Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Avira durch Gruppenrichtlinie geblockt - Trojaner?

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 15.06.2014, 01:37   #1
Lorelai!
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Hallo,

ich habe jetzt wohl ein ernsthaftes Problem auf meinem Laptop, Windows Vista, 32 Bit-Betriebssystem, Home Premium.
Ich kann Avira nicht mehr starten und nur sehr schwer deinstallieren, da die Fehlermeldung kommt, dass das Programm durch eine Gruppenrichtlinie geblockt ist und ich mich an den Systemadministrator wenden soll.
Eine Mitteilung meiner Bank habe ich auch schon bekommen, dass meine Online-Banking-Daten ausgespäht worden sind und auf einem ausländischen Phishing-Server gespeichert worden sind.

Ich habe schon AVG 2014 und Kaspersky installiert und laufen lassen und da ist jetzt soweit alles in Ordnung. Die ein, zwei Bedrohungen sind neutralisiert, die dort angezeigt worden sind. Im gesicherten Modus war ich anschließend, um Avira mit dem "Avira Registry Cleaner" komplett deinstallieren zu können. Nach Neuinstallation zeigt er mir die gleiche Fehlermeldung noch an.
Also scheint es wirklich ein Trojaner zu sein. Ich kenne mich leider so gar nicht aus und habe versucht, mich ein bisschen schlau zu lesen...

Kann mir jemand helfen?
Vielen, vielen Dank!

Grüße,
Lorelai!

Alt 15.06.2014, 01:42   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Hallo und

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!




Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 15.06.2014, 03:20   #3
Lorelai!
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Hallo,

schon mal vielen Dank für die Hilfe.
Leider bin ich überhaupt nicht fit in Informatik und hab jetzt versucht, den Schritten zu folgen.

Ich habe Malwarebytes Anti-Malware, Emsisoft Anti Malware und ESET Online Scan nicht. Avira kann ich nicht öffnen, sodass ich leider nicht weiß, wie ich Logs in Kaspersky auslesen kann.
Ich hab eine Datei mit dem Screenshot der Funde bei Kaspersky mal angehängt. Vielleicht hilft das weiter...
Außer dass im Internet Explorer keine Downloads mehr möglich sind seit einer Woche, ist mir nichts weiteres aufgefallen.


Hier ist FRST (hab meinen Nachnamen überall gelöscht):


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:12-06-2014 02
Ran by Claudia (administrator) on CLAUDIA1 on 15-06-2014 02:11:49
Running from C:\Users\Claudia\Desktop
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.24.7\GoogleCrashHandler.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
(ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
(Empolis GmbH) C:\Program Files\Common Files\Gnab\Service\ServiceController.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
() C:\Program Files\Launch Manager\LaunchAp.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe
(Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe
(Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe
(Wistron) C:\Program Files\Launch Manager\WButton.exe
(Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
() C:\Windows\System32\PSIService.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
() C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\pvrservice.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe
(Sonix) C:\Windows\vsnp2uvc.exe
() C:\Windows\FixCamera.exe
() C:\Windows\tsnp2uvc.exe
() C:\Program Files\1&1 Surf-Stick\AssistantServices.exe
() C:\Program Files\1&1 Surf-Stick\UIExec.exe
() C:\Program Files\TV IR\TV IR.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Google Inc.) C:\Program Files\Picasa2\PicasaMediaDetector.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(1&1 Mail & Media GmbH) C:\Users\Claudia\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe
(Microsoft Corporation) C:\Windows\System32\p2phost.exe
(ArcSoft, Inc.) C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
(Dropbox, Inc.) C:\Users\Claudia Grützmacher\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Opera Software) C:\Program Files\Opera\opera.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6025216 2008-04-01] (Realtek Semiconductor)
HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-08-31] (Synaptics, Inc.)
HKLM\...\Run: [LaunchAp] => C:\Program Files\Launch Manager\LaunchAp.exe [32768 2007-09-01] ()
HKLM\...\Run: [HotkeyApp] => C:\Program Files\Launch Manager\HotkeyApp.exe [188416 2007-09-06] (Wistron)
HKLM\...\Run: [CtrlVol] => "C:\Program Files\Launch Manager\CtrlVol.exe"
HKLM\...\Run: [LMgrOSD] => C:\Program Files\Launch Manager\OSD.exe [180224 2006-12-26] (Wistron Corp.)
HKLM\...\Run: [Wbutton] => C:\Program Files\Launch Manager\Wbutton.exe [86016 2007-09-07] (Wistron)
HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( )
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [Corel Photo Downloader] => "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" -startup
HKLM\...\Run: [Corel File Shell Monitor] => C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16200 2007-10-30] ()
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe [581632 2007-11-30] (Sonix)
HKLM\...\Run: [FixCamera] => C:\Windows\FixCamera.exe [20480 2007-02-12] ()
HKLM\...\Run: [tsnp2uvc] => C:\Windows\tsnp2uvc.exe [249856 2007-12-04] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-05-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated)
HKLM\...\Run: [UIExec] => C:\Program Files\1&1 Surf-Stick\UIExec.exe [139088 2010-09-30] ()
HKLM\...\Run: [TV IR] => C:\Program Files\TV IR\TV IR.exe [692318 2010-12-22] ()
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [183376 2014-05-14] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-09] (Avira Operations GmbH & Co. KG)
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe [443968 2008-02-26] (Google Inc.)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [EPSON SX420W Series] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Epson Stylus SX420W(Netzwerk)] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Device Detection] => C:\Program Files\Lidl_Fotos\dd.exe
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [GMX Application {sync-000021}] => C:\Users\Claudia Grützmacher\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe [878080 2013-08-09] (1&1 Mail & Media GmbH)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\RunOnce: [Shockwave Updater] - C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1100429.exe [439736 2008-03-19] (Adobe Systems, Inc.)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {680ae5c9-5a41-11de-81b4-0015afb8023d} - G:\BlueJ.bat
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {b7bf007e-eef6-11e3-92c0-000ae4cddb4b} - F:\HTC_Sync_Manager_PC.exe
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk
ShortcutTarget: TMMonitor.lnk -> C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.)
Startup: C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} -  No File
URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
SearchScopes: HKCU - {01_TL-YODL-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_google&q={searchTerms}
SearchScopes: HKCU - {03_TL-TELEFONBUCH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_telefonbuch&q={searchTerms}
SearchScopes: HKCU - {04_TL-AMAZON-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_amazon&q={searchTerms}
SearchScopes: HKCU - {05_TL-EBAY-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_ebay&q={searchTerms}
SearchScopes: HKCU - {06_TL-DISCOUNT24-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_discount24&q={searchTerms}
SearchScopes: HKCU - {07_TL-CONRAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_conrad&q={searchTerms}
SearchScopes: HKCU - {08_TL-OTTO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_otto&q={searchTerms}
SearchScopes: HKCU - {09_TL-CLIPFISH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_clipfish&q={searchTerms}
SearchScopes: HKCU - {10_TL-MYVIDEO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_myvideo&q={searchTerms}
SearchScopes: HKCU - {11_TL-MUSICLOAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_musicload&q={searchTerms}
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
SearchScopes: HKCU - {CF739809-1C6C-47C0-85B9-569DBB141420} URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?gct=&gc=1&q={searchTerms}&crm=1&toolbar=DVS
SearchScopes: HKCU - {DBAFD4EB-E4E1-4A25-97C2-D1CB5F7D0368} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=971163&p={searchTerms}
BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: No Name - {7E853D72-626A-48EC-A868-BA8D5E23E045} -  No File
BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
Toolbar: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - DVDVideoSoftTB Toolbar - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 83.169.185.161 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default
FF DefaultSearchEngine: ICQ Search
FF SearchEngineOrder.1: Ask
FF SelectedSearchEngine: ICQ Search
FF Homepage: hxxp://www.hiergehtslos.de
FF Keyword.URL: hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Claudia Grützmacher\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\ask.xml
FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\icqplugin.xml
FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\clipfish.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\conrad.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\discount24.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\ebay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\musicload.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\myvideo.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\otto.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\quelle.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\telefonbuch-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\webnews.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009-08-13]
FF Extension: ICQ Toolbar - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2011-04-24]
FF Extension: DVDVideoSoftTB Community Toolbar - C:\Users\Claudia Grützmacher\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} [2011-10-29]
FF Extension: Free YouTube Download (Free Studio) Menu - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2012-12-31]
FF Extension: DVDVideoSoft Toolbar - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} [2009-12-18]
FF Extension: Firefox Companion for eBay - C:\Program Files\Mozilla Firefox\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088} [2008-11-14]
FF Extension: ICQ Toolbar - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2008-12-15]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions:  - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-14]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-14]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-14]
FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard Software\BullGuard\antispam\tbspamfilter

Chrome: 
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (DivX Web Player) - C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll (DivX,Inc.)
CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-06-14]
CHR Extension: (Google Wallet) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-14]
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-06-14]
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2012-12-31]

========================== Services (Whitelisted) =================

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [123984 2014-05-14] (Avira Operations GmbH & Co. KG)
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-19] (Empolis GmbH) [File not signed]
S2 gupdate1c9e6034feeea56; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-05] (Google Inc.)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () [File not signed]
R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1801216 2008-02-28] (Buhl Data Service GmbH) [File not signed]
R2 UI Assistant Service; C:\Program Files\1&1 Surf-Stick\AssistantServices.exe [253264 2010-09-30] ()
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2006-06-14] (Ulead Systems, Inc.) [File not signed]
S3 usnjsvc; C:\Program Files\MSN Messenger\usnsvc.exe [97136 2007-01-19] (Microsoft Corporation)
R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118784 2007-09-11] (Wistron Corp.) [File not signed]

==================== Drivers (Whitelisted) ====================

R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed]
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [122136 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [198936 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [149784 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [192280 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [237848 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [107288 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-05-09] (Avira Operations GmbH & Co. KG)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [210200 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-05-09] (Avira Operations GmbH & Co. KG)
S3 DVC; C:\Windows\System32\Drivers\DVC.sys [38401 2001-09-09] (Samsung Electronics) [File not signed]
R1 Hotkey; C:\Windows\system32\Drivers\Hotkey.sys [9867 2003-04-28] () [File not signed]
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-06-14] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-06-14] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-06-14] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-06-14] (Kaspersky Lab ZAO)
R0 Si3531; C:\Windows\System32\DRIVERS\Si3531.sys [212008 2008-07-25] (Silicon Image, Inc)
R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17064 2008-07-25] (Silicon Image, Inc.)
R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12200 2008-07-25] (Silicon Image, Inc.)
S3 smsbda; C:\Windows\System32\drivers\smsbda.sys [45440 2011-03-06] (Siano)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [9610880 2007-11-29] ()
S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-05-09] (Avira GmbH)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [94304 2014-06-14] (Kaspersky Lab ZAO)
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-15 02:11 - 2014-06-15 02:14 - 00034989 _____ () C:\Users\Claudia\Desktop\FRST.txt
2014-06-15 02:05 - 2014-06-15 02:12 - 00000000 ____D () C:\FRST
2014-06-15 02:03 - 2014-06-15 02:03 - 01073152 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe
2014-06-15 00:42 - 2014-06-15 00:42 - 00001006 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-06-15 00:42 - 2014-06-15 00:42 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-15 00:41 - 2014-06-15 00:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Claudia Grützmacher\Desktop\avira_de_av_4019404326__ws.exe
2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe
2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam
2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus
2014-06-14 14:04 - 2014-06-14 14:02 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2014-06-14 13:57 - 2014-06-15 01:49 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-14 13:57 - 2014-06-14 14:31 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-14 13:57 - 2014-06-14 14:31 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking
2014-06-13 22:53 - 2014-06-13 22:53 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\AVG2014
2014-06-13 22:52 - 2014-06-13 22:52 - 00000862 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software
2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-06-13 22:50 - 2014-06-13 22:53 - 00000000 ____D () C:\ProgramData\AVG2014
2014-06-13 22:50 - 2014-06-13 22:50 - 00000000 ___HD () C:\$AVG
2014-06-13 22:49 - 2014-06-13 22:49 - 00000000 ____D () C:\Program Files\AVG
2014-06-13 22:47 - 2014-06-14 18:29 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-13 22:47 - 2014-06-13 22:58 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Avg2014
2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData
2014-06-13 22:42 - 2014-06-13 22:45 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe
2014-06-13 21:56 - 2014-06-13 22:41 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing
2014-06-11 19:28 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 19:27 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 19:27 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 19:27 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 19:27 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 19:27 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 19:27 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 19:27 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-11 19:27 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 19:27 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 19:27 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-11 19:27 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-11 19:27 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 19:27 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 19:27 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 19:27 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC
2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations
2014-06-08 12:42 - 2014-06-08 12:56 - 00000000 ____D () C:\Temp
2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC
2014-06-08 12:42 - 2009-06-10 09:49 - 00024576 _____ (HTC, Corporation) C:\Windows\system32\Drivers\ANDROIDUSB.sys
2014-06-08 12:42 - 2009-06-09 07:41 - 01122664 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll
2014-06-07 20:30 - 2014-06-07 20:30 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe
2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet
2014-06-07 19:56 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet
2014-05-18 00:39 - 2014-05-18 00:39 - 00000000 ____D () C:\Users\Claudia\restore
2014-05-18 00:02 - 2014-06-14 01:26 - 00000000 ____D () C:\ProgramData\tmp
2014-05-18 00:02 - 2014-05-18 16:35 - 00000000 ____D () C:\ProgramData\hps
2014-05-18 00:01 - 2014-05-18 00:01 - 00001106 _____ () C:\Users\Public\Desktop\OnlineFotoservice.lnk
2014-05-18 00:01 - 2014-05-18 00:01 - 00001091 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
2014-05-18 00:01 - 2014-05-18 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnlineFotoservice
2014-05-17 23:20 - 2014-05-17 23:20 - 00000000 ____D () C:\Program Files\OnlineFotoservice
2014-05-16 20:11 - 2014-05-16 20:11 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-05-16 19:46 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll

==================== One Month Modified Files and Folders =======

2014-06-15 02:14 - 2014-06-15 02:11 - 00034989 _____ () C:\Users\Claudia\Desktop\FRST.txt
2014-06-15 02:14 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Temp
2014-06-15 02:12 - 2014-06-15 02:05 - 00000000 ____D () C:\FRST
2014-06-15 02:06 - 2012-09-08 16:32 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Dropbox
2014-06-15 02:05 - 2009-06-30 19:24 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-15 02:03 - 2014-06-15 02:03 - 01073152 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe
2014-06-15 01:49 - 2014-06-14 13:57 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-15 01:24 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-15 01:24 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-15 01:11 - 2008-01-21 09:16 - 01643446 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-15 00:48 - 2008-08-07 13:55 - 01501350 _____ () C:\Windows\WindowsUpdate.log
2014-06-15 00:42 - 2014-06-15 00:42 - 00001006 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-06-15 00:42 - 2014-06-15 00:42 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-15 00:42 - 2012-11-25 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-06-15 00:42 - 2012-10-23 16:35 - 00000000 ____D () C:\ProgramData\Avira
2014-06-15 00:42 - 2012-10-23 16:35 - 00000000 ____D () C:\Program Files\Avira
2014-06-15 00:41 - 2014-06-15 00:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Claudia\Desktop\avira_de_av_4019404326__ws.exe
2014-06-15 00:35 - 2014-05-13 22:19 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\DropboxMaster
2014-06-15 00:35 - 2012-09-08 16:36 - 00000000 ___RD () C:\Users\Claudia\Dropbox
2014-06-15 00:31 - 2009-06-30 19:24 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-15 00:31 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-15 00:24 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe
2014-06-14 19:19 - 2012-11-17 22:37 - 00001967 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-14 18:29 - 2014-06-13 22:47 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-14 15:05 - 2008-01-21 04:47 - 00431444 _____ () C:\Windows\PFRO.log
2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam
2014-06-14 14:31 - 2014-06-14 13:57 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-14 14:31 - 2014-06-14 13:57 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-14 14:31 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2014-06-14 14:31 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys
2014-06-14 14:31 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus
2014-06-14 14:02 - 2014-06-14 14:04 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2014-06-14 14:01 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia
2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-06-14 01:26 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\tmp
2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking
2014-06-13 22:58 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Avg2014
2014-06-13 22:53 - 2014-06-13 22:53 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\AVG2014
2014-06-13 22:53 - 2014-06-13 22:50 - 00000000 ____D () C:\ProgramData\AVG2014
2014-06-13 22:52 - 2014-06-13 22:52 - 00000862 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software
2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-06-13 22:50 - 2014-06-13 22:50 - 00000000 ___HD () C:\$AVG
2014-06-13 22:49 - 2014-06-13 22:49 - 00000000 ____D () C:\Program Files\AVG
2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData
2014-06-13 22:45 - 2014-06-13 22:42 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe
2014-06-13 22:41 - 2014-06-13 21:56 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing
2014-06-11 20:10 - 2008-04-21 14:41 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-11 20:05 - 2013-08-06 20:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 20:05 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-06-11 19:53 - 2008-11-30 15:45 - 00002627 _____ () C:\Users\Claudia\Desktop\Microsoft Office Word 2007.lnk
2014-06-11 19:49 - 2009-08-24 13:59 - 00000000 ____D () C:\Users\Claudia\Documents\Bewerbung
2014-06-09 01:59 - 2008-08-07 18:11 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Corel
2014-06-09 00:54 - 2008-08-07 19:39 - 00000000 ____D () C:\Users\Claudia\Documents\My PSP Files
2014-06-09 00:54 - 2008-08-07 18:12 - 00004182 ___SH () C:\Windows\system32\KGyGaAvL.sys
2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2014-06-08 13:24 - 2006-11-02 14:52 - 00162202 _____ () C:\Windows\setupact.log
2014-06-08 12:56 - 2014-06-08 12:42 - 00000000 ____D () C:\Temp
2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC
2014-06-08 12:54 - 2008-04-21 09:32 - 00025966 _____ () C:\Windows\DPINST.LOG
2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations
2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC
2014-06-07 20:30 - 2014-06-07 20:30 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe
2014-06-07 20:25 - 2012-07-08 20:11 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-06-07 20:25 - 2011-07-13 22:41 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet
2014-06-07 19:59 - 2014-06-07 19:56 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet
2014-06-07 19:57 - 2008-04-21 10:34 - 00000000 ____D () C:\ProgramData\Adobe
2014-05-28 18:48 - 2014-06-11 19:27 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-28 18:39 - 2014-06-11 19:27 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-28 18:38 - 2014-06-11 19:27 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-28 18:33 - 2014-06-11 19:27 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-28 18:32 - 2014-06-11 19:27 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-28 18:32 - 2014-06-11 19:27 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-28 18:31 - 2014-06-11 19:27 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-05-28 18:31 - 2014-06-11 19:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-28 18:30 - 2014-06-11 19:27 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-28 18:29 - 2014-06-11 19:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-05-28 18:29 - 2014-06-11 19:27 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-05-28 18:28 - 2014-06-11 19:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-24 12:35 - 2012-09-08 16:36 - 00000965 _____ () C:\Users\Claudia\Desktop\Dropbox.lnk
2014-05-24 12:35 - 2012-09-08 16:33 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-18 21:51 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-18 19:45 - 2009-06-08 18:48 - 00000000 ____D () C:\Program Files\Picasa2
2014-05-18 19:10 - 2009-11-15 15:52 - 00130060 _____ () C:\Users\Claudia\AppData\Roaming\mdbu.bin
2014-05-18 16:35 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\hps
2014-05-18 00:39 - 2014-05-18 00:39 - 00000000 ____D () C:\Users\Claudia\restore
2014-05-18 00:01 - 2014-05-18 00:01 - 00001106 _____ () C:\Users\Public\Desktop\OnlineFotoservice.lnk
2014-05-18 00:01 - 2014-05-18 00:01 - 00001091 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
2014-05-18 00:01 - 2014-05-18 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnlineFotoservice
2014-05-17 23:20 - 2014-05-17 23:20 - 00000000 ____D () C:\Program Files\OnlineFotoservice
2014-05-16 20:11 - 2014-05-16 20:11 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER

Files to move or delete:
====================
C:\Users\Claudia\AppData\Roaming\desktop.ini


Some content of TEMP:
====================
C:\Users\Claudia\AppData\Local\Temp\ABD2BC~1.exe
C:\Users\Claudia\AppData\Local\Temp\AdobeUpdater12345.exe
C:\Users\Claudia\AppData\Local\Temp\AskSLib.dll
C:\Users\Claudia\AppData\Local\Temp\avgnt.exe
C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuztmgc.dll
C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe
C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe
C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe
C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe
C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe
C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe
C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe
C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\unwise.exe
C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll
C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe
C:\Users\Claudia\AppData\Local\Temp\_is30.exe
C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe
C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe
C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe
C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-15 00:39

==================== End Of Log ============================
         
--- --- ---


Additional scan result of Farbar Recovery Scan Tool (x86) Version:12-

06-2014 02
Ran by Claudia at 2014-06-15 02:15:54
Running from C:\Users\Claudia\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-

AAE50FA36859}
AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-

06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Kaspersky Anti-Virus (Enabled - Up to date) {179979E8-273D-D14E-

0543-2861940E4886}
AS: Kaspersky Anti-Virus (Enabled - Up to date) {ACF8980C-0107-DEC0-

3FF3-1313EF89023B}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-

9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44

-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-

2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{90120000-

0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B-

8FD1FF0E6438}) (Version: - Microsoft)
Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{91120000-

002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-

8FD1FF0E6438}) (Version: - Microsoft)
1&1 Surf-Stick (HKLM\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04})

(Version: 1.0.0.2 - )
3531-W-D (HKLM\...\{BD1587F7-B8D0-4111-8F1F-3327628AB02F}) (Version:

1.5.18 - Silicon Image)
AAC Decoder (HKLM\...\{AEF9DC35ADDF4825B049ACBFD1C6EB37}) (Version:

7.1.0 - DivX, Inc.)
ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6-

2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
ABBYY FineReader 9.0 Sprint (HKLM\...\ABBYY FineReader 9.0 Sprint)

(Version: 9.01.513.58212 - ABBYY)
ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212 - ABBYY) Hidden
Activation Assistant for the 2007 Microsoft Office suites

(HKLM\...\Activation Assistant for the 2007 Microsoft Office suites)

(Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version:

1.0 - Microsoft Corporation) Hidden
Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX)

(Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin)

(Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 8.3.0 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-

A83000000003}) (Version: 8.3.0 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM\...\Adobe Shockwave Player) (Version: 11

- Adobe Systems, Inc.)
Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version:

- Agere Systems)
ArcSoft MediaConverter 2 (HKLM\...\{83DA46EC-2CB1-4649-9100-

C4F98D8DA8CD}) (Version: - ArcSoft)
ArcSoft PhotoImpression 5 (HKLM\...\{4FE82F4B-B7D8-4E65-84AD-

E0436CDE57DD}) (Version: - ArcSoft)
ArcSoft ShowBiz DVD 2 (HKLM\...\{E883DCB3-766D-4166-8B28-

33C8FE451F2B}) (Version: - ArcSoft)
ArcSoft TotalMedia 3.5 (HKLM\...\{29E44E9D-ACB2-4D2D-849F-

5361C941B7E1}) (Version: 3.5.7.362 - ArcSoft)
AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1

- )
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4592 - AVG Technologies)
AVG 2014 (Version: 14.0.3964 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4592 - AVG Technologies) Hidden
Avira (HKLM\...\{68e29fba-92b1-4f6f-a604-1d8679da3a9f}) (Version:

1.1.13.24161 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version:

14.0.4.642 - Avira)
Camera RAW Plug-In for EPSON Creativity Suite (HKLM\...\{93EA9C3E-

BDFD-4309-A605-9B5BBC0CCEFD}) (Version: 2.2.0.0 - SEIKO EPSON

CORPORATION)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-

0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft

Corporation)
Conduit Engine (HKLM\...\conduitEngine) (Version: - Conduit Ltd.)

<==== ATTENTION
Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721})

(Version: 2.00.0000 - Corel Corporation)
Corel Paint Shop Pro Photo X2 (HKLM\...\{64E72FB1-2343-4977-B4A8-

262CD53D0BD3}) (Version: 12.010.0000 - Corel Corporation)
Digital Video (HKLM\...\{C833C7B6-1140-471D-932B-391B5CA66D7D})

(Version: 1.00.000 - )
DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version:

6.8.5 - DivX, Inc.)
DivX Converter (HKLM\...\{13F3917B56CD4C25848BDC69916971BB}) (Version:

7.0.0 - DivX, Inc.)
DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version:

7.0.0 - DivX, Inc.)
DivX Player (HKLM\...\{8ADFC4160D694100B5B8A22DE9DCABD9}) (Version:

7.0.0 - DivX, Inc.)
DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters)

(Version: - DivX, Inc.)
DivX Version Checker (HKLM\...\{3FC7CBBC4C1E11DCA1A752EA55D89593})

(Version: 7.0.0.19 - DivX, Inc.)
DivX Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29})

(Version: 1.4.2 - DivX,Inc.)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
DVDVideoSoft Toolbar (HKLM\...\DVDVideoSoft Toolbar) (Version: - )
DVDVideoSoftTB Toolbar (HKLM\...\DVDVideoSoftTB Toolbar) (Version:

6.3.3.3 - DVDVideoSoftTB)
EPSON Attach To Email (HKLM\...\InstallShield_{20C45B32-5AB6-46A4-

94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM\...\{67EDD823-135A-4D59-87BD-950616D6E857})

(Version: 3.3.0.0 - )
EPSON Easy Photo Print (HKLM\...\{3D78F2A2-C893-4ABD-B5FE-

AD7011837755}) (Version: 1.5.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print 2 (HKLM\...\{39F58DDB-B2B8-4B86-AF20-

4706A80EB30D}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)

(HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000

- SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47})

(Version: 2.40.0001 - SEIKO EPSON CORPORATION)
EPSON File Manager (HKLM\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6})

(Version: 1.3.0.0 - )
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson

Corporation)
EPSON Scan Assistant (HKLM\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64})

(Version: 1.10.00 - )
EPSON Stylus CX7300_CX8300_DX7400_DX8400 Handbuch (HKLM\...\EPSON

Stylus CX7300_CX8300_DX7400_DX8400 Benutzerhandbuch) (Version: - )
EPSON SX420W Series Handbuch (HKLM\...\EPSON SX420W Series Manual)

(Version: - )
EPSON SX420W Series Netzwerk-Handbuch (HKLM\...\EPSON SX420W Series

Network Guide) (Version: - )
EPSON SX420W Series Printer Uninstall (HKLM\...\EPSON SX420W Series)

(Version: - SEIKO EPSON Corporation)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities)

(Version: - SEIKO EPSON Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799})

(Version: 2.4i - SEIKO EPSON CORPORATION)
EpsonNet Setup 3.2 (HKLM\...\{C9D8A041-2963-4B31-8FFC-1500F3DB9293})

(Version: 3.2a - SEIKO EPSON CORPORATION)
Firebird SQL Server - MAGIX Edition (HKLM\...\Firebird SQL Server D)

(Version: 2.0.1.8 - MAGIX AG)
Free Audio CD Burner version 1.2 (HKLM\...\Free Audio CD Burner_is1)

(Version: - DVDVideoSoft Limited.)
Free YouTube Download version 3.0.16.923 (HKLM\...\Free YouTube

Download_is1) (Version: - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.11.37.1212 (HKLM\...\Free

YouTube to MP3 Converter_is1) (Version: 3.11.37.1212 - DVDVideoSoft

Ltd.)
GMX MediaCenter 1.5.1765.0 (HKCU\...\GMX Application {sync-000021})

(Version: 1.5.1765.0 - 1&1 Mail & Media GmbH)
Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 -

Google Inc.)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E})

(Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
H.264 Decoder (HKLM\...\{A96E97134CA649888820BCDE5E300BBD}) (Version:

1.0.0 - DivX, Inc.)
ICQ7.4 (HKLM\...\{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}) (Version: 7.4

- ICQ)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:

- Intel Corporation)
Intel(R) Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-

5E35E2C0E09E}) (Version: - )
InterVideo WinDVD 8 (HKLM\...\InstallShield_{20471B27-D702-4FE8-8DEC-

0702CC8C0A85}) (Version: 8.0-B9.385 - InterVideo Inc.)
InterVideo WinDVD 8 (Version: 8.0-B9.385 - InterVideo Inc.) Hidden
IPTInstaller (HKLM\...\{6965F2F4-1CD2-4F42-A8EF-9EF433F9AA72})

(Version: 4.0.4 - HTC)
Java(TM) 6 Update 5 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160050})

(Version: 1.6.0.50 - Sun Microsystems, Inc.)
Kaspersky Anti-Virus (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-

231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab)
Kaspersky Anti-Virus (Version: 14.0.0.4651 - Kaspersky Lab) Hidden
Launch Manager V1.4.9 (HKLM\...\{D0846526-66DD-4DC9-A02C-

98F9A2806812}) (Version: 1.4.9 - Wistron Corp.)
LG PC Suite II (HKLM\...\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6})

(Version: 2.00.0000 - LG PC Suite)
LG PC Suite II (Version: 2.00.0000 - LG PC Suite) Hidden
LG USB Modem driver (HKLM\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579})

(Version: 4.9.4 - LG Electronics)
MD86351 Driver Install (HKLM\...\InstallShield_{B3A9DC22-6162-4844-

BEB3-853BAFB980E0}) (Version: 6.3.6.1 - Ihr Firmenname)
MD86351 Driver Install (Version: 6.3.6.1 - Ihr Firmenname) Hidden
MEDION Fotos auf CD Nord (HKLM\...\MEDION Fotos auf CD Nord D)

(Version: 6.0.2.0 - MAGIX AG)
Medion Media Center 0 (Version: 1.0.12.0 - Medion) Hidden
MEDIONbox (HKLM\...\{27FDF949-69CE-435A-8372-339F72336AC5}) (Version:

1.09.0000.00052 - Medion)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1

(1033)) (Version: - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 1.1 Security Update (KB2698023)

(HKLM\...\M2698023) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941)

(HKLM\...\M2833941) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB979906)

(HKLM\...\M979906) (Version: - )
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU

(HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu)

(Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version:

3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework

3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft

Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft

Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-

45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft

Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-

CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft

Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-

0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-

199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-

0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-

199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft)

Hidden
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version:

12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version:

12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft

Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000

-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version:

12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR)

(Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000

- Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-

7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (Version:

12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000

- Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 -

Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 -

Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: -

Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000

- Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version:

12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 -

Microsoft Corporation) Hidden
Microsoft Picture It! Foto Premium 9 (HKLM\...\PictureIt_v9) (Version:

9.0.0.0000 - Microsoft Corporation)
Microsoft Picture It! Foto Premium 9 (Version: 9.0.0.0000 - Microsoft

Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-

2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

(HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version:

8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-

4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-

493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

(HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version:

9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

(HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022

- Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729

(HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729

- Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

(HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729

- Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

(HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version:

9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

(HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version:

9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

(HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219

- Microsoft Corporation)
Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C})

(Version: 9.7.0621 - Microsoft Corporation)
Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation)

Hidden
MindManager Smart (HKLM\...\MindManager Smart) (Version: 2.1.3 -

Mindjet LLC)
MKV Splitter (HKLM\...\{AAC389499AEF40428987B3D30CFC76C9}) (Version:

1.0.0 - DivX, Inc.)
Move Networks Media Player for Internet Explorer (HKCU\...\Move

Networks Player - IE) (Version: - )
Mozilla Firefox (3.0) (HKLM\...\Mozilla Firefox (3.0)) (Version: 3.0

(de) - Mozilla)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-

6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-

F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-

8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-

8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031})

(Version: 8.3.124 - Nero AG)
neroxml (Version: 1.0.0 - Nero AG) Hidden
OnlineFotoservice (HKLM\...\OnlineFotoservice) (Version: 5.1.5 - CEWE

Stiftung u Co. KGaA)
Opera 12.12 (HKLM\...\Opera 12.12.1707) (Version: 12.12.1707 - Opera

Software ASA)
PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}

_is1) (Version: - PDF24.org)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version:

0.9.8 - Frank Heindörfer, Philip Chinery)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Ralink Wireless LAN (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF})

(Version: 1.00.0000 - RaLink)
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for

Windows Vista (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476})

(Version: 1.00.0000 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-

8A7C-958108FE7DBC}) (Version: 6.0.1.5595 - Realtek Semiconductor

Corp.)
Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-

CE685433FA7D}) (Version: - Realtek Semiconductor Corp.)
Rossmann Fotoservice 2.6 (HKLM\...\Rossmann Fotoservice_is1) (Version:

- )
Sceneo AbsolutTV (HKLM\...\{4C73B683-B15D-4B94-AC7A-520B70C4FFE9})

(Version: - )
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D})

(Version: 6.11.102 - Skype Technologies S.A.)
Switch Sound File Converter (HKLM\...\Switch) (Version: - NCH

Software)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version:

10.0.14.0 - Synaptics)
TV IR (HKLM\...\InstallShield_{8CFE319F-DC08-48BA-B011-37ED5C9733B5})

(Version: 1.00.0000 - Ihr Firmenname)
TV IR (Version: 1.00.0000 - Ihr Firmenname) Hidden
Ulead DVD MovieFactory 5 (HKLM\...\{FF164702-AF8B-4F2F-8038-

74A4C536866B}) (Version: 5.3 - Ulead Systems, Inc.)
Ulead PhotoImpact 12 (HKLM\...\{11AFE21E-B193-430D-B57A-DFF7815BB962})

(Version: 12.0 - Ulead System)
Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version: - )
Update for 2007 Microsoft Office System (KB967642)

(HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D

-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for 2007 Microsoft Office System (KB967642)

(HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_

{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

(HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1

- Microsoft Corporation)
Update for Microsoft Office 2007 Help for Common Features (KB963673)

(HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{AB365889

-0395-4FAD-B702-CA5985D53D42}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition

(HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B

-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition

(HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_

{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition

(HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0

-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition

(HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_

{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition

(HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945

-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition

(HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_

{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft)
Update for Microsoft Office Access 2007 Help (KB963663)

(HKLM\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{6B76A18A

-AA1E-42AB-A7AD-6C84BBB43987}) (Version: - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678)

(HKLM\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{199DF7B6

-169C-448C-B511-1054101BE9C9}) (Version: - Microsoft)
Update for Microsoft Office Infopath 2007 Help (KB963662)

(HKLM\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{716B81B8

-B13C-41DF-8EAC-7A2F656CAB63}) (Version: - Microsoft)
Update for Microsoft Office OneNote 2007 Help (KB963670)

(HKLM\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2744EF05

-38E1-4D5D-B333-E021EDAEA245}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition

(HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3

-4F61-494E-8BCA-E3AC7760C924}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition

(HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068

-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Help (KB963677)

(HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{0451F231

-E3E3-4943-AB9F-58EB96171784}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2881065)

32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{B7EF38F7-1D58-4085-A9A4-0F6C69A5AA1E}) (Version: -

Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)

(HKLM\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{397B1D4F

-ED7B-4ACA-A637-43B670843876}) (Version: - Microsoft)
Update for Microsoft Office Publisher 2007 Help (KB963667)

(HKLM\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2E40DE55

-B289-4C8B-8901-5D369B16814F}) (Version: - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671)

(HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{CD11C6A2

-FFC6-4271-8EAB-79C3582F505C}) (Version: - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665)

(HKLM\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{80E762AA

-C921-4839-9D7D-DB62A72C0726}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678)

(HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_

{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)

(HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_

{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665)

(HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_

{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
USB Video Device (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F})

(Version: 5.8.18100.101 - Sonix)
VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0 - DivX, Inc) Hidden
VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B

-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 1.1.10 (HKLM\...\VLC media player) (Version: 1.1.10 -

VideoLAN)
WavePad Sound Editor (HKLM\...\WavePad) (Version: - NCH Software)
Windows Live Messenger (HKLM\...\{279DB581-239C-4E13-97F8-

0F48E40BE75C}) (Version: 8.1.0178.00 - Microsoft Corporation)
WinRAR (HKLM\...\WinRAR archiver) (Version: - )
WISO Mein Geld 2008 Professional (HKLM\...\{D8D22773-14BF-4178-A683-

3DBA515C2A26}) (Version: 9.00.01.0023 - Buhl Data Service GmbH)
XVID Codec Installation (HKLM\...\{534C6D59-D6E3-48A6-AD0B-

747799019960}) (Version: - )

==================== Restore Points =========================

04-06-2014 17:38:03 Geplanter Prüfpunkt
07-06-2014 18:44:11 Windows Update
08-06-2014 10:42:59 Gerätetreiber-Paketinstallation: HTC, Corporation
08-06-2014 10:46:45 Gerätetreiber-Paketinstallation: HTC Corporation

Netzwerkadapter
08-06-2014 10:49:34 Gerätetreiber-Paketinstallation: HTC Corporation

Tragbare Geräte
08-06-2014 10:54:49 Gerätetreiber-Paketinstallation: HTC

Netzwerkprotokoll
11-06-2014 17:26:28 Windows Update
11-06-2014 18:00:59 Windows Update
13-06-2014 20:48:59 Installed AVG 2014
13-06-2014 20:50:05 Installed AVG 2014
14-06-2014 11:59:34 Gerätetreiber-Paketinstallation: Kaspersky Lab

Netzwerkdienst

==================== Hosts content: ==========================

2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A

C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0D4A3951-D115-4E17-9495-26DC510E1359} - System32

\Tasks\{19864B7B-6EBE-4684-9FF9-DD775F771854} => C:\Program

Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32

\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32

\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32

\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32

\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32

\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {574969E9-0C4A-4A75-A6C7-549B08CDB6C6} - System32

\Tasks\GoogleUpdateTaskMachineUA => C:\Program

Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.)
Task: {8AC7F5E7-9061-45A6-95FE-B269516DA561} - System32

\Tasks\GoogleUpdateTaskMachineCore => C:\Program

Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.)
Task: {B7794283-DDB2-48C6-9B9B-3AC33999A0C1} - System32

\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe

/d sdengin2.dll,ExecuteScheduledBackup
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32

\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo =>

C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {EEEAB8B8-067F-4F56-8432-3BBC88C3CC8F} - System32

\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32

\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program

Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program

Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2009-09-04 19:29 - 2001-10-28 17:42 - 00116224 _____ ()

C:\Windows\System32\pdfcmnnt.dll
2009-10-03 11:47 - 2005-06-28 13:59 - 00053248 _____ () C:\Program

Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll
2010-01-11 21:06 - 2009-12-12 16:12 - 00141824 _____ () C:\Program

Files\WinRAR\rarext.dll
2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program

Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\dblite.dll
2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program

Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\kpcengine.2.3.dll
2013-07-21 20:03 - 2013-07-21 20:03 - 03391488 _____ ()

c:\windows\assembly\nativeimages1_v1.1.4322

\mscorlib\1.0.5000.0__b77a5c561934e089_b0c6b048\mscorlib.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 01966080 _____ ()

c:\windows\assembly\nativeimages1_v1.1.4322

\system\1.0.5000.0__b77a5c561934e089_c7c004ef\system.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 03035136 _____ ()

c:\windows\assembly\nativeimages1_v1.1.4322

\system.windows.forms\1.0.5000.0__b77a5c561934e089_5c188a8d\system.win

dows.forms.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 02088960 _____ ()

c:\windows\assembly\nativeimages1_v1.1.4322

\system.xml\1.0.5000.0__b77a5c561934e089_821dd40b\system.xml.dll
2008-04-22 08:37 - 2007-04-19 12:11 - 00006656 _____ () c:\program

files\medion\medionbox\program\structconverter.dll
2009-08-18 20:24 - 2009-04-11 08:28 - 00368640 _____ ()

C:\Windows\system32\msjetoledb40.dll
2012-10-08 17:04 - 2012-10-08 17:04 - 00166912 _____ () C:\Program

Files\HTC\Internet Pass-Through\PassThruSvr.exe
2008-04-21 09:37 - 2007-09-01 14:03 - 00032768 _____ () C:\Program

Files\Launch Manager\LaunchAp.exe
2007-06-05 13:20 - 2007-06-05 13:20 - 00177704 _____ ()

C:\Windows\system32\PSIService.exe
2007-10-30 19:52 - 2007-10-30 19:52 - 00016200 _____ () C:\Program

Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
2008-04-22 08:30 - 2007-05-16 22:48 - 00421955 _____ () C:\Program

Files\Sceneo\AbsolutTV\Services\PVR\tvtvRemote.dll
2011-01-08 16:14 - 2007-02-12 15:50 - 00020480 _____ ()

C:\Windows\FixCamera.exe
2011-01-08 16:14 - 2007-12-04 19:28 - 00249856 _____ ()

C:\Windows\tsnp2uvc.exe
2011-08-06 14:59 - 2010-09-30 14:00 - 00253264 _____ () C:\Program

Files\1&1 Surf-Stick\AssistantServices.exe
2011-08-06 14:59 - 2010-09-30 14:00 - 00139088 _____ () C:\Program

Files\1&1 Surf-Stick\UIExec.exe
2010-12-22 11:27 - 2010-12-22 11:27 - 00692318 _____ () C:\Program

Files\TV IR\TV IR.exe
2010-06-18 00:09 - 2010-06-18 00:09 - 00167936 _____ () C:\Program

Files\TV IR\RmCard.dll
2008-01-15 00:40 - 2008-01-15 00:40 - 00053248 _____ () C:\Program

Files\TV IR\LWExt.dll
2009-03-09 11:52 - 2009-03-09 11:52 - 00053248 _____ () C:\Program

Files\TV IR\tmir.dll
2012-10-21 13:31 - 2007-04-19 09:33 - 00035584 _____ () C:\Program

Files\ArcSoft\TotalMedia 3.5\uPiApi.dll
2014-06-15 00:34 - 2014-06-15 00:34 - 00043008 _____ ()

C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.

{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuztmgc.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ ()

C:\Users\Claudia\AppData\Roaming\Dropbox\bin\libcef.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00835584 _____ () C:\Program

Files\Opera\gstreamer\gstreamer.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00093696 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstaudioconvert.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00094208 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstaudioresample.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00057344 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstautodetect.dll
2011-12-11 13:21 - 2012-12-19 20:32 - 00096256 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstcoreplugins.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00062976 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstdecodebin2.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00067072 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstdirectsound.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00158208 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00312832 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstoggdec.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00038912 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstwaveform.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00073728 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstwavparse.dll
2011-08-14 15:39 - 2012-12-19 20:32 - 00101888 _____ () C:\Program

Files\Opera\gstreamer\plugins\gstwebmdec.dll
2014-06-07 20:25 - 2014-06-07 20:25 - 16361136 _____ ()

C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll
2014-05-14 14:27 - 2014-05-14 14:27 - 00137296 _____ () C:\Program

Files\Avira\My Avira\Avira.OE.NativeCore.dll
2014-05-14 14:27 - 2014-05-14 14:27 - 00065616 _____ () C:\Program

Files\Avira\My Avira\Avira.OE.AvConnectorNative.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Claudia\Beweis.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Beweis.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Beweis.png:

{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Desktop\Foto20103.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Desktop\Foto20103.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia \Desktop\Foto20103.jpg:{4c8cc155-6c1e-11d1-8e41-

00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen,

Celle.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen,

Celle.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:{4c8cc155-6c1e

-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen,

Celle.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen,

Celle.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:{4c8cc155-6c1e

-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\ebay

lederjacke.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\ebay

lederjacke.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\ebay

lederjacke.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:{4c8cc155-6c1e-11d1-8e41-

00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Muster

Inspektion VW.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Muster

Inspektion VW.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Muster

Inspektion VW.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\pikante

spaghetti.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\pikante

spaghetti.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\pikante

spaghetti.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\vertrag

maik1.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag

maik1.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:{4c8cc155-

6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\vertrag

maik2.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag

maik2.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:{4c8cc155-

6c1e-11d1-8e41-00c04fb9386d}

==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/15/2014 00:33:52 AM) (Source: WinMgmt) (EventID: 10) (User:

)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent

WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND

TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 00:27:44 AM) (Source: WinMgmt) (EventID: 10) (User:

)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent

WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND

TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 00:26:54 AM) (Source: EventSystem) (EventID: 4609)

(User: )
Description: d:\longhorn\com\complus\src\events\tier1

\eventsystemobj.cpp458007043c

Error: (06/14/2014 11:59:38 PM) (Source: Application Error) (EventID:

1000) (User: )
Description: Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version

3.3.3.0, Zeitstempel 0x47c6bd1b, fehlerhaftes Modul unknown, Version

0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset

0x17271727,
Prozess-ID 0xecc, Anwendungsstartzeit NMIndexStoreSvr.exe0.

Error: (06/14/2014 11:57:39 PM) (Source: WinMgmt) (EventID: 10) (User:

)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent

WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND

TargetInstance.LoadPercentage > 990x80041003

Error: (06/14/2014 11:52:43 PM) (Source: Application Hang) (EventID:

1002) (User: )
Description: Programm nero.exe, Version 8.3.2.2 arbeitet nicht mehr

mit Windows zusammen und wurde beendet. Überprüfen Sie den

Problemverlauf im Applet "Lösungen für Probleme" in der

Systemsteuerung, um nach weiteren Informationen über das Problem zu

suchen.
Prozess-ID: 10e8
Anfangszeit: 01cf881a8af268df
Zeitpunkt der Beendigung: 52

Error: (06/14/2014 05:32:32 PM) (Source: Windows Search Service)

(EventID: 3013) (User: )
Description: Eintrag <C:\USERS\CLAUDIA\{C00C4FB5-D3BF-

4E0A-B53C-B250F89CE13C}\KLIM6.SYS> in der Hash-Zuordnung kann nicht

aktualisiert werden.

Kontext: Anwendung, SystemIndex Katalog


Details:
Ein an das System angeschlossenes Gerät funktioniert

nicht. (0x8007001f)

Error: (06/14/2014 05:32:32 PM) (Source: Windows Search Service)

(EventID: 3013) (User: )
Description: Eintrag <C:\USERS\CLAUDIA\{C00C4FB5-D3BF-

4E0A-B53C-B250F89CE13C}\KLIM6.INF> in der Hash-Zuordnung kann nicht

aktualisiert werden.

Kontext: Anwendung, SystemIndex Katalog


Details:
Ein an das System angeschlossenes Gerät funktioniert

nicht. (0x8007001f)

Error: (06/14/2014 03:06:46 PM) (Source: WinMgmt) (EventID: 10) (User:

)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent

WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND

TargetInstance.LoadPercentage > 990x80041003

Error: (06/14/2014 02:33:58 PM) (Source: MsiInstaller) (EventID: 1023)

(User: NT-AUTORITÄT)
Description: Produkt: Kaspersky Anti-Virus - Update "Kaspersky

Internet Security 2014 (Patch c)" konnte nicht installiert werden.

Fehlercode 1603. Weitere Informationen sind in der Protokolldatei

C:\Windows\TEMP\MSI9a992.LOG enthalten.


System errors:
=============

Microsoft Office Sessions:
=========================
Error: (05/07/2013 08:37:08 PM) (Source: Microsoft Office 12 Sessions)

(EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word,

Application Version: 12.0.6668.5000, Microsoft Office Version:

12.0.6612.1000. This session lasted 810 seconds with 720 seconds of

active time. This session ended with a crash.

Error: (05/13/2011 02:44:54 PM) (Source: Microsoft Office 12 Sessions)

(EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word,

Application Version: 12.0.6545.5000, Microsoft Office Version:

12.0.6425.1000. This session lasted 1089 seconds with 120 seconds of

active time. This session ended with a crash.

Error: (03/20/2011 05:35:34 PM) (Source: Microsoft Office 12 Sessions)

(EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel,

Application Version: 12.0.6545.5000, Microsoft Office Version:

12.0.6425.1000. This session lasted 4422 seconds with 900 seconds of

active time. This session ended with a crash.


CodeIntegrity Errors:
===================================
Date: 2014-06-15 02:15:27.775
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:26.317
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:24.992
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:23.672
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:22.062
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\klkbdflt.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:20.637
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\klkbdflt.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:19.107
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\klkbdflt.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:17.767
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\klkbdflt.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:16.515
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\klif.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.

Date: 2014-06-15 02:15:15.147
Description: Die Abbildintegrität der Datei

"\Device\HarddiskVolume1\Windows\System32\drivers\klif.sys" konnte

nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf

dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 71%
Total physical RAM: 3061.69 MB
Available physical RAM: 885.3 MB
Total Pagefile: 6335.64 MB
Available Pagefile: 3489.04 MB
Total Virtual: 2047.88 MB
Available Virtual: 1890.87 MB

==================== Drives ================================

Drive c: (BOOT) (Fixed) (Total:207.5 GB) (Free:101.39 GB) NTFS ==>

[Drive with boot components (obtained from BCD)]
Drive d: (RECOVER) (Fixed) (Total:25.37 GB) (Free:5.96 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID:

4B64DFC2)
Partition 1: (Active) - (Size=207 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=25 GB) - (Type=OF Extended)

==================== End Of Log ============================[/CODE]



Vielen, vielen Dank!
__________________
Angehängte Grafiken
Dateityp: jpg Funde Kaspersky.jpg (45,0 KB, 107x aufgerufen)

Alt 15.06.2014, 20:35   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION
C:\Users\Claudia\AppData\Local\Temp\ABD2BC~1.exe
C:\Users\Claudia\AppData\Local\Temp\AdobeUpdater12345.exe
C:\Users\Claudia\AppData\Local\Temp\AskSLib.dll
C:\Users\Claudia\AppData\Local\Temp\avgnt.exe
C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuztmgc.dll
C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe
C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe
C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe
C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe
C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe
C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe
C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe
C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\unwise.exe
C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll
C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe
C:\Users\Claudia\AppData\Local\Temp\_is30.exe
C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe
C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe
C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe
C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 16.06.2014, 23:46   #5
Lorelai!
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Danke für deine Hilfe.

Nachfolgend der Inhalt von Fixlog:

Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:16-06-2014
Ran by Claudia at 2014-06-16 23:38:49 Run:1
Running from C:\Users\Claudia\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION
C:\Users\Claudia\AppData\Local\Temp\ABD2BC~1.exe
C:\Users\Claudia\AppData\Local\Temp\AdobeUpdater12345.exe
C:\Users\Claudia\AppData\Local\Temp\AskSLib.dll
C:\Users\Claudia\AppData\Local\Temp\avgnt.exe
C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuztmgc.dll
C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe
C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe
C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe
C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe
C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe
C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe
C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe
C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\unwise.exe
C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll
C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe
C:\Users\Claudia\AppData\Local\Temp\_is30.exe
C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe
C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe
C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe
C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe
*****************

HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
C:\Users\Claudia\AppData\Local\Temp\ABD2BC~1.exe => Moved successfully.
C:\Users\Claudia\AppData\Local\Temp\AdobeUpdater12345.exe => Moved successfully.
C:\Users\Claudia\AppData\Local\Temp\AskSLib.dll => Moved successfully.
         


Alt 16.06.2014, 23:53   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Adware/Junkware/Toolbars entfernen


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________
--> Avira durch Gruppenrichtlinie geblockt - Trojaner?

Alt 17.06.2014, 20:32   #7
Lorelai!
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Hallo,

den adwCleander musste ich dreimal neu starten, weil keine Rückmeldung vorhanden war bzw. habe ich nach jeweils 10 Minuten "keine Rückmeldung" das Programm über den TaskManager geschlossen, da mir leider die Geduld fehlte. Beim dritten Mal habe ich länger abgewartet und dann hat er sich irgendwann wieder gefangen. Hoffe, die zwei Abbrüche haben keine Auswirkungen gehabt.

Bei FRST hat er keinen Addition-Log erstellt. Habe dann gesehen, dass das Häkchen bei "Addition" irgendwie nicht angehakt gewesen ist.
Soll ich FRST nochmal starten mit dem Häkchen "Addition"?

Hier sind die Logs:

AdwCleaner:

Code:
ATTFilter
# AdwCleaner v3.212 - Bericht erstellt am 17/06/2014 um 18:52:03
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Claudia - CLAUDIA1
# Gestartet von : C:\Users\Claudia\Desktop\adwcleaner_3.212.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Users\CLAUDI~1\AppData\Local\Temp\CT2269050
Ordner Gelöscht : C:\Users\Claudia\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Claudia\AppData\LocalLow\ConduitEngine
Ordner Gelöscht : C:\Users\Claudia\AppData\LocalLow\DVDVideoSoftTB
Ordner Gelöscht : C:\Users\Claudia\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\ConduitCommon
Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\ICQToolbarData
Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\CT2269050
Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Ordner Gelöscht : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Ordner Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
Ordner Gelöscht : C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Datei Gelöscht : C:\Program Files\Mozilla Firefox\.autoreg
Datei Gelöscht : C:\Program Files\Mozilla Firefox\Components\AskSearch.js
Datei Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\Ask.xml
Datei Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\icqplugin.xml
Datei Gelöscht : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\icqplugin-1.xml

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7EEF445-225F-4684-B155-FB4DE7B6AFFB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E7EEF445-225F-4684-B155-FB4DE7B6AFFB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A16010A2-0CC9-46A1-98D2-8EFBD1D813B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75A1D390-381B-47EC-A560-46E874AD9393}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8F31308-FAEB-45B6-B3FE-DEBCBA33FB65}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\conduitEngine
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\conduitEngine
Schlüssel Gelöscht : HKLM\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar

***** [ Browser ] *****

-\\ Internet Explorer v9.0.8112.16555

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

-\\ Mozilla Firefox v3.0 (de)

[ Datei : C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\prefs.js ]

Zeile gelöscht : user_pref("CT2269050..clientLogIsEnabled", false);
Zeile gelöscht : user_pref("CT2269050..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2269050..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/default.aspx");
Zeile gelöscht : user_pref("CT2269050.AppTrackingLastCheckTime", "Mon Mar 18 2013 18:49:50 GMT+0100");
Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129575150554007677", true);
Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129681780741097243", true);
Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129853623028165512", true);
Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129881141106886992", true);
Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_129977890572899945", true);
Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_130100683276316706", true);
Zeile gelöscht : user_pref("CT2269050.BrowserCompStateIsOpen_1359634297000", true);
Zeile gelöscht : user_pref("CT2269050.CTID", "CT2269050");
Zeile gelöscht : user_pref("CT2269050.CurrentServerDate", "22-1-2014");
Zeile gelöscht : user_pref("CT2269050.DialogsAlignMode", "LTR");
Zeile gelöscht : user_pref("CT2269050.DialogsGetterLastCheckTime", "Mon Jan 20 2014 18:43:31 GMT+0100");
Zeile gelöscht : user_pref("CT2269050.DownloadReferralCookieData", "");
Zeile gelöscht : user_pref("CT2269050.EMailNotifierPollDate", "Sun Jun 15 2014 00:40:27 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.ExternalComponentPollDate8877840225553681985", "Sat May 15 2010 17:16:19 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.FirstServerDate", "19-2-2012");
Zeile gelöscht : user_pref("CT2269050.FirstTime", true);
Zeile gelöscht : user_pref("CT2269050.FirstTimeFF3", true);
Zeile gelöscht : user_pref("CT2269050.FixPageNotFoundErrors", true);
Zeile gelöscht : user_pref("CT2269050.GroupingServerCheckInterval", 1440);
Zeile gelöscht : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gelöscht : user_pref("CT2269050.HasUserGlobalKeys", true);
Zeile gelöscht : user_pref("CT2269050.HomePageProtectorEnabled", false);
Zeile gelöscht : user_pref("CT2269050.HomepageBeforeUnload", "hxxp://www.hiergehtslos.de");
Zeile gelöscht : user_pref("CT2269050.Initialize", true);
Zeile gelöscht : user_pref("CT2269050.InitializeCommonPrefs", true);
Zeile gelöscht : user_pref("CT2269050.InstallationAndCookieDataSentCount", 3);
Zeile gelöscht : user_pref("CT2269050.InstallationType", "UnknownIntegration");
Zeile gelöscht : user_pref("CT2269050.InstalledDate", "Fri Dec 18 2009 22:19:24 GMT+0100");
Zeile gelöscht : user_pref("CT2269050.InvalidateCache", false);
Zeile gelöscht : user_pref("CT2269050.IsAlertDBUpdated", true);
Zeile gelöscht : user_pref("CT2269050.IsGrouping", false);
Zeile gelöscht : user_pref("CT2269050.IsMulticommunity", false);
Zeile gelöscht : user_pref("CT2269050.IsOpenThankYouPage", false);
Zeile gelöscht : user_pref("CT2269050.IsOpenUninstallPage", false);
Zeile gelöscht : user_pref("CT2269050.LanguagePackLastCheckTime", "Sun Jun 15 2014 00:40:26 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gelöscht : user_pref("CT2269050.LastLogin_2.4.0.4", "Sun Jun 15 2014 00:40:26 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.LastLogin_3.7.0.6", "Tue Jan 21 2014 22:04:01 GMT+0100");
Zeile gelöscht : user_pref("CT2269050.LatestVersion", "3.20.0.4");
Zeile gelöscht : user_pref("CT2269050.Locale", "en");
Zeile gelöscht : user_pref("CT2269050.LoginCache", 4);
Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipHeight", "83");
Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipWidth", "295");
Zeile gelöscht : user_pref("CT2269050.MyStuffEnabledAtInstallation", true);
Zeile gelöscht : user_pref("CT2269050.RadioIsPodcast", false);
Zeile gelöscht : user_pref("CT2269050.RadioLastCheckTime", "Sun Jun 15 2014 00:40:26 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.RadioLastUpdateIPServer", "3");
Zeile gelöscht : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
Zeile gelöscht : user_pref("CT2269050.RadioMediaID", "12473383");
Zeile gelöscht : user_pref("CT2269050.RadioMediaType", "Media Player");
Zeile gelöscht : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383");
Zeile gelöscht : user_pref("CT2269050.RadioShrinkedFromSetup", false);
Zeile gelöscht : user_pref("CT2269050.RadioStationName", "Hotmix%20108");
Zeile gelöscht : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082");
Zeile gelöscht : user_pref("CT2269050.SHRINK_TOOLBAR", 1);
Zeile gelöscht : user_pref("CT2269050.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2269050&octid=EB_ORIGINAL_CTID&SearchSource=1&CUI=SB_CUI&UM=UM_ID");
Zeile gelöscht : user_pref("CT2269050.SearchEngineBeforeUnload", "ICQ Search");
Zeile gelöscht : user_pref("CT2269050.SearchFromAddressBarIsInit", true);
Zeile gelöscht : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=");
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabEnabled", true);
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Sun Jun 15 2014 00:40:24 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID&UM=UM_ID");
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2269050.SearchProtectorEnabled", false);
Zeile gelöscht : user_pref("CT2269050.SearchProtectorToolbarDisabled", false);
Zeile gelöscht : user_pref("CT2269050.ServiceMapLastCheckTime", "Tue Jan 21 2014 22:04:00 GMT+0100");
Zeile gelöscht : user_pref("CT2269050.SettingsCheckIntervalMin", 120);
Zeile gelöscht : user_pref("CT2269050.SettingsLastCheckTime", "Sun Jun 15 2014 00:40:24 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.SettingsLastUpdate", "1389625828");
Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Fri Jun 13 2014 22:42:45 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1331805997");
Zeile gelöscht : user_pref("CT2269050.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2269050.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
Zeile gelöscht : user_pref("CT2269050.UserID", "UN55505124345968816");
Zeile gelöscht : user_pref("CT2269050.WeatherNetwork", "");
Zeile gelöscht : user_pref("CT2269050.WeatherPollDate", "Sun Jun 15 2014 00:40:27 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.WeatherUnit", "C");
Zeile gelöscht : user_pref("CT2269050.[object Object]", "696E6B72403E72717A6F7846494A7D7B7C204D217C");
Zeile gelöscht : user_pref("CT2269050.alertChannelId", "666138");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B474953462D584D503D263F2D2E3135443B464E4F5B565E695B426D6265523B544243464959505B637D737B6E55217578654E675[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C4748402C574C4F3C253E2C2E2B2F433A454E59505B57676A66426D62455E69543D56444643465B525D66716C216E6B587D73675[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462B554A4D4B4749594D33535D4F432C45333439344A414C565B5E6C656E706C7164736D4D786D705D465F4D4E534D645B66705[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e.:2z527", "247E707273303C3833477B473C3F2C742E7E7D792022342B36282A2B474A545D4B585553553762575A4730493A3A3D3B3F4F46514345465E47494A657576747B767154796F634C65565[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F564654524C474A595A4851505E51523964595C49324B393C3B3E5047525D6C6A6B6F786D68506A6F7171742256227679664F6[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C4343534E2D585B3C253E2C302E34433A45515862695E675A416C6164513A5341454348584F5A666D7B7C7174726E702174745B2[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e06cg5el8:", "6E6D6B6B73716C737571");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737171797772797B77242F4B49474F42357D5D5C3D");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E41295547484D515A4E5A59325D5255422B443237303749404B585E685E706E6E6674626E696B4D786D705D465F4D524B51645B66732[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473E454745482F5A4F523F2841302D2F33463D48566265685C6B675F6D70604873686B58415A4946484B5F56616F7C217D74747[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D3229344356554E472E594E51325E4F412A4335373231483F4A59655F5F626C5B717369756975744D786D70517E6B60496252505451675[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352C37474B59574B4A4858584E5E3762573A535E49324B3A3D3F3B504752626C625D75786D766A7C517C7174614A63525557526[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A522B55553A233C2B2F282941384354515E5D56615F56685C426D6265523B544346494A59505B6C697A7E21702370765925797[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D49564A50592E594E314A55402942322E332F473E495B5D595A6A5E58707262674974696C59425B4B474B51605762747C2473737[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B364953545259585A5A50524E36615659462F4838353D3C4D444F626C6D6B72716A77614D786D705D465F4F4C5451645B66797[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347513F445559424C5A315C5154412A4333323037483F4A5E68565B5970606E6C666164734C776C6F5C455E4E4D4B51635A6579247[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E782332293449565540472E594E513E274030323533453C475C5558636A656E625E6C616B7068734B766B6E5B445D4D4F524F6259647927767[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4F44504C4754585C5048345F5457442D46373135344B424D636B5D5F5F73696B4A756A6D5A435C4D474B4961586379226F742[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A30273249485545442C574C4F3C253E2F2A2D2D433A455C67555B5E3F6A5F624F3851423D403F564D586F7A68786C717154207477644D66575[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354D462C574C4F3C253E2F2B2B31433A455D6356575C5C5A416C6164513A5344404045584F5A7273717A786D2256227679664F6[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352C37502E4F4747315C5154412A4334313738483F4A635F5A6A645E625A4772676A5740594A474D4D5E55607971246E7778257[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B36505459574C554F515B345F5457442D46373637384B424D676B706E606F61666B63664D786D705D465F504F5050645B66212[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A35504F5346482F5A4F523F28413233342F463D48635C5D66626A436E6366533C55464748425A515C77707773202371215925797[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3652504C5249555256525C35605558452E47383B38364C434E6A706F5F65635D736F677578684C65706B54207477644D66575[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2A554A2D46513C253E302B332C433A45626756516259655F5F436E63465F6A553E5749444C445C535E7B21747C7821745A267[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A52404548564F58315C5154412A4335342F37483F4A68646B645D5E626462616D6971726B6C786A517C7174614A6355544F566[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352C37565949484E4F51525C4E4C55535B54605A5A3E695E614E37503B3D41544B567575656D7367796D6D7C55217578654E675[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E3128335351565551575A4F584C5E335E5356432C4534383649404B6B59566C686B46716669563F58474B485C535E7E6C6956227679664F6[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C484A2C574C2F48533E27403233433A45665B68505C5E406B6E4F38514343544B56776C79616D6F517C71547873634C6557566[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C32293423524C5457474A4E50565D4A61515F5D575255643D685D604D364F3D3E3E3D544B5645486A736D696F527D7275624B645253535[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b-0?3g>d", "3D3D3C3E6B4240707A45454875207A484E4F254E7C53232A515524292B59262E595F292B");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b-0?3g@6:5;", "");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E4249357D37382F3A494D5D513F283338435D6554695B65546D57695D5D686365533C70766C66755E");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484776213F3E484F4E4D4648502B564B4E2E5959595F4C564F3764535750");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b5ba==9cjag", "6B6A6E3D736E72747A7172727A747D777E7C7E4E24");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6B6B73716C73746F727A79");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b9643g3/9e", "6A");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b<:222h64<", "393F352F3E");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b=+03eh8h8j?:", "4443");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9b?b0d:8aj62<h", "6D");
Zeile gelöscht : user_pref("CT2269050.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Zeile gelöscht : user_pref("CT2269050.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E");
Zeile gelöscht : user_pref("CT2269050.backendstorage.hxxp://storage_conduit_com/marketplace/83/6d/8399d181-be98-42f2-b035-1616f617316d/.pricesparrowuuid", "31383639343833342D373033352D343944352D393343452D3634393236414[...]
Zeile gelöscht : user_pref("CT2269050.backendstorage.pg_enable", "74727565");
Zeile gelöscht : user_pref("CT2269050.backendstorage.searchappstate", "32");
Zeile gelöscht : user_pref("CT2269050.backendstorage.searchapptracking", "73656E74");
Zeile gelöscht : user_pref("CT2269050.clientLogIsEnabled", false);
Zeile gelöscht : user_pref("CT2269050.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2269050.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...]
Zeile gelöscht : user_pref("CT2269050.globalFirstTimeInfoLastCheckTime", "Mon Jan 20 2014 18:43:32 GMT+0100");
Zeile gelöscht : user_pref("CT2269050.homepageProtectorEnableByLogin", true);
Zeile gelöscht : user_pref("CT2269050.initDone", true);
Zeile gelöscht : user_pref("CT2269050.isAppTrackingManagerOn", false);
Zeile gelöscht : user_pref("CT2269050.isFirstRadioInstallation", false);
Zeile gelöscht : user_pref("CT2269050.myStuffEnabled", true);
Zeile gelöscht : user_pref("CT2269050.myStuffPublihserMinWidth", 400);
Zeile gelöscht : user_pref("CT2269050.myStuffSearchUrl", "hxxp://appstrm.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gelöscht : user_pref("CT2269050.oldAppsList", "128834881989343894,128834881989343895,111,129466585399606892,129881140170815901,129391330693125668,129863783591067571,129881141106886992,129121052374999726,12995731[...]
Zeile gelöscht : user_pref("CT2269050.revertSettingsEnabled", true);
Zeile gelöscht : user_pref("CT2269050.searchProtectorDialogDelayInSec", 10);
Zeile gelöscht : user_pref("CT2269050.searchProtectorEnableByLogin", true);
Zeile gelöscht : user_pref("CT2269050.testingCtid", "");
Zeile gelöscht : user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Tue Jan 21 2014 22:04:01 GMT+0100");
Zeile gelöscht : user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Tue Jan 21 2014 22:04:01 GMT+0100");
Zeile gelöscht : user_pref("CT2269050.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2269050/CT2269050", "\"2563dd4b064526bd769907469114d1003\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666138/661999/DE", "\"0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", "\"1365594729\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "G9mW7heT/8xIX1frcduu0A==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en&ctid=CT2269050", "eSzELtoCN6VQCYiv1tPI+g==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "2E1/v7EfCEDbv3VaBQMELg==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en&ctid=CT2269050", "HYogGBUvv90IWu2NxeLYvA==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "UgzXjW7BIkfdx+x39Ruv3w==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en&ctid=CT2269050", "aXc5Vsxqu/hbyzW/5Q4N6w==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "4BgM4MhF/sOgPsDNmIs3Yw==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en&ctid=CT2269050", "ZI41WLbm1fFgx4gn0bs99Q==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en&ctid=CT2269050&UM=UM_UNINSTALL_ID", "9tP0a9tLQ7LYpUSrjHx9xA==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"c70353cabc2ce1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.0.6", "\"dfe74040abc2ce1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2269050", "\"7097fd37277b6a1b754b125bd11d0197\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2269050&octid=CT2269050", "\"ef808ae2fa8a68c5242bd2287b0ac9b41\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer_dead.gif", "\"0a8c48d3330c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.gif", "\"0e2106f3030c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif", "\"0f475394430c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif", "\"08d9ef44430c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif", "\"066e8863030c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE", "\"46d3090900b361b16f35d04d99e415ff\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"cac9bd75d98049295759dd50972793f2\"");
Zeile gelöscht : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Claudia\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\mp504yaj.default\\conduitCommon\\modules\\3.7.0.6");
Zeile gelöscht : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.7.0.6");
Zeile gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2269050");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2269050");
Zeile gelöscht : user_pref("CommunityToolbar.globalUserId", "09618dba-2061-4c2c-98ad-999d0e1bd89a");
Zeile gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Zeile gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Zeile gelöscht : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Mon Jan 20 2014 18:43:32 GMT+0100");
Zeile gelöscht : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Tue Jan 21 2014 22:04:08 GMT+0100");
Zeile gelöscht : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);
Zeile gelöscht : user_pref("CommunityToolbar.notifications.locale", "en");
Zeile gelöscht : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Tue Jan 21 2014 22:04:01 GMT+0100");
Zeile gelöscht : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Zeile gelöscht : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Zeile gelöscht : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Zeile gelöscht : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Zeile gelöscht : user_pref("CommunityToolbar.notifications.userId", "4b508a22-e933-4bfd-9e1e-9bd7f9932079");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.hiergehtslos.de");
Zeile gelöscht : user_pref("extensions.snipit.askTbInstalled", true);
Zeile gelöscht : user_pref("icqtoolbar.allowSendURL", false);
Zeile gelöscht : user_pref("icqtoolbar.engineVerified", false);
Zeile gelöscht : user_pref("icqtoolbar.geolastmodified", 1402785625);
Zeile gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options");
Zeile gelöscht : user_pref("icqtoolbar.history", "lufthansa%20karriere%20cockpit||vox%20now%20||claudia%20nachname||zdf%20mediathek||web||air%20berlin%20counter%20card||dsb%20dm%202011%20limitzahlen||dsb%20dm%2020[...]
Zeile gelöscht : user_pref("icqtoolbar.icqgeo", 49);
Zeile gelöscht : user_pref("icqtoolbar.installTime", "1313249385");
Zeile gelöscht : user_pref("icqtoolbar.installsource", "1");
Zeile gelöscht : user_pref("icqtoolbar.newtab_state", "1");
Zeile gelöscht : user_pref("icqtoolbar.numberOfSearches", 0);
Zeile gelöscht : user_pref("icqtoolbar.previousFFVersion", "3.0");
Zeile gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
Zeile gelöscht : user_pref("icqtoolbar.suggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.uniqueID", "122669170112266906761229625558098");
Zeile gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1402785628);
Zeile gelöscht : user_pref("icqtoolbar.version", "1.1.9");
Zeile gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Zeile gelöscht : user_pref("icqtoolbar.voucherWasShown", 0);
Zeile gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.xmlLanguage", "de");

-\\ Google Chrome v35.0.1916.153

[ Datei : C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [36836 octets] - [17/06/2014 18:22:20]
AdwCleaner[R1].txt - [36528 octets] - [17/06/2014 18:34:30]
AdwCleaner[R2].txt - [36648 octets] - [17/06/2014 18:50:52]
AdwCleaner[S0].txt - [771 octets] - [17/06/2014 18:24:41]
AdwCleaner[S1].txt - [394 octets] - [17/06/2014 18:35:37]
AdwCleaner[S2].txt - [34110 octets] - [17/06/2014 18:52:03]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [34171 octets] ##########
         

Der JRT-Log:

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Claudia on 17.06.2014 at 19:57:52,17
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from C:\Users\Claudia\AppData\Roaming\mozilla\firefox\profiles\mp504yaj.default\prefs.js

user_pref("extensions.snipit.chromeURL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q={searchTerms}&crm=1");
user_pref("keyword.URL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=");



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.06.2014 at 20:03:21,43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

Der FRST-Log:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:16-06-2014
Ran by Claudia (administrator) on CLAUDIA1 on 17-06-2014 20:05:39
Running from C:\Users\Claudia\Desktop
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
(ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
() C:\Program Files\Launch Manager\LaunchAp.exe
(Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe
(Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe
(Wistron) C:\Program Files\Launch Manager\WButton.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
() C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
(Empolis GmbH) C:\Program Files\Common Files\Gnab\Service\ServiceController.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe
(Sonix) C:\Windows\vsnp2uvc.exe
() C:\Windows\FixCamera.exe
() C:\Windows\tsnp2uvc.exe
() C:\Program Files\1&1 Surf-Stick\UIExec.exe
() C:\Program Files\TV IR\TV IR.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Google Inc.) C:\Program Files\Picasa2\PicasaMediaDetector.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(1&1 Mail & Media GmbH) C:\Users\Claudia\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe
(Microsoft Corporation) C:\Windows\System32\p2phost.exe
(ArcSoft, Inc.) C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
(Dropbox, Inc.) C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe
() C:\Windows\System32\PSIService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\pvrservice.exe
() C:\Program Files\1&1 Surf-Stick\AssistantServices.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe
(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\sdclt.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6025216 2008-04-01] (Realtek Semiconductor)
HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-08-31] (Synaptics, Inc.)
HKLM\...\Run: [LaunchAp] => C:\Program Files\Launch Manager\LaunchAp.exe [32768 2007-09-01] ()
HKLM\...\Run: [HotkeyApp] => C:\Program Files\Launch Manager\HotkeyApp.exe [188416 2007-09-06] (Wistron)
HKLM\...\Run: [CtrlVol] => "C:\Program Files\Launch Manager\CtrlVol.exe"
HKLM\...\Run: [LMgrOSD] => C:\Program Files\Launch Manager\OSD.exe [180224 2006-12-26] (Wistron Corp.)
HKLM\...\Run: [Wbutton] => C:\Program Files\Launch Manager\Wbutton.exe [86016 2007-09-07] (Wistron)
HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( )
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [Corel Photo Downloader] => "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" -startup
HKLM\...\Run: [Corel File Shell Monitor] => C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16200 2007-10-30] ()
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe [581632 2007-11-30] (Sonix)
HKLM\...\Run: [FixCamera] => C:\Windows\FixCamera.exe [20480 2007-02-12] ()
HKLM\...\Run: [tsnp2uvc] => C:\Windows\tsnp2uvc.exe [249856 2007-12-04] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-05-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated)
HKLM\...\Run: [UIExec] => C:\Program Files\1&1 Surf-Stick\UIExec.exe [139088 2010-09-30] ()
HKLM\...\Run: [TV IR] => C:\Program Files\TV IR\TV IR.exe [692318 2010-12-22] ()
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [183376 2014-05-14] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-09] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe [443968 2008-02-26] (Google Inc.)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [EPSON SX420W Series] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Epson Stylus SX420W(Netzwerk)] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Device Detection] => C:\Program Files\Lidl_Fotos\dd.exe
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [GMX Application {sync-000021}] => C:\Users\Claudia Grützmacher\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe [878080 2013-08-09] (1&1 Mail & Media GmbH)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\RunOnce: [Shockwave Updater] - C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1100429.exe [439736 2008-03-19] (Adobe Systems, Inc.)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {680ae5c9-5a41-11de-81b4-0015afb8023d} - G:\BlueJ.bat
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {b7bf007e-eef6-11e3-92c0-000ae4cddb4b} - F:\HTC_Sync_Manager_PC.exe
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk
ShortcutTarget: TMMonitor.lnk -> C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.)
Startup: C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {01_TL-YODL-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_google&q={searchTerms}
SearchScopes: HKCU - {03_TL-TELEFONBUCH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_telefonbuch&q={searchTerms}
SearchScopes: HKCU - {04_TL-AMAZON-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_amazon&q={searchTerms}
SearchScopes: HKCU - {05_TL-EBAY-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_ebay&q={searchTerms}
SearchScopes: HKCU - {06_TL-DISCOUNT24-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_discount24&q={searchTerms}
SearchScopes: HKCU - {07_TL-CONRAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_conrad&q={searchTerms}
SearchScopes: HKCU - {08_TL-OTTO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_otto&q={searchTerms}
SearchScopes: HKCU - {09_TL-CLIPFISH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_clipfish&q={searchTerms}
SearchScopes: HKCU - {10_TL-MYVIDEO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_myvideo&q={searchTerms}
SearchScopes: HKCU - {11_TL-MUSICLOAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_musicload&q={searchTerms}
SearchScopes: HKCU - {DBAFD4EB-E4E1-4A25-97C2-D1CB5F7D0368} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=971163&p={searchTerms}
BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: No Name - {7E853D72-626A-48EC-A868-BA8D5E23E045} -  No File
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
Toolbar: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - DVDVideoSoftTB Toolbar - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 83.169.185.161 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default
FF DefaultSearchEngine: ICQ Search
FF SearchEngineOrder.1: Ask
FF SelectedSearchEngine: ICQ Search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\clipfish.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\conrad.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\discount24.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\ebay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\musicload.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\myvideo.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\otto.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\quelle.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\telefonbuch-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\webnews.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009-08-13]
FF Extension: Firefox Companion for eBay - C:\Program Files\Mozilla Firefox\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088} [2008-11-14]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions:  - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-14]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-14]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-14]
FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard Software\BullGuard\antispam\tbspamfilter

Chrome: 
=======
CHR HomePage: 
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (DivX Web Player) - C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll (DivX,Inc.)
CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (No Name) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-06-14]
CHR Extension: (Google Wallet) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-14]
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]

========================== Services (Whitelisted) =================

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [123984 2014-05-14] (Avira Operations GmbH & Co. KG)
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-19] (Empolis GmbH) [File not signed]
S2 gupdate1c9e6034feeea56; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-05] (Google Inc.)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () [File not signed]
R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1801216 2008-02-28] (Buhl Data Service GmbH) [File not signed]
R2 UI Assistant Service; C:\Program Files\1&1 Surf-Stick\AssistantServices.exe [253264 2010-09-30] ()
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2006-06-14] (Ulead Systems, Inc.) [File not signed]
S3 usnjsvc; C:\Program Files\MSN Messenger\usnsvc.exe [97136 2007-01-19] (Microsoft Corporation)
R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118784 2007-09-11] (Wistron Corp.) [File not signed]

==================== Drivers (Whitelisted) ====================

R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed]
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-05-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-05-09] (Avira Operations GmbH & Co. KG)
S3 DVC; C:\Windows\System32\Drivers\DVC.sys [38401 2001-09-09] (Samsung Electronics) [File not signed]
R1 Hotkey; C:\Windows\system32\Drivers\Hotkey.sys [9867 2003-04-28] () [File not signed]
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-06-14] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-06-14] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-06-14] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-06-14] (Kaspersky Lab ZAO)
R0 Si3531; C:\Windows\System32\DRIVERS\Si3531.sys [212008 2008-07-25] (Silicon Image, Inc)
R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17064 2008-07-25] (Silicon Image, Inc.)
R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12200 2008-07-25] (Silicon Image, Inc.)
S3 smsbda; C:\Windows\System32\drivers\smsbda.sys [45440 2011-03-06] (Siano)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [9610880 2007-11-29] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-05-09] (Avira GmbH)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [94304 2014-06-14] (Kaspersky Lab ZAO)
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-17 20:03 - 2014-06-17 20:03 - 00001033 _____ () C:\Users\Claudia\Desktop\JRT.txt
2014-06-17 19:57 - 2014-06-17 19:57 - 01016261 _____ (Thisisu) C:\Users\Claudia\Desktop\JRT.exe
2014-06-17 19:57 - 2014-06-17 19:57 - 00000000 ____D () C:\Windows\ERUNT
2014-06-17 18:23 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-06-17 18:22 - 2014-06-17 19:06 - 00000000 ____D () C:\AdwCleaner
2014-06-17 18:20 - 2014-06-17 18:20 - 01333465 _____ () C:\Users\Claudia\Desktop\adwcleaner_3.212.exe
2014-06-16 23:37 - 2014-06-16 23:37 - 00000000 ____D () C:\Users\Claudia\Desktop\FRST-OlderVersion
2014-06-16 21:59 - 2014-06-16 21:59 - 00002812 _____ () C:\Users\Claudia\Desktop\Fixlist.txt
2014-06-15 10:35 - 2014-06-15 10:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Claudia\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-15 03:23 - 2014-06-15 03:23 - 00055613 _____ () C:\Users\Claudia\Desktop\FRST ohne Nachname.txt
2014-06-15 03:23 - 2014-06-15 03:23 - 00043788 _____ () C:\Users\Claudia\Desktop\Addition ohne Nachname.txt
2014-06-15 02:15 - 2014-06-15 02:29 - 00044164 _____ () C:\Users\Claudia\Desktop\Addition.txt
2014-06-15 02:11 - 2014-06-17 20:05 - 00029574 _____ () C:\Users\Claudia\Desktop\FRST.txt
2014-06-15 02:05 - 2014-06-17 20:05 - 00000000 ____D () C:\FRST
2014-06-15 02:03 - 2014-06-16 23:37 - 01072640 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe
2014-06-15 00:42 - 2014-06-15 00:42 - 00001006 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-06-15 00:42 - 2014-06-15 00:42 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-15 00:41 - 2014-06-15 00:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Claudia\Desktop\avira_de_av_4019404326__ws.exe
2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe
2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam
2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus
2014-06-14 14:04 - 2014-06-14 14:02 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2014-06-14 13:57 - 2014-06-17 19:50 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-14 13:57 - 2014-06-14 14:31 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-14 13:57 - 2014-06-14 14:31 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking
2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software
2014-06-13 22:47 - 2014-06-17 19:45 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData
2014-06-13 22:42 - 2014-06-13 22:45 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe
2014-06-13 21:56 - 2014-06-13 22:41 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing
2014-06-11 19:28 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 19:27 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 19:27 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 19:27 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 19:27 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 19:27 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 19:27 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 19:27 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-11 19:27 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 19:27 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 19:27 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-11 19:27 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-11 19:27 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 19:27 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 19:27 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 19:27 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC
2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations
2014-06-08 12:42 - 2014-06-08 12:56 - 00000000 ____D () C:\Temp
2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC
2014-06-08 12:42 - 2009-06-10 09:49 - 00024576 _____ (HTC, Corporation) C:\Windows\system32\Drivers\ANDROIDUSB.sys
2014-06-08 12:42 - 2009-06-09 07:41 - 01122664 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll
2014-06-07 20:30 - 2014-06-16 22:17 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe
2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet
2014-06-07 19:56 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet
2014-05-18 00:39 - 2014-05-18 00:39 - 00000000 ____D () C:\Users\Claudia\restore
2014-05-18 00:02 - 2014-06-14 01:26 - 00000000 ____D () C:\ProgramData\tmp
2014-05-18 00:02 - 2014-05-18 16:35 - 00000000 ____D () C:\ProgramData\hps
2014-05-18 00:01 - 2014-05-18 00:01 - 00001106 _____ () C:\Users\Public\Desktop\OnlineFotoservice.lnk
2014-05-18 00:01 - 2014-05-18 00:01 - 00001091 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
2014-05-18 00:01 - 2014-05-18 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnlineFotoservice

==================== One Month Modified Files and Folders =======

2014-06-17 20:06 - 2014-06-15 02:11 - 00029574 _____ () C:\Users\Claudia\Desktop\FRST.txt
2014-06-17 20:06 - 2012-09-08 16:32 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Dropbox
2014-06-17 20:06 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Temp
2014-06-17 20:05 - 2014-06-15 02:05 - 00000000 ____D () C:\FRST
2014-06-17 20:03 - 2014-06-17 20:03 - 00001033 _____ () C:\Users\Claudia\Desktop\JRT.txt
2014-06-17 19:57 - 2014-06-17 19:57 - 01016261 _____ (Thisisu) C:\Users\Claudia\Desktop\JRT.exe
2014-06-17 19:57 - 2014-06-17 19:57 - 00000000 ____D () C:\Windows\ERUNT
2014-06-17 19:55 - 2008-08-07 13:55 - 01578003 _____ () C:\Windows\WindowsUpdate.log
2014-06-17 19:50 - 2014-06-14 13:57 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-17 19:50 - 2014-05-13 22:19 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\DropboxMaster
2014-06-17 19:50 - 2012-09-08 16:36 - 00000000 ___RD () C:\Users\Claudia\Dropbox
2014-06-17 19:48 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-17 19:48 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-17 19:46 - 2009-06-30 19:24 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-17 19:46 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-17 19:45 - 2014-06-13 22:47 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-17 19:45 - 2008-01-21 04:47 - 00526790 _____ () C:\Windows\PFRO.log
2014-06-17 19:45 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-17 19:16 - 2009-06-30 19:24 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-17 19:06 - 2014-06-17 18:22 - 00000000 ____D () C:\AdwCleaner
2014-06-17 19:06 - 2008-11-14 21:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-17 18:24 - 2012-12-31 17:41 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2014-06-17 18:24 - 2008-08-07 14:18 - 00000000 ____D () C:\ProgramData\ICQ
2014-06-17 18:20 - 2014-06-17 18:20 - 01333465 _____ () C:\Users\Claudia\Desktop\adwcleaner_3.212.exe
2014-06-17 18:18 - 2009-08-24 13:59 - 00000000 ____D () C:\Users\Claudia\Documents\Bewerbung
2014-06-17 18:15 - 2008-11-30 15:45 - 00002627 _____ () C:\Users\Claudia\Desktop\Microsoft Office Word 2007.lnk
2014-06-16 23:37 - 2014-06-16 23:37 - 00000000 ____D () C:\Users\Claudia\Desktop\FRST-OlderVersion
2014-06-16 23:37 - 2014-06-15 02:03 - 01072640 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe
2014-06-16 22:17 - 2014-06-07 20:30 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe
2014-06-16 22:06 - 2008-01-21 09:16 - 01643446 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-16 22:02 - 2006-11-02 14:52 - 00162998 _____ () C:\Windows\setupact.log
2014-06-16 21:59 - 2014-06-16 21:59 - 00002812 _____ () C:\Users\Claudia\Desktop\Fixlist.txt
2014-06-15 10:35 - 2014-06-15 10:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Claudia\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-15 03:23 - 2014-06-15 03:23 - 00055613 _____ () C:\Users\Claudia\Desktop\FRST ohne Nachname.txt
2014-06-15 03:23 - 2014-06-15 03:23 - 00043788 _____ () C:\Users\Claudia\Desktop\Addition ohne Nachname.txt
2014-06-15 02:29 - 2014-06-15 02:15 - 00044164 _____ () C:\Users\Claudia\Desktop\Addition.txt
2014-06-15 00:42 - 2014-06-15 00:42 - 00001006 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-06-15 00:42 - 2014-06-15 00:42 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-15 00:42 - 2012-11-25 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-06-15 00:42 - 2012-10-23 16:35 - 00000000 ____D () C:\ProgramData\Avira
2014-06-15 00:42 - 2012-10-23 16:35 - 00000000 ____D () C:\Program Files\Avira
2014-06-15 00:41 - 2014-06-15 00:41 - 04536336 _____ (Avira Operations GmbH & Co. KG) C:\Users\Claudia Grützmacher\Desktop\avira_de_av_4019404326__ws.exe
2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe
2014-06-14 19:19 - 2012-11-17 22:37 - 00001967 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam
2014-06-14 14:31 - 2014-06-14 13:57 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-14 14:31 - 2014-06-14 13:57 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-14 14:31 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2014-06-14 14:31 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys
2014-06-14 14:31 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus
2014-06-14 14:02 - 2014-06-14 14:04 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2014-06-14 14:01 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia
2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-06-14 01:26 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\tmp
2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking
2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software
2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData
2014-06-13 22:45 - 2014-06-13 22:42 - 164819976 _____ (AVG Technologies) C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe
2014-06-13 22:41 - 2014-06-13 21:56 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing
2014-06-11 20:10 - 2008-04-21 14:41 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-11 20:05 - 2013-08-06 20:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 20:05 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-06-09 01:59 - 2008-08-07 18:11 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Corel
2014-06-09 00:54 - 2008-08-07 19:39 - 00000000 ____D () C:\Users\Claudia\Documents\My PSP Files
2014-06-09 00:54 - 2008-08-07 18:12 - 00004182 ___SH () C:\Windows\system32\KGyGaAvL.sys
2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2014-06-08 12:56 - 2014-06-08 12:42 - 00000000 ____D () C:\Temp
2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC
2014-06-08 12:54 - 2008-04-21 09:32 - 00025966 _____ () C:\Windows\DPINST.LOG
2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations
2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC
2014-06-07 20:25 - 2012-07-08 20:11 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-06-07 20:25 - 2011-07-13 22:41 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet (1).RequestDispatcherServlet
2014-06-07 19:59 - 2014-06-07 19:56 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet
2014-06-07 19:57 - 2008-04-21 10:34 - 00000000 ____D () C:\ProgramData\Adobe
2014-05-28 18:48 - 2014-06-11 19:27 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-28 18:39 - 2014-06-11 19:27 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-28 18:38 - 2014-06-11 19:27 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-28 18:33 - 2014-06-11 19:27 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-28 18:32 - 2014-06-11 19:27 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-28 18:32 - 2014-06-11 19:27 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-28 18:31 - 2014-06-11 19:27 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-05-28 18:31 - 2014-06-11 19:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-28 18:30 - 2014-06-11 19:27 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-28 18:29 - 2014-06-11 19:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-05-28 18:29 - 2014-06-11 19:27 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-05-28 18:28 - 2014-06-11 19:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-24 12:35 - 2012-09-08 16:36 - 00000965 _____ () C:\Users\Claudia\Desktop\Dropbox.lnk
2014-05-24 12:35 - 2012-09-08 16:33 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-18 21:51 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-18 19:45 - 2009-06-08 18:48 - 00000000 ____D () C:\Program Files\Picasa2
2014-05-18 19:10 - 2009-11-15 15:52 - 00130060 _____ () C:\Users\Claudia\AppData\Roaming\mdbu.bin
2014-05-18 16:35 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\hps
2014-05-18 00:39 - 2014-05-18 00:39 - 00000000 ____D () C:\Users\Claudia\restore
2014-05-18 00:01 - 2014-05-18 00:01 - 00001106 _____ () C:\Users\Public\Desktop\OnlineFotoservice.lnk
2014-05-18 00:01 - 2014-05-18 00:01 - 00001091 _____ () C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
2014-05-18 00:01 - 2014-05-18 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnlineFotoservice

Files to move or delete:
====================
C:\Users\Claudia\AppData\Roaming\desktop.ini


Some content of TEMP:
====================
C:\Users\Claudia\AppData\Local\Temp\avgnt.exe
C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpv7f1bw.dll
C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe
C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe
C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe
C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe
C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe
C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe
C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe
C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\Quarantine.exe
C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\unwise.exe
C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll
C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe
C:\Users\Claudia\AppData\Local\Temp\_is30.exe
C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe
C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe
C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe
C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-17 19:55

==================== End Of Log ============================
         
--- --- ---

Alt 17.06.2014, 22:03   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Bitte auch ne neue Addition.txt erstellen, dazu FRST starten und einen Haken setzen bei Addition.txt, dann auf Scan klicken.

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 17.06.2014, 23:05   #9
Lorelai!
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Ich musste vorhin auch AVG deinstallieren, da ich den Schutz nicht deaktivieren konnte. Habe zwar mehrmals draufgeklickt, aber in der AVG-Historie wurde keine Abschaltung vermerkt.
Vielen Dank für deine Hilfe.


Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version:16-06-2014
Ran by Claudia at 2014-06-17 22:52:42
Running from C:\Users\Claudia\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Kaspersky Anti-Virus (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Anti-Virus (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

 Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-

44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
 Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-

7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
1&1 Surf-Stick (HKLM\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - )
3531-W-D (HKLM\...\{BD1587F7-B8D0-4111-8F1F-3327628AB02F}) (Version: 1.5.18 - Silicon Image)
AAC Decoder (HKLM\...\{AEF9DC35ADDF4825B049ACBFD1C6EB37}) (Version: 7.1.0 - DivX, Inc.)
ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software 

House)
ABBYY FineReader 9.0 Sprint (HKLM\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY)
ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212 - ABBYY) Hidden
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office 

suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 8.3.0 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A83000000003}) (Version: 8.3.0 - Adobe Systems 

Incorporated)
Adobe Shockwave Player (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.)
Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version:  - Agere Systems)
ArcSoft MediaConverter 2 (HKLM\...\{83DA46EC-2CB1-4649-9100-C4F98D8DA8CD}) (Version:  - ArcSoft)
ArcSoft PhotoImpression 5 (HKLM\...\{4FE82F4B-B7D8-4E65-84AD-E0436CDE57DD}) (Version:  - ArcSoft)
ArcSoft ShowBiz DVD 2 (HKLM\...\{E883DCB3-766D-4166-8B28-33C8FE451F2B}) (Version:  - ArcSoft)
ArcSoft TotalMedia 3.5 (HKLM\...\{29E44E9D-ACB2-4D2D-849F-5361C941B7E1}) (Version: 3.5.7.362 - ArcSoft)
AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - )
Avira (HKLM\...\{68e29fba-92b1-4f6f-a604-1d8679da3a9f}) (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.13.24161 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira)
Camera RAW Plug-In for EPSON Creativity Suite (HKLM\...\{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}) (Version: 2.2.0.0 - SEIKO 

EPSON CORPORATION)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - 

Microsoft Corporation)
Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation)
Corel Paint Shop Pro Photo X2 (HKLM\...\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}) (Version: 12.010.0000 - Corel Corporation)
Digital Video (HKLM\...\{C833C7B6-1140-471D-932B-391B5CA66D7D}) (Version: 1.00.000 - )
DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.8.5 - DivX, Inc.)
DivX Converter (HKLM\...\{13F3917B56CD4C25848BDC69916971BB}) (Version: 7.0.0 - DivX, Inc.)
DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.0.0 - DivX, Inc.)
DivX Player (HKLM\...\{8ADFC4160D694100B5B8A22DE9DCABD9}) (Version: 7.0.0 - DivX, Inc.)
DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters) (Version:  - DivX, Inc.)
DivX Version Checker (HKLM\...\{3FC7CBBC4C1E11DCA1A752EA55D89593}) (Version: 7.0.0.19 - DivX, Inc.)
DivX Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 1.4.2 - DivX,Inc.)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
DVDVideoSoft Toolbar (HKLM\...\DVDVideoSoft Toolbar) (Version:  - )
EPSON Attach To Email (HKLM\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.3.0.0 - )
EPSON Easy Photo Print (HKLM\...\{3D78F2A2-C893-4ABD-B5FE-AD7011837755}) (Version: 1.5.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print 2 (HKLM\...\{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 

1.00.0000 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION)
EPSON File Manager (HKLM\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - )
EPSON Scan (HKLM\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON Scan Assistant (HKLM\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
EPSON Stylus CX7300_CX8300_DX7400_DX8400 Handbuch (HKLM\...\EPSON Stylus CX7300_CX8300_DX7400_DX8400 Benutzerhandbuch) 

(Version:  - )
EPSON SX420W Series Handbuch (HKLM\...\EPSON SX420W Series Manual) (Version:  - )
EPSON SX420W Series Netzwerk-Handbuch (HKLM\...\EPSON SX420W Series Network Guide) (Version:  - )
EPSON SX420W Series Printer Uninstall (HKLM\...\EPSON SX420W Series) (Version:  - SEIKO EPSON Corporation)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4i - SEIKO EPSON CORPORATION)
EpsonNet Setup 3.2 (HKLM\...\{C9D8A041-2963-4B31-8FFC-1500F3DB9293}) (Version: 3.2a - SEIKO EPSON CORPORATION)
Firebird SQL Server - MAGIX Edition (HKLM\...\Firebird SQL Server D) (Version: 2.0.1.8 - MAGIX AG)
Free Audio CD Burner version 1.2 (HKLM\...\Free Audio CD Burner_is1) (Version:  - DVDVideoSoft Limited.)
Free YouTube Download version 3.0.16.923 (HKLM\...\Free YouTube Download_is1) (Version:  - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.11.37.1212 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.37.1212 - 

DVDVideoSoft Ltd.)
GMX MediaCenter 1.5.1765.0 (HKCU\...\GMX Application {sync-000021}) (Version: 1.5.1765.0 - 1&1 Mail & Media GmbH)
Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
H.264 Decoder (HKLM\...\{A96E97134CA649888820BCDE5E300BBD}) (Version: 1.0.0 - DivX, Inc.)
ICQ7.4 (HKLM\...\{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}) (Version: 7.4 - ICQ)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - Intel Corporation)
Intel(R) Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - )
InterVideo WinDVD 8 (HKLM\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B9.385 - InterVideo 

Inc.)
InterVideo WinDVD 8 (Version: 8.0-B9.385 - InterVideo Inc.) Hidden
IPTInstaller (HKLM\...\{6965F2F4-1CD2-4F42-A8EF-9EF433F9AA72}) (Version: 4.0.4 - HTC)
Java(TM) 6 Update 5 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.)
Kaspersky Anti-Virus (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab)
Kaspersky Anti-Virus (Version: 14.0.0.4651 - Kaspersky Lab) Hidden
Launch Manager V1.4.9 (HKLM\...\{D0846526-66DD-4DC9-A02C-98F9A2806812}) (Version: 1.4.9 - Wistron Corp.)
LG PC Suite II (HKLM\...\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}) (Version: 2.00.0000 - LG PC Suite)
LG PC Suite II (Version: 2.00.0000 - LG PC Suite) Hidden
LG USB Modem driver (HKLM\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: 4.9.4 - LG Electronics)
MD86351 Driver Install (HKLM\...\InstallShield_{B3A9DC22-6162-4844-BEB3-853BAFB980E0}) (Version: 6.3.6.1 - Ihr Firmenname)
MD86351 Driver Install (Version: 6.3.6.1 - Ihr Firmenname) Hidden
MEDION Fotos auf CD Nord (HKLM\...\MEDION Fotos auf CD Nord D) (Version: 6.0.2.0 - MAGIX AG)
Medion Media Center 0 (Version: 1.0.12.0 - Medion) Hidden
MEDIONbox (HKLM\...\{27FDF949-69CE-435A-8372-339F72336AC5}) (Version: 1.09.0000.00052 - Medion)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version:  - )
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) 

(Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - 

Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft 

Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-

48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-

48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - 

Microsoft Corporation)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft 

Corporation)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Picture It! Foto Premium 9 (HKLM\...\PictureIt_v9) (Version: 9.0.0.0000 - Microsoft Corporation)
Microsoft Picture It! Foto Premium 9 (Version: 9.0.0.0000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) 

(Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - 

Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - 

Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) 

(Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 

9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 

9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 

9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 

9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 

9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 

10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation)
Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation) Hidden
MindManager Smart (HKLM\...\MindManager Smart) (Version: 2.1.3 - Mindjet LLC)
MKV Splitter (HKLM\...\{AAC389499AEF40428987B3D30CFC76C9}) (Version: 1.0.0 - DivX, Inc.)
Move Networks Media Player for Internet Explorer (HKCU\...\Move Networks Player - IE) (Version:  - )
Mozilla Firefox (3.0) (HKLM\...\Mozilla Firefox (3.0)) (Version: 3.0 (de) - Mozilla)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG)
neroxml (Version: 1.0.0 - Nero AG) Hidden
OnlineFotoservice (HKLM\...\OnlineFotoservice) (Version: 5.1.5 - CEWE Stiftung u Co. KGaA)
Opera 12.12 (HKLM\...\Opera 12.12.1707) (Version: 12.12.1707 - Opera Software ASA)
PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 0.9.8 - Frank Heindörfer, Philip Chinery)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Ralink Wireless LAN (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.00.0000 - RaLink)
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista (HKLM\...\{8833FFB6-5B0C-4764-81AA-

06DFEED9A476}) (Version: 1.00.0000 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5595 - Realtek 

Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version:  - Realtek Semiconductor Corp.)
Rossmann Fotoservice 2.6 (HKLM\...\Rossmann Fotoservice_is1) (Version:  - )
Sceneo AbsolutTV (HKLM\...\{4C73B683-B15D-4B94-AC7A-520B70C4FFE9}) (Version:  - )
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Switch Sound File Converter (HKLM\...\Switch) (Version:  - NCH Software)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.0.14.0 - Synaptics)
TV IR (HKLM\...\InstallShield_{8CFE319F-DC08-48BA-B011-37ED5C9733B5}) (Version: 1.00.0000 - Ihr Firmenname)
TV IR (Version: 1.00.0000 - Ihr Firmenname) Hidden
Ulead DVD MovieFactory 5 (HKLM\...\{FF164702-AF8B-4F2F-8038-74A4C536866B}) (Version: 5.3 - Ulead Systems, Inc.)
Ulead PhotoImpact 12 (HKLM\...\{11AFE21E-B193-430D-B57A-DFF7815BB962}) (Version: 12.0 - Ulead System)
Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version:  - )
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-

5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_

{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) 

(Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}

_ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}

_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}

_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}

_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Access 2007 Help (KB963663) (HKLM\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_

{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version:  - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_

{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_

{716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version:  - Microsoft)
Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_

{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}

_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_

{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2881065) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-

0000000FF1CE}_ENTERPRISE_{B7EF38F7-1D58-4085-A9A4-0F6C69A5AA1E}) (Version:  - Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_

{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_

{2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version:  - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_

{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_

{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_

{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}

_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_

{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
USB Video Device (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.18100.101 - Sonix)
VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0 - DivX, Inc) Hidden
VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG 

Technologies CZ, s.r.o.)
VLC media player 1.1.10 (HKLM\...\VLC media player) (Version: 1.1.10 - VideoLAN)
WavePad Sound Editor (HKLM\...\WavePad) (Version:  - NCH Software)
Windows Live Messenger (HKLM\...\{279DB581-239C-4E13-97F8-0F48E40BE75C}) (Version: 8.1.0178.00 - Microsoft Corporation)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )
WISO Mein Geld 2008 Professional (HKLM\...\{D8D22773-14BF-4178-A683-3DBA515C2A26}) (Version: 9.00.01.0023 - Buhl Data 

Service GmbH)
XVID Codec Installation (HKLM\...\{534C6D59-D6E3-48A6-AD0B-747799019960}) (Version:  - )

==================== Restore Points  =========================

04-06-2014 17:38:03 Geplanter Prüfpunkt
07-06-2014 18:44:11 Windows Update
08-06-2014 10:42:59 Gerätetreiber-Paketinstallation: HTC, Corporation
08-06-2014 10:46:45 Gerätetreiber-Paketinstallation: HTC Corporation Netzwerkadapter
08-06-2014 10:49:34 Gerätetreiber-Paketinstallation: HTC Corporation Tragbare Geräte
08-06-2014 10:54:49 Gerätetreiber-Paketinstallation: HTC Netzwerkprotokoll
11-06-2014 17:26:28 Windows Update
11-06-2014 18:00:59 Windows Update
13-06-2014 20:48:59 Installed AVG 2014
13-06-2014 20:50:05 Installed AVG 2014
14-06-2014 11:59:34 Gerätetreiber-Paketinstallation: Kaspersky Lab Netzwerkdienst
17-06-2014 17:36:53 Removed AVG 2014
17-06-2014 17:41:24 Removed AVG 2014

==================== Hosts content: ==========================

2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0D4A3951-D115-4E17-9495-26DC510E1359} - System32\Tasks\{19864B7B-6EBE-4684-9FF9-DD775F771854} => C:\Program 

Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32

\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {574969E9-0C4A-4A75-A6C7-549B08CDB6C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program 

Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.)
Task: {8AC7F5E7-9061-45A6-95FE-B269516DA561} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program 

Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.)
Task: {B7794283-DDB2-48C6-9B9B-3AC33999A0C1} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => 

Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => 

C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {EEEAB8B8-067F-4F56-8432-3BBC88C3CC8F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32

\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2009-09-04 19:29 - 2001-10-28 17:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll
2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0

\kpcengine.2.3.dll
2009-10-03 11:47 - 2005-06-28 13:59 - 00053248 _____ () C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll
2013-07-21 20:03 - 2013-07-21 20:03 - 03391488 _____ () c:\windows\assembly\nativeimages1_v1.1.4322

\mscorlib\1.0.5000.0__b77a5c561934e089_b0c6b048\mscorlib.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 01966080 _____ () c:\windows\assembly\nativeimages1_v1.1.4322

\system\1.0.5000.0__b77a5c561934e089_c7c004ef\system.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 03035136 _____ () c:\windows\assembly\nativeimages1_v1.1.4322

\system.windows.forms\1.0.5000.0__b77a5c561934e089_5c188a8d\system.windows.forms.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 02088960 _____ () c:\windows\assembly\nativeimages1_v1.1.4322

\system.xml\1.0.5000.0__b77a5c561934e089_821dd40b\system.xml.dll
2008-04-21 09:37 - 2007-09-01 14:03 - 00032768 _____ () C:\Program Files\Launch Manager\LaunchAp.exe
2007-10-30 19:52 - 2007-10-30 19:52 - 00016200 _____ () C:\Program Files\Corel\Corel Paint Shop Pro Photo X2

\CorelIOMonitor.exe
2011-01-08 16:14 - 2007-02-12 15:50 - 00020480 _____ () C:\Windows\FixCamera.exe
2011-01-08 16:14 - 2007-12-04 19:28 - 00249856 _____ () C:\Windows\tsnp2uvc.exe
2008-04-22 08:37 - 2007-04-19 12:11 - 00006656 _____ () c:\program files\medion\medionbox\program\structconverter.dll
2009-08-18 20:24 - 2009-04-11 08:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll
2011-08-06 14:59 - 2010-09-30 14:00 - 00139088 _____ () C:\Program Files\1&1 Surf-Stick\UIExec.exe
2010-12-22 11:27 - 2010-12-22 11:27 - 00692318 _____ () C:\Program Files\TV IR\TV IR.exe
2010-06-18 00:09 - 2010-06-18 00:09 - 00167936 _____ () C:\Program Files\TV IR\RmCard.dll
2008-01-15 00:40 - 2008-01-15 00:40 - 00053248 _____ () C:\Program Files\TV IR\LWExt.dll
2009-03-09 11:52 - 2009-03-09 11:52 - 00053248 _____ () C:\Program Files\TV IR\tmir.dll
2012-10-08 17:04 - 2012-10-08 17:04 - 00166912 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2014-06-17 18:10 - 2014-05-14 14:27 - 00049744 _____ () C:\Users\Claudia\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2012-10-21 13:31 - 2007-04-19 09:33 - 00035584 _____ () C:\Program Files\ArcSoft\TotalMedia 3.5\uPiApi.dll
2014-06-17 22:47 - 2014-06-17 22:47 - 00043008 _____ () C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-

5bce-5766-8f84-3e3e7ecf0d81}.tmp0paq4m.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Claudia\AppData\Roaming\Dropbox\bin\libcef.dll
2007-06-05 13:20 - 2007-06-05 13:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe
2008-04-22 08:30 - 2007-05-16 22:48 - 00421955 _____ () C:\Program Files\Sceneo\AbsolutTV\Services\PVR\tvtvRemote.dll
2011-08-06 14:59 - 2010-09-30 14:00 - 00253264 _____ () C:\Program Files\1&1 Surf-Stick\AssistantServices.exe
2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0

\dblite.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Claudia\Beweis.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Beweis.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Beweis.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/17/2014 10:45:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" 

AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/17/2014 10:46:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Avira Service Host

Error: (06/17/2014 10:46:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Windows Search%%1053

Error: (06/17/2014 10:46:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Windows Search

Error: (06/17/2014 10:45:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058


Microsoft Office Sessions:
=========================
Error: (05/07/2013 08:37:08 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office 

Version: 12.0.6612.1000. This session lasted 810 seconds with 720 seconds of active time.  This session ended with a 

crash.

Error: (05/13/2011 02:44:54 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office 

Version: 12.0.6425.1000. This session lasted 1089 seconds with 120 seconds of active time.  This session ended with a 

crash.

Error: (03/20/2011 05:35:34 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6545.5000, Microsoft Office 

Version: 12.0.6425.1000. This session lasted 4422 seconds with 900 seconds of active time.  This session ended with a 

crash.


CodeIntegrity Errors:
===================================
  Date: 2014-06-17 22:52:26.481
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:52:25.545
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:52:24.562
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:52:23.470
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:51:46.326
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:51:45.515
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:51:44.719
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:51:43.783
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 20:07:15.026
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 20:07:14.309
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kneps.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Percentage of memory in use: 48%
Total physical RAM: 3061.69 MB
Available physical RAM: 1563.23 MB
Total Pagefile: 6339.64 MB
Available Pagefile: 4521.53 MB
Total Virtual: 2047.88 MB
Available Virtual: 1907.03 MB

==================== Drives ================================

Drive c: (BOOT) (Fixed) (Total:207.5 GB) (Free:100.29 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVER) (Fixed) (Total:25.37 GB) (Free:5.96 GB) FAT32
Drive g: () (Removable) (Total:1.84 GB) (Free:0 GB) FAT

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 4B64DFC2)
Partition 1: (Active) - (Size=207 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=25 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 2 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End Of Log ============================
         

Alt 17.06.2014, 23:09   #10
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Zitat:
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Kaspersky Anti-Virus (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Anti-Virus (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
Oh man, das seh ich ja jetzt erst
Wieso knallst du dir das System mit Virenscanner zu, damit erreichst du nur das Gegenteil! Alle runter, bis auf einen!Am besten AntiVir deinstallieren.
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 18.06.2014, 18:46   #11
Lorelai!
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



AntiVir (Avira) ist jetzt deinstalliert. Habe jetzt nur noch Kaspersky drauf.

Sorry. Als sich letzte Woche AntiVir weder starten noch deinstallieren ließ, habe ich gehofft, dass irgendein anderer Virenscanner den Virus erkennt und vernichtet... Eigentlich weiß ich auch, dass man nicht mehr als einen Virenscanner haben sollte... für mich zählte in dem Moment nur, den Virus irgendwie zu erkennen und zu löschen...

Was soll ich als nächstes machen?

Alt 18.06.2014, 20:50   #12
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 18.06.2014, 22:57   #13
Lorelai!
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:18-06-2014
Ran by Claudia (administrator) on CLAUDIA1 on 18-06-2014 22:26:03
Running from C:\Users\Claudia\Desktop
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
(ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe
(Empolis GmbH) C:\Program Files\Common Files\Gnab\Service\ServiceController.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe
() C:\Windows\System32\PSIService.exe
(Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\pvrservice.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
() C:\Program Files\1&1 Surf-Stick\AssistantServices.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
() C:\Program Files\Launch Manager\LaunchAp.exe
(Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe
(Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe
(Wistron) C:\Program Files\Launch Manager\WButton.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
() C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe
(Sonix) C:\Windows\vsnp2uvc.exe
() C:\Windows\FixCamera.exe
() C:\Windows\tsnp2uvc.exe
() C:\Program Files\1&1 Surf-Stick\UIExec.exe
() C:\Program Files\TV IR\TV IR.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google Inc.) C:\Program Files\Picasa2\PicasaMediaDetector.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGCE.EXE
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(1&1 Mail & Media GmbH) C:\Users\Claudia\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe
(Microsoft Corporation) C:\Windows\System32\p2phost.exe
(ArcSoft, Inc.) C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Dropbox, Inc.) C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft 

Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel 

Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6025216 2008-04-01] (Realtek Semiconductor)
HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-08-31] (Synaptics, Inc.)
HKLM\...\Run: [LaunchAp] => C:\Program Files\Launch Manager\LaunchAp.exe [32768 2007-09-01] ()
HKLM\...\Run: [HotkeyApp] => C:\Program Files\Launch Manager\HotkeyApp.exe [188416 2007-09-06] (Wistron)
HKLM\...\Run: [CtrlVol] => "C:\Program Files\Launch Manager\CtrlVol.exe"
HKLM\...\Run: [LMgrOSD] => C:\Program Files\Launch Manager\OSD.exe [180224 2006-12-26] (Wistron Corp.)
HKLM\...\Run: [Wbutton] => C:\Program Files\Launch Manager\Wbutton.exe [86016 2007-09-07] (Wistron)
HKLM\...\Run: [toolbar_eula_launcher] => C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( )
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] 

(Microsoft Corporation)
HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] 

(Microsoft Corporation)
HKLM\...\Run: [Corel Photo Downloader] => "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel 

PhotoDownloader.exe" -startup
HKLM\...\Run: [Corel File Shell Monitor] => C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16200 

2007-10-30] ()
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] 

(SEIKO EPSON CORPORATION)
HKLM\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe [581632 2007-11-30] (Sonix)
HKLM\...\Run: [FixCamera] => C:\Windows\FixCamera.exe [20480 2007-02-12] ()
HKLM\...\Run: [tsnp2uvc] => C:\Windows\tsnp2uvc.exe [249856 2007-12-04] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-05-27] 

(Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems 

Incorporated)
HKLM\...\Run: [UIExec] => C:\Program Files\1&1 Surf-Stick\UIExec.exe [139088 2010-09-30] ()
HKLM\...\Run: [TV IR] => C:\Program Files\TV IR\TV IR.exe [692318 2010-12-22] ()
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe 

[207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => 

C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2

\PicasaMediaDetector.exe [443968 2008-02-26] (Google Inc.)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [EPSON SX420W Series] => C:\Windows\system32

\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Epson Stylus SX420W(Netzwerk)] => C:\Windows\system32

\spool\DRIVERS\W32X86\3\E_FATIGCE.EXE [200704 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-

21] (Microsoft Corporation)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [Device Detection] => C:\Program Files\Lidl_Fotos\dd.exe
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [GMX Application {sync-000021}] => C:\Users\Claudia 

Grützmacher\AppData\Local\GMX Application {sync-000021}\gmx_mediacenter.exe [878080 2013-08-09] (1&1 Mail & Media GmbH)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 

2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\RunOnce: [Shockwave Updater] - C:\Windows\System32\Adobe\Shockwave 

11\SwHelper_1100429.exe [439736 2008-03-19] (Adobe Systems, Inc.)
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {680ae5c9-5a41-11de-81b4-0015afb8023d} - G:\BlueJ.bat
HKU\S-1-5-21-3856976919-2596979157-3738053339-1003\...\MountPoints2: {b7bf007e-eef6-11e3-92c0-000ae4cddb4b} - 

F:\HTC_Sync_Manager_PC.exe
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL => C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk
ShortcutTarget: TMMonitor.lnk -> C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.)
Startup: C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Claudia\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program 

Files\DVDVideoSoft\tbDVD1.dll No File
URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program 

Files\DVDVideoSoft\tbDVD1.dll No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {01_TL-YODL-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_google&q=

{searchTerms}
SearchScopes: HKCU - {03_TL-TELEFONBUCH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-

splug_telefonbuch&q={searchTerms}
SearchScopes: HKCU - {04_TL-AMAZON-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_amazon&q=

{searchTerms}
SearchScopes: HKCU - {05_TL-EBAY-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_ebay&q={searchTerms}
SearchScopes: HKCU - {06_TL-DISCOUNT24-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_discount24&q=

{searchTerms}
SearchScopes: HKCU - {07_TL-CONRAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_conrad&q=

{searchTerms}
SearchScopes: HKCU - {08_TL-OTTO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_otto&q={searchTerms}
SearchScopes: HKCU - {09_TL-CLIPFISH-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_clipfish&q=

{searchTerms}
SearchScopes: HKCU - {10_TL-MYVIDEO-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_myvideo&q=

{searchTerms}
SearchScopes: HKCU - {11_TL-MUSICLOAD-DE-E1416B8B2E3A} URL = hxxp://www.yodl.de/href.php?hrefname=FF-splug_musicload&q=

{searchTerms}
SearchScopes: HKCU - {DBAFD4EB-E4E1-4A25-97C2-D1CB5F7D0368} URL = hxxp://de.search.yahoo.com/search?fr=chr-

greentree_ie&ei=utf-8&type=971163&p={searchTerms}
BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common 

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 

14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12

\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-

Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun 

Microsystems, Inc.)
BHO: No Name - {7E853D72-626A-48EC-A868-BA8D5E23E045} -  No File
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo 

Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 

14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 

14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll No File
Toolbar: HKLM - DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll 

No File
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo 

Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - DVDVideoSoftTB Toolbar - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Program Files\DVDVideoSoft\tbDVD1.dll 

No File
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} 

hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12

\GrooveSystemServices.dll (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll 

(Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information 

Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll 

(Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype 

Technologies)
Tcpip\Parameters: [DhcpNameServer] 83.169.185.161 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default
FF DefaultSearchEngine: ICQ Search
FF SearchEngineOrder.1: Ask
FF SelectedSearchEngine: ICQ Search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, 

Inc)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft 

Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation 

Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll 

(Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll 

(Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\clipfish.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\conrad.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\discount24.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\ebay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\musicload.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\myvideo.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\otto.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\quelle.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\telefonbuch-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\webnews.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - 

C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{20a82645-c095-46ed-80e3-

08825760534b} [2009-08-13]
FF Extension: Firefox Companion for eBay - C:\Program Files\Mozilla Firefox\extensions\{62760FD6-B943-48C9-AB09-

F99C6FE96088} [2008-11-14]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows 

Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation 

Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions:  - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0

\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\url_advisor@kaspersky.com 

[2014-06-14]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 

14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\virtual_keyboard@kaspersky.com 

[2014-06-14]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 

14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\FFExt\content_blocker@kaspersky.com 

[2014-06-14]
FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] - C:\Program Files\BullGuard 

Software\BullGuard\antispam\tbspamfilter

Chrome: 
=======
CHR HomePage: 
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (DivX Web Player) - C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll (DivX,Inc.)
CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll (DivX, Inc)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft 

Corp.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Picasa) - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation 

Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (No Name) - C:\Users\Claudia\AppData\Local\Google\Chrome\User 

Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-06-14]
CHR Extension: (Google Wallet) - C:\Users\Claudia\AppData\Local\Google\Chrome\User 

Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-14]
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 

14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 

14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 

14.0.0\ChromeExt\virtkbd.crx [2013-10-17]

========================== Services (Whitelisted) =================

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00

\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON 

CORPORATION) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe [1527900 2005-11

-17] (MAGIX®) [File not signed]
R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-19] (Empolis GmbH) [File 

not signed]
S2 gupdate1c9e6034feeea56; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-06-05] (Google Inc.)
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () [File not signed]
R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File 

not signed]
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1801216 2008-02-28] (Buhl Data Service GmbH) 

[File not signed]
R2 UI Assistant Service; C:\Program Files\1&1 Surf-Stick\AssistantServices.exe [253264 2010-09-30] ()
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2006-06-14] (Ulead Systems, 

Inc.) [File not signed]
S3 usnjsvc; C:\Program Files\MSN Messenger\usnsvc.exe [97136 2007-01-19] (Microsoft Corporation)
R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118784 2007-09-11] (Wistron Corp.) [File not signed]

==================== Drivers (Whitelisted) ====================

R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed]
S3 DVC; C:\Windows\System32\Drivers\DVC.sys [38401 2001-09-09] (Samsung Electronics) [File not signed]
R1 Hotkey; C:\Windows\system32\Drivers\Hotkey.sys [9867 2003-04-28] () [File not signed]
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-06-14] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-06-14] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-06-14] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2014-06-14] (Kaspersky Lab ZAO)
R0 Si3531; C:\Windows\System32\DRIVERS\Si3531.sys [212008 2008-07-25] (Silicon Image, Inc)
R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17064 2008-07-25] (Silicon Image, Inc.)
R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12200 2008-07-25] (Silicon Image, Inc.)
S3 smsbda; C:\Windows\System32\drivers\smsbda.sys [45440 2011-03-06] (Siano)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [9610880 2007-11-29] ()
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [94304 2014-06-14] (Kaspersky Lab ZAO)
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-17 20:03 - 2014-06-17 20:03 - 00001033 _____ () C:\Users\Claudia\Desktop\JRT.txt
2014-06-17 19:57 - 2014-06-17 19:57 - 01016261 _____ (Thisisu) C:\Users\Claudia\Desktop\JRT.exe
2014-06-17 19:57 - 2014-06-17 19:57 - 00000000 ____D () C:\Windows\ERUNT
2014-06-17 18:23 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-06-17 18:22 - 2014-06-17 19:06 - 00000000 ____D () C:\AdwCleaner
2014-06-17 18:20 - 2014-06-17 18:20 - 01333465 _____ () C:\Users\Claudia\Desktop\adwcleaner_3.212.exe
2014-06-16 23:37 - 2014-06-18 22:25 - 00000000 ____D () C:\Users\Claudia\Desktop\FRST-OlderVersion
2014-06-16 21:59 - 2014-06-16 21:59 - 00002812 _____ () C:\Users\Claudia\Desktop\Fixlist.txt
2014-06-15 10:35 - 2014-06-15 10:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Claudia\Desktop\mbam-setup-

2.0.2.1012.exe
2014-06-15 03:23 - 2014-06-15 03:23 - 00055613 _____ () C:\Users\Claudia\Desktop\FRST ohne Nachname.txt
2014-06-15 03:23 - 2014-06-15 03:23 - 00043788 _____ () C:\Users\Claudia\Desktop\Addition ohne Nachname.txt
2014-06-15 02:15 - 2014-06-17 22:55 - 00039907 _____ () C:\Users\Claudia\Desktop\Addition.txt
2014-06-15 02:11 - 2014-06-18 22:26 - 00027693 _____ () C:\Users\Claudia\Desktop\FRST.txt
2014-06-15 02:05 - 2014-06-18 22:26 - 00000000 ____D () C:\FRST
2014-06-15 02:03 - 2014-06-18 22:25 - 01072128 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe
2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe
2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam
2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky 

Anti-Virus
2014-06-14 14:04 - 2014-06-14 14:02 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2014-06-14 13:57 - 2014-06-18 22:20 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-14 13:57 - 2014-06-14 14:31 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-14 13:57 - 2014-06-14 14:31 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking
2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software
2014-06-13 22:47 - 2014-06-17 19:45 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData
2014-06-13 22:42 - 2014-06-13 22:45 - 164819976 _____ (AVG Technologies) 

C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe
2014-06-13 21:56 - 2014-06-13 22:41 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing
2014-06-11 19:28 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 19:27 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 19:27 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 19:27 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 19:27 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 19:27 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 19:27 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 19:27 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-11 19:27 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 19:27 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 19:27 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 19:27 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 19:27 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-11 19:27 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-11 19:27 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 19:27 - 2014-04-05 04:42 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 19:27 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 19:27 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC
2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations
2014-06-08 12:42 - 2014-06-08 12:56 - 00000000 ____D () C:\Temp
2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC
2014-06-08 12:42 - 2009-06-10 09:49 - 00024576 _____ (HTC, Corporation) C:\Windows\system32\Drivers\ANDROIDUSB.sys
2014-06-08 12:42 - 2009-06-09 07:41 - 01122664 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll
2014-06-07 20:30 - 2014-06-16 22:17 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe
2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet 

(1).RequestDispatcherServlet
2014-06-07 19:56 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet

==================== One Month Modified Files and Folders =======

2014-06-18 22:26 - 2014-06-15 02:11 - 00027693 _____ () C:\Users\Claudia\Desktop\FRST.txt
2014-06-18 22:26 - 2014-06-15 02:05 - 00000000 ____D () C:\FRST
2014-06-18 22:25 - 2014-06-16 23:37 - 00000000 ____D () C:\Users\Claudia\Desktop\FRST-OlderVersion
2014-06-18 22:25 - 2014-06-15 02:03 - 01072128 _____ (Farbar) C:\Users\Claudia\Desktop\FRST.exe
2014-06-18 22:24 - 2008-08-07 13:55 - 01607600 _____ () C:\Windows\WindowsUpdate.log
2014-06-18 22:23 - 2012-09-08 16:32 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Dropbox
2014-06-18 22:22 - 2014-05-13 22:19 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\DropboxMaster
2014-06-18 22:22 - 2012-09-08 16:36 - 00000000 ___RD () C:\Users\Claudia\Dropbox
2014-06-18 22:20 - 2014-06-14 13:57 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-18 22:19 - 2009-06-30 19:24 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-18 22:19 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-18 22:19 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-

1.C7483456-A289-439d-8115-601632D005A0
2014-06-18 22:19 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-

0.C7483456-A289-439d-8115-601632D005A0
2014-06-18 18:49 - 2006-11-02 15:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-18 18:22 - 2008-01-21 04:47 - 00527116 _____ () C:\Windows\PFRO.log
2014-06-18 18:17 - 2009-06-30 19:24 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-17 22:55 - 2014-06-15 02:15 - 00039907 _____ () C:\Users\Claudia\Desktop\Addition.txt
2014-06-17 20:03 - 2014-06-17 20:03 - 00001033 _____ () C:\Users\Claudia\Desktop\JRT.txt
2014-06-17 19:57 - 2014-06-17 19:57 - 01016261 _____ (Thisisu) C:\Users\Claudia\Desktop\JRT.exe
2014-06-17 19:57 - 2014-06-17 19:57 - 00000000 ____D () C:\Windows\ERUNT
2014-06-17 19:45 - 2014-06-13 22:47 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-17 19:06 - 2014-06-17 18:22 - 00000000 ____D () C:\AdwCleaner
2014-06-17 19:06 - 2008-11-14 21:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-17 18:24 - 2012-12-31 17:41 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2014-06-17 18:24 - 2008-08-07 14:18 - 00000000 ____D () C:\ProgramData\ICQ
2014-06-17 18:20 - 2014-06-17 18:20 - 01333465 _____ () C:\Users\Claudia\Desktop\adwcleaner_3.212.exe
2014-06-17 18:18 - 2009-08-24 13:59 - 00000000 ____D () C:\Users\Claudia\Documents\Bewerbung
2014-06-17 18:15 - 2008-11-30 15:45 - 00002627 _____ () C:\Users\Claudia\Desktop\Microsoft Office Word 2007.lnk
2014-06-16 22:17 - 2014-06-07 20:30 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Adobe
2014-06-16 22:06 - 2008-01-21 09:16 - 01643446 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-16 22:02 - 2006-11-02 14:52 - 00162998 _____ () C:\Windows\setupact.log
2014-06-16 21:59 - 2014-06-16 21:59 - 00002812 _____ () C:\Users\Claudia\Desktop\Fixlist.txt
2014-06-15 10:35 - 2014-06-15 10:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Claudia 

Grützmacher\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-15 03:23 - 2014-06-15 03:23 - 00055613 _____ () C:\Users\Claudia\Desktop\FRST ohne Nachname.txt
2014-06-15 03:23 - 2014-06-15 03:23 - 00043788 _____ () C:\Users\Claudia\Desktop\Addition ohne Nachname.txt
2014-06-14 22:13 - 2014-06-14 22:13 - 00227096 _____ () C:\Users\Claudia\Desktop\avira_registry_cleaner_de.exe
2014-06-14 19:19 - 2012-11-17 22:37 - 00001967 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-14 14:46 - 2014-06-14 14:46 - 00262144 _____ () C:\Windows\system32\config\elam
2014-06-14 14:31 - 2014-06-14 13:57 - 00576608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-14 14:31 - 2014-06-14 13:57 - 00094304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-14 14:31 - 2013-10-17 15:47 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2014-06-14 14:31 - 2013-10-17 15:47 - 00025184 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys
2014-06-14 14:31 - 2013-06-06 17:38 - 00144992 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2014-06-14 14:04 - 2014-06-14 14:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky 

Anti-Virus
2014-06-14 14:02 - 2014-06-14 14:04 - 00000970 _____ () C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2014-06-14 14:01 - 2008-08-07 14:00 - 00000000 ____D () C:\Users\Claudia
2014-06-14 13:57 - 2014-06-14 13:57 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-06-14 01:26 - 2014-05-18 00:02 - 00000000 ____D () C:\ProgramData\tmp
2014-06-14 01:15 - 2014-06-14 01:15 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\PeerNetworking
2014-06-13 22:52 - 2014-06-13 22:52 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\TuneUp Software
2014-06-13 22:47 - 2014-06-13 22:47 - 00000000 ____D () C:\Users\Claudia\AppData\Local\MFAData
2014-06-13 22:45 - 2014-06-13 22:42 - 164819976 _____ (AVG Technologies) 

C:\Users\Claudia\Desktop\avg_free_x64_all_2014_4592a7484.exe
2014-06-13 22:41 - 2014-06-13 21:56 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Nico Mak Computing
2014-06-11 20:10 - 2008-04-21 14:41 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-11 20:05 - 2013-08-06 20:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 20:05 - 2006-11-02 12:24 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-06-09 01:59 - 2008-08-07 18:11 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Corel
2014-06-09 00:54 - 2008-08-07 19:39 - 00000000 ____D () C:\Users\Claudia\Documents\My PSP Files
2014-06-09 00:54 - 2008-08-07 18:12 - 00004182 ___SH () C:\Windows\system32\KGyGaAvL.sys
2014-06-08 13:24 - 2014-06-08 13:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2014-06-08 12:56 - 2014-06-08 12:42 - 00000000 ____D () C:\Temp
2014-06-08 12:54 - 2014-06-08 12:54 - 00000000 ____D () C:\Program Files\HTC
2014-06-08 12:54 - 2008-04-21 09:32 - 00025966 _____ () C:\Windows\DPINST.LOG
2014-06-08 12:45 - 2014-06-08 12:45 - 00000000 ____D () C:\Users\Claudia\AppData\Local\Downloaded Installations
2014-06-08 12:42 - 2014-06-08 12:42 - 00000000 ____D () C:\ProgramData\HTC
2014-06-07 20:25 - 2012-07-08 20:11 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-06-07 20:25 - 2011-07-13 22:41 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32

\FlashPlayerCPLApp.cpl
2014-06-07 19:59 - 2014-06-07 19:59 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet 

(1).RequestDispatcherServlet
2014-06-07 19:59 - 2014-06-07 19:56 - 00009598 _____ () C:\Users\Claudia\Downloads\de.his.servlet.RequestDispatcherServlet
2014-06-07 19:57 - 2008-04-21 10:34 - 00000000 ____D () C:\ProgramData\Adobe
2014-05-28 18:48 - 2014-06-11 19:27 - 12356608 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-28 18:39 - 2014-06-11 19:27 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-28 18:38 - 2014-06-11 19:27 - 09711104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-28 18:33 - 2014-06-11 19:27 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-28 18:32 - 2014-06-11 19:27 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-28 18:32 - 2014-06-11 19:27 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-28 18:31 - 2014-06-11 19:27 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-05-28 18:31 - 2014-06-11 19:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-28 18:30 - 2014-06-11 19:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-28 18:30 - 2014-06-11 19:27 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-28 18:29 - 2014-06-11 19:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-28 18:29 - 2014-06-11 19:27 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-05-28 18:29 - 2014-06-11 19:27 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-05-28 18:28 - 2014-06-11 19:27 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-24 12:35 - 2012-09-08 16:36 - 00000965 _____ () C:\Users\Claudia\Desktop\Dropbox.lnk
2014-05-24 12:35 - 2012-09-08 16:33 - 00000000 ____D () C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start 

Menu\Programs\Dropbox

Files to move or delete:
====================
C:\Users\Claudia\AppData\Roaming\desktop.ini


Some content of TEMP:
====================
C:\Users\Claudia\AppData\Local\Temp\avgnt.exe
C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp_32ceb.dll
C:\Users\Claudia\AppData\Local\Temp\ffunzip.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Claudia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Claudia\AppData\Local\Temp\GDM272F.exe
C:\Users\Claudia\AppData\Local\Temp\GDM34A6.exe
C:\Users\Claudia\AppData\Local\Temp\GLF3BB0.tmp.ConduitEngineSetup.exe
C:\Users\Claudia\AppData\Local\Temp\GoogleChromeInstaller.exe
C:\Users\Claudia\AppData\Local\Temp\IcqUpdater.exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssa_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10ax_gtbp_mssd_aih[1].exe
C:\Users\Claudia\AppData\Local\Temp\install_flashplayer10_mssd_aih.exe
C:\Users\Claudia\AppData\Local\Temp\JiveXViewerStart1363355292.exe
C:\Users\Claudia\AppData\Local\Temp\Opera_1150_int_Setup.exe
C:\Users\Claudia\AppData\Local\Temp\prxGLF3BB0.tmp.tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\Quarantine.exe
C:\Users\Claudia\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll
C:\Users\Claudia\AppData\Local\Temp\unwise.exe
C:\Users\Claudia\AppData\Local\Temp\VisusClient.dll
C:\Users\Claudia\AppData\Local\Temp\wpsetup.exe
C:\Users\Claudia\AppData\Local\Temp\_is30.exe
C:\Users\Claudia\AppData\Local\Temp\_is6CF6.exe
C:\Users\Claudia\AppData\Local\Temp\_is92AD.exe
C:\Users\Claudia\AppData\Local\Temp\{1167C4F7-64B6-4A1D-A0A5-B605C6CDE10F}-26.0.1410.64_25.0.1364.172_chrome_updater.exe
C:\Users\Claudia\AppData\Local\Temp\{5A7A4717-CEF4-4E4A-B23E-0838114D47F8}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{C2722232-3395-42BA-9B03-4B2C787E8081}-chrome_installer.exe
C:\Users\Claudia\AppData\Local\Temp\{D2416B08-7E6C-4C05-B27E-05A6DEC53BCD}-30.0.1599.69_29.0.1547.76_chrome_updater.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-18 22:25

==================== End Of Log ============================
         
--- --- ---



Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version:18-06-2014
Ran by Claudia at 2014-06-18 22:27:44
Running from C:\Users\Claudia\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Kaspersky Anti-Virus (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Anti-Virus (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

 Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-

44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
 Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-

7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
1&1 Surf-Stick (HKLM\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - )
3531-W-D (HKLM\...\{BD1587F7-B8D0-4111-8F1F-3327628AB02F}) (Version: 1.5.18 - Silicon Image)
AAC Decoder (HKLM\...\{AEF9DC35ADDF4825B049ACBFD1C6EB37}) (Version: 7.1.0 - DivX, Inc.)
ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software 

House)
ABBYY FineReader 9.0 Sprint (HKLM\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY)
ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212 - ABBYY) Hidden
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office 

suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 8.3.0 - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-A83000000003}) (Version: 8.3.0 - Adobe Systems 

Incorporated)
Adobe Shockwave Player (HKLM\...\Adobe Shockwave Player) (Version: 11 - Adobe Systems, Inc.)
Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version:  - Agere Systems)
ArcSoft MediaConverter 2 (HKLM\...\{83DA46EC-2CB1-4649-9100-C4F98D8DA8CD}) (Version:  - ArcSoft)
ArcSoft PhotoImpression 5 (HKLM\...\{4FE82F4B-B7D8-4E65-84AD-E0436CDE57DD}) (Version:  - ArcSoft)
ArcSoft ShowBiz DVD 2 (HKLM\...\{E883DCB3-766D-4166-8B28-33C8FE451F2B}) (Version:  - ArcSoft)
ArcSoft TotalMedia 3.5 (HKLM\...\{29E44E9D-ACB2-4D2D-849F-5361C941B7E1}) (Version: 3.5.7.362 - ArcSoft)
AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - )
Camera RAW Plug-In for EPSON Creativity Suite (HKLM\...\{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}) (Version: 2.2.0.0 - SEIKO 

EPSON CORPORATION)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - 

Microsoft Corporation)
Corel MediaOne (HKLM\...\{A062A15F-9CAC-4B88-98DF-87628A0BD721}) (Version: 2.00.0000 - Corel Corporation)
Corel Paint Shop Pro Photo X2 (HKLM\...\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}) (Version: 12.010.0000 - Corel Corporation)
Digital Video (HKLM\...\{C833C7B6-1140-471D-932B-391B5CA66D7D}) (Version: 1.00.000 - )
DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.8.5 - DivX, Inc.)
DivX Converter (HKLM\...\{13F3917B56CD4C25848BDC69916971BB}) (Version: 7.0.0 - DivX, Inc.)
DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.0.0 - DivX, Inc.)
DivX Player (HKLM\...\{8ADFC4160D694100B5B8A22DE9DCABD9}) (Version: 7.0.0 - DivX, Inc.)
DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters) (Version:  - DivX, Inc.)
DivX Version Checker (HKLM\...\{3FC7CBBC4C1E11DCA1A752EA55D89593}) (Version: 7.0.0.19 - DivX, Inc.)
DivX Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 1.4.2 - DivX,Inc.)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
DVDVideoSoft Toolbar (HKLM\...\DVDVideoSoft Toolbar) (Version:  - )
EPSON Attach To Email (HKLM\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.3.0.0 - )
EPSON Easy Photo Print (HKLM\...\{3D78F2A2-C893-4ABD-B5FE-AD7011837755}) (Version: 1.5.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print 2 (HKLM\...\{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 

1.00.0000 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION)
EPSON File Manager (HKLM\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - )
EPSON Scan (HKLM\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON Scan Assistant (HKLM\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
EPSON Stylus CX7300_CX8300_DX7400_DX8400 Handbuch (HKLM\...\EPSON Stylus CX7300_CX8300_DX7400_DX8400 Benutzerhandbuch) 

(Version:  - )
EPSON SX420W Series Handbuch (HKLM\...\EPSON SX420W Series Manual) (Version:  - )
EPSON SX420W Series Netzwerk-Handbuch (HKLM\...\EPSON SX420W Series Network Guide) (Version:  - )
EPSON SX420W Series Printer Uninstall (HKLM\...\EPSON SX420W Series) (Version:  - SEIKO EPSON Corporation)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.4i - SEIKO EPSON CORPORATION)
EpsonNet Setup 3.2 (HKLM\...\{C9D8A041-2963-4B31-8FFC-1500F3DB9293}) (Version: 3.2a - SEIKO EPSON CORPORATION)
Firebird SQL Server - MAGIX Edition (HKLM\...\Firebird SQL Server D) (Version: 2.0.1.8 - MAGIX AG)
Free Audio CD Burner version 1.2 (HKLM\...\Free Audio CD Burner_is1) (Version:  - DVDVideoSoft Limited.)
Free YouTube Download version 3.0.16.923 (HKLM\...\Free YouTube Download_is1) (Version:  - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.11.37.1212 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.37.1212 - 

DVDVideoSoft Ltd.)
GMX MediaCenter 1.5.1765.0 (HKCU\...\GMX Application {sync-000021}) (Version: 1.5.1765.0 - 1&1 Mail & Media GmbH)
Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
H.264 Decoder (HKLM\...\{A96E97134CA649888820BCDE5E300BBD}) (Version: 1.0.0 - DivX, Inc.)
ICQ7.4 (HKLM\...\{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}) (Version: 7.4 - ICQ)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - Intel Corporation)
Intel(R) Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - )
InterVideo WinDVD 8 (HKLM\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B9.385 - InterVideo 

Inc.)
InterVideo WinDVD 8 (Version: 8.0-B9.385 - InterVideo Inc.) Hidden
IPTInstaller (HKLM\...\{6965F2F4-1CD2-4F42-A8EF-9EF433F9AA72}) (Version: 4.0.4 - HTC)
Java(TM) 6 Update 5 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.)
Kaspersky Anti-Virus (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab)
Kaspersky Anti-Virus (Version: 14.0.0.4651 - Kaspersky Lab) Hidden
Launch Manager V1.4.9 (HKLM\...\{D0846526-66DD-4DC9-A02C-98F9A2806812}) (Version: 1.4.9 - Wistron Corp.)
LG PC Suite II (HKLM\...\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}) (Version: 2.00.0000 - LG PC Suite)
LG PC Suite II (Version: 2.00.0000 - LG PC Suite) Hidden
LG USB Modem driver (HKLM\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: 4.9.4 - LG Electronics)
MD86351 Driver Install (HKLM\...\InstallShield_{B3A9DC22-6162-4844-BEB3-853BAFB980E0}) (Version: 6.3.6.1 - Ihr Firmenname)
MD86351 Driver Install (Version: 6.3.6.1 - Ihr Firmenname) Hidden
MEDION Fotos auf CD Nord (HKLM\...\MEDION Fotos auf CD Nord D) (Version: 6.0.2.0 - MAGIX AG)
Medion Media Center 0 (Version: 1.0.12.0 - Medion) Hidden
MEDIONbox (HKLM\...\{27FDF949-69CE-435A-8372-339F72336AC5}) (Version: 1.09.0000.00052 - Medion)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version:  - )
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) 

(Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - 

Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft 

Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-

48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-

48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - 

Microsoft Corporation)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft 

Corporation)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Picture It! Foto Premium 9 (HKLM\...\PictureIt_v9) (Version: 9.0.0.0000 - Microsoft Corporation)
Microsoft Picture It! Foto Premium 9 (Version: 9.0.0.0000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) 

(Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - 

Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - 

Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) 

(Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 

9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 

9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 

9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 

9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 

9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 

10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation)
Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation) Hidden
MindManager Smart (HKLM\...\MindManager Smart) (Version: 2.1.3 - Mindjet LLC)
MKV Splitter (HKLM\...\{AAC389499AEF40428987B3D30CFC76C9}) (Version: 1.0.0 - DivX, Inc.)
Move Networks Media Player for Internet Explorer (HKCU\...\Move Networks Player - IE) (Version:  - )
Mozilla Firefox (3.0) (HKLM\...\Mozilla Firefox (3.0)) (Version: 3.0 (de) - Mozilla)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 8 Essentials (HKLM\...\{47948554-90C6-4AAC-8CFA-D23CE11C1031}) (Version: 8.3.124 - Nero AG)
neroxml (Version: 1.0.0 - Nero AG) Hidden
OnlineFotoservice (HKLM\...\OnlineFotoservice) (Version: 5.1.5 - CEWE Stiftung u Co. KGaA)
Opera 12.12 (HKLM\...\Opera 12.12.1707) (Version: 12.12.1707 - Opera Software ASA)
PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 0.9.8 - Frank Heindörfer, Philip Chinery)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Ralink Wireless LAN (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.00.0000 - RaLink)
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista (HKLM\...\{8833FFB6-5B0C-4764-81AA-

06DFEED9A476}) (Version: 1.00.0000 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5595 - Realtek 

Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version:  - Realtek Semiconductor Corp.)
Rossmann Fotoservice 2.6 (HKLM\...\Rossmann Fotoservice_is1) (Version:  - )
Sceneo AbsolutTV (HKLM\...\{4C73B683-B15D-4B94-AC7A-520B70C4FFE9}) (Version:  - )
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Switch Sound File Converter (HKLM\...\Switch) (Version:  - NCH Software)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.0.14.0 - Synaptics)
TV IR (HKLM\...\InstallShield_{8CFE319F-DC08-48BA-B011-37ED5C9733B5}) (Version: 1.00.0000 - Ihr Firmenname)
TV IR (Version: 1.00.0000 - Ihr Firmenname) Hidden
Ulead DVD MovieFactory 5 (HKLM\...\{FF164702-AF8B-4F2F-8038-74A4C536866B}) (Version: 5.3 - Ulead Systems, Inc.)
Ulead PhotoImpact 12 (HKLM\...\{11AFE21E-B193-430D-B57A-DFF7815BB962}) (Version: 12.0 - Ulead System)
Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version:  - )
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-

5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_

{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) 

(Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}

_ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}

_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}

_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}

_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Access 2007 Help (KB963663) (HKLM\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_

{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version:  - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_

{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_

{716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version:  - Microsoft)
Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_

{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}

_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}

_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_

{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2881065) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-

0000000FF1CE}_ENTERPRISE_{B7EF38F7-1D58-4085-A9A4-0F6C69A5AA1E}) (Version:  - Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_

{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_

{2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version:  - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_

{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_

{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_

{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}

_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_

{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
USB Video Device (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.18100.101 - Sonix)
VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0 - DivX, Inc) Hidden
VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG 

Technologies CZ, s.r.o.)
VLC media player 1.1.10 (HKLM\...\VLC media player) (Version: 1.1.10 - VideoLAN)
WavePad Sound Editor (HKLM\...\WavePad) (Version:  - NCH Software)
Windows Live Messenger (HKLM\...\{279DB581-239C-4E13-97F8-0F48E40BE75C}) (Version: 8.1.0178.00 - Microsoft Corporation)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )
WISO Mein Geld 2008 Professional (HKLM\...\{D8D22773-14BF-4178-A683-3DBA515C2A26}) (Version: 9.00.01.0023 - Buhl Data 

Service GmbH)
XVID Codec Installation (HKLM\...\{534C6D59-D6E3-48A6-AD0B-747799019960}) (Version:  - )

==================== Restore Points  =========================

04-06-2014 17:38:03 Geplanter Prüfpunkt
07-06-2014 18:44:11 Windows Update
08-06-2014 10:42:59 Gerätetreiber-Paketinstallation: HTC, Corporation
08-06-2014 10:46:45 Gerätetreiber-Paketinstallation: HTC Corporation Netzwerkadapter
08-06-2014 10:49:34 Gerätetreiber-Paketinstallation: HTC Corporation Tragbare Geräte
08-06-2014 10:54:49 Gerätetreiber-Paketinstallation: HTC Netzwerkprotokoll
11-06-2014 17:26:28 Windows Update
11-06-2014 18:00:59 Windows Update
13-06-2014 20:48:59 Installed AVG 2014
13-06-2014 20:50:05 Installed AVG 2014
14-06-2014 11:59:34 Gerätetreiber-Paketinstallation: Kaspersky Lab Netzwerkdienst
17-06-2014 17:36:53 Removed AVG 2014
17-06-2014 17:41:24 Removed AVG 2014

==================== Hosts content: ==========================

2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0D4A3951-D115-4E17-9495-26DC510E1359} - System32\Tasks\{19864B7B-6EBE-4684-9FF9-DD775F771854} => C:\Program 

Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32

\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {574969E9-0C4A-4A75-A6C7-549B08CDB6C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program 

Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.)
Task: {8AC7F5E7-9061-45A6-95FE-B269516DA561} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program 

Files\Google\Update\GoogleUpdate.exe [2009-06-05] (Google Inc.)
Task: {B7794283-DDB2-48C6-9B9B-3AC33999A0C1} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => 

Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => 

C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {EEEAB8B8-067F-4F56-8432-3BBC88C3CC8F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32

\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2009-09-04 19:29 - 2001-10-28 17:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll
2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0

\dblite.dll
2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0

\kpcengine.2.3.dll
2013-07-21 20:03 - 2013-07-21 20:03 - 03391488 _____ () c:\windows\assembly\nativeimages1_v1.1.4322

\mscorlib\1.0.5000.0__b77a5c561934e089_b0c6b048\mscorlib.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 01966080 _____ () c:\windows\assembly\nativeimages1_v1.1.4322

\system\1.0.5000.0__b77a5c561934e089_c7c004ef\system.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 03035136 _____ () c:\windows\assembly\nativeimages1_v1.1.4322

\system.windows.forms\1.0.5000.0__b77a5c561934e089_5c188a8d\system.windows.forms.dll
2013-07-21 20:02 - 2013-07-21 20:02 - 02088960 _____ () c:\windows\assembly\nativeimages1_v1.1.4322

\system.xml\1.0.5000.0__b77a5c561934e089_821dd40b\system.xml.dll
2009-10-03 11:47 - 2005-06-28 13:59 - 00053248 _____ () C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll
2008-04-22 08:37 - 2007-04-19 12:11 - 00006656 _____ () c:\program files\medion\medionbox\program\structconverter.dll
2009-08-18 20:24 - 2009-04-11 08:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll
2012-10-08 17:04 - 2012-10-08 17:04 - 00166912 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2007-06-05 13:20 - 2007-06-05 13:20 - 00177704 _____ () C:\Windows\system32\PSIService.exe
2008-04-22 08:30 - 2007-05-16 22:48 - 00421955 _____ () C:\Program Files\Sceneo\AbsolutTV\Services\PVR\tvtvRemote.dll
2011-08-06 14:59 - 2010-09-30 14:00 - 00253264 _____ () C:\Program Files\1&1 Surf-Stick\AssistantServices.exe
2008-04-21 09:37 - 2007-09-01 14:03 - 00032768 _____ () C:\Program Files\Launch Manager\LaunchAp.exe
2007-10-30 19:52 - 2007-10-30 19:52 - 00016200 _____ () C:\Program Files\Corel\Corel Paint Shop Pro Photo X2

\CorelIOMonitor.exe
2011-01-08 16:14 - 2007-02-12 15:50 - 00020480 _____ () C:\Windows\FixCamera.exe
2011-01-08 16:14 - 2007-12-04 19:28 - 00249856 _____ () C:\Windows\tsnp2uvc.exe
2011-08-06 14:59 - 2010-09-30 14:00 - 00139088 _____ () C:\Program Files\1&1 Surf-Stick\UIExec.exe
2010-12-22 11:27 - 2010-12-22 11:27 - 00692318 _____ () C:\Program Files\TV IR\TV IR.exe
2010-06-18 00:09 - 2010-06-18 00:09 - 00167936 _____ () C:\Program Files\TV IR\RmCard.dll
2008-01-15 00:40 - 2008-01-15 00:40 - 00053248 _____ () C:\Program Files\TV IR\LWExt.dll
2009-03-09 11:52 - 2009-03-09 11:52 - 00053248 _____ () C:\Program Files\TV IR\tmir.dll
2012-10-21 13:31 - 2007-04-19 09:33 - 00035584 _____ () C:\Program Files\ArcSoft\TotalMedia 3.5\uPiApi.dll
2014-06-18 22:22 - 2014-06-18 22:22 - 00043008 _____ () C:\Users\Claudia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-

5bce-5766-8f84-3e3e7ecf0d81}.tmp_32ceb.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Claudia\AppData\Roaming\Dropbox\bin\libcef.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Claudia\Beweis.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Beweis.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Beweis.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Desktop\Funde Kaspersky.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Busverbindungen, Celle.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\ebay lederjacke.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\erziehungsauftrag.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\Muster Inspektion VW.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Claudia\Documents\pikante spaghetti.png:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik1.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:Updt_SummaryInformation
AlternateDataStreams: C:\Users\Public\vertrag maik2.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/18/2014 10:20:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 3.3.3.0, Zeitstempel 0x47c6bd1b, fehlerhaftes Modul 

unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x17271727,
Prozess-ID 0x100c, Anwendungsstartzeit NMIndexStoreSvr.exe0.

Error: (06/18/2014 10:19:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" 

AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/18/2014 06:25:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 3.3.3.0, Zeitstempel 0x47c6bd1b, fehlerhaftes Modul 

unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x17271727,
Prozess-ID 0x1248, Anwendungsstartzeit NMIndexStoreSvr.exe0.

Error: (06/18/2014 06:23:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" 

AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/18/2014 06:06:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" 

AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/18/2014 06:05:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 3.3.3.0, Zeitstempel 0x47c6bd1b, fehlerhaftes Modul 

unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x03030303,
Prozess-ID 0xb18, Anwendungsstartzeit NMIndexStoreSvr.exe0.

Error: (06/17/2014 10:45:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" 

AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/18/2014 10:19:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (06/18/2014 06:23:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (06/18/2014 06:06:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (06/17/2014 10:46:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Avira Service Host

Error: (06/17/2014 10:46:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Windows Search%%1053

Error: (06/17/2014 10:46:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Windows Search

Error: (06/17/2014 10:45:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058


Microsoft Office Sessions:
=========================
Error: (05/07/2013 08:37:08 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office 

Version: 12.0.6612.1000. This session lasted 810 seconds with 720 seconds of active time.  This session ended with a 

crash.

Error: (05/13/2011 02:44:54 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office 

Version: 12.0.6425.1000. This session lasted 1089 seconds with 120 seconds of active time.  This session ended with a 

crash.

Error: (03/20/2011 05:35:34 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6545.5000, Microsoft Office 

Version: 12.0.6425.1000. This session lasted 4422 seconds with 900 seconds of active time.  This session ended with a 

crash.


CodeIntegrity Errors:
===================================
  Date: 2014-06-18 22:27:18.072
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-18 22:27:17.246
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-18 22:27:16.419
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-18 22:27:15.592
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-18 22:26:34.611
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-18 22:26:33.722
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-18 22:26:32.817
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-18 22:26:31.912
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:52:26.481
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-17 22:52:25.545
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\kl1.sys" konnte nicht 

überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Percentage of memory in use: 48%
Total physical RAM: 3061.69 MB
Available physical RAM: 1576.18 MB
Total Pagefile: 6325.64 MB
Available Pagefile: 4708.42 MB
Total Virtual: 2047.88 MB
Available Virtual: 1902.56 MB

==================== Drives ================================

Drive c: (BOOT) (Fixed) (Total:207.5 GB) (Free:100.71 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVER) (Fixed) (Total:25.37 GB) (Free:5.96 GB) FAT32
Drive g: () (Removable) (Total:1.84 GB) (Free:0 GB) FAT

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 4B64DFC2)
Partition 1: (Active) - (Size=207 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=25 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 2 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End Of Log ============================
         

Alt 19.06.2014, 12:02   #14
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Okay, dann Kontrollscans mit MBAM und ESET bitte:

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 20.06.2014, 05:14   #15
Lorelai!
 
Avira durch Gruppenrichtlinie geblockt - Trojaner? - Standard

Avira durch Gruppenrichtlinie geblockt - Trojaner?



Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 19.06.2014
Suchlauf-Zeit: 19:42:48
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.06.19.08
Rootkit Datenbank: v2014.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows Vista Service Pack 2
CPU: x86
Dateisystem: NTFS
Benutzer: Claudia 

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 265427
Verstrichene Zeit: 26 Min, 14 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 1
Rogue.PersonalAntiVirus, C:\Program Files\PersonalAV, In Quarantäne, [64f0df9bbfbc132396a1424004fe16ea], 

Dateien: 2
PUP.Optional.FreeTwitTube.A, C:\Users\Claudia\AppData\Local\Temp\ibtmpd366498\component_583, In Quarantäne, [401428522e4d64d2bf0fd7af1ee3d927], 
PUP.Optional.FileScout.A, C:\Users\Claudia\AppData\Local\Temp\ibtmpd366498\component_600, In Quarantäne, [82d2b9c138439c9a4a6fe12afc0532ce], 

Physische Sektoren: 0
(No malicious items detected)


(end)
         

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=4aa60037e628a54ab4c957fd7d7f1aa5
# engine=18789
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-06-19 11:02:48
# local_time=2014-06-20 01:02:48 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1='Kaspersky Anti-Virus'
# compatibility_mode=1293 16777213 100 100 16254 34696988 0 0
# compatibility_mode_1=''
# compatibility_mode=5892 16776574 100 100 526189 240751694 0 0
# scanned=281141
# found=16
# cleaned=0
# scan_time=15133
sh=A981E3D6F03D3BD57D1472F33A4093A01533F8A8 ft=1 fh=7aaf7b3d0491af48 vn="Variante von MSIL/AdvancedSystemProtector.A evtl. unerwünschte Anwendung" ac=I fn="C:\$Recycle.Bin\S-1-5-21-3856976919-2596979157-3738053339-1003\$R4GLCRP.exe"
sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir"
sh=664270A860DDB3D6F23F617D0615070330A71A30 ft=1 fh=192f7aaecaa32147 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert.dll.vir"
sh=6EEA45F0AC75053D955E44A1735997B263EDF882 ft=1 fh=be934e040f354c5e vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert0.dll.vir"
sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\ConduitEngine\ConduitEngine.dll.vir"
sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\DVDVideoSoftTB\tbDVDV.dll.vir"
sh=5101F30DCAB10FED68ECD473A99AEB523EF0DC44 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\Local\Temp\CT2269050\chrome\dvdvideosofttb.jar.vir"
sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\LocalLow\ConduitEngine\ConduitEngine.dll.vir"
sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\LocalLow\DVDVideoSoftTB\tbDVDV.dll.vir"
sh=5101F30DCAB10FED68ECD473A99AEB523EF0DC44 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\dvdvideosofttb.jar.vir"
sh=972A6701E512D4D717B91B1C8E0EC542BCCEB247 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\mp504yaj.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\chrome\dvdvideosoft.jar.vir"
sh=E5C5C36DDD3DC414086EB9EC20DCEF13C06DDD94 ft=1 fh=f4eb487f30a3126f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Claudia\AppData\Local\Temp\tbDVDV.dll"
sh=B5A6C2CFC53E52AD5DF76AD819AF9F53424C5E75 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Claudia\AppData\Local\Temp\tbff.xpi"
sh=7A5B168BB2B8C06B2A9134B656BBF195830D21C2 ft=1 fh=55d4f387d8566cf4 vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Claudia\AppData\LocalLow\DVDVideoSoft\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.1.1\bin\PriceGongIE.dll"
sh=66141F092657FC9801DCFED65C7B99A578B043D6 ft=1 fh=398a74cdcc9e1d42 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Claudia\Downloads\FreeYouTubeToMp3Converter.exe"
sh=D03FB2F36539640C5C3C84686CBE465E6E466316 ft=1 fh=6ee776d5f517fb67 vn="Variante von Win32/KillProc.A evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\FixCamera.exe"
         

Antwort

Themen zu Avira durch Gruppenrichtlinie geblockt - Trojaner?
avira anti virus trojaner, fehlermeldung, geblockt, gruppenrichtlinie, komplett, msil/advancedsystemprotector.a, neuinstallation, nicht mehr, pup.optional.filescout.a, pup.optional.freetwittube.a, registry, rogue.personalantivirus, trojaner?, win32/killproc.a, win32/pricegong.a, win32/toolbar.conduit, win32/toolbar.conduit.a, win32/toolbar.conduit.b, win32/toolbar.conduit.y, windows, windows vista, wirklich



Ähnliche Themen: Avira durch Gruppenrichtlinie geblockt - Trojaner?


  1. Windows 7, Trojaner von Avira geblockt + entfernt, Malwarebytes möglicher Fund aber von Avira geblockt
    Log-Analyse und Auswertung - 13.05.2015 (13)
  2. Avira durch gruppenrichtlinie blokiert
    Log-Analyse und Auswertung - 16.03.2015 (21)
  3. Avira Pro - Dieses Programm wurde durch eine Gruppenrichtlinie geblockt.
    Plagegeister aller Art und deren Bekämpfung - 16.10.2014 (12)
  4. Anwendung durch Gruppenrichtlinie geblockt --->Kaspersky startet nicht
    Plagegeister aller Art und deren Bekämpfung - 24.09.2014 (3)
  5. Windows Vista G Data: Dieses Programm wurde durch eine Gruppenrichtlinie geblockt
    Log-Analyse und Auswertung - 23.08.2014 (9)
  6. Windows Vista: Anti-Vir lässt sich nicht mehr starten - geblockt durch Gruppenrichtlinie
    Log-Analyse und Auswertung - 22.08.2014 (11)
  7. Dieses Programm wurde durch eine Gruppenrichtlinie geblockt - G-Data nicht startbar
    Plagegeister aller Art und deren Bekämpfung - 27.07.2014 (41)
  8. Avira durch gruppenrichtlinie blockiert
    Log-Analyse und Auswertung - 26.07.2014 (17)
  9. Avira: Dieses Programm wurde durch eine Gruppenrichtlinie geblockt --> Onlinebanking gesperrt
    Log-Analyse und Auswertung - 24.07.2014 (12)
  10. "Avira wird durch eine Gruppenrichtlinie blockiert" Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 02.07.2014 (12)
  11. Avira durch Gruppenrichtlinie blockiert
    Log-Analyse und Auswertung - 28.06.2014 (13)
  12. "Avira wird durch eine Gruppenrichtlinie blockiert" - Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 22.06.2014 (16)
  13. Avira wird von Gruppenrichtlinie geblockt
    Plagegeister aller Art und deren Bekämpfung - 16.06.2014 (9)
  14. avgui "wurde durch eine Gruppenrichtlinie geblockt [...] Weitere Infos vom SysAdmin"
    Plagegeister aller Art und deren Bekämpfung - 09.06.2014 (18)
  15. Windows 7 64bit, Security Essentials wird durch Gruppenrichtlinie geblockt + Werbung poppt auf
    Log-Analyse und Auswertung - 08.06.2014 (9)
  16. Avast wurde durch eine Gruppenrichtlinie geblockt
    Plagegeister aller Art und deren Bekämpfung - 01.06.2014 (9)
  17. Avira wegen Gruppenrichtlinie geblockt / RegSvr32 Fehler
    Log-Analyse und Auswertung - 01.06.2014 (15)

Zum Thema Avira durch Gruppenrichtlinie geblockt - Trojaner? - Hallo, ich habe jetzt wohl ein ernsthaftes Problem auf meinem Laptop, Windows Vista, 32 Bit-Betriebssystem, Home Premium. Ich kann Avira nicht mehr starten und nur sehr schwer deinstallieren, da die - Avira durch Gruppenrichtlinie geblockt - Trojaner?...
Archiv
Du betrachtest: Avira durch Gruppenrichtlinie geblockt - Trojaner? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.