\ProgramData\Freemium
2013-09-13 12:11 - 2013-09-13 12:11 - 00010464 _____ C:\Windows\SysWOW64\sx_p2d.tlb
2013-09-13 12:09 - 2013-09-13 12:09 - 00000000 ____D C:\Users\Nadine333\Downloads\freepdf
2013-09-13 12:08 - 2013-08-19 11:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-13 11:56 - 2013-09-13 11:56 - 00444400 _____ C:\Users\Nadine333\Downloads\DLG_free-pdf-perfect_chip_de-DE10.exe
2013-09-13 08:42 - 2011-04-19 16:09 - 00000000 ___RD C:\Users\Nadine333\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-13 08:35 - 2010-12-07 05:34 - 00000000 ____D C:\Program Files\Google
2013-09-13 08:35 - 2010-12-07 05:34 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-12 23:21 - 2011-04-22 18:38 - 01527912 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-09-12 23:21 - 2011-04-22 18:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2013-09-12 23:21 - 2010-12-07 14:13 - 00654852 _____ C:\Windows\system32\perfh007.dat
2013-09-12 23:21 - 2010-12-07 14:13 - 00130434 _____ C:\Windows\system32\perfc007.dat
2013-09-12 23:20 - 2013-08-14 15:10 - 00000000 ____D C:\Windows\system32\MRT
2013-09-12 23:17 - 2011-04-29 18:23 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-12 21:35 - 2013-05-08 00:50 - 00013874 _____ C:\Windows\IE10_main.log
2013-09-12 21:26 - 2011-04-19 16:14 - 00000000 ____D C:\Users\Nadine333\AppData\Local\Google
2013-09-12 21:26 - 2010-12-07 05:34 - 00000000 ____D C:\ProgramData\Google
2013-09-12 21:04 - 2012-04-18 21:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-12 21:04 - 2012-04-18 21:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-12 21:04 - 2011-06-17 15:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-12 20:55 - 2011-04-25 10:45 - 00000000 ____D C:\Update
2013-09-12 20:48 - 2010-12-07 05:35 - 00000000 ____D C:\ProgramData\Sony Corporation
2013-09-10 11:32 - 2013-09-10 11:30 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-09-06 09:07 - 2013-03-27 19:17 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-26 18:32 - 2013-03-04 21:19 - 00000000 ___RD C:\Users\Nadine333\Desktop\Vienna pics
2013-08-25 21:32 - 2011-04-24 01:11 - 00000000 ____D C:\Users\Nadine333\Desktop\Handy pics
2013-08-25 18:32 - 2011-04-20 11:12 - 00000000 ____D C:\Users\Nadine333\Documents\Bewerbungsunterlagen
2013-08-24 21:43 - 2012-04-30 20:08 - 00000000 ____D C:\Users\Nadine333\Documents\Word Dateien
2013-08-24 21:40 - 2013-02-06 20:23 - 00000000 ____D C:\Users\Public\Documents\Wohnung
2013-08-21 15:27 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-21 07:53 - 2012-05-05 11:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-20 11:16 - 2009-07-14 07:13 - 01500294 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-20 10:14 - 2013-05-06 14:11 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-20 10:14 - 2013-03-27 19:17 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-19 11:54 - 2013-08-19 11:54 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-08-19 11:54 - 2013-08-19 11:53 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-19 11:54 - 2013-08-19 11:53 - 00000000 ____D C:\Program Files\iTunes
2013-08-19 11:54 - 2013-08-19 11:53 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-08-19 11:53 - 2013-08-19 11:53 - 00000000 ____D C:\Program Files\iPod

Files to move or delete:
====================
C:\Users\Gast\AppData\Local\Temp\AskSLib.dll
C:\Users\Gast\AppData\Local\Temp\msgA344.exe
C:\Users\Nadine333\AppData\Local\Temp\84962-658111-microsoft-office-2010-professional.exe
C:\Users\Nadine333\AppData\Local\Temp\apptorun.exe
C:\Users\Nadine333\AppData\Local\Temp\AskSLib.dll
C:\Users\Nadine333\AppData\Local\Temp\EAD27CA.exe
C:\Users\Nadine333\AppData\Local\Temp\EAD2A0D.exe
C:\Users\Nadine333\AppData\Local\Temp\EAD3890.exe
C:\Users\Nadine333\AppData\Local\Temp\EAD3C7.exe
C:\Users\Nadine333\AppData\Local\Temp\EAD54B.exe
C:\Users\Nadine333\AppData\Local\Temp\EAD5502.exe
C:\Users\Nadine333\AppData\Local\Temp\EAD9936.exe
C:\Users\Nadine333\AppData\Local\Temp\EADA622.exe
C:\Users\Nadine333\AppData\Local\Temp\EADC88B.exe
C:\Users\Nadine333\AppData\Local\Temp\EADCD4C.exe
C:\Users\Nadine333\AppData\Local\Temp\EADEEA2.exe
C:\Users\Nadine333\AppData\Local\Temp\EADF5E6.exe
C:\Users\Nadine333\AppData\Local\Temp\installerdll166687.dll
C:\Users\Nadine333\AppData\Local\Temp\installerdll188558.dll
C:\Users\Nadine333\AppData\Local\Temp\installerdll44766234.dll
C:\Users\Nadine333\AppData\Local\Temp\installerdll44788729.dll
C:\Users\Nadine333\AppData\Local\Temp\instloffer.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-1.6.0_20-windows-i586-iftw.exe_90744722.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-6u20-windows-i586-jinstall_uac.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Nadine333\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Nadine333\AppData\Local\Temp\Quarantine.exe
C:\Users\Nadine333\AppData\Local\Temp\Setup.exe
C:\Users\Nadine333\AppData\Local\Temp\SIMEEI2Installer.exe
C:\Users\Nadine333\AppData\Local\Temp\SIMEEIInstaller.exe
C:\Users\Nadine333\AppData\Local\Temp\SIntf16.dll
C:\Users\Nadine333\AppData\Local\Temp\SIntf32.dll
C:\Users\Nadine333\AppData\Local\Temp\SIntfNT.dll
C:\Users\Nadine333\AppData\Local\Temp\_is7E05.exe
C:\Users\Nadine333\AppData\Local\Temp\~convert4585880079106920541.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-09-13 20:56

==================== End Of Log ============================
         
--- --- ---

--- --- ---

 

Themen zu Getwindowinfo entfernen
dankbar, entferne, entfernen, getwindowinfo, hilfe, hilfe!, hilfe!!, hilfe!!!, troja, trojaner




Ähnliche Themen: Getwindowinfo entfernen


  1. getwindowinfo entfernen
    Plagegeister aller Art und deren Bekämpfung - 29.03.2015 (19)
  2. Internet Explorer Meldung getwindowinfo
    Log-Analyse und Auswertung - 03.02.2014 (10)
  3. getwindowinfo-Virus
    Plagegeister aller Art und deren Bekämpfung - 10.12.2013 (3)
  4. Problem mit getwindowinfo
    Log-Analyse und Auswertung - 02.11.2013 (15)
  5. getwindowinfo entfernen
    Plagegeister aller Art und deren Bekämpfung - 29.10.2013 (15)
  6. Vielen Dank an M-K-D-B bei der Beseitigung von getwindowinfo
    Lob, Kritik und Wünsche - 26.10.2013 (1)
  7. getwindowinfo Problem
    Log-Analyse und Auswertung - 25.10.2013 (12)
  8. 2x | getwindowinfo entfernen
    Mülltonne - 24.10.2013 (1)
  9. Getwindowinfo
    Plagegeister aller Art und deren Bekämpfung - 23.10.2013 (23)
  10. getwindowinfo entfernen unter windows 7 ?
    Plagegeister aller Art und deren Bekämpfung - 03.10.2013 (16)
  11. Getwindowinfo
    Plagegeister aller Art und deren Bekämpfung - 17.09.2013 (12)
  12. getwindowinfo - Trojaner
    Plagegeister aller Art und deren Bekämpfung - 11.09.2013 (1)
  13. getwindowinfo Virus
    Plagegeister aller Art und deren Bekämpfung - 04.09.2013 (7)
  14. Internetexplorer öffnet getwindowinfo
    Plagegeister aller Art und deren Bekämpfung - 29.08.2013 (5)
  15. getwindowinfo
    Plagegeister aller Art und deren Bekämpfung - 26.08.2013 (15)
  16. getwindowinfo öffnet meinen internetexplorer
    Plagegeister aller Art und deren Bekämpfung - 24.08.2013 (5)
  17. getwindowinfo/
    Plagegeister aller Art und deren Bekämpfung - 03.08.2013 (24)

Zum Thema Getwindowinfo entfernen - Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-09-2013 Ran by Nadine333 at 2013-09-15 19:39:09 Run:2 Running from C:\Users\Nadine333\Downloads Boot Mode: Normal ============================================== Content of fixlist: - Getwindowinfo entfernen...
Archiv
Du betrachtest: Getwindowinfo entfernen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.