|   | marshaller | 03.09.2013 16:43 |  
 Malwarebytes Anti-Malware 1.75.0.1300 
Malwarebytes : Free anti-malware download  
Datenbank Version: v2013.09.03.05  
Windows 7 Service Pack 1 x64 NTFS 
Internet Explorer 10.0.9200.16660 
Markus :: MARKUS-PC [Administrator]  
03.09.2013 16:48:59 
mbam-log-2013-09-03 (16-48-59).txt  
Art des Suchlaufs: Quick-Scan 
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM 
Deaktivierte Suchlaufeinstellungen: P2P 
Durchsuchte Objekte: 246225 
Laufzeit: 5 Minute(n), 42 Sekunde(n)  
Infizierte Speicherprozesse: 0 
(Keine bösartigen Objekte gefunden)  
Infizierte Speichermodule: 0 
(Keine bösartigen Objekte gefunden)  
Infizierte Registrierungsschlüssel: 0 
(Keine bösartigen Objekte gefunden)  
Infizierte Registrierungswerte: 0 
(Keine bösartigen Objekte gefunden)  
Infizierte Dateiobjekte der Registrierung: 0 
(Keine bösartigen Objekte gefunden)  
Infizierte Verzeichnisse: 3 
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.  
Infizierte Dateien: 5 
C:\Users\Markus\Downloads\SoftonicDownloader_fuer_photoscape.exe (PUP.Optional.Softonic) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. 
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.  
(Ende)  
AdwCleaner Logfile:   Code: 
 # AdwCleaner v3.002 - Bericht erstellt am 03/09/2013 um 17:08:12# Updated 01/09/2013 von Xplode
 # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
 # Benutzername : Markus - MARKUS-PC
 # Gestartet von : C:\Users\Markus\Downloads\adwcleaner.exe
 # Option : Löschen
 
 ***** [ Dienste ] *****
 
 
 ***** [ Dateien / Ordner ] *****
 
 Ordner Gelöscht : C:\ProgramData\Ask
 Ordner Gelöscht : C:\ProgramData\boost_interprocess
 Ordner Gelöscht : C:\Program Files (x86)\Ask.com
 Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
 Ordner Gelöscht : C:\Users\Markus\AppData\LocalLow\AskToolbar
 Ordner Gelöscht : C:\Users\Markus\AppData\Roaming\dvdvideosoftiehelpers
 Ordner Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\guamnss2.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
 Ordner Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\guamnss2.default\Extensions\toolbar@ask.com
 Datei Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\guamnss2.default\searchplugins\Askcom.xml
 Datei Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\guamnss2.default\searchplugins\askcomsearch.xml
 Datei Gelöscht : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\guamnss2.default\user.js
 Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
 
 ***** [ Verknüpfungen ] *****
 
 
 ***** [ Registrierungsdatenbank ] *****
 
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_minecraft-server_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_minecraft-server_RASMANCS
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_snowflakes-screensaver_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_snowflakes-screensaver_RASMANCS
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
 Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
 Schlüssel Gelöscht : HKCU\Software\Ask.com
 Schlüssel Gelöscht : HKCU\Software\Conduit
 Schlüssel Gelöscht : HKCU\Software\Softonic
 Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar
 Schlüssel Gelöscht : HKLM\Software\AskToolbar
 Schlüssel Gelöscht : HKLM\Software\Conduit
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
 
 ***** [ Browser ] *****
 
 -\\ Internet Explorer v10.0.9200.16660
 
 
 -\\ Mozilla Firefox v16.0.1 (de)
 
 [ Datei : C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\guamnss2.default\prefs.js ]
 
 Zeile gelöscht : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");
 Zeile gelöscht : user_pref("extensions.asktb.abar-war-regex", "conduit\\.com");
 Zeile gelöscht : user_pref("extensions.asktb.apn_dbr", "ie_8.0.7600.16385");
 Zeile gelöscht : user_pref("extensions.asktb.autofill-competitor-query-enabled", true);
 Zeile gelöscht : user_pref("extensions.asktb.cbid", "U3");
 Zeile gelöscht : user_pref("extensions.asktb.config-updated", false);
 Zeile gelöscht : user_pref("extensions.asktb.crumb", "2011.12.10+08.56.23-toolbar016iad-DE-UGFzc2F1LEdlcm1hbnk%3D");
 Zeile gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}&gct=bar");
 Zeile gelöscht : user_pref("extensions.asktb.displaybehavior", "");
 Zeile gelöscht : user_pref("extensions.asktb.displaytext", "");
 Zeile gelöscht : user_pref("extensions.asktb.dtid", "OSJ000YYDE");
 Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
 Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX0260");
 Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C");
 Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "");
 Zeile gelöscht : user_pref("extensions.asktb.ff19-config-first-run", "true");
 Zeile gelöscht : user_pref("extensions.asktb.first-restart-after-config-update", true);
 Zeile gelöscht : user_pref("extensions.asktb.guid", "B031AFAF-8C65-45B7-BAE8-D2CBE41A072B");
 Zeile gelöscht : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxps://websearch.ask.com\", [...]
 Zeile gelöscht : user_pref("extensions.asktb.if", "su");
 Zeile gelöscht : user_pref("extensions.asktb.keyword-toggled-in-session", false);
 Zeile gelöscht : user_pref("extensions.asktb.last-config-req", "1365797284247");
 Zeile gelöscht : user_pref("extensions.asktb.locale", "de_DE");
 Zeile gelöscht : user_pref("extensions.asktb.location", "Passau,Germany");
 Zeile gelöscht : user_pref("extensions.asktb.lstation", "");
 Zeile gelöscht : user_pref("extensions.asktb.new-tab-opt-out", true);
 Zeile gelöscht : user_pref("extensions.asktb.news-native-on", true);
 Zeile gelöscht : user_pref("extensions.asktb.o", "100000027");
 Zeile gelöscht : user_pref("extensions.asktb.pstate", "");
 Zeile gelöscht : user_pref("extensions.asktb.qsrc", "2871");
 Zeile gelöscht : user_pref("extensions.asktb.sa", "YES");
 Zeile gelöscht : user_pref("extensions.asktb.saguid", "A9714D93-6C10-4E47-A4AB-EDEAEA0715D9");
 Zeile gelöscht : user_pref("extensions.asktb.search-suggestions-enabled", true);
 Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade", true);
 Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", true);
 Zeile gelöscht : user_pref("extensions.asktb.socialmini-first", true);
 Zeile gelöscht : user_pref("extensions.asktb.socialmini-interval", "1200000");
 Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
 Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-items", "30");
 Zeile gelöscht : user_pref("extensions.asktb.socialmini-native-on", true);
 Zeile gelöscht : user_pref("extensions.asktb.socialmini-speed", "10000");
 Zeile gelöscht : user_pref("extensions.asktb.socialmini-transition-first-open", false);
 Zeile gelöscht : user_pref("extensions.asktb.themeid", "");
 Zeile gelöscht : user_pref("extensions.asktb.timeinstalled", "09.02.2013 14:00:18");
 Zeile gelöscht : user_pref("extensions.asktb.to", "");
 
 -\\ Google Chrome v
 
 [ Datei : C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
 *************************
 
 AdwCleaner[R0].txt - [9789 octets] - [03/09/2013 17:05:27]
 AdwCleaner[S0].txt - [9571 octets] - [03/09/2013 17:08:12]
 
 ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9631 octets] ##########
 --- --- ---  
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Junkware Removal Tool (JRT) by Thisisu 
Version: 5.5.7 (09.01.2013:1) 
OS: Windows 7 Home Premium x64 
Ran by Markus on 03.09.2013 at 17:22:27.89 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~     
~~~ Services    
~~~ Registry Values    
~~~ Registry Keys  
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\features\a28b4d68debaa244eb686953b7074fef 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\a28b4d68debaa244eb686953b7074fef 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{45CC3F28-C6C3-4BEF-9334-5FC96807A555}    
~~~ Files    
~~~ Folders  
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess" 
Successfully deleted: [Folder] "C:\Users\Markus\appdata\local\apn"    
~~~ FireFox  
Emptied folder: C:\Users\Markus\AppData\Roaming\mozilla\firefox\profiles\guamnss2.default\minidumps [2 files]    
~~~ Event Viewer Logs were cleared      
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Scan was completed on 03.09.2013 at 17:29:46.97 
End of JRT log 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
FRST Logfile:  
FRST Logfile:  
FRST Logfile:   Code: 
 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2013 01Ran by Markus (administrator) on MARKUS-PC on 03-09-2013 17:37:21
 Running from C:\Users\Markus\Desktop
 Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
 Internet Explorer Version 10
 Boot Mode: Normal
 
 ==================== Processes (Whitelisted) =================
 
 (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
 (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
 (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
 (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
 (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
 (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
 (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
 (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
 (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
 (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
 (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
 (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
 (Intel Corporation) C:\Windows\System32\igfxtray.exe
 (Intel Corporation) C:\Windows\System32\hkcmd.exe
 (Intel Corporation) C:\Windows\System32\igfxpers.exe
 (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
 (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
 (Akamai Technologies, Inc.) C:\Users\Markus\AppData\Local\Akamai\netsession_win.exe
 (Intel Corporation) C:\Windows\system32\igfxext.exe
 (Akamai Technologies, Inc.) C:\Users\Markus\AppData\Local\Akamai\netsession_win.exe
 () C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
 (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe
 (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
 (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
 (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
 (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
 (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
 (CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
 (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
 (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
 (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
 (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
 (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
 (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
 (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
 (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
 (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
 (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
 (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
 (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
 (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
 (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe
 
 ==================== Registry (Whitelisted) ==================
 
 HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11725928 2010-12-23] (Realtek Semiconductor)
 HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2186856 2010-12-10] (Realtek Semiconductor)
 HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-10-08] ()
 HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
 HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860040 2011-01-06] (Acer Incorporated)
 HKLM\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\ootag.exe [13856 2010-02-23] (Microsoft)
 HKLM\...\Policies\Explorer: [NoDrives] 0
 HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Markus\AppData\Local\Akamai\netsession_win.exe [4480768 2013-01-26] (Akamai Technologies, Inc.)
 HKCU\...\Run: [KPeerNexonEU] - C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [438272 2012-05-13] (NEXON Inc.)
 HKCU\...\Run: [EADM] - C:\Users\Public\Desktop\Noten\Origin\Origin.exe [3549528 2013-07-31] (Electronic Arts)
 HKCU\...\Run: [Facebook Update] - C:\Users\Markus\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-03-02] (Facebook Inc.)
 HKCU\...\Policies\Explorer: [NoDrives] 0
 HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-14] (Intel Corporation)
 HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [1675160 2012-03-21] (McAfee, Inc.)
 HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-28] (Egis Technology Inc.)
 HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-18] (Egis Technology Inc.)
 HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-18] (Egis Technology Inc.)
 HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
 HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
 HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296768 2010-11-12] (NTI Corporation)
 HKLM-x32\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft)
 HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
 HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1078352 2011-02-24] (Dritek System Inc.)
 HKLM-x32\...\Run: [MDS_Menu] - C:\Program Files (x86)\Acer\clear.fi\MediaEspresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
 HKLM-x32\...\Run: [ArcadeMovieService] - C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2010-12-09] (CyberLink Corp.)
 HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
 HKLM-x32\...\Run: [] -  [x]
 HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
 HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG)
 HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
 HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
 AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-03] (NVIDIA Corporation)
 AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-03] (NVIDIA Corporation)
 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
 ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
 ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
 Startup: C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
 ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
 
 ==================== Internet (Whitelisted) ====================
 
 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
 URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} -  No File
 URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
 SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL No File
 BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20130901104020.dll (McAfee, Inc.)
 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
 BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
 BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
 BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
 BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
 BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll ()
 BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
 BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20130901104020.dll (McAfee, Inc.)
 BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
 BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
 BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
 BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
 BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
 BHO-x32: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
 BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
 Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
 Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
 Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
 Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
 DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
 Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
 Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
 Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.)
 Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.)
 Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
 
 FireFox:
 ========
 FF ProfilePath: C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\guamnss2.default
 FF DefaultSearchEngine: Ask.com Search
 FF SearchEngineOrder.1: Ask.com Search
 FF SelectedSearchEngine: Ask.com Search
 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
 FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
 FF Plugin: @microsoft.com/GENUINE - disabled No File
 FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
 FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
 FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
 FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
 FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
 FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
 FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
 FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
 FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
 FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Markus\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Markus\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Markus\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Markus\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] C:\Program Files (x86)\McAfee\SiteAdvisor
 FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor
 FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] C:\Program Files (x86)\Common Files\McAfee\SystemCore
 FF Extension: McAfee ScriptScan for Firefox - C:\Program Files (x86)\Common Files\McAfee\SystemCore
 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
 Chrome:
 =======
 CHR HomePage: hxxp://www.bsmparty.de/
 CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
 CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
 CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
 CHR Plugin: (Native Client) - C:\Users\Markus\AppData\Local\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
 CHR Plugin: (Chrome PDF Viewer) - C:\Users\Markus\AppData\Local\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
 CHR Plugin: (Shockwave Flash) - C:\Users\Markus\AppData\Local\Google\Chrome\Application\29.0.1547.57\gcswf32.dll No File
 CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
 CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
 CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
 CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
 CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
 CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
 CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
 CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll ()
 CHR Extension: (YouTube) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
 CHR Extension: (Google Search) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
 CHR Extension: (SiteAdvisor) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.2.1341_1
 CHR Extension: (Chrome In-App Payments service) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
 CHR Extension: (Gmail) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
 CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx
 
 ==================== Services (Whitelisted) =================
 
 R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-02] (Akamai Technologies, Inc.)
 R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG)
 R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG)
 R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-20] (Avira Operations GmbH & Co. KG)
 R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
 R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [502064 2012-08-23] (McAfee, Inc.)
 S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199304 2012-05-25] (McAfee, Inc.)
 R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [210616 2012-05-25] (McAfee, Inc.)
 R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [162224 2012-05-25] (McAfee, Inc.)
 R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
 R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2010-11-12] (NTI Corporation)
 
 ==================== Drivers (Whitelisted) ====================
 
 R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-03] (Avira Operations GmbH & Co. KG)
 R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG)
 R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-06] (Avira Operations GmbH & Co. KG)
 R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [65264 2012-02-22] (McAfee, Inc.)
 R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [160792 2012-02-22] (McAfee, Inc.)
 R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [229528 2012-02-22] (McAfee, Inc.)
 R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [487296 2012-02-22] (McAfee, Inc.)
 R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [647208 2012-02-22] (McAfee, Inc.)
 R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75936 2012-02-22] (McAfee, Inc.)
 S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [100912 2012-02-22] (McAfee, Inc.)
 R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [289664 2012-02-22] (McAfee, Inc.)
 U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
 S3 catchme; \??\C:\ComboFix\catchme.sys [x]
 S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
 U3 mfeavfk01; No ImagePath
 
 ==================== NetSvcs (Whitelisted) ===================
 
 
 ==================== One Month Created Files and Folders ========
 
 2013-09-03 17:29 - 2013-09-03 17:29 - 00001572 _____ C:\Users\Markus\Desktop\JRT.txt
 2013-09-03 17:22 - 2013-09-03 17:22 - 00000000 ____D C:\Windows\ERUNT
 2013-09-03 17:19 - 2013-09-03 17:19 - 01028757 _____ (Thisisu) C:\Users\Markus\Desktop\JRT.exe
 2013-09-03 17:05 - 2013-09-03 17:08 - 00000000 ____D C:\AdwCleaner
 2013-09-03 17:03 - 2013-09-03 17:04 - 01037134 _____ C:\Users\Markus\Downloads\adwcleaner.exe
 2013-09-03 16:43 - 2013-09-03 16:43 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Malwarebytes
 2013-09-03 16:42 - 2013-09-03 16:42 - 00000843 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 2013-09-03 16:42 - 2013-09-03 16:42 - 00000000 ____D C:\ProgramData\Malwarebytes
 2013-09-03 16:42 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
 2013-09-03 16:34 - 2013-09-03 16:38 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Markus\Downloads\mbam-setup-1.75.0.1300.exe
 2013-09-03 11:59 - 2013-09-03 11:59 - 00024229 _____ C:\ComboFix.txt
 2013-09-03 11:29 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
 2013-09-03 11:29 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
 2013-09-03 11:29 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
 2013-09-03 11:27 - 2013-09-03 11:59 - 00000000 ____D C:\Qoobox
 2013-09-03 11:26 - 2013-09-03 11:54 - 00000000 ____D C:\Windows\erdnt
 2013-09-03 11:10 - 2013-09-03 11:12 - 05119472 ____R (Swearware) C:\Users\Markus\Desktop\ComboFix.exe
 2013-09-02 22:32 - 2013-09-02 22:48 - 00040762 _____ C:\Users\Markus\Downloads\FRST.txt
 2013-09-02 22:31 - 2013-09-02 22:32 - 00063148 _____ C:\Users\Markus\Downloads\Addition.txt
 2013-09-02 22:28 - 2013-09-02 22:28 - 00000000 ____D C:\FRST
 2013-08-20 00:30 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
 2013-08-20 00:30 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
 2013-08-20 00:30 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
 2013-08-20 00:30 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
 2013-08-20 00:30 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
 2013-08-20 00:30 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
 2013-08-20 00:30 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
 2013-08-20 00:30 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
 2013-08-20 00:30 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
 2013-08-20 00:30 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
 2013-08-20 00:30 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
 2013-08-20 00:30 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
 2013-08-19 21:21 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
 2013-08-19 21:21 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
 2013-08-19 21:21 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
 2013-08-19 21:21 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
 2013-08-19 21:21 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
 2013-08-19 21:21 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
 2013-08-19 21:21 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
 2013-08-19 21:21 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
 2013-08-19 21:16 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
 2013-08-19 21:16 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
 2013-08-19 21:11 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
 2013-08-19 21:11 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
 2013-08-19 21:11 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
 2013-08-19 21:11 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
 2013-08-19 21:11 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
 2013-08-19 21:11 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
 
 ==================== One Month Modified Files and Folders =======
 
 2013-09-03 17:36 - 2013-09-03 17:35 - 01950474 _____ (Farbar) C:\Users\Markus\Desktop\FRST64.exe
 2013-09-03 17:29 - 2013-09-03 17:29 - 00001572 _____ C:\Users\Markus\Desktop\JRT.txt
 2013-09-03 17:28 - 2011-04-12 19:52 - 01282876 _____ C:\Windows\WindowsUpdate.log
 2013-09-03 17:22 - 2013-09-03 17:22 - 00000000 ____D C:\Windows\ERUNT
 2013-09-03 17:19 - 2013-09-03 17:19 - 01028757 _____ (Thisisu) C:\Users\Markus\Desktop\JRT.exe
 2013-09-03 17:17 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
 2013-09-03 17:17 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
 2013-09-03 17:15 - 2011-07-14 20:26 - 00000000 ____D C:\ProgramData\clear.fi
 2013-09-03 17:13 - 2012-03-03 16:09 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
 2013-09-03 17:10 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
 2013-09-03 17:10 - 2009-07-14 06:51 - 00114119 _____ C:\Windows\setupact.log
 2013-09-03 17:08 - 2013-09-03 17:05 - 00000000 ____D C:\AdwCleaner
 2013-09-03 17:04 - 2013-09-03 17:03 - 01037134 _____ C:\Users\Markus\Downloads\adwcleaner.exe
 2013-09-03 17:00 - 2011-12-10 16:14 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-585079726-1089566547-995126460-1001UA.job
 2013-09-03 16:57 - 2011-04-12 19:49 - 00545902 _____ C:\Windows\PFRO.log
 2013-09-03 16:49 - 2013-03-02 23:44 - 00000932 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-585079726-1089566547-995126460-1001UA.job
 2013-09-03 16:47 - 2012-03-03 16:09 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
 2013-09-03 16:43 - 2013-09-03 16:43 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Malwarebytes
 2013-09-03 16:42 - 2013-09-03 16:42 - 00000843 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 2013-09-03 16:42 - 2013-09-03 16:42 - 00000000 ____D C:\ProgramData\Malwarebytes
 2013-09-03 16:42 - 2012-08-03 18:11 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
 2013-09-03 16:42 - 2012-05-13 09:06 - 00000000 ____D C:\Download
 2013-09-03 16:38 - 2013-09-03 16:34 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Markus\Downloads\mbam-setup-1.75.0.1300.exe
 2013-09-03 11:59 - 2013-09-03 11:59 - 00024229 _____ C:\ComboFix.txt
 2013-09-03 11:59 - 2013-09-03 11:27 - 00000000 ____D C:\Qoobox
 2013-09-03 11:54 - 2013-09-03 11:26 - 00000000 ____D C:\Windows\erdnt
 2013-09-03 11:45 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
 2013-09-03 11:12 - 2013-09-03 11:10 - 05119472 ____R (Swearware) C:\Users\Markus\Desktop\ComboFix.exe
 2013-09-03 11:06 - 2013-06-14 15:35 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
 2013-09-02 22:49 - 2013-03-02 23:44 - 00000910 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-585079726-1089566547-995126460-1001Core.job
 2013-09-02 22:48 - 2013-09-02 22:32 - 00040762 _____ C:\Users\Markus\Downloads\FRST.txt
 2013-09-02 22:32 - 2013-09-02 22:31 - 00063148 _____ C:\Users\Markus\Downloads\Addition.txt
 2013-09-02 22:28 - 2013-09-02 22:28 - 00000000 ____D C:\FRST
 2013-09-01 10:40 - 2011-10-09 13:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
 2013-08-28 14:21 - 2011-07-17 20:42 - 07870976 ___SH C:\Users\Markus\Desktop\Thumbs.db
 2013-08-28 13:44 - 2011-08-28 11:20 - 00000000 ___RD C:\Program Files (x86)\Skype
 2013-08-28 13:44 - 2011-08-28 11:20 - 00000000 ____D C:\ProgramData\Skype
 2013-08-28 13:43 - 2011-08-28 11:20 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Skype
 2013-08-24 16:21 - 2011-07-17 20:25 - 00000000 ___RD C:\Users\Markus\Desktop\diverses
 2013-08-24 14:59 - 2011-02-22 15:27 - 00000000 ____D C:\Program Files\mcafee
 2013-08-22 14:57 - 2012-08-03 18:11 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
 2013-08-22 14:57 - 2012-08-03 18:11 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
 2013-08-22 14:57 - 2012-03-03 16:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
 2013-08-20 19:00 - 2011-12-10 16:14 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-585079726-1089566547-995126460-1001Core.job
 2013-08-20 10:26 - 2013-06-14 15:40 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
 2013-08-20 10:26 - 2013-06-14 15:35 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
 2013-08-20 00:28 - 2011-04-13 05:43 - 00654400 _____ C:\Windows\system32\perfh007.dat
 2013-08-20 00:28 - 2011-04-13 05:43 - 00130240 _____ C:\Windows\system32\perfc007.dat
 2013-08-20 00:28 - 2009-07-14 07:13 - 01520734 _____ C:\Windows\system32\PerfStringBackup.INI
 2013-08-09 23:56 - 2012-02-29 19:45 - 00000000 ____D C:\Users\Markus\Desktop\schule
 
 Files to move or delete:
 ====================
 C:\Users\Markus\jagex_cl_runescape_LIVE.dat
 C:\Users\Markus\jagex_runescape_preferences.dat
 C:\Users\Markus\jagex_runescape_preferences2.dat
 C:\Users\Markus\AppData\Local\Temp\Quarantine.exe
 C:\Users\Markus\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
 C:\Users\Markus\AppData\Local\Temp\clear.fiClient\cabarc.exe
 
 ==================== Bamital & volsnap Check =================
 
 C:\Windows\System32\winlogon.exe => MD5 is legit
 C:\Windows\System32\wininit.exe => MD5 is legit
 C:\Windows\SysWOW64\wininit.exe => MD5 is legit
 C:\Windows\explorer.exe => MD5 is legit
 C:\Windows\SysWOW64\explorer.exe => MD5 is legit
 C:\Windows\System32\svchost.exe => MD5 is legit
 C:\Windows\SysWOW64\svchost.exe => MD5 is legit
 C:\Windows\System32\services.exe => MD5 is legit
 C:\Windows\System32\User32.dll => MD5 is legit
 C:\Windows\SysWOW64\User32.dll => MD5 is legit
 C:\Windows\System32\userinit.exe => MD5 is legit
 C:\Windows\SysWOW64\userinit.exe => MD5 is legit
 C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
 LastRegBack: 2013-08-20 18:28
 
 ==================== End Of Log ============================
 --- --- ---  
--- --- ---  
--- --- ---   
FRST Logfile:  
FRST Logfile:   Code: 
 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2013 01Ran by Markus (administrator) on MARKUS-PC on 03-09-2013 17:37:21
 Running from C:\Users\Markus\Desktop
 Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
 Internet Explorer Version 10
 Boot Mode: Normal
 
 ==================== Processes (Whitelisted) =================
 
 (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
 (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
 (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
 (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
 (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
 (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
 (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
 (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
 (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
 (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
 (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
 (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
 (Intel Corporation) C:\Windows\System32\igfxtray.exe
 (Intel Corporation) C:\Windows\System32\hkcmd.exe
 (Intel Corporation) C:\Windows\System32\igfxpers.exe
 (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
 (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
 (Akamai Technologies, Inc.) C:\Users\Markus\AppData\Local\Akamai\netsession_win.exe
 (Intel Corporation) C:\Windows\system32\igfxext.exe
 (Akamai Technologies, Inc.) C:\Users\Markus\AppData\Local\Akamai\netsession_win.exe
 () C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
 (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe
 (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
 (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
 (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
 (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
 (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
 (CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
 (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
 (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
 (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
 (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
 (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
 (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
 (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
 (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
 (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
 (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
 (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
 (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
 (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
 (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe
 
 ==================== Registry (Whitelisted) ==================
 
 HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11725928 2010-12-23] (Realtek Semiconductor)
 HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2186856 2010-12-10] (Realtek Semiconductor)
 HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-10-08] ()
 HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
 HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860040 2011-01-06] (Acer Incorporated)
 HKLM\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\ootag.exe [13856 2010-02-23] (Microsoft)
 HKLM\...\Policies\Explorer: [NoDrives] 0
 HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Markus\AppData\Local\Akamai\netsession_win.exe [4480768 2013-01-26] (Akamai Technologies, Inc.)
 HKCU\...\Run: [KPeerNexonEU] - C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [438272 2012-05-13] (NEXON Inc.)
 HKCU\...\Run: [EADM] - C:\Users\Public\Desktop\Noten\Origin\Origin.exe [3549528 2013-07-31] (Electronic Arts)
 HKCU\...\Run: [Facebook Update] - C:\Users\Markus\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-03-02] (Facebook Inc.)
 HKCU\...\Policies\Explorer: [NoDrives] 0
 HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-14] (Intel Corporation)
 HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [1675160 2012-03-21] (McAfee, Inc.)
 HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-28] (Egis Technology Inc.)
 HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-18] (Egis Technology Inc.)
 HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-18] (Egis Technology Inc.)
 HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
 HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
 HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296768 2010-11-12] (NTI Corporation)
 HKLM-x32\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft)
 HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
 HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1078352 2011-02-24] (Dritek System Inc.)
 HKLM-x32\...\Run: [MDS_Menu] - C:\Program Files (x86)\Acer\clear.fi\MediaEspresso\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
 HKLM-x32\...\Run: [ArcadeMovieService] - C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2010-12-09] (CyberLink Corp.)
 HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
 HKLM-x32\...\Run: [] -  [x]
 HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
 HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG)
 HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
 HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
 AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-03] (NVIDIA Corporation)
 AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-03] (NVIDIA Corporation)
 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
 ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
 ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
 Startup: C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
 ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
 
 ==================== Internet (Whitelisted) ====================
 
 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
 URLSearchHook: (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} -  No File
 URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
 SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL No File
 BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20130901104020.dll (McAfee, Inc.)
 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
 BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
 BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
 BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
 BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
 BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll ()
 BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
 BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20130901104020.dll (McAfee, Inc.)
 BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
 BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
 BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
 BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
 BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
 BHO-x32: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
 BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
 Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
 Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
 Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
 Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
 DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
 Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
 Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
 Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
 Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.)
 Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.)
 Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
 
 FireFox:
 ========
 FF ProfilePath: C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\guamnss2.default
 FF DefaultSearchEngine: Ask.com Search
 FF SearchEngineOrder.1: Ask.com Search
 FF SelectedSearchEngine: Ask.com Search
 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
 FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
 FF Plugin: @microsoft.com/GENUINE - disabled No File
 FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
 FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
 FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
 FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
 FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
 FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
 FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
 FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
 FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
 FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Markus\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Markus\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Markus\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Markus\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] C:\Program Files (x86)\McAfee\SiteAdvisor
 FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor
 FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] C:\Program Files (x86)\Common Files\McAfee\SystemCore
 FF Extension: McAfee ScriptScan for Firefox - C:\Program Files (x86)\Common Files\McAfee\SystemCore
 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
 Chrome:
 =======
 CHR HomePage: hxxp://www.bsmparty.de/
 CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
 CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
 CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
 CHR Plugin: (Native Client) - C:\Users\Markus\AppData\Local\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
 CHR Plugin: (Chrome PDF Viewer) - C:\Users\Markus\AppData\Local\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
 CHR Plugin: (Shockwave Flash) - C:\Users\Markus\AppData\Local\Google\Chrome\Application\29.0.1547.57\gcswf32.dll No File
 CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
 CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
 CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
 CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
 CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
 CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
 CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
 CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll ()
 CHR Extension: (YouTube) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
 CHR Extension: (Google Search) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
 CHR Extension: (SiteAdvisor) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.2.1341_1
 CHR Extension: (Chrome In-App Payments service) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
 CHR Extension: (Gmail) - C:\Users\Markus\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
 CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx
 
 ==================== Services (Whitelisted) =================
 
 R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-02] (Akamai Technologies, Inc.)
 R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG)
 R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG)
 R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-20] (Avira Operations GmbH & Co. KG)
 R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
 R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [502064 2012-08-23] (McAfee, Inc.)
 S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199304 2012-05-25] (McAfee, Inc.)
 R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [210616 2012-05-25] (McAfee, Inc.)
 R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [162224 2012-05-25] (McAfee, Inc.)
 R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
 R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
 R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2010-11-12] (NTI Corporation)
 
 ==================== Drivers (Whitelisted) ====================
 
 R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-03] (Avira Operations GmbH & Co. KG)
 R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG)
 R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-06] (Avira Operations GmbH & Co. KG)
 R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [65264 2012-02-22] (McAfee, Inc.)
 R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [160792 2012-02-22] (McAfee, Inc.)
 R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [229528 2012-02-22] (McAfee, Inc.)
 R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [487296 2012-02-22] (McAfee, Inc.)
 R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [647208 2012-02-22] (McAfee, Inc.)
 R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75936 2012-02-22] (McAfee, Inc.)
 S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [100912 2012-02-22] (McAfee, Inc.)
 R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [289664 2012-02-22] (McAfee, Inc.)
 U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
 S3 catchme; \??\C:\ComboFix\catchme.sys [x]
 S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
 U3 mfeavfk01; No ImagePath
 
 ==================== NetSvcs (Whitelisted) ===================
 
 
 ==================== One Month Created Files and Folders ========
 
 2013-09-03 17:29 - 2013-09-03 17:29 - 00001572 _____ C:\Users\Markus\Desktop\JRT.txt
 2013-09-03 17:22 - 2013-09-03 17:22 - 00000000 ____D C:\Windows\ERUNT
 2013-09-03 17:19 - 2013-09-03 17:19 - 01028757 _____ (Thisisu) C:\Users\Markus\Desktop\JRT.exe
 2013-09-03 17:05 - 2013-09-03 17:08 - 00000000 ____D C:\AdwCleaner
 2013-09-03 17:03 - 2013-09-03 17:04 - 01037134 _____ C:\Users\Markus\Downloads\adwcleaner.exe
 2013-09-03 16:43 - 2013-09-03 16:43 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Malwarebytes
 2013-09-03 16:42 - 2013-09-03 16:42 - 00000843 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 2013-09-03 16:42 - 2013-09-03 16:42 - 00000000 ____D C:\ProgramData\Malwarebytes
 2013-09-03 16:42 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
 2013-09-03 16:34 - 2013-09-03 16:38 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Markus\Downloads\mbam-setup-1.75.0.1300.exe
 2013-09-03 11:59 - 2013-09-03 11:59 - 00024229 _____ C:\ComboFix.txt
 2013-09-03 11:29 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
 2013-09-03 11:29 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
 2013-09-03 11:29 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
 2013-09-03 11:29 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
 2013-09-03 11:27 - 2013-09-03 11:59 - 00000000 ____D C:\Qoobox
 2013-09-03 11:26 - 2013-09-03 11:54 - 00000000 ____D C:\Windows\erdnt
 2013-09-03 11:10 - 2013-09-03 11:12 - 05119472 ____R (Swearware) C:\Users\Markus\Desktop\ComboFix.exe
 2013-09-02 22:32 - 2013-09-02 22:48 - 00040762 _____ C:\Users\Markus\Downloads\FRST.txt
 2013-09-02 22:31 - 2013-09-02 22:32 - 00063148 _____ C:\Users\Markus\Downloads\Addition.txt
 2013-09-02 22:28 - 2013-09-02 22:28 - 00000000 ____D C:\FRST
 2013-08-20 00:30 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
 2013-08-20 00:30 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
 2013-08-20 00:30 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
 2013-08-20 00:30 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
 2013-08-20 00:30 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
 2013-08-20 00:30 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
 2013-08-20 00:30 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
 2013-08-20 00:30 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
 2013-08-20 00:30 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
 2013-08-20 00:30 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
 2013-08-20 00:30 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
 2013-08-20 00:30 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
 2013-08-20 00:30 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
 2013-08-20 00:30 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
 2013-08-19 21:21 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
 2013-08-19 21:21 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
 2013-08-19 21:21 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
 2013-08-19 21:21 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
 2013-08-19 21:21 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
 2013-08-19 21:21 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
 2013-08-19 21:21 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
 2013-08-19 21:21 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
 2013-08-19 21:16 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
 2013-08-19 21:16 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
 2013-08-19 21:11 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
 2013-08-19 21:11 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
 2013-08-19 21:11 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
 2013-08-19 21:11 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
 2013-08-19 21:11 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
 2013-08-19 21:11 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
 
 ==================== One Month Modified Files and Folders =======
 
 2013-09-03 17:36 - 2013-09-03 17:35 - 01950474 _____ (Farbar) C:\Users\Markus\Desktop\FRST64.exe
 2013-09-03 17:29 - 2013-09-03 17:29 - 00001572 _____ C:\Users\Markus\Desktop\JRT.txt
 2013-09-03 17:28 - 2011-04-12 19:52 - 01282876 _____ C:\Windows\WindowsUpdate.log
 2013-09-03 17:22 - 2013-09-03 17:22 - 00000000 ____D C:\Windows\ERUNT
 2013-09-03 17:19 - 2013-09-03 17:19 - 01028757 _____ (Thisisu) C:\Users\Markus\Desktop\JRT.exe
 2013-09-03 17:17 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
 2013-09-03 17:17 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
 2013-09-03 17:15 - 2011-07-14 20:26 - 00000000 ____D C:\ProgramData\clear.fi
 2013-09-03 17:13 - 2012-03-03 16:09 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
 2013-09-03 17:10 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
 2013-09-03 17:10 - 2009-07-14 06:51 - 00114119 _____ C:\Windows\setupact.log
 2013-09-03 17:08 - 2013-09-03 17:05 - 00000000 ____D C:\AdwCleaner
 2013-09-03 17:04 - 2013-09-03 17:03 - 01037134 _____ C:\Users\Markus\Downloads\adwcleaner.exe
 2013-09-03 17:00 - 2011-12-10 16:14 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-585079726-1089566547-995126460-1001UA.job
 2013-09-03 16:57 - 2011-04-12 19:49 - 00545902 _____ C:\Windows\PFRO.log
 2013-09-03 16:49 - 2013-03-02 23:44 - 00000932 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-585079726-1089566547-995126460-1001UA.job
 2013-09-03 16:47 - 2012-03-03 16:09 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
 2013-09-03 16:43 - 2013-09-03 16:43 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Malwarebytes
 2013-09-03 16:42 - 2013-09-03 16:42 - 00000843 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 2013-09-03 16:42 - 2013-09-03 16:42 - 00000000 ____D C:\ProgramData\Malwarebytes
 2013-09-03 16:42 - 2012-08-03 18:11 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
 2013-09-03 16:42 - 2012-05-13 09:06 - 00000000 ____D C:\Download
 2013-09-03 16:38 - 2013-09-03 16:34 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Markus\Downloads\mbam-setup-1.75.0.1300.exe
 2013-09-03 11:59 - 2013-09-03 11:59 - 00024229 _____ C:\ComboFix.txt
 2013-09-03 11:59 - 2013-09-03 11:27 - 00000000 ____D C:\Qoobox
 2013-09-03 11:54 - 2013-09-03 11:26 - 00000000 ____D C:\Windows\erdnt
 2013-09-03 11:45 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
 2013-09-03 11:12 - 2013-09-03 11:10 - 05119472 ____R (Swearware) C:\Users\Markus\Desktop\ComboFix.exe
 2013-09-03 11:06 - 2013-06-14 15:35 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
 2013-09-02 22:49 - 2013-03-02 23:44 - 00000910 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-585079726-1089566547-995126460-1001Core.job
 2013-09-02 22:48 - 2013-09-02 22:32 - 00040762 _____ C:\Users\Markus\Downloads\FRST.txt
 2013-09-02 22:32 - 2013-09-02 22:31 - 00063148 _____ C:\Users\Markus\Downloads\Addition.txt
 2013-09-02 22:28 - 2013-09-02 22:28 - 00000000 ____D C:\FRST
 2013-09-01 10:40 - 2011-10-09 13:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
 2013-08-28 14:21 - 2011-07-17 20:42 - 07870976 ___SH C:\Users\Markus\Desktop\Thumbs.db
 2013-08-28 13:44 - 2011-08-28 11:20 - 00000000 ___RD C:\Program Files (x86)\Skype
 2013-08-28 13:44 - 2011-08-28 11:20 - 00000000 ____D C:\ProgramData\Skype
 2013-08-28 13:43 - 2011-08-28 11:20 - 00000000 ____D C:\Users\Markus\AppData\Roaming\Skype
 2013-08-24 16:21 - 2011-07-17 20:25 - 00000000 ___RD C:\Users\Markus\Desktop\diverses
 2013-08-24 14:59 - 2011-02-22 15:27 - 00000000 ____D C:\Program Files\mcafee
 2013-08-22 14:57 - 2012-08-03 18:11 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
 2013-08-22 14:57 - 2012-08-03 18:11 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
 2013-08-22 14:57 - 2012-03-03 16:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
 2013-08-20 19:00 - 2011-12-10 16:14 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-585079726-1089566547-995126460-1001Core.job
 2013-08-20 10:26 - 2013-06-14 15:40 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
 2013-08-20 10:26 - 2013-06-14 15:35 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
 2013-08-20 00:28 - 2011-04-13 05:43 - 00654400 _____ C:\Windows\system32\perfh007.dat
 2013-08-20 00:28 - 2011-04-13 05:43 - 00130240 _____ C:\Windows\system32\perfc007.dat
 2013-08-20 00:28 - 2009-07-14 07:13 - 01520734 _____ C:\Windows\system32\PerfStringBackup.INI
 2013-08-09 23:56 - 2012-02-29 19:45 - 00000000 ____D C:\Users\Markus\Desktop\schule
 
 Files to move or delete:
 ====================
 C:\Users\Markus\jagex_cl_runescape_LIVE.dat
 C:\Users\Markus\jagex_runescape_preferences.dat
 C:\Users\Markus\jagex_runescape_preferences2.dat
 C:\Users\Markus\AppData\Local\Temp\Quarantine.exe
 C:\Users\Markus\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
 C:\Users\Markus\AppData\Local\Temp\clear.fiClient\cabarc.exe
 
 ==================== Bamital & volsnap Check =================
 
 C:\Windows\System32\winlogon.exe => MD5 is legit
 C:\Windows\System32\wininit.exe => MD5 is legit
 C:\Windows\SysWOW64\wininit.exe => MD5 is legit
 C:\Windows\explorer.exe => MD5 is legit
 C:\Windows\SysWOW64\explorer.exe => MD5 is legit
 C:\Windows\System32\svchost.exe => MD5 is legit
 C:\Windows\SysWOW64\svchost.exe => MD5 is legit
 C:\Windows\System32\services.exe => MD5 is legit
 C:\Windows\System32\User32.dll => MD5 is legit
 C:\Windows\SysWOW64\User32.dll => MD5 is legit
 C:\Windows\System32\userinit.exe => MD5 is legit
 C:\Windows\SysWOW64\userinit.exe => MD5 is legit
 C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
 LastRegBack: 2013-08-20 18:28
 
 ==================== End Of Log ============================
 --- --- ---  
--- --- ---  |