hauskran | 27.08.2013 12:41 | Code:
# AdwCleaner v3.001 - Report created 27/08/2013 at 13:13:29
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Sigrid - SIGRID-PC
# Running from : C:\Users\Sigrid\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : Web Assistant
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\IBUpdaterService
Folder Deleted : C:\ProgramData\Iminent
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\Iminent
Folder Deleted : C:\Program Files (x86)\Search Settings
Folder Deleted : C:\Program Files (x86)\Wajam
Folder Deleted : C:\Program Files (x86)\Common Files\spigot
Folder Deleted : C:\Program Files\Web Assistant
Folder Deleted : C:\Users\Sigrid\AppData\Local\Smartbar
Folder Deleted : C:\Users\Sigrid\AppData\Local\Temp\Smartbar
Folder Deleted : C:\Users\Sigrid\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Sigrid\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Deleted : C:\Users\Sigrid\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Sigrid\AppData\LocalLow\Smartbar
Folder Deleted : C:\Users\Sigrid\AppData\Roaming\Desktopicon
Folder Deleted : C:\Users\Sigrid\AppData\Roaming\Iminent
Folder Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\Conduit
Folder Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\ConduitEngine
Folder Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\Extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}
Folder Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\r74y5ue3.default-1372489467664\Extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}
Folder Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\Extensions\engine@conduit.com
Folder Deleted : C:\Users\Sigrid\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Folder Deleted : C:\Users\Sigrid\AppData\Local\Google\Chrome\User Data\Default\Extensions\licjnkifamhpbaefhdpacpmihicfbomb
File Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\Extensions\pricepeep@getpricepeep.com.xpi
File Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\r74y5ue3.default-1372489467664\Extensions\pricepeep@getpricepeep.com.xpi
File Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\r74y5ue3.default-1372489467664\Extensions\webbooster@iminent.com.xpi
File Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\searchplugins\Web Search.xml
File Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\user.js
File Deleted : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\r74y5ue3.default-1372489467664\user.js
File Deleted : C:\Users\Sigrid\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader55984_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader55984_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader71282[1]_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader71282[1]_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_avira-free-antivirus-2013_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_avira-free-antivirus-2013_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-hide-ip[1]_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-hide-ip[1]_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hypercam[1]_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hypercam[1]_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photoscape_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_photoscape_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_vdownloader_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_vdownloader_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\incredibar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\IncrediMail_MediaBar_2
Key Deleted : HKCU\Software\AppDataLow\Software\LyricsContainer
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\ImInstaller
Key Deleted : HKLM\Software\Web Assistant
Key Deleted : [x64] HKLM\SOFTWARE\Web Assistant
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v22.0 (de)
[ File : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\prefs.js ]
Line Deleted : user_pref("CT2724386..clientLogIsEnabled", false);
Line Deleted : user_pref("CT2724386..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2724386..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2724386.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Line Deleted : user_pref("CT2724386.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2724386.BrowserCompStateIsOpen_129626311033612748", true);
Line Deleted : user_pref("CT2724386.BrowserCompStateIsOpen_129723003199914047", true);
Line Deleted : user_pref("CT2724386.BrowserCompStateIsOpen_129847484448267081", true);
Line Deleted : user_pref("CT2724386.BrowserCompStateIsOpen_129851872283658385", true);
Line Deleted : user_pref("CT2724386.BrowserCompStateIsOpen_129904362619180486", true);
Line Deleted : user_pref("CT2724386.BrowserCompStateIsOpen_130040907554784951", true);
Line Deleted : user_pref("CT2724386.BrowserCompStateIsOpen_1366729482000", true);
Line Deleted : user_pref("CT2724386.BrowserCompStateIsOpen_1367226373000", true);
Line Deleted : user_pref("CT2724386.CT2724407.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CT2724431.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CT2727162.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CT2727622.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CT2727646.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CT2727678.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CT2727750.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CTID", "ct2724407");
Line Deleted : user_pref("CT2724386.CommunitiesChangesLastCheckTime", "Wed Apr 25 2012 23:13:48 GMT+0200");
Line Deleted : user_pref("CT2724386.CommunitiesChangesLastUrl", "hxxp://grouping.services.conduit.com/GroupingRequest.ctp?type=ToolbarsInfo&ctids=CT2724407,CT2724431,CT2727162,CT2727622,CT2727646,CT2727678,CT2727750[...]
Line Deleted : user_pref("CT2724386.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CurrentServerDate", "26-8-2013");
Line Deleted : user_pref("CT2724386.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2724386.DialogsGetterLastCheckTime", "Sat Aug 24 2013 07:29:01 GMT+0200");
Line Deleted : user_pref("CT2724386.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2724386.FirstServerDate", "26-2-2011");
Line Deleted : user_pref("CT2724386.FirstTime", true);
Line Deleted : user_pref("CT2724386.FirstTimeFF3", true);
Line Deleted : user_pref("CT2724386.FirstTimeSettingsDone", true);
Line Deleted : user_pref("CT2724386.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2724386.GroupingLastCheckTime", "Wed Apr 25 2012 23:13:48 GMT+0200");
Line Deleted : user_pref("CT2724386.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2724386.GroupingLastResponse", false);
Line Deleted : user_pref("CT2724386.GroupingLastServerUpdateTime", "129428537538270000");
Line Deleted : user_pref("CT2724386.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2724386.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2724386.HasUserGlobalKeys", true);
Line Deleted : user_pref("CT2724386.Initialize", true);
Line Deleted : user_pref("CT2724386.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2724386.InstallationAndCookieDataSentCount", 3);
Line Deleted : user_pref("CT2724386.InstallationId", "IncrediMail_MediaBar_2.exe");
Line Deleted : user_pref("CT2724386.InstallationType", "ConduitIntegration");
Line Deleted : user_pref("CT2724386.InstalledDate", "Sat Feb 26 2011 08:43:57 GMT+0100");
Line Deleted : user_pref("CT2724386.InvalidateCache", false);
Line Deleted : user_pref("CT2724386.IsGrouping", false);
Line Deleted : user_pref("CT2724386.IsMulticommunity", false);
Line Deleted : user_pref("CT2724386.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2724386.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2724386.LanguagePackLastCheckTime", "Sat Feb 26 2011 08:43:59 GMT+0100");
Line Deleted : user_pref("CT2724386.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2724386.LastLogin_2.7.2.0", "Sun Feb 27 2011 00:15:55 GMT+0100");
Line Deleted : user_pref("CT2724386.LastLogin_3.12.2.3", "Fri Jun 01 2012 20:56:28 GMT+0200");
Line Deleted : user_pref("CT2724386.LastLogin_3.13.0.6", "Tue Jul 17 2012 13:26:28 GMT+0200");
Line Deleted : user_pref("CT2724386.LastLogin_3.14.1.0", "Thu Aug 23 2012 11:29:26 GMT+0200");
Line Deleted : user_pref("CT2724386.LastLogin_3.15.1.0", "Wed Mar 06 2013 09:40:34 GMT+0100");
Line Deleted : user_pref("CT2724386.LastLogin_3.18.0.7", "Mon Jul 15 2013 20:46:49 GMT+0200");
Line Deleted : user_pref("CT2724386.LastLogin_3.19.0.3", "Mon Aug 26 2013 08:31:09 GMT+0200");
Line Deleted : user_pref("CT2724386.LatestVersion", "3.19.0.3");
Line Deleted : user_pref("CT2724386.Locale", "en");
Line Deleted : user_pref("CT2724386.LoginCache", 4);
Line Deleted : user_pref("CT2724386.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2724386.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2724386.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2724386.MyStuffEnabledAtInstallation", true);
Line Deleted : user_pref("CT2724386.RadioIsPodcast", false);
Line Deleted : user_pref("CT2724386.RadioLastCheckTime", "Sat Feb 26 2011 08:43:58 GMT+0100");
Line Deleted : user_pref("CT2724386.RadioLastUpdateIPServer", "0");
Line Deleted : user_pref("CT2724386.RadioMediaID", "21080119");
Line Deleted : user_pref("CT2724386.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2724386.RadioMenuSelectedID", "EBRadioMenu_CT272438621080119");
Line Deleted : user_pref("CT2724386.RadioStationName", "Royal-Radio%20");
Line Deleted : user_pref("CT2724386.RadioStationURL", "");
Line Deleted : user_pref("CT2724386.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2724386&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2724386.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2724386.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2724386&q=");
Line Deleted : user_pref("CT2724386.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2724386.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.SearchInNewTabLastCheckTime", "Sat Feb 26 2011 08:43:59 GMT+0100");
Line Deleted : user_pref("CT2724386.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID&UM=UM_ID");
Line Deleted : user_pref("CT2724386.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2724386.SearchProtectorToolbarDisabled", true);
Line Deleted : user_pref("CT2724386.ServiceMapLastCheckTime", "Mon Aug 26 2013 08:31:06 GMT+0200");
Line Deleted : user_pref("CT2724386.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2724386.SettingsLastCheckTime", "Sat Feb 26 2011 08:43:57 GMT+0100");
Line Deleted : user_pref("CT2724386.SettingsLastUpdate", "1298372953");
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsLastCheck", "Sat Feb 26 2011 08:43:57 GMT+0100");
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsLastUpdate", "1246790578");
Line Deleted : user_pref("CT2724386.ToolbarDisabled", true);
Line Deleted : user_pref("CT2724386.ToolbarShrinkedFromSetup", false);
Line Deleted : user_pref("CT2724386.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2724386");
Line Deleted : user_pref("CT2724386.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
Line Deleted : user_pref("CT2724386.UserID", "UN44288507094877940");
Line Deleted : user_pref("CT2724386.ValidationData_Toolbar", 0);
Line Deleted : user_pref("CT2724386.WeatherNetwork", "");
Line Deleted : user_pref("CT2724386.WeatherPollDate", "Sun Feb 27 2011 00:15:56 GMT+0100");
Line Deleted : user_pref("CT2724386.WeatherUnit", "C");
Line Deleted : user_pref("CT2724386.alertChannelId", "1116652");
Line Deleted : user_pref("CT2724386.clientLogIsEnabled", true);
Line Deleted : user_pref("CT2724386.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2724386.ct2724407.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2724386.ct2724407.FirstTimeSettingsDone", true);
Line Deleted : user_pref("CT2724386.ct2724407.GroupingInvalidateCache", false);
Line Deleted : user_pref("CT2724386.ct2724407.GroupingLastCheckTime", "Wed Apr 25 2012 23:13:48 GMT+0200");
Line Deleted : user_pref("CT2724386.ct2724407.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2724386.ct2724407.GroupingLastResponse", false);
Line Deleted : user_pref("CT2724386.ct2724407.GroupingLastServerUpdateTime", "129428749243100000");
Line Deleted : user_pref("CT2724386.ct2724407.InvalidateCache", false);
Line Deleted : user_pref("CT2724386.ct2724407.LanguagePackLastCheckTime", "Mon Aug 26 2013 08:31:09 GMT+0200");
Line Deleted : user_pref("CT2724386.ct2724407.Locale", "de");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastCheckTime", "Sat Feb 26 2011 08:43:58 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastUpdateServer", "129249047784100000");
Line Deleted : user_pref("CT2724386.ct2724407.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2724407&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2724386.ct2724407.SearchInNewTabLastCheckTime", "Mon Aug 26 2013 08:31:07 GMT+0200");
Line Deleted : user_pref("CT2724386.ct2724407.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2724386.ct2724407.SettingsLastCheckTime", "Mon Aug 26 2013 08:31:06 GMT+0200");
Line Deleted : user_pref("CT2724386.ct2724407.SettingsLastUpdate", "1377486721");
Line Deleted : user_pref("CT2724386.ct2724407.ThirdPartyComponentsLastCheck", "Sat Feb 26 2011 08:43:57 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.ThirdPartyComponentsLastUpdate", "1255348257");
Line Deleted : user_pref("CT2724386.ct2724407.toolbarAppMetaDataLastCheckTime", "Mon Aug 26 2013 08:31:09 GMT+0200");
Line Deleted : user_pref("CT2724386.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...]
Line Deleted : user_pref("CT2724386.homepageProtectorEnableByLogin", true);
Line Deleted : user_pref("CT2724386.initDone", true);
Line Deleted : user_pref("CT2724386.myStuffEnabled", true);
Line Deleted : user_pref("CT2724386.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2724386.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2724386.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2724386.revertSettingsEnabled", true);
Line Deleted : user_pref("CT2724386.searchProtectorDialogDelayInSec", 10);
Line Deleted : user_pref("CT2724386.searchProtectorEnableByLogin", true);
Line Deleted : user_pref("CT2724386.testingCtid", "");
Line Deleted : user_pref("CT2724386.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2724386.usagesFlag", 2);
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/ct2724407/CT2724386", "\"604125ae99b947dc64903f7c84a8ab8f3\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=ct2724407", "\"1367226872\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"803651ba7facb1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.5.1", "\"8028f138140cc1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.2.3", "\"4ead38b3e6bcd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0e0a4327275cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.1.0", "\"0343677cfb1cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18.0.7", "\"0343677cfb1cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.19.0.3", "\"97e416bb586ce1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2724386", "\"9971ee9815a5fc569766cf6ddcaaca8e\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"f9fa8a8e42cd88c8ac04338185306727\"");
Line Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Line Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Line Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2724386,ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2724386");
Line Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon May 30 2011 14:01:46 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Fri Jul 15 2011 18:30:50 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Line Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Line Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Fri Jul 15 2011 18:30:34 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Line Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Line Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Line Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Line Deleted : user_pref("CommunityToolbar.alert.userId", "1934532e-1b04-425e-ac9c-127cd65c85b0");
Line Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Feb 26 2011 08:43:58 GMT+0100");
Line Deleted : user_pref("CommunityToolbar.globalUserId", "8e19dcac-d900-42cc-b648-c89400dba742");
Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Fri Jul 15 2011 19:00:52 GMT+0200");
Line Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Line Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Fri Jul 15 2011 18:30:34 GMT+0200");
Line Deleted : user_pref("ConduitEngine.FirstServerDate", "05/30/2011 15");
Line Deleted : user_pref("ConduitEngine.FirstTime", true);
Line Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Line Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Line Deleted : user_pref("ConduitEngine.Initialize", true);
Line Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Line Deleted : user_pref("ConduitEngine.InstalledDate", "Mon May 30 2011 14:01:45 GMT+0200");
Line Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Line Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Line Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Line Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Fri Jul 15 2011 18:30:34 GMT+0200");
Line Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Fri Jul 15 2011 18:30:34 GMT+0200");
Line Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Fri Jul 15 2011 18:30:34 GMT+0200");
Line Deleted : user_pref("ConduitEngine.UserID", "UN04513357280686048");
Line Deleted : user_pref("ConduitEngine.componentAlertEnabled", false);
Line Deleted : user_pref("ConduitEngine.engineLocale", "de");
Line Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Fri Jul 15 2011 18:30:34 GMT+0200");
Line Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Fri Jul 15 2011 18:30:34 GMT+0200");
Line Deleted : user_pref("ConduitEngine.initDone", true);
Line Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{8E9E3331-D360-4f87-8803-52DE43566502}\":{\"descriptor\":\"C:\\\\Program Files\\\\Web Assistant\\\\Firefox\",\"mtim[...]
Line Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.sweetim.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"h[...]
Line Deleted : user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=toolbar|babsrc=tb_ss|invocationType=tb50-ie-aolsoftonic-tbsbox-en-us|invocationType=tb50-ff-aolsoftonic[...]
Line Deleted : user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.mywebsearch.com\":\"searc[...]
[ File : C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\r74y5ue3.default-1372489467664\prefs.js ]
-\\ Google Chrome v
[ File : C:\Users\Sigrid\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [28930 octets] - [27/08/2013 13:06:58]
AdwCleaner[R1].txt - [28921 octets] - [27/08/2013 13:13:09]
AdwCleaner[S0].txt - [29064 octets] - [27/08/2013 13:13:29]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [29125 octets] ########## Code:
A~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.4 (08.22.2013:1)
OS: Windows 7 Home Premium x64
Ran by Sigrid on 27.08.2013 at 13:30:51,61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.08.2013 at 13:34:42,30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-08-2013 01
Ran by Sigrid (administrator) on 27-08-2013 13:38:05
Running from C:\Users\Sigrid\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(AVM Berlin) C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(AVM Berlin) C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe
(AVM Berlin) C:\Program Files (x86)\FRITZ!DSL\StCenter.exe
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(ACD Systems, Ltd.) C:\Program Files (x86)\ACD Systems\DevDetect\DevDetect.exe
() C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
(SAMSUNG ELECTRONICS) C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
() C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKCU\...\Run: [Logitech Vid] - C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe [5458704 2009-07-16] (Logitech Inc.)
HKCU\...\Run: [EPLTarget\P0000000000000001] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-10-31] (SEIKO EPSON CORPORATION)
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1093464 2013-06-21] (Garmin Ltd or its subsidiaries)
MountPoints2: {2fc90b86-4d6d-11e1-b4ee-001c4af2c242} - F:\setup.exe -a
MountPoints2: {b96e3044-6c9c-11df-ad7b-806e6f6e6963} - E:\SETUP.EXE /AUTORUN
MountPoints2: {dd7a2bad-b138-11df-a743-90fba6e1659a} - G:\pushinst.exe
MountPoints2: {dd7a2bb0-b138-11df-a743-90fba6e1659a} - K:\pushinst.exe
HKLM-x32\...\Run: [Hotkey Utility] - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [629280 2009-08-18] ()
HKLM-x32\...\Run: [EgisTecLiveUpdate] - C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-04] (Egis Technology Inc.)
HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [1794048 2008-10-28] (AVM Berlin)
HKLM-x32\...\Run: [Camera Detector] - C:\PROGRA~2\ACDSYS~1\DEVDET~1\DEVDET~1.EXE [208896 2002-12-18] (ACD Systems, Ltd.)
HKLM-x32\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] ()
HKLM-x32\...\Run: [SMSTray] - C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe [484888 2009-03-21] (SAMSUNG ELECTRONICS)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [220744 2011-12-16] (Geek Software GmbH)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-02] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [EEventManager] - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [162336 2009-07-22] ()
Startup: C:\Users\Sigrid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk
ShortcutTarget: FRITZ!DSL Protect.lnk -> C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
Startup: C:\Users\Sigrid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
ShortcutTarget: FRITZ!DSL Startcenter.lnk -> C:\Program Files (x86)\FRITZ!DSL\StCenter.exe (AVM Berlin)
==================== Internet (Whitelisted) ====================
ProxyServer: 178.217.14.33:9090
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_m3203&r=17360810z516pe4g5v135w46n1t73q
URLSearchHook: (No Name) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - No File
URLSearchHook: (No Name) - {238d4b4c-d63c-42a7-b6d8-dc96c8c0f5b9} - No File
SearchScopes: HKCU - {2BFF74D9-71F7-42B1-9C29-417A6BD92012} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=867034&p={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll No File
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKCU - No Name - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - No File
Toolbar: HKCU - No Name - {238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9} - No File
Handler: msdaipp - No CLSID Value -
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Winsock: Catalog5 07 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880] (AVM Berlin)
Winsock: Catalog9 01 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880] (AVM Berlin)
Winsock: Catalog9 02 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880] (AVM Berlin)
Winsock: Catalog9 03 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880] (AVM Berlin)
Winsock: Catalog9 14 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880] (AVM Berlin)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default
FF SelectedSearchEngine: Yahoo
FF Homepage: hxxp://www.Google.de
FF Keyword.URL: hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=867034&p=
FF NetworkProxy: "backup.ftp", "178.217.14.33"
FF NetworkProxy: "backup.ftp_port", 9090
FF NetworkProxy: "backup.gopher", "188.94.228.46"
FF NetworkProxy: "backup.gopher_port", 80
FF NetworkProxy: "backup.socks", "178.217.14.33"
FF NetworkProxy: "backup.socks_port", 9090
FF NetworkProxy: "backup.ssl", "178.217.14.33"
FF NetworkProxy: "backup.ssl_port", 9090
FF NetworkProxy: "ftp", "178.217.14.33"
FF NetworkProxy: "ftp_port", 9090
FF NetworkProxy: "gopher", "188.94.228.46"
FF NetworkProxy: "gopher_port", 80
FF NetworkProxy: "http", "178.217.14.33"
FF NetworkProxy: "http_port", 9090
FF NetworkProxy: "no_proxies_on", "localhost,127.0.0.1"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "178.217.14.33"
FF NetworkProxy: "socks_port", 9090
FF NetworkProxy: "ssl", "178.217.14.33"
FF NetworkProxy: "ssl_port", 9090
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\Sigrid\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Garmin Communicator - C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
FF Extension: DownloadHelper - C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: No Name - C:\Users\Sigrid\AppData\Roaming\Mozilla\Firefox\Profiles\qyurwghw.default\Extensions\{e798194d-0d55-e397-a59b-ad2c3b2591ae}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
Chrome:
=======
CHR HomePage: "homepage": "hxxp://start.iminent.com/?appId=E48A8E4D-E32D-49C4-85CA-54F39671A82B",
CHR RestoreOnStartup: "hxxp://start.iminent.com/?appId=E48A8E4D-E32D-49C4-85CA-54F39671A82B"
==================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-02] (Avira Operations GmbH & Co. KG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [364544 2008-10-28] (AVM Berlin)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [219992 2013-06-21] (Garmin Ltd or its subsidiaries)
R2 IGDCTRL; C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE [87344 2007-09-04] (AVM Berlin)
R2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
R2 yksvc; C:\Windows\System32\yk62x64.dll [496128 2009-09-28] (Marvell)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-30] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-30] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-30] (Avira Operations GmbH & Co. KG)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2008-10-28] (AVM Berlin)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2008-10-28] (AVM GmbH)
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R2 npf; C:\Windows\System32\drivers\npf.sys [47632 2010-01-27] (CACE Technologies, Inc.)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
S3 cpuz132; \??\C:\Users\Sigrid\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-27 13:34 - 2013-08-27 13:34 - 00000626 _____ C:\Users\Sigrid\Desktop\JRT.txt
2013-08-27 13:25 - 2013-08-27 13:25 - 00000000 ____D C:\Windows\ERUNT
2013-08-27 13:22 - 2013-08-27 13:22 - 01021434 _____ (Thisisu) C:\Users\Sigrid\Desktop\JRT.exe
2013-08-27 13:17 - 2013-08-27 13:17 - 00029234 _____ C:\Users\Sigrid\Desktop\AdwCleaner[S0].txt
2013-08-27 13:11 - 2013-08-27 13:11 - 00994642 _____ C:\Users\Sigrid\Desktop\adwcleaner.exe
2013-08-27 12:54 - 2013-08-27 13:13 - 00000000 ____D C:\AdwCleaner
2013-08-27 06:49 - 2013-08-27 06:49 - 00000000 ____D C:\FRST
2013-08-26 15:59 - 2013-08-27 07:35 - 00000000 ____D C:\Users\Sigrid\Desktop\PC
2013-08-26 12:09 - 2013-08-26 12:09 - 00000000 _____ C:\Users\Sigrid\defogger_reenable
2013-08-21 14:27 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-21 14:27 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-21 14:27 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-21 14:27 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-21 14:27 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-21 14:27 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-21 14:27 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-21 14:27 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-21 14:27 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-21 14:27 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-21 14:27 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-21 14:27 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-21 14:27 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-21 14:27 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-21 11:47 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-21 11:47 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-21 11:47 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-21 11:47 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-21 11:47 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-21 11:47 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-21 11:47 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-21 11:47 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-21 11:47 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-21 11:47 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-21 11:47 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-21 11:47 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-21 11:47 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-21 11:47 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-21 11:46 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-21 11:46 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-14 07:41 - 2013-08-26 10:35 - 00000000 ____D C:\Windows\system32\MRT
2013-07-31 19:28 - 2013-08-27 13:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-31 19:28 - 2013-07-31 19:28 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-31 10:13 - 2013-07-31 10:13 - 464292448 _____ C:\Windows\MEMORY.DMP
2013-07-31 10:13 - 2013-07-31 10:13 - 00274784 _____ C:\Windows\Minidump\073113-28969-01.dmp
2013-07-31 09:41 - 2013-07-31 09:41 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-07-31 09:41 - 2013-07-31 09:41 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-07-31 09:41 - 2013-07-31 09:41 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-07-31 09:41 - 2013-07-31 09:41 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-07-31 09:41 - 2013-07-31 09:41 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-07-31 09:41 - 2013-07-31 09:41 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-07-31 09:41 - 2013-07-31 09:41 - 00000000 ____D C:\Program Files\Java
2013-07-31 09:39 - 2013-07-31 09:40 - 33150376 _____ (Oracle Corporation) C:\Users\Sigrid\Desktop\jre-7u25-windows-x64.exe
2013-07-31 09:37 - 2013-07-31 09:37 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-31 09:37 - 2013-07-31 09:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-31 09:37 - 2013-07-31 09:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-31 09:37 - 2013-07-31 09:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-31 09:37 - 2013-07-31 09:37 - 00000000 ____D C:\Program Files (x86)\Java
==================== One Month Modified Files and Folders =======
2013-08-27 13:37 - 2013-08-27 13:37 - 01578852 _____ (Farbar) C:\Users\Sigrid\Downloads\FRST64.exe
2013-08-27 13:34 - 2013-08-27 13:34 - 00000626 _____ C:\Users\Sigrid\Desktop\JRT.txt
2013-08-27 13:32 - 2013-07-31 19:28 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-27 13:25 - 2013-08-27 13:25 - 00000000 ____D C:\Windows\ERUNT
2013-08-27 13:23 - 2010-08-26 21:43 - 00000000 ____D C:\Users\Sigrid\AppData\Roaming\FRITZ!
2013-08-27 13:23 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-27 13:23 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-27 13:22 - 2013-08-27 13:22 - 01021434 _____ (Thisisu) C:\Users\Sigrid\Desktop\JRT.exe
2013-08-27 13:17 - 2013-08-27 13:17 - 00029234 _____ C:\Users\Sigrid\Desktop\AdwCleaner[S0].txt
2013-08-27 13:15 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-27 13:14 - 2013-07-25 15:46 - 00004200 _____ C:\Windows\setupact.log
2013-08-27 13:14 - 2009-10-12 13:56 - 02108174 _____ C:\Windows\PFRO.log
2013-08-27 13:13 - 2013-08-27 12:54 - 00000000 ____D C:\AdwCleaner
2013-08-27 13:13 - 2010-05-31 12:13 - 02024703 _____ C:\Windows\WindowsUpdate.log
2013-08-27 13:11 - 2013-08-27 13:11 - 00994642 _____ C:\Users\Sigrid\Desktop\adwcleaner.exe
2013-08-27 12:56 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-08-27 07:35 - 2013-08-26 15:59 - 00000000 ____D C:\Users\Sigrid\Desktop\PC
2013-08-27 06:49 - 2013-08-27 06:49 - 00000000 ____D C:\FRST
2013-08-26 14:47 - 2010-08-26 20:50 - 00000000 ____D C:\Users\Sigrid
2013-08-26 14:44 - 2013-07-14 09:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-26 14:44 - 2012-12-28 20:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-26 14:44 - 2010-08-27 10:08 - 00000000 ____D C:\Users\Sigrid\AppData\Roaming\vlc
2013-08-26 14:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2013-08-26 14:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-26 14:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-08-26 14:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-08-26 14:44 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-08-26 14:41 - 2010-08-26 20:59 - 00000000 ____D C:\Users\Sigrid\AppData\Local\Google
2013-08-26 12:09 - 2013-08-26 12:09 - 00000000 _____ C:\Users\Sigrid\defogger_reenable
2013-08-26 10:35 - 2013-08-14 07:41 - 00000000 ____D C:\Windows\system32\MRT
2013-08-21 14:25 - 2010-05-13 03:29 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-08-21 14:25 - 2010-05-13 03:29 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-08-21 14:25 - 2009-07-14 07:13 - 01519798 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-21 14:22 - 2010-08-27 09:35 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-21 14:22 - 2009-07-14 04:34 - 00000531 _____ C:\Windows\win.ini
2013-08-11 15:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-31 19:28 - 2013-07-31 19:28 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-31 19:28 - 2012-05-20 23:23 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-31 19:28 - 2011-05-20 05:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-31 19:27 - 2010-08-29 08:34 - 00000000 ____D C:\Users\Sigrid\AppData\Local\Adobe
2013-07-31 11:42 - 2010-08-27 17:53 - 00000000 ___RD C:\Users\Sigrid\Desktop\Verknüpfungen
2013-07-31 10:19 - 2013-07-22 08:23 - 00000000 ____D C:\Users\Sigrid\Documents\Bandicam
2013-07-31 10:13 - 2013-07-31 10:13 - 464292448 _____ C:\Windows\MEMORY.DMP
2013-07-31 10:13 - 2013-07-31 10:13 - 00274784 _____ C:\Windows\Minidump\073113-28969-01.dmp
2013-07-31 10:13 - 2012-01-20 19:54 - 00000000 ____D C:\Windows\Minidump
2013-07-31 09:41 - 2013-07-31 09:41 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-07-31 09:41 - 2013-07-31 09:41 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-07-31 09:41 - 2013-07-31 09:41 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-07-31 09:41 - 2013-07-31 09:41 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-07-31 09:41 - 2013-07-31 09:41 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-07-31 09:41 - 2013-07-31 09:41 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-07-31 09:41 - 2013-07-31 09:41 - 00000000 ____D C:\Program Files\Java
2013-07-31 09:40 - 2013-07-31 09:39 - 33150376 _____ (Oracle Corporation) C:\Users\Sigrid\Desktop\jre-7u25-windows-x64.exe
2013-07-31 09:37 - 2013-07-31 09:37 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-31 09:37 - 2013-07-31 09:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-31 09:37 - 2013-07-31 09:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-31 09:37 - 2013-07-31 09:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-31 09:37 - 2013-07-31 09:37 - 00000000 ____D C:\Program Files (x86)\Java
2013-07-31 09:37 - 2012-06-07 08:33 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2013-07-31 09:37 - 2011-10-31 18:16 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-07-28 07:05 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
Files to move or delete:
====================
C:\Users\Sigrid\AppData\Local\Temp\AMPing.exe
C:\Users\Sigrid\AppData\Local\Temp\bdfilters.dll
C:\Users\Sigrid\AppData\Local\Temp\InstallManager_BAB_BAB.exe
C:\Users\Sigrid\AppData\Local\Temp\install_flashplayer11x32_mssd_aaa_aih.exe
C:\Users\Sigrid\AppData\Local\Temp\LyricsContainertmp.exe
C:\Users\Sigrid\AppData\Local\Temp\Quarantine.exe
C:\Users\Sigrid\AppData\Local\Temp\SeeSimilarSetup.exe
C:\Users\Sigrid\AppData\Local\Temp\_is1AA2.exe
C:\Users\Sigrid\AppData\Local\Temp\{D6324573-C889-4632-8CF4-089ACB9A27EA}\ISSetup.dll
C:\Users\Sigrid\AppData\Local\Temp\{D6324573-C889-4632-8CF4-089ACB9A27EA}\_Setup.dll
C:\Users\Sigrid\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\CbsProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\CompatProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\DismCore.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\DismCorePS.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\DismHost.exe
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\DismProv.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\DmiProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\FolderProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\IntlProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\LogProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\MsiProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\OSProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\SmiProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\TransmogProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\UnattendProvider.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\wdscore.dll
C:\Users\Sigrid\AppData\Local\Temp\2CFE03AE-B1BA-4C20-BCD9-CB74B3572AA7\WimProvider.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-22 15:19
==================== End Of Log ============================ --- --- --- |