Hungry Ghost | 24.08.2013 20:48 | Hallo schrauber,
danke für deine weiteren Anweisungen.
Habe die Scans durchgeführt, hier sind die neuen Logfiles:
---------------------------------------------------------------------------------------
1. MALWAREBYTES ANTI-MALWARE-Logfile:
--------------------------------------------------------------------------------------- Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.24.04
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19453
Sebastian :: SEBASTIAN-PC [Administrator]
Schutz: Deaktiviert
24/08/2013 19:45:08
mbam-log-2013-08-24 (19-45-08).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 262290
Laufzeit: 16 Minute(n), 35 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 1
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 1
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0T1M2Q2W -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 2
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=b3a3c66c-34eb-415e-b9af-6d6823522c70&searchtype=ds&q={searchTerms}&installDate=05/04/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=b3a3c66c-34eb-415e-b9af-6d6823522c70&searchtype=ds&q={searchTerms}&installDate=05/04/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
C:\Users\Sebastian\AppData\Local\Temp\CDBurnerXP-updates\cdbxp_setup_4.5.2.4214.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
---------------------------------------------------------------------------------------
2. ADW CLEANER-Logfile:
--------------------------------------------------------------------------------------- Code:
# AdwCleaner v3.001 - Report created 24/08/2013 at 20:44:04
# Updated 24/08/2013 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Sebastian - SEBASTIAN-PC
# Running from : C:\Users\Sebastian\Desktop\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Sebastian\AppData\Local\ext_piccshare
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Common\LuaRT
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Intermediate
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\SCheck
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\SSync
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{AA994882-F391-4D2E-806F-8908DA4814ED}
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\afurladvisor@anchorfree.com
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\engine@conduit.com
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\engine@plasmoo.com
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\plugin@yontoo.com
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\quickstores@quickstores.de
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\search@searchsettings.com
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\software@loadtubes.com
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\support@predictad.com
Folder Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\toolbar@ask.com
Folder Deleted : C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec
File Deleted : C:\END
File Deleted : C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk
File Deleted : C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\QuickStores.url
File Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\searchplugins\plasmoo.xml
File Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\searchplugins\Web Search.xml
File Deleted : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\user.js
File Deleted : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
File Deleted : C:\Windows\System32\Tasks\YourFile Update
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [dnshelp@dnshelp.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\defdhglnppeioeflggkmglipcecffkhk
Key Deleted : HKCU\Software\Google\Chrome\Extensions\docfnddcclkgokdfpnmngpiliiachclb
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF98CF31-9EF6-49FA-BCF2-719BFC14AB96}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CF98CF31-9EF6-49FA-BCF2-719BFC14AB96}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile Update
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{337E4D11-A745-4B1E-AA58-0F1EF57884CB}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{337E4D11-A745-4B1E-AA58-0F1EF57884CB}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Intermediate]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [scheck]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ssync]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\AutocompletePro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.Band
Key Deleted : HKLM\SOFTWARE\Classes\wtb.Band.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.NotificationSource
Key Deleted : HKLM\SOFTWARE\Classes\wtb.NotificationSource.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Key Deleted : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Key Deleted : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0033426.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0033426.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0033426.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0033426.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{0C58B7D1-D415-492B-A149-E976156BD3B8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9E6E73E7-C370-4607-9AB5-CD141A139175}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{507BA2C7-4851-4D96-8BD5-650668F922AC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B424109-6F99-4306-8F2B-0B2BB1C8C415}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C0EB0A9-265F-4D9D-AF96-0EF2403A73E8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9DF046E1-80F7-43E0-80C0-0AD696799C8F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D0FD0502-5878-441D-A3C0-9A4531C526CB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3E46008-1902-41A7-91C7-26EC6E0B66D2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{40C3CC16-7269-4B32-9531-17F2950FB06F}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks []
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKCU\Software\AutocompleteProBHO
Key Deleted : HKCU\Software\Ciuvo
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\httogroup
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\performersoft llc
Key Deleted : HKCU\Software\piccshare
Key Deleted : HKCU\Software\ProtectedSearch
Key Deleted : HKCU\Software\Search Settings
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Key Deleted : HKCU\Software\AppDataLow\Software\pdfforge
Key Deleted : HKCU\Software\AppDataLow\Software\Plus-HD-2.3
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\Winload
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\DVDVideoSoftTB
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\pdfforge
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\Plus-HD-2.3
Key Deleted : HKLM\Software\Search Settings
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\Software\YourFileDownloader
Key Deleted : HKLM\Software\Winload
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4EF8BE6A-899C-4196-94E7-297C5F7A203E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4EF8BE6A-899C-4196-94E7-297C5F7A203E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{83AA2913-C123-4146-85BD-AD8F93971D39}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{D08D9F98-1C78-4704-87E6-368B0023D831}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AutocompletePro3_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DesktopIconAmazon
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\loadtbs-3.0
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\piccshare
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Plus-HD-2.3
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Protected Search_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\QuickStores-Toolbar_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\YourFileDownloader
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winload Toolbar
Product Deleted : Ask Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.19453
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
-\\ Mozilla Firefox v4.0 (de)
[ File : C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\prefs.js ]
Line Deleted : user_pref("CT2269050..clientLogIsEnabled", true);
Line Deleted : user_pref("CT2269050..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2269050..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2269050.CTID", "CT2269050");
Line Deleted : user_pref("CT2269050.CurrentServerDate", "25-1-2011");
Line Deleted : user_pref("CT2269050.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2269050.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2269050.EMailNotifierPollDate", "Tue Jan 25 2011 10:45:37 GMT+0100");
Line Deleted : user_pref("CT2269050.FirstServerDate", "17-12-2010");
Line Deleted : user_pref("CT2269050.FirstTime", true);
Line Deleted : user_pref("CT2269050.FirstTimeFF3", true);
Line Deleted : user_pref("CT2269050.FirstTimeSettingsDone", true);
Line Deleted : user_pref("CT2269050.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2269050.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2269050.HasUserGlobalKeys", true);
Line Deleted : user_pref("CT2269050.Initialize", true);
Line Deleted : user_pref("CT2269050.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2269050.InstallationAndCookieDataSentCount", 3);
Line Deleted : user_pref("CT2269050.InstallationType", "UnknownIntegration");
Line Deleted : user_pref("CT2269050.InstalledDate", "Fri Dec 17 2010 13:39:46 GMT+0100");
Line Deleted : user_pref("CT2269050.InvalidateCache", false);
Line Deleted : user_pref("CT2269050.IsGrouping", false);
Line Deleted : user_pref("CT2269050.IsMulticommunity", false);
Line Deleted : user_pref("CT2269050.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2269050.IsOpenUninstallPage", false);
Line Deleted : user_pref("CT2269050.LanguagePackLastCheckTime", "Mon Jan 24 2011 21:42:35 GMT+0100");
Line Deleted : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2269050.LastLogin_2.7.2.0", "Wed Jan 19 2011 21:36:32 GMT+0100");
Line Deleted : user_pref("CT2269050.LastLogin_3.2.2.0", "Tue Jan 25 2011 10:45:40 GMT+0100");
Line Deleted : user_pref("CT2269050.LatestVersion", "3.2.5.2");
Line Deleted : user_pref("CT2269050.Locale", "en");
Line Deleted : user_pref("CT2269050.LoginCache", 4);
Line Deleted : user_pref("CT2269050.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2269050.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2269050.RadioIsPodcast", false);
Line Deleted : user_pref("CT2269050.RadioLastCheckTime", "Mon Jan 24 2011 21:42:36 GMT+0100");
Line Deleted : user_pref("CT2269050.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
Line Deleted : user_pref("CT2269050.RadioMediaID", "12473383");
Line Deleted : user_pref("CT2269050.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383");
Line Deleted : user_pref("CT2269050.RadioStationName", "Hotmix%20108");
Line Deleted : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082");
Line Deleted : user_pref("CT2269050.SavedHomepage", "hxxp://search.orbitdownloader.com");
Line Deleted : user_pref("CT2269050.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2269050&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2269050.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&q=");
Line Deleted : user_pref("CT2269050.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Mon Jan 24 2011 21:42:38 GMT+0100");
Line Deleted : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2269050.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2269050.ServiceMapLastCheckTime", "Wed Nov 14 2012 18:29:14 GMT+0100");
Line Deleted : user_pref("CT2269050.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2269050.SettingsLastCheckTime", "Tue Jan 25 2011 10:45:35 GMT+0100");
Line Deleted : user_pref("CT2269050.SettingsLastUpdate", "1295944639");
Line Deleted : user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Tue Jan 18 2011 20:26:51 GMT+0100");
Line Deleted : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1246790578");
Line Deleted : user_pref("CT2269050.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
Line Deleted : user_pref("CT2269050.UserID", "UN90526340153496352");
Line Deleted : user_pref("CT2269050.WeatherNetwork", "");
Line Deleted : user_pref("CT2269050.WeatherPollDate", "Tue Jan 25 2011 10:45:44 GMT+0100");
Line Deleted : user_pref("CT2269050.WeatherUnit", "C");
Line Deleted : user_pref("CT2269050.alertChannelId", "666138");
Line Deleted : user_pref("CT2269050.clientLogIsEnabled", false);
Line Deleted : user_pref("CT2269050.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2269050.myStuffEnabled", true);
Line Deleted : user_pref("CT2269050.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2269050.testingCtid", "");
Line Deleted : user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Mon Jan 24 2011 21:42:35 GMT+0100");
Line Deleted : user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Mon Jan 24 2011 21:42:35 GMT+0100");
Line Deleted : user_pref("CT2269050.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2319825..clientLogIsEnabled", true);
Line Deleted : user_pref("CT2319825..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2319825..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2319825.CTID", "CT2319825");
Line Deleted : user_pref("CT2319825.CurrentServerDate", "11-4-2011");
Line Deleted : user_pref("CT2319825.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2319825.DialogsGetterLastCheckTime", "Wed Nov 14 2012 18:29:11 GMT+0100");
Line Deleted : user_pref("CT2319825.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2319825.EMailNotifierPollDate", "Wed Nov 14 2012 18:29:07 GMT+0100");
Line Deleted : user_pref("CT2319825.FeedPollDate11908299", "Wed Nov 14 2012 18:29:12 GMT+0100");
Line Deleted : user_pref("CT2319825.FirstServerDate", "23-3-2011");
Line Deleted : user_pref("CT2319825.FirstTime", true);
Line Deleted : user_pref("CT2319825.FirstTimeFF3", true);
Line Deleted : user_pref("CT2319825.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2319825.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2319825.HasUserGlobalKeys", true);
Line Deleted : user_pref("CT2319825.Initialize", true);
Line Deleted : user_pref("CT2319825.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2319825.InstallationAndCookieDataSentCount", 3);
Line Deleted : user_pref("CT2319825.InstalledDate", "Wed Mar 23 2011 10:41:26 GMT+0100");
Line Deleted : user_pref("CT2319825.InvalidateCache", false);
Line Deleted : user_pref("CT2319825.IsGrouping", false);
Line Deleted : user_pref("CT2319825.IsMulticommunity", false);
Line Deleted : user_pref("CT2319825.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2319825.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2319825.LanguagePackLastCheckTime", "Wed Nov 14 2012 18:29:11 GMT+0100");
Line Deleted : user_pref("CT2319825.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2319825.LastLogin_3.2.2.0", "Mon Apr 11 2011 18:09:46 GMT+0200");
Line Deleted : user_pref("CT2319825.LatestVersion", "3.2.5.2");
Line Deleted : user_pref("CT2319825.Locale", "de");
Line Deleted : user_pref("CT2319825.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2319825.MCDetectTooltipShow", false);
Line Deleted : user_pref("CT2319825.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2319825.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2319825.RadioIsPodcast", false);
Line Deleted : user_pref("CT2319825.RadioLastCheckTime", "Wed Nov 14 2012 18:29:11 GMT+0100");
Line Deleted : user_pref("CT2319825.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2319825.RadioLastUpdateServer", "129224641269630000");
Line Deleted : user_pref("CT2319825.RadioMediaID", "11949532");
Line Deleted : user_pref("CT2319825.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2319825.RadioMenuSelectedID", "EBRadioMenu_CT231982511949532");
Line Deleted : user_pref("CT2319825.RadioStationName", "1Live");
Line Deleted : user_pref("CT2319825.RadioStationURL", "hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_einslive_a");
Line Deleted : user_pref("CT2319825.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2319825.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2319825&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2319825.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q=");
Line Deleted : user_pref("CT2319825.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2319825.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2319825.SearchInNewTabLastCheckTime", "Sun Apr 10 2011 20:15:34 GMT+0200");
Line Deleted : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2319825.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2319825.ServiceMapLastCheckTime", "Wed Nov 14 2012 18:29:11 GMT+0100");
Line Deleted : user_pref("CT2319825.SettingsLastCheckTime", "Wed Nov 14 2012 18:29:06 GMT+0100");
Line Deleted : user_pref("CT2319825.SettingsLastUpdate", "1300873232");
Line Deleted : user_pref("CT2319825.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2319825.ThirdPartyComponentsLastCheck", "Mon Nov 05 2012 11:35:02 GMT+0100");
Line Deleted : user_pref("CT2319825.ThirdPartyComponentsLastUpdate", "1255344657");
Line Deleted : user_pref("CT2319825.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2319825.UserID", "UN64505035231747553");
Line Deleted : user_pref("CT2319825.ValidationData_Search", 0);
Line Deleted : user_pref("CT2319825.ValidationData_Toolbar", 2);
Line Deleted : user_pref("CT2319825.WeatherNetwork", "");
Line Deleted : user_pref("CT2319825.WeatherPollDate", "Wed Nov 14 2012 18:29:12 GMT+0100");
Line Deleted : user_pref("CT2319825.WeatherUnit", "C");
Line Deleted : user_pref("CT2319825.alertChannelId", "715912");
Line Deleted : user_pref("CT2319825.backendstorage.id", "35333636373231");
Line Deleted : user_pref("CT2319825.globalFirstTimeInfoLastCheckTime", "Wed Nov 14 2012 18:29:11 GMT+0100");
Line Deleted : user_pref("CT2319825.myStuffEnabled", true);
Line Deleted : user_pref("CT2319825.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2319825.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2319825.testingCtid", "");
Line Deleted : user_pref("CT2319825.toolbarAppMetaDataLastCheckTime", "Wed Nov 14 2012 18:29:11 GMT+0100");
Line Deleted : user_pref("CT2319825.toolbarContextMenuLastCheckTime", "Wed Mar 23 2011 10:41:38 GMT+0100");
Line Deleted : user_pref("CT2319825.usagesFlag", 2);
Line Deleted : user_pref("CT2325506..clientLogIsEnabled", true);
Line Deleted : user_pref("CT2325506..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2325506..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2325506.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2325506.CTID", "CT2325506");
Line Deleted : user_pref("CT2325506.CommunitiesChangesLastCheckTime", "0");
Line Deleted : user_pref("CT2325506.CurrentServerDate", "25-1-2011");
Line Deleted : user_pref("CT2325506.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2325506.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2325506.EMailNotifierPollDate", "Tue Jan 25 2011 10:45:52 GMT+0100");
Line Deleted : user_pref("CT2325506.FeedLastCount128733872087331273", 10);
Line Deleted : user_pref("CT2325506.FeedPollDate128733872087331273", "Tue Jan 25 2011 10:45:54 GMT+0100");
Line Deleted : user_pref("CT2325506.FirstServerDate", "24-1-2011");
Line Deleted : user_pref("CT2325506.FirstTime", true);
Line Deleted : user_pref("CT2325506.FirstTimeFF3", true);
Line Deleted : user_pref("CT2325506.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2325506.GroupingInvalidateCache", false);
Line Deleted : user_pref("CT2325506.GroupingLastCheckTime", "0");
Line Deleted : user_pref("CT2325506.GroupingLastServerUpdateTime", "0");
Line Deleted : user_pref("CT2325506.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2325506.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2325506.HasUserGlobalKeys", true);
Line Deleted : user_pref("CT2325506.Initialize", true);
Line Deleted : user_pref("CT2325506.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2325506.InstallationAndCookieDataSentCount", 3);
Line Deleted : user_pref("CT2325506.InstallationId", "Integrated_CT2325506.exe");
Line Deleted : user_pref("CT2325506.InstallationType", "ConduitIntegration");
Line Deleted : user_pref("CT2325506.InstalledDate", "Mon Jan 24 2011 23:41:40 GMT+0100");
Line Deleted : user_pref("CT2325506.InvalidateCache", false);
Line Deleted : user_pref("CT2325506.IsGrouping", false);
Line Deleted : user_pref("CT2325506.IsMulticommunity", false);
Line Deleted : user_pref("CT2325506.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2325506.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2325506.LanguagePackLastCheckTime", "Mon Jan 24 2011 21:42:56 GMT+0100");
Line Deleted : user_pref("CT2325506.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2325506.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2325506.LastLogin_3.2.2.0", "Tue Jan 25 2011 19:59:18 GMT+0100");
Line Deleted : user_pref("CT2325506.LatestVersion", "3.2.5.2");
Line Deleted : user_pref("CT2325506.Locale", "de");
Line Deleted : user_pref("CT2325506.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2325506.MCDetectTooltipShow", false);
Line Deleted : user_pref("CT2325506.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2325506.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2325506.RadioIsPodcast", false);
Line Deleted : user_pref("CT2325506.RadioLastCheckTime", "Tue Jan 25 2011 10:47:38 GMT+0100");
Line Deleted : user_pref("CT2325506.RadioLastUpdateIPServer", "0");
Line Deleted : user_pref("CT2325506.RadioMediaID", "9962");
Line Deleted : user_pref("CT2325506.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2325506.RadioMenuSelectedID", "EBRadioMenu_CT23255069962");
Line Deleted : user_pref("CT2325506.RadioStationName", "California%20Rock");
Line Deleted : user_pref("CT2325506.RadioStationURL", "hxxp://feedlive.net/california.asx");
Line Deleted : user_pref("CT2325506.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2325506.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2325506&q=");
Line Deleted : user_pref("CT2325506.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2325506.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2325506.SearchInNewTabLastCheckTime", "Mon Jan 24 2011 21:42:53 GMT+0100");
Line Deleted : user_pref("CT2325506.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2325506.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2325506.ServiceMapLastCheckTime", "Mon Jan 24 2011 21:42:39 GMT+0100");
Line Deleted : user_pref("CT2325506.SettingsLastCheckTime", "Tue Jan 25 2011 19:59:14 GMT+0100");
Line Deleted : user_pref("CT2325506.SettingsLastUpdate", "1295944703");
Line Deleted : user_pref("CT2325506.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2325506.ThirdPartyComponentsLastCheck", "Mon Jan 24 2011 21:42:39 GMT+0100");
Line Deleted : user_pref("CT2325506.ThirdPartyComponentsLastUpdate", "1255348257");
Line Deleted : user_pref("CT2325506.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
Line Deleted : user_pref("CT2325506.UserID", "UN93830662005828382");
Line Deleted : user_pref("CT2325506.WeatherNetwork", "");
Line Deleted : user_pref("CT2325506.WeatherPollDate", "Tue Jan 25 2011 10:45:53 GMT+0100");
Line Deleted : user_pref("CT2325506.WeatherUnit", "C");
Line Deleted : user_pref("CT2325506.alertChannelId", "721521");
Line Deleted : user_pref("CT2325506.components.1000034", false);
Line Deleted : user_pref("CT2325506.components.1000082", false);
Line Deleted : user_pref("CT2325506.components.1000234", false);
Line Deleted : user_pref("CT2325506.components.128733871675769250", false);
Line Deleted : user_pref("CT2325506.components.128733871908582040", false);
Line Deleted : user_pref("CT2325506.components.128733872087331273", false);
Line Deleted : user_pref("CT2325506.components.128860923969337817", false);
Line Deleted : user_pref("CT2325506.components.128918569854169144", false);
Line Deleted : user_pref("CT2325506.components.128918573790107246", false);
Line Deleted : user_pref("CT2325506.components.129225522780665764", false);
Line Deleted : user_pref("CT2325506.components.3568429344344734706", false);
Line Deleted : user_pref("CT2325506.myStuffEnabled", true);
Line Deleted : user_pref("CT2325506.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2325506.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2325506.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2325506.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2325506.testingCtid", "");
Line Deleted : user_pref("CT2325506.toolbarAppMetaDataLastCheckTime", "Mon Jan 24 2011 21:42:51 GMT+0100");
Line Deleted : user_pref("CT2325506.toolbarContextMenuLastCheckTime", "Mon Jan 24 2011 21:42:56 GMT+0100");
Line Deleted : user_pref("CT2325506.usagesFlag", 2);
Line Deleted : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "CT2319825");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/715912/711772/DE", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/721521/717372/DE", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", "\"1280150108\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2319825", "\"1282729563\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2325506", "\"1278411263\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=de", "L+tncv4eqt6Qm5T3dzChdA==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "wVmmvqqOMqrv5xct1cJIHg==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=de", "uwY9T5AsudBxjradvWCAOA==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "poKjTfHs0NrVUIalKI8jyg==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=de", "D/tN3YiKFksK+RjZytPhIA==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "Dclc8oo4TTv7+mAkSlUSWg==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=de", "SuMy8xgBA7+FodOxmk9aiQ==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "SuMy8xgBA7+FodOxmk9aiQ==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"634333631231730000\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634303635100000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/2011 5:25:10 PM", "634303635100000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2269050/CT2269050", "\"1295944639\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2319825/CT2319825", "\"1300873232\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2325506/CT2325506", "\"1295944703\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/equalizer_dead.gif", "\"09586ee4e19c81:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/minimize.gif", "\"09586ee4e19c81:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/play.gif", "\"09586ee4e19c81:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/stop.gif", "\"09586ee4e19c81:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/vol.gif", "\"09586ee4e19c81:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"634351849102130000\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634310612473900000\"");
Line Deleted : user_pref("CommunityToolbar.EngineOwner", "CT2325506");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{26647ca4-a2a7-4eac-8a72-761aa9141de7}");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "www.freeware-download.com");
Line Deleted : user_pref("CommunityToolbar.IsEngineShown", false);
Line Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2325506");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{26647ca4-a2a7-4eac-8a72-761aa9141de7}");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "www.freeware-download.com");
Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://plasmoo.com/index.htm?SearchMashine=true&q=");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2269050,CT2325506,ConduitEngine,CT2319825");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2269050,CT2325506,CT2319825");
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Apr 10 2011 20:15:34 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.locale", "");
Line Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 0);
Line Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Aug 14 2013 14:13:08 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "");
Line Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Line Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Line Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Line Deleted : user_pref("CommunityToolbar.alert.userId", "e20a0179-74a7-4a91-95a6-bb4fd75bc785");
Line Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Wed Nov 14 2012 18:29:07 GMT+0100");
Line Deleted : user_pref("CommunityToolbar.globalUserId", "78f9913b-8f9a-40ca-9d51-8e89705905b9");
Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2269050");
Line Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Sat Jul 20 2013 17:45:50 GMT+0200");
Line Deleted : user_pref("ConduitEngine.FirstServerDate", "01/24/2011 23");
Line Deleted : user_pref("ConduitEngine.FirstTime", true);
Line Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Line Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Line Deleted : user_pref("ConduitEngine.Initialize", true);
Line Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Line Deleted : user_pref("ConduitEngine.InstalledDate", "Mon Jan 24 2011 23:42:08 GMT+0100");
Line Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Line Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Line Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Line Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Nov 14 2012 18:29:14 GMT+0100");
Line Deleted : user_pref("ConduitEngine.LastLogin_3.2.2.0", "Tue Jan 25 2011 10:45:45 GMT+0100");
Line Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Thu Aug 23 2012 03:01:58 GMT+0200");
Line Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Line Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Nov 14 2012 18:29:14 GMT+0100");
Line Deleted : user_pref("ConduitEngine.UserID", "UN92796171958376562");
Line Deleted : user_pref("ConduitEngine.engineLocale", "de");
Line Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Nov 14 2012 18:29:14 GMT+0100");
Line Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Sat Jul 20 2013 17:45:50 GMT+0200");
Line Deleted : user_pref("ConduitEngine.initDone", true);
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.ClearSearchHistoryOnClose", "false");
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.CurrentLanguageSelection", "English");
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.CurrentNavigationSelection", "Current window");
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.CurrentSearchEngineSelection", "US: United States of America");
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.DisplayRecentSearches", "true");
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.ShowButtonText2", "true");
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.setupExtension", "true");
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.userEnable", true);
Line Deleted : user_pref("DownTangoFTToolbar_2937.global.userID", "aefe1f33f5f46eb31459f881c6d26463");
Line Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "Plasmoo");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.fbdownloader.com/search.php?channel=sfde203fbdgy21&q=");
Line Deleted : user_pref("browser.search.order.1", "Web Search");
Line Deleted : user_pref("browser.search.selectedEngine", "Search the web");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=b3a3c66c-34eb-415e-b9af-6d6823522c70&searchtype=hp&installDate=05/04/2013");
Line Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=111789&tt=280612_7_");
Line Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "040bfd6d000000000000002163bb1b38");
Line Deleted : user_pref("extensions.BabylonToolbar_i.id", "040bfd6d000000000000002163bb1b38");
Line Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15520");
Line Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);
Line Deleted : user_pref("extensions.BabylonToolbar_i.ovrDmn", "isearch.babylon.com");
Line Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Line Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Line Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1720:17:04");
Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.backgroundjs", "\n\n/*****************************************************************************[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.js", "\n\n /************************************************************************************\[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_104.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_13.name", "CrossriderAppUtils");
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_14.name", "CrossriderUtils");
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==true)&&(typeof _[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.a[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_con[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_78.name", "CrossriderInfo");
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_87.code", "var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform==\[...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_91.code", "(function(h){var o=(function(){var Q=0;var Y=\"\";function P(ab){return [...]
Line Deleted : user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...]
Line Deleted : user_pref("extensions.crossrider.bic", "13afff77718e57d3a2d887603af3aac5");
Line Deleted : user_pref("extensions.enabledAddons", "finder@meingutscheincode.de:2.0,{02450954-cdd9-410f-b1da-db804e18c671}:0.96.3,{3112ca9c-de6d-4884-a869-9855de68056c}:7.1.20101113Wb1,quickstores@quickstores.de:1[...]
Line Deleted : user_pref("extensions.enabledItems", "{b3a3c66c-34eb-415e-b9af-6d6823522c70}:1.0,{3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872,avg@igeared:6.103.018.001,engine@conduit.com:3.2.2.0,{ACAA314B-EEBA-48[...]
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\W[...]
Line Deleted : user_pref("extensions.snipit.askTbInstalled", true);
Line Deleted : user_pref("extentions.y2layers.defaultEnableAppsList", "twittube,buzzdock,YontooNewOffers");
Line Deleted : user_pref("extentions.y2layers.installId", "7a00aa57-e145-4f64-97fe-1b2bcdaefde1");
Line Deleted : user_pref("icqtoolbar.engineVerified", false);
Line Deleted : user_pref("icqtoolbar.installTime", "1317319993");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "4.0");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.uniqueID", "130545949113054597311317319993450");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1376482397);
Line Deleted : user_pref("icqtoolbar.version", "1.1.9");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "de");
Line Deleted : user_pref("keyword.URL", "hxxp://search.fbdownloader.com/search.php?channel=sfde203fbdgy21&q=");
Line Deleted : user_pref("plasmoo.search.engine.prevkeywordurl", "hxxp://search.fbdownloader.com/search.php?channel=sfde203fbdgy21&q=");
Line Deleted : user_pref("plasmoo.search.engine.prevsearchdefaultenginename", "Search the web");
Line Deleted : user_pref("plasmoo.search.engine.prevsearchdefaultthisenginename", "Search");
Line Deleted : user_pref("plasmoo.search.engine.prevsearchdefaulturl", "hxxp://search.fbdownloader.com/search.php?channel=sfde203fbdgy21&q=");
Line Deleted : user_pref("plasmoo.search.engine.prevsearchselectedengine", "Search the web");
Line Deleted : user_pref("plasmoo.search.engine.prevstartuphomepage", "hxxp://feed.snap.do/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=b3a3c66c-34eb-415e-b9af-6d6823522c70&searchtype=hp&installDat[...]
Line Deleted : user_pref("plasmoo.search.engine.status", "INSTALLED");
Line Deleted : user_pref("quickstores.toolbar.affid", "2017");
Line Deleted : user_pref("quickstores.toolbar.guid", "{79EA0A13-99E7-848D-7AAE-C282D3469DA3}");
Line Deleted : user_pref("browser.search.defaultengine", "Web Search");
Line Deleted : user_pref("browser.search.defaultenginename", "Search the web");
-\\ Google Chrome v29.0.1547.57
[ File : C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [82569 octets] - [22/08/2013 01:19:54]
AdwCleaner[R1].txt - [66890 octets] - [24/08/2013 20:20:31]
AdwCleaner[S0].txt - [4430 octets] - [22/08/2013 01:22:36]
AdwCleaner[S1].txt - [62709 octets] - [24/08/2013 20:44:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [62770 octets] ##########
---------------------------------------------------------------------------------------
3. JUNKWARE REMOVAL TOOL-Logfile:
--------------------------------------------------------------------------------------- Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.4 (08.22.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Sebastian on 24/08/2013 at 21:01:26,06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Failed to stop: [Service] hshld
Successfully stopped: [Service] hsstrayservice
Successfully deleted: [Service] hsstrayservice
Failed to stop: [Service] hsswd
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\anchorfree
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\hotspotshield
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\simplytech
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\simplytech
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\hotspotshield
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\uniblue
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\features\a6eb8fe4c9986914497e92c7f5a702e3
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\a6eb8fe4c9986914497e92c7f5a702e3
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550355345526}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366346626}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440344344426}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2269050
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2319825
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2325506
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550355345526}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660366346626}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440344344426}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011501160}
~~~ Files
Failed to delete: [File] "C:\Users\Sebastian\appdata\local\google\chrome\user data\default\ext_piccshare"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\hotspot shield"
Successfully deleted: [Folder] "C:\Users\Sebastian\AppData\Roaming\hotspot shield"
Successfully deleted: [Folder] "C:\Program Files\hotspot shield"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted the following from C:\Users\Sebastian\AppData\Roaming\mozilla\firefox\profiles\i2cb9wbv.default\prefs.js
user_pref("extensions.a7125a2857e6847aa9d72e81874f4d47ed3fcdb92135d4a8a8cf611e3b57c5fdacom33426.33426.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"
user_pref("google.toolbar.button_option.cached.gtbSearchBlogs", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchBlogs\" t
user_pref("google.toolbar.button_option.cached.gtbSearchPhotos", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchPhotos\"
user_pref("google.toolbar.button_option.cached.gtbSearchScholar", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchScholar
user_pref("google.toolbar.button_option.cached.gtbstoolbar-google-com_CTK0Y7F4MTG6NKYH03WT-xml", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.o
user_pref("google.toolbar.button_option.cached.gtbstoolbar-google-com_J66T77NJDBMW4FEUU7FA-xml", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.o
user_pref("google.toolbar.search-icon", "data:image/x-icon;base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7PT7/3zF6/9Ptu//RbHx/
Emptied folder: C:\Users\Sebastian\AppData\Roaming\mozilla\firefox\profiles\i2cb9wbv.default\minidumps [26 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24/08/2013 at 21:07:25,87
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
---------------------------------------------------------------------------------------
4. FRST-Logfile (neu):
---------------------------------------------------------------------------------------
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-08-2013 01
Ran by Sebastian (administrator) on 24-08-2013 21:37:41
Running from C:\Users\Sebastian\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(AVM Berlin) C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
() C:\Program Files\CDBurnerXP\NMSAccessU.exe
() C:\Windows\system32\PSIService.exe
(Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Toshiba) C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
(TOSHIBA) C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
(Chicony) C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files\Unlocker\UnlockerAssistant.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(TuneClone.COM) C:\Program Files\TuneClone\TuneClone.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(TOSHIBA) C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\System32\p2phost.exe
(Nokia) C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Akamai Technologies, Inc.) C:\Users\Sebastian\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
() C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Akamai Technologies, Inc.) C:\Users\Sebastian\AppData\Local\Akamai\netsession_win.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6037504 2008-04-08] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\...\Run: [NDSTray.exe] - NDSTray.exe [x]
HKLM\...\Run: [Toshiba TEMPO] - C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe [103824 2008-08-26] (Toshiba Europe GmbH)
HKLM\...\Run: [topi] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [581632 2007-07-10] (TOSHIBA)
HKLM\...\Run: [Camera Assistant Software] - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [417792 2008-04-29] (Chicony)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [431456 2008-01-17] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [54608 2007-10-31] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [509816 2008-01-25] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [716800 2008-03-19] (TOSHIBA Corporation)
HKLM\...\Run: [QuickFinder Scheduler] - C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE [83568 2007-01-03] (Corel Corporation)
HKLM\...\Run: [UnlockerAssistant] - C:\Program Files\Unlocker\UnlockerAssistant.exe [17408 2010-07-04] ()
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [TuneClone] - C:\Program Files\TuneClone\TuneClone.exe [4550656 2012-02-24] (TuneClone.COM)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [TrojanScanner] - C:\Program Files\Trojan Remover\Trjscan.exe [1247504 2012-09-14] (Simply Super Software)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-09] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-06-20] (RealNetworks, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKCU\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [430080 2008-04-24] (TOSHIBA)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [CollaborationHost] - C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [PC Suite Tray] - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [1479680 2010-05-14] (Nokia)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-10-24] (Google Inc.)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Sebastian\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\Default\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-04-24] (TOSHIBA)
HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-04-24] (TOSHIBA)
HKU\fbwuser\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\fbwuser\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-04-24] (TOSHIBA)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Metacafe.lnk
ShortcutTarget: Metacafe.lnk -> C:\Program Files\Metacafe\MetacafeAgent.exe (Metacafe)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\fbwuser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File
Toolbar: HKCU -No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - No File
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\29.0.1547.57\npchrome_frame.dll (Google Inc.)
Handler: ipp - No CLSID Value -
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{432464BA-CDAD-4B34-900E-178E765E3DBA}: [NameServer]8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default
FF NewTab: about:blank
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 52505
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files\Magic 3GP Video Converter\codec\real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files\Magic 3GP Video Converter\codec\real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=8 - C:\Users\Sebastian\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101799.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\searchplugins\search_the_web.xml
FF Extension: No Name - C:\Users\Sebastian\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Mein Gutscheincode Finder - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\finder@meingutscheincode.de
FF Extension: No Name - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\informationaltab@piro.sakura.ne.jp
FF Extension: BrOwwsae2saevEe - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\jyu_k@vmqhpwftiy.co.uk
FF Extension: Smart Bookmarks Bar - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\smartbookmarksbar@remy.juteau
FF Extension: YouPlayer - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\youplayer@addons.mozilla.org
FF Extension: Screengrab - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF Extension: Site Launcher - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{20291fcc-1471-46c8-8213-5911f5ce6d67}
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: Google Toolbar for Firefox - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF Extension: DownTango Launcher - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{411beae9-8c58-477c-8903-201536f61512}
FF Extension: Stylish - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
FF Extension: Yahoo! Toolbar - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF Extension: Interclue - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
FF Extension: dvscontextmenuy - C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\i2cb9wbv.default\Extensions\dvscontextmenuy@dvdvideosoft.com
FF Extension: VideoGet FireFox extension - C:\Program Files\Mozilla Firefox\extensions\{85E85FF9-E50C-42DE-8A3D-61485FD6C8DB}
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF Extension: Skype extension for Firefox - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{3f963a5b-e555-4543-90e2-c3908898db71}] C:\Program Files\AVG\AVG9\Firefox
FF HKLM\...\Firefox\Extensions: [bkmrksync@nokia.com] C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
Chrome:
=======
CHR HomePage: hxxp://google.de/
CHR Extension: (YouTube) - C:\Users\SEBAST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\SEBAST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (DVDVideoSoft) - C:\Users\SEBAST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.2.3.3_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\SEBAST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Google Reader) - C:\Users\SEBAST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.4_0
CHR Extension: (Gmail) - C:\Users\SEBAST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [aaaaplmcbjhigpfkmaffahlojgchbgfk] - C:\Users\Sebastian\AppData\Local\APN\GoogleCRXs\aaaaplmcbjhigpfkmaffahlojgchbgfk_7.14.1.0.crx
CHR HKLM\...\Chrome\Extension: [gladcbhcbkdeddbidiblppadjdjalidb] - C:\Program Files\DownTangoFTToolbar\chrome\DownTangoFTToolbar.crx
========================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-09] (Avira Operations GmbH & Co. KG)
S3 CGVPNCliSrvc; C:\Program Files\CyberGhost VPN\CGVPNCliService.exe [2438696 2012-05-04] (mobile concepts GmbH)
R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-17] (TOSHIBA CORPORATION)
R2 IGDCTRL; C:\Program Files\FRITZ!DSL\IGDCTRL.EXE [87344 2007-09-04] (AVM Berlin)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2008-10-20] ()
R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [174656 2006-11-02] ()
R3 SmartFaceVWatchSrv; C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [73728 2008-04-24] (Toshiba)
R2 TempoMonitoringService; C:\Program Files\Toshiba TEMPRO\TempoSVC.exe [99720 2008-08-26] (Toshiba Europe GmbH)
R2 TOSHIBA SMART Log Service; c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation)
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.)
S2 hshld; C:\Program Files\Hotspot Shield\bin\cmw_srv.exe [x]
S2 HssWd; C:\Program Files\Hotspot Shield\bin\hsswd.exe [x]
S2 RoxLiveShare9; "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [x]
==================== Drivers (Whitelisted) ====================
R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 ASPI; C:\Windows\System32\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-03-20] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-03-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-20] (Avira Operations GmbH & Co. KG)
R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [41160 2013-07-24] (AnchorFree Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 PSSDK42; C:\Windows\system32\Drivers\pssdk42.sys [38976 2011-06-29] (microOLAP Technologies LTD)
R1 PSSDKLBF; C:\Windows\system32\Drivers\pssdklbf.sys [53312 2011-06-29] (microOLAP Technologies LTD)
S3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [141408 2008-02-27] (Realtek Semiconductor Corp.)
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [290304 2007-12-26] (Realtek Semiconductor Corporation )
R1 RtlProt; C:\Windows\System32\DRIVERS\rtlprot.sys [25896 2007-04-23] (Windows (R) Codename Longhorn DDK provider)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] ()
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2011-12-15] (The OpenVPN Project)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [37064 2013-04-24] (Anchorfree Inc.)
R0 tclondrv; C:\Windows\System32\DRIVERS\tclondrv.sys [28776 2012-02-24] (TuneClone Software)
R3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.)
S3 catchme; \??\C:\Users\SEBAST~1\AppData\Local\Temp\catchme.sys [x]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 uscbs108; system32\DRIVERS\uscbs108.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-24 21:36 - 2013-08-24 21:36 - 01070693 _____ (Farbar) C:\Users\Sebastian\Desktop\FRST.exe
2013-08-24 21:07 - 2013-08-24 21:07 - 00004622 _____ C:\Users\Sebastian\Desktop\JRT.txt
2013-08-24 21:00 - 2013-08-24 21:00 - 01021434 _____ (Thisisu) C:\Users\Sebastian\Desktop\JRT.exe
2013-08-24 21:00 - 2013-08-24 21:00 - 00000000 ____D C:\Windows\ERUNT
2013-08-24 20:52 - 2013-08-24 20:52 - 00062851 _____ C:\Users\Sebastian\Desktop\AdwCleaner[S1].txt
2013-08-24 18:11 - 2013-08-24 18:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sebastian\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-24 17:59 - 2013-08-24 18:01 - 00000000 ____D C:\Users\Sebastian\Desktop\LocalCDDB
2013-08-24 17:59 - 2013-08-24 17:59 - 00000000 ____D C:\Users\Sebastian\Desktop\Patti Smith. Banga (WAVE)
2013-08-24 08:09 - 2013-08-24 08:09 - 00938096 _____ C:\Users\Sebastian\Downloads\goldentiger (1).exe
2013-08-24 04:54 - 2013-08-24 04:54 - 00024490 _____ C:\Users\Sebastian\Desktop\Combofix.txt
2013-08-24 04:53 - 2013-08-24 04:53 - 00024490 _____ C:\ComboFix.txt
2013-08-23 20:26 - 2013-08-24 04:53 - 00000000 ____D C:\ComboFix
2013-08-23 20:26 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-23 20:26 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-23 20:26 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-23 20:26 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-23 20:26 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-23 20:26 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-23 20:26 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-23 20:26 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-23 20:19 - 2013-08-24 20:07 - 00001294 _____ C:\Windows\PFRO.log
2013-08-23 20:13 - 2013-08-23 20:13 - 00000000 ____D C:\Users\Sebastian\Documents\ProcAlyzer Dumps
2013-08-23 20:04 - 2013-08-24 04:53 - 00000000 ____D C:\Qoobox
2013-08-23 20:03 - 2013-08-23 20:52 - 00000000 ____D C:\Windows\erdnt
2013-08-23 19:57 - 2013-08-23 19:57 - 05111180 ____R (Swearware) C:\Users\Sebastian\Desktop\ComboFix.exe
2013-08-23 18:57 - 2013-08-23 18:57 - 00938096 _____ C:\Users\Sebastian\Downloads\goldentiger.exe
2013-08-23 18:56 - 2013-08-23 18:56 - 00000000 ____D C:\Users\Sebastian\Desktop\Logfiles für trojaner-board.de
2013-08-23 18:15 - 2013-08-23 18:15 - 01110476 _____ C:\Users\Sebastian\Desktop\7z920.exe
2013-08-23 18:15 - 2013-08-23 18:15 - 00000000 ____D C:\Program Files\7-Zip
2013-08-23 11:35 - 2013-08-23 11:35 - 00377856 _____ C:\Users\Sebastian\Desktop\gmer_2.1.19163.exe
2013-08-23 11:25 - 2013-08-23 11:25 - 00000000 ____D C:\FRST
2013-08-23 11:19 - 2013-08-23 11:20 - 00000480 _____ C:\Users\Sebastian\Desktop\defogger_disable.log
2013-08-23 11:18 - 2013-08-23 11:18 - 00050477 _____ C:\Users\Sebastian\Desktop\Defogger.exe
2013-08-22 22:31 - 2013-08-22 22:34 - 00000000 ____D C:\sh4ldr
2013-08-22 11:58 - 2013-08-22 11:58 - 00000000 ____D C:\Users\Sebastian\Ein Herz und eine Seele
2013-08-22 01:19 - 2013-08-24 20:45 - 00000000 ____D C:\AdwCleaner
2013-08-22 01:19 - 2013-08-24 20:18 - 00994642 _____ C:\Users\Sebastian\Desktop\AdwCleaner.exe
2013-08-21 21:49 - 2013-08-21 21:51 - 00000000 ____D C:\Users\Sebastian\Desktop\VEGAN
2013-08-21 15:03 - 2013-08-21 15:03 - 00000306 __RSH C:\ProgramData\ntuser.pol
2013-08-21 10:54 - 2013-08-22 00:08 - 00000000 ____D C:\Users\Sebastian\Desktop\Marc Bekoff. Das unnötige Leiden der Tiere (2001)
2013-08-19 22:20 - 2013-08-19 22:20 - 00000000 ____D C:\Users\Sebastian\Desktop\Hey Veganer! (youtube.com)
2013-08-19 21:39 - 2013-08-19 22:05 - 34683132 _____ C:\Users\Sebastian\Desktop\Warum haben Tiere Rechte.flv
2013-08-19 15:55 - 2013-07-24 04:10 - 00041160 _____ (AnchorFree Inc.) C:\Windows\system32\Drivers\hssdrv6.sys
2013-08-19 15:54 - 2013-08-19 15:56 - 00000878 _____ C:\Users\Public\Desktop\Hotspot Shield.lnk
2013-08-15 00:14 - 2013-08-15 00:16 - 46940808 _____ C:\Users\Sebastian\Desktop\Warum essen wir nicht unsere Haustiere_ Melanie Joy im Interview.flv
2013-08-14 13:31 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 13:31 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-14 13:31 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 13:31 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 13:31 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2013-08-14 13:31 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-14 13:30 - 2013-07-24 02:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 13:30 - 2013-07-24 02:33 - 00916480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 13:30 - 2013-07-24 02:33 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2013-08-14 13:30 - 2013-07-24 02:33 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-08-14 13:30 - 2013-07-24 02:33 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 11111936 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 06016512 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-14 13:30 - 2013-07-24 02:32 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-08-14 13:30 - 2013-07-24 02:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 13:30 - 2013-07-24 01:56 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-08-14 13:30 - 2013-07-24 01:49 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 13:30 - 2013-07-24 01:49 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 13:30 - 2013-07-24 01:49 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-14 13:30 - 2013-07-24 01:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-08-14 13:30 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 13:30 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 13:30 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 13:29 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 13:29 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 13:29 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-01 00:00 - 2013-08-15 11:10 - 00000000 ____D C:\Windows\system32\MRT
2013-07-28 18:12 - 2013-07-28 18:10 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-07-28 18:11 - 2013-07-28 18:10 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-07-28 18:11 - 2013-07-28 18:10 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-07-28 18:11 - 2013-07-28 18:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-07-28 11:11 - 2013-07-28 11:11 - 00000000 ____D C:\ProgramData\hssff
2013-07-27 17:39 - 2013-08-11 09:27 - 00000000 ____D C:\Users\Sebastian\Desktop\KEIN PLASTIK
2013-07-25 11:34 - 2013-07-25 11:34 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-07-25 11:32 - 2013-08-22 23:09 - 00000000 ____D C:\Windows\471D8B37C5B344579FA1B3C693334F4F.TMP
==================== One Month Modified Files and Folders =======
2013-08-24 21:37 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-08-24 21:36 - 2013-08-24 21:36 - 01070693 _____ (Farbar) C:\Users\Sebastian\Desktop\FRST.exe
2013-08-24 21:30 - 2011-10-24 19:17 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-24 21:08 - 2013-03-05 13:03 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-24 21:07 - 2013-08-24 21:07 - 00004622 _____ C:\Users\Sebastian\Desktop\JRT.txt
2013-08-24 21:00 - 2013-08-24 21:00 - 01021434 _____ (Thisisu) C:\Users\Sebastian\Desktop\JRT.exe
2013-08-24 21:00 - 2013-08-24 21:00 - 00000000 ____D C:\Windows\ERUNT
2013-08-24 20:53 - 2012-07-01 20:41 - 00000000 ____D C:\Users\Public\Documents\TuneClone
2013-08-24 20:52 - 2013-08-24 20:52 - 00062851 _____ C:\Users\Sebastian\Desktop\AdwCleaner[S1].txt
2013-08-24 20:51 - 2011-06-30 10:18 - 00000000 ____D C:\Program Files\Common Files\Akamai
2013-08-24 20:50 - 2011-10-24 19:17 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-24 20:49 - 2009-07-22 06:45 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2013-08-24 20:49 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-24 20:49 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-24 20:49 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-24 20:47 - 2012-03-24 08:56 - 02016713 _____ C:\Windows\WindowsUpdate.log
2013-08-24 20:47 - 2006-11-02 15:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-24 20:45 - 2013-08-22 01:19 - 00000000 ____D C:\AdwCleaner
2013-08-24 20:44 - 2013-07-20 17:39 - 00000000 ____D C:\Users\Sebastian\AppData\Roaming\Common
2013-08-24 20:27 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\tracing
2013-08-24 20:18 - 2013-08-22 01:19 - 00994642 _____ C:\Users\Sebastian\Desktop\AdwCleaner.exe
2013-08-24 20:07 - 2013-08-23 20:19 - 00001294 _____ C:\Windows\PFRO.log
2013-08-24 20:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-24 18:16 - 2013-02-07 18:18 - 00000871 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-24 18:16 - 2011-01-25 18:18 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-24 18:11 - 2013-08-24 18:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sebastian\Desktop\mbam-setup-1.75.0.1300.exe
2013-08-24 18:01 - 2013-08-24 17:59 - 00000000 ____D C:\Users\Sebastian\Desktop\LocalCDDB
2013-08-24 17:59 - 2013-08-24 17:59 - 00000000 ____D C:\Users\Sebastian\Desktop\Patti Smith. Banga (WAVE)
2013-08-24 08:09 - 2013-08-24 08:09 - 00938096 _____ C:\Users\Sebastian\Downloads\goldentiger (1).exe
2013-08-24 07:38 - 2009-04-04 15:08 - 00006944 _____ C:\Users\SEBAST~1\AppData\Local\d3d9caps.dat
2013-08-24 07:37 - 2009-11-18 14:28 - 00000426 ____H C:\Windows\Tasks\User_Feed_Synchronization-{02653207-0637-447F-B9C7-8F48139372F2}.job
2013-08-24 04:54 - 2013-08-24 04:54 - 00024490 _____ C:\Users\Sebastian\Desktop\Combofix.txt
2013-08-24 04:54 - 2010-02-09 00:51 - 00000000 ____D C:\Users\Sebastian\AppData\Local\Apps\2.0
2013-08-24 04:53 - 2013-08-24 04:53 - 00024490 _____ C:\ComboFix.txt
2013-08-24 04:53 - 2013-08-23 20:26 - 00000000 ____D C:\ComboFix
2013-08-24 04:53 - 2013-08-23 20:04 - 00000000 ____D C:\Qoobox
2013-08-23 20:52 - 2013-08-23 20:03 - 00000000 ____D C:\Windows\erdnt
2013-08-23 20:51 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2013-08-23 20:49 - 2012-06-29 19:53 - 00000000 ____D C:\Users\Sebastian\AppData\Roaming\convert
2013-08-23 20:19 - 2013-03-12 17:54 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-08-23 20:13 - 2013-08-23 20:13 - 00000000 ____D C:\Users\Sebastian\Documents\ProcAlyzer Dumps
2013-08-23 20:13 - 2013-03-12 17:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-23 19:57 - 2013-08-23 19:57 - 05111180 ____R (Swearware) C:\Users\Sebastian\Desktop\ComboFix.exe
2013-08-23 18:57 - 2013-08-23 18:57 - 00938096 _____ C:\Users\Sebastian\Downloads\goldentiger.exe
2013-08-23 18:56 - 2013-08-23 18:56 - 00000000 ____D C:\Users\Sebastian\Desktop\Logfiles für trojaner-board.de
2013-08-23 18:15 - 2013-08-23 18:15 - 01110476 _____ C:\Users\Sebastian\Desktop\7z920.exe
2013-08-23 18:15 - 2013-08-23 18:15 - 00000000 ____D C:\Program Files\7-Zip
2013-08-23 17:16 - 2009-01-19 10:25 - 00000000 ____D C:\Users\Sebastian
2013-08-23 12:15 - 2009-01-20 00:03 - 00241152 _____ C:\Users\SEBAST~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-08-23 11:35 - 2013-08-23 11:35 - 00377856 _____ C:\Users\Sebastian\Desktop\gmer_2.1.19163.exe
2013-08-23 11:25 - 2013-08-23 11:25 - 00000000 ____D C:\FRST
2013-08-23 11:20 - 2013-08-23 11:19 - 00000480 _____ C:\Users\Sebastian\Desktop\defogger_disable.log
2013-08-23 11:18 - 2013-08-23 11:18 - 00050477 _____ C:\Users\Sebastian\Desktop\Defogger.exe
2013-08-22 23:54 - 2011-01-24 20:00 - 00000000 ____D C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2013-08-22 23:31 - 2009-09-01 17:10 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-08-22 23:16 - 2009-01-19 10:26 - 00135992 _____ C:\Users\SEBAST~1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-22 23:11 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\Msdtc
2013-08-22 23:10 - 2006-11-02 12:22 - 60817408 _____ C:\Windows\system32\config\software_previous
2013-08-22 23:10 - 2006-11-02 12:22 - 45875200 _____ C:\Windows\system32\config\components_previous
2013-08-22 23:10 - 2006-11-02 12:22 - 25427968 _____ C:\Windows\system32\config\system_previous
2013-08-22 23:10 - 2006-11-02 12:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2013-08-22 23:10 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2013-08-22 23:10 - 2006-11-02 12:22 - 00024576 _____ C:\Windows\system32\config\security_previous
2013-08-22 23:09 - 2013-07-25 11:32 - 00000000 ____D C:\Windows\471D8B37C5B344579FA1B3C693334F4F.TMP
2013-08-22 23:09 - 2012-07-28 12:05 - 00000000 ____D C:\Program Files\MurGee Auto Mouse Click
2013-08-22 23:09 - 2011-11-14 22:09 - 00000000 ____D C:\Users\SEBAST~1\AppData\Local\Akamai
2013-08-22 23:09 - 2011-01-24 20:00 - 00000000 ____D C:\Program Files\Unlocker
2013-08-22 23:09 - 2010-12-17 13:13 - 00000000 ____D C:\Users\Sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2013-08-22 23:09 - 2010-08-26 19:19 - 00000000 ____D C:\Users\Sebastian\Philosophie
2013-08-22 23:09 - 2010-08-26 19:17 - 00000000 ____D C:\Users\Sebastian\Körper und Psyche
2013-08-22 23:09 - 2010-04-03 14:46 - 00000000 ____D C:\Users\Sebastian\Hörbücher + Vorträge
2013-08-22 23:09 - 2009-04-18 19:11 - 00000000 ____D C:\Program Files\NCH Swift Sound
2013-08-22 23:09 - 2009-04-18 19:11 - 00000000 ____D C:\Program Files\NCH Software
2013-08-22 23:09 - 2009-03-30 13:04 - 00000000 ____D C:\Users\Sebastian\Lyrik
2013-08-22 23:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool
2013-08-22 23:08 - 2013-04-05 18:57 - 00000000 ____D C:\Program Files\Exact Audio Copy
2013-08-22 23:08 - 2009-07-12 20:24 - 00000000 ____D C:\Program Files\DVD Ripper Wizard
2013-08-22 23:08 - 2009-01-26 12:54 - 00000000 ____D C:\Program Files\DivX
2013-08-22 23:08 - 2008-10-07 17:13 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2013-08-22 23:08 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\registration
2013-08-22 22:34 - 2013-08-22 22:31 - 00000000 ____D C:\sh4ldr
2013-08-22 22:34 - 2012-05-09 11:54 - 00000000 ____D C:\ProgramData\NCH Software
2013-08-22 12:27 - 2010-08-26 19:17 - 00000000 ____D C:\Users\Sebastian\Körper und Psyche (A-Z)
2013-08-22 12:18 - 2010-04-03 14:46 - 00000000 ____D C:\Users\Sebastian\Hörbücher + Vorträge + Podcasts
2013-08-22 12:14 - 2010-08-26 19:19 - 00000000 ____D C:\Users\Sebastian\Literatur
2013-08-22 12:13 - 2008-10-08 10:03 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-22 11:58 - 2013-08-22 11:58 - 00000000 ____D C:\Users\Sebastian\Ein Herz und eine Seele
2013-08-22 01:48 - 2012-05-09 11:51 - 00000000 ____D C:\Users\Sebastian\AppData\Roaming\NCH Software
2013-08-22 01:24 - 2009-04-18 19:12 - 00000000 ____D C:\Users\Sebastian\AppData\Roaming\NCH Swift Sound
2013-08-22 01:22 - 2009-05-16 00:06 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-08-22 01:22 - 2009-01-19 12:20 - 00000000 ____D C:\ProgramData\ICQ
2013-08-22 00:53 - 2008-01-21 09:16 - 00875622 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-22 00:42 - 2009-04-07 16:18 - 00000000 ____D C:\Users\Sebastian\Desktop\Isabella
2013-08-22 00:15 - 2013-04-05 17:30 - 00000000 ____D C:\Users\Sebastian\Desktop\CDex
2013-08-22 00:08 - 2013-08-21 10:54 - 00000000 ____D C:\Users\Sebastian\Desktop\Marc Bekoff. Das unnötige Leiden der Tiere (2001)
2013-08-21 22:08 - 2013-03-05 13:03 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-08-21 22:08 - 2011-12-09 20:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-08-21 21:51 - 2013-08-21 21:49 - 00000000 ____D C:\Users\Sebastian\Desktop\VEGAN
2013-08-21 15:03 - 2013-08-21 15:03 - 00000306 __RSH C:\ProgramData\ntuser.pol
2013-08-21 15:03 - 2006-11-02 13:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-08-19 22:20 - 2013-08-19 22:20 - 00000000 ____D C:\Users\Sebastian\Desktop\Hey Veganer! (youtube.com)
2013-08-19 22:05 - 2013-08-19 21:39 - 34683132 _____ C:\Users\Sebastian\Desktop\Warum haben Tiere Rechte.flv
2013-08-19 15:56 - 2013-08-19 15:54 - 00000878 _____ C:\Users\Public\Desktop\Hotspot Shield.lnk
2013-08-15 13:15 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-08-15 12:13 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-15 11:10 - 2013-08-01 00:00 - 00000000 ____D C:\Windows\system32\MRT
2013-08-15 10:56 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-08-15 00:16 - 2013-08-15 00:14 - 46940808 _____ C:\Users\Sebastian\Desktop\Warum essen wir nicht unsere Haustiere_ Melanie Joy im Interview.flv
2013-08-11 09:27 - 2013-07-27 17:39 - 00000000 ____D C:\Users\Sebastian\Desktop\KEIN PLASTIK
2013-08-09 16:40 - 2012-07-01 20:41 - 00000000 ____D C:\Users\Sebastian\Documents\TuneClone
2013-07-28 18:12 - 2008-10-07 16:32 - 00000000 ____D C:\Program Files\Common Files\Java
2013-07-28 18:10 - 2013-07-28 18:12 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-07-28 18:10 - 2013-07-28 18:11 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-07-28 18:10 - 2013-07-28 18:11 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-07-28 18:10 - 2013-07-28 18:11 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-07-28 18:10 - 2013-02-07 16:18 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npdeployJava1.dll
2013-07-28 18:10 - 2011-04-13 16:00 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-07-28 18:10 - 2008-10-07 16:32 - 00000000 ____D C:\Program Files\Java
2013-07-28 15:16 - 2012-02-19 15:42 - 00000000 ____D C:\Program Files\Bullfrog
2013-07-28 11:19 - 2009-01-20 18:19 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-28 11:11 - 2013-07-28 11:11 - 00000000 ____D C:\ProgramData\hssff
2013-07-26 12:18 - 2013-03-20 13:12 - 00000038 _____ C:\Windows\AviSplitter.INI
2013-07-25 11:34 - 2013-07-25 11:34 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-07-25 09:37 - 2010-12-07 17:22 - 00000000 ____D C:\Program Files\UltimateZip
Files to move or delete:
====================
C:\Users\SEBAST~1\AppData\Local\Temp\Quarantine.exe
C:\Users\SEBAST~1\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\SEBAST~1\AppData\Local\Temp\jrt\erunt\ERUNT.EXE.manifest
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-24 20:56
==================== End Of Log ============================ --- --- ---
Danke für die Hilfe.
Gruß,
Hungry Ghost |