Nighty99 | 26.08.2013 19:44 | ihavenet auf XP Auf einem XP Rechner öffnet sich in Firefox die ihavenet Seite sowie diverse andere Werbeseiten.
Wie es aussieht ist auch ASK mit dabei.
FRST-Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-08-2013
Ran by Plank (administrator) on 26-08-2013 20:39:38
Running from C:\Dokumente und Einstellungen\Plank\Eigene Dateien\Downloads
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avguard.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(VIA Technologies, Inc.) C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe
(Inprise Corporation) C:\Programme\InterBase Corp\InterBase\Bin\ibguard.exe
() C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
({StringFileInfo_CompanyName}) C:\Programme\Ask.com\Updater\Updater.exe
(Brother Industries, Ltd.) C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avgnt.exe
(Inprise Corporation) C:\Programme\InterBase Corp\InterBase\Bin\ibserver.exe
(Brother Industries, Ltd.) C:\Programme\Brother\ControlCenter3\brccMCtl.exe
(Nero AG) C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\PROGRA~1\MESSEN~1\Msmsgs.exe
(Nero AG) C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe
(Brother Industries, Ltd.) C:\Programme\Brother\Brmfcmon\BrMfcmon.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.bin
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE
(TeamViewer GmbH) C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) c:\dokume~1\plank\lokale~1\temp\teamviewer\version8\TeamViewer_Desktop.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HDAudDeck] - C:\Programme\VIA\VIAudioi\HDADeck\HDeck.exe [29835264 2008-06-27] (VIA Technologies, Inc.)
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13529088 2008-05-02] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - nwiz.exe /install [x]
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [86016 2008-05-02] (NVIDIA Corporation)
HKLM\...\Run: [NeroFilterCheck] - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [EPSON Stylus D88 Series] - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE /P23 "EPSON Stylus D88 Series" /O6 "USB002" /M "Stylus D88" [x]
HKLM\...\Run: [InterBase Guardian] - C:\Programme\InterBase Corp\InterBase\Bin\ibguard.exe [22016 2000-06-23] (Inprise Corporation)
HKLM\...\Run: [Samsung PanelMgr] - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [524288 2008-05-07] ()
HKLM\...\Run: [] - [x]
HKLM\...\Run: [ApnUpdater] - C:\Programme\Ask.com\Updater\Updater.exe [888488 2011-09-08] ({StringFileInfo_CompanyName})
HKLM\...\Run: [SSBkgdUpdate] - C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM\...\Run: [BrMfcWnd] - C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe [1150976 2009-01-19] (Brother Industries, Ltd.)
HKLM\...\Run: [ControlCenter3] - C:\Programme\Brother\ControlCenter3\brctrcen.exe [114688 2009-01-09] (Brother Industries, Ltd.)
HKLM\...\Run: [avgnt] - C:\Programme\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [PaperPort PTD] - "C:\Programme\ScanSoft\PaperPort\pptd40nt.exe" [x]
HKLM\...\Run: [IndexSearch] - C:\Programme\ScanSoft\PaperPort\IndexSearch.exe [46368 2007-10-11] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort11reminder] - C:\Programme\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKLM\...\Command Processor: <======= ATTENTION
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe [139264 2006-11-16] (Nero AG)
HKCU\...\Run: [MSMSGS] - C:\PROGRA~1\MESSEN~1\Msmsgs.exe [1660952 2008-06-02] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMFirstStart.exe [ 2006-11-16] (Nero AG)
HKU\user\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe [ 2006-11-16] (Nero AG)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Programme\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\VR-NetWorld Auftragsprüfung.lnk
ShortcutTarget: VR-NetWorld Auftragsprüfung.lnk -> C:\Programme\VR-NetWorld\vrtoolcheckorder.exe (VR-NetWorld Software)
Startup: C:\Dokumente und Einstellungen\Plank\Startmenü\Programme\Autostart\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
BHO: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU -Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Winsock: Catalog9 01 C:\Programme\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Programme\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 14 C:\Programme\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla\Firefox\Profiles\8n1stvgc.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla\Firefox\Profiles\8n1stvgc.default\searchplugins\duckduckgo.xml
FF Extension: Bitdefender QuickScan - C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla\Firefox\Profiles\8n1stvgc.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF Extension: Default - C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [84024 2013-07-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-02] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [117656 2013-08-24] (Mozilla Foundation)
S3 NBService; C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2006-11-10] (Nero AG)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-04-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-01] (Avira Operations GmbH & Co. KG)
R3 BrScnUsb; C:\Windows\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
S2 DgiVecp; C:\WINDOWS\system32\Drivers\DgiVecp.sys [41984 2007-08-13] (Samsung Electronics Co., Ltd.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 monfilt; C:\Windows\System32\drivers\monfilt.sys [1389056 2008-02-14] (Creative Technology Ltd.)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [54016 2008-01-29] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [22016 2008-01-29] (NVIDIA Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [277376 2008-05-21] (VIA Technologies, Inc.)
S4 IntelIde; No ImagePath
S2 SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-26 20:12 - 2013-08-26 20:13 - 00000000 ____D C:\AdwCleaner
2013-08-26 20:02 - 2013-08-26 20:03 - 00000000 ____D C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\QuickScan
2013-08-26 19:21 - 2013-08-26 19:21 - 00000000 ____D C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Malwarebytes
2013-08-26 19:20 - 2013-08-26 19:20 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-26 19:20 - 2013-08-26 19:20 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-26 19:20 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-08-26 19:04 - 2013-08-26 19:04 - 00000000 ____D C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\TeamViewer
2013-08-26 19:00 - 2013-08-26 19:00 - 00000000 ____D C:\WINDOWS\pss
2013-08-26 18:55 - 2013-08-26 18:55 - 00000000 ____D C:\WINDOWS\CSC
2013-08-24 22:21 - 2013-08-24 22:21 - 00000104 _____ C:\Dokumente und Einstellungen\Plank\Desktop\Internet.lnk
2013-08-24 22:19 - 2013-08-24 22:19 - 00000696 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
2013-08-24 22:19 - 2013-08-24 22:19 - 00000000 ____D C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla
2013-08-24 20:01 - 2013-08-24 22:19 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-08-18 22:15 - 2013-08-18 22:15 - 00015776 _____ C:\WINDOWS\KB2863058.log
2013-08-18 22:15 - 2013-08-18 22:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-18 22:15 - 2013-08-18 22:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-18 22:15 - 2013-08-18 22:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-18 22:15 - 2013-08-18 22:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-18 22:10 - 2013-08-18 22:15 - 00024511 _____ C:\WINDOWS\KB2859537.log
2013-08-18 22:10 - 2013-08-18 22:15 - 00022752 _____ C:\WINDOWS\KB2850869.log
2013-08-18 22:09 - 2013-08-18 22:13 - 00112408 _____ C:\WINDOWS\KB2862772-IE7.log
2013-07-29 20:02 - 2013-08-09 12:34 - 00000000 ____D C:\Programme\Mozilla Thunderbird
==================== One Month Modified Files and Folders =======
2013-08-26 20:36 - 2013-01-14 16:30 - 00000000 ____D C:\WINDOWS\system32\NtmsData
2013-08-26 20:36 - 2011-07-04 08:05 - 00000226 _____ C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
2013-08-26 20:35 - 2009-06-19 11:37 - 00000000 ____D C:\WINDOWS\Registration
2013-08-26 20:13 - 2013-08-26 20:12 - 00000000 ____D C:\AdwCleaner
2013-08-26 20:03 - 2013-08-26 20:02 - 00000000 ____D C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\QuickScan
2013-08-26 19:53 - 2009-06-19 11:39 - 01119025 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-26 19:46 - 2012-04-20 09:20 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-26 19:26 - 2009-06-19 11:46 - 00032532 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-26 19:21 - 2013-08-26 19:21 - 00000000 ____D C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Malwarebytes
2013-08-26 19:20 - 2013-08-26 19:20 - 00000756 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-26 19:20 - 2013-08-26 19:20 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-26 19:20 - 2009-06-19 12:07 - 00000000 ___RD C:\Programme
2013-08-26 19:13 - 2009-06-19 12:07 - 01045582 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-26 19:10 - 2009-06-19 12:09 - 00000259 _____ C:\WINDOWS\wiadebug.log
2013-08-26 19:09 - 2012-12-14 14:31 - 00000300 _____ C:\WINDOWS\Tasks\XRGFRW.job
2013-08-26 19:09 - 2009-06-19 12:09 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-08-26 19:09 - 2009-06-19 11:55 - 00182038 _____ C:\WINDOWS\system32\nvapps.xml
2013-08-26 19:09 - 2009-06-19 11:46 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-26 19:09 - 2008-04-14 14:00 - 00012598 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-26 19:04 - 2013-08-26 19:04 - 00000000 ____D C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\TeamViewer
2013-08-26 19:00 - 2013-08-26 19:00 - 00000000 ____D C:\WINDOWS\pss
2013-08-26 18:55 - 2013-08-26 18:55 - 00000000 ____D C:\WINDOWS\CSC
2013-08-25 14:23 - 2009-09-25 15:44 - 00000300 ___SH C:\Dokumente und Einstellungen\Plank\ntuser.ini
2013-08-25 14:23 - 2009-09-25 15:44 - 00000000 ____D C:\Dokumente und Einstellungen\Plank
2013-08-24 22:21 - 2013-08-24 22:21 - 00000104 _____ C:\Dokumente und Einstellungen\Plank\Desktop\Internet.lnk
2013-08-24 22:19 - 2013-08-24 22:19 - 00000696 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
2013-08-24 22:19 - 2013-08-24 22:19 - 00000000 ____D C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla
2013-08-24 22:19 - 2013-08-24 20:01 - 00000000 ____D C:\Programme\Mozilla Firefox
2013-08-24 21:05 - 2012-05-11 10:13 - 00000000 ____D C:\Programme\Mozilla Maintenance Service
2013-08-24 20:46 - 2009-06-19 11:46 - 00000190 ___SH C:\Dokumente und Einstellungen\user\ntuser.ini
2013-08-21 13:46 - 2012-04-20 09:20 - 00692104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-08-21 13:46 - 2011-05-20 10:50 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-08-20 11:48 - 2012-12-29 20:14 - 00000000 ____D C:\Programme\VR-NetWorld
2013-08-19 06:12 - 2009-06-19 12:03 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-08-18 22:15 - 2013-08-18 22:15 - 00015776 _____ C:\WINDOWS\KB2863058.log
2013-08-18 22:15 - 2013-08-18 22:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-18 22:15 - 2013-08-18 22:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-18 22:15 - 2013-08-18 22:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-18 22:15 - 2013-08-18 22:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-18 22:15 - 2013-08-18 22:10 - 00024511 _____ C:\WINDOWS\KB2859537.log
2013-08-18 22:15 - 2013-08-18 22:10 - 00022752 _____ C:\WINDOWS\KB2850869.log
2013-08-18 22:15 - 2009-06-19 12:08 - 00637814 _____ C:\WINDOWS\system32\TZLog.log
2013-08-18 22:15 - 2009-06-19 12:08 - 00192274 _____ C:\WINDOWS\updspapi.log
2013-08-18 22:15 - 2009-06-19 12:07 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-08-18 22:15 - 2009-06-19 12:07 - 01885592 _____ C:\WINDOWS\FaxSetup.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00913300 _____ C:\WINDOWS\ocgen.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00872701 _____ C:\WINDOWS\tsoc.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00638316 _____ C:\WINDOWS\comsetup.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00583268 _____ C:\WINDOWS\msmqinst.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00384991 _____ C:\WINDOWS\ntdtcsetup.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00331448 _____ C:\WINDOWS\netfxocm.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00130567 _____ C:\WINDOWS\MedCtrOC.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00104638 _____ C:\WINDOWS\ocmsn.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00095527 _____ C:\WINDOWS\tabletoc.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00094668 _____ C:\WINDOWS\msgsocm.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00073223 _____ C:\WINDOWS\iis6.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00001374 _____ C:\WINDOWS\imsins.log
2013-08-18 22:15 - 2009-06-19 12:07 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-08-18 22:13 - 2013-08-18 22:09 - 00112408 _____ C:\WINDOWS\KB2862772-IE7.log
2013-08-18 22:12 - 2009-10-10 12:10 - 00000000 ____D C:\WINDOWS\ie7updates
2013-08-18 22:12 - 2009-06-19 13:00 - 00000000 ____D C:\WINDOWS\system32\de-de
2013-08-09 12:34 - 2013-07-29 20:02 - 00000000 ____D C:\Programme\Mozilla Thunderbird
2013-08-05 19:54 - 2009-09-25 16:16 - 00002477 _____ C:\Dokumente und Einstellungen\Plank\Desktop\Microsoft Word (2).lnk
Files to move or delete:
====================
C:\DOKUME~1\Plank\LOKALE~1\Temp\AskSLib.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\setup.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\_is10B.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\_isF3.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{bd29a8fd-217d-4409-b838-ddaf4a9e9c57}\isrt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{bd29a8fd-217d-4409-b838-ddaf4a9e9c57}\_IsRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{b9a8d165-3be4-4a80-aa39-078457784dc9}\isrt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{b9a8d165-3be4-4a80-aa39-078457784dc9}\_IsRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8815f011-43af-4f50-bbd8-d78ed3d6f5b9}\isrt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8815f011-43af-4f50-bbd8-d78ed3d6f5b9}\_IsRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\BrC3Rgin.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\BrLogRx.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\difxapi.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\MSVCP60.DLL
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Drivers\BrScnFlt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brAutCrp.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccbul.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccchn.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brcccht.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brcccze.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccdan.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccDCtl.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccdut.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brcceng.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccFCtl.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccfile.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccfin.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccfre.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccger.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brcchun.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccimg.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccita.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccjpn.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\BrccMCtl.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccnor.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccpol.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccpor.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccptb.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccrom.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccrus.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccspa.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccsrch.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccsvk.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccswe.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brcctrk.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brcctwn.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccusa.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\brccwia.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\BrCtrCen.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\BrDbgOut.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\BrImgPDF.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lfawd12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lfbmp12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\LFCMP12n.DLL
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lfeps12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lffax12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lflma12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lflmb12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lfmsp12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lfpcx12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\Lfpng12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\LFPNM12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lftif12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lfwfx12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lfwmf12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lfwpg12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\LTDIS12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\ltefx12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\ltfil12n.DLL
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\ltimg12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\ltkrn12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\lttwn12n.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\LTWND12n.DLL
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ControlCenter\RLACMPCAPI.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ContrlCenter\maxutil.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\ContrlCenter\pperr.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndBul.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndChn.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndCht.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndCze.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndDan.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndDut.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndEng.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndFin.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndFrc.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndFre.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndGer.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndHun.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndIta.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndJpn.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndNor.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndPol.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndPor.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndPtb.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndRom.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndRus.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndSpa.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndSvk.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndSwe.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndTrk.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BrmfcwndUsa.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon_NotUninstall\BroSNMP.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\BrDbgOut.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\BrFirmUpdateCheck.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\BRHOOK.DLL
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\brif03a.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\brlm03a.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\BRLMW03A.DLL
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\BrMfcMon.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\BrMfcWnd.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{8502AD48-B630-4534-B724-075608924FC3}\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\Brmfcmon\BrMfimon.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{68ae2bac-390f-4b76-b30e-8276f1120410}\isrt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{68ae2bac-390f-4b76-b30e-8276f1120410}\_IsRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{685773cb-b0cb-40b9-b7a5-468165c2ab6c}\isrt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{685773cb-b0cb-40b9-b7a5-468165c2ab6c}\_IsRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{3a8fb7f9-7eda-4078-90cf-be3016444201}\isrt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{3a8fb7f9-7eda-4078-90cf-be3016444201}\_IsRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{32797030-9F2A-43FD-81C2-B0EE982434A6}\ISSetup.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{32797030-9F2A-43FD-81C2-B0EE982434A6}\_Setup.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{2321DF80-8D24-40E0-B7A6-A66D05DA9AB3}\{D9461574-5FC0-4641-BBDC-D1038B196F55}\BrC3Rgin.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{2321DF80-8D24-40E0-B7A6-A66D05DA9AB3}\{D9461574-5FC0-4641-BBDC-D1038B196F55}\difxapi.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{2321DF80-8D24-40E0-B7A6-A66D05DA9AB3}\{D9461574-5FC0-4641-BBDC-D1038B196F55}\MSVCP60.DLL
C:\DOKUME~1\Plank\LOKALE~1\Temp\{2321DF80-8D24-40E0-B7A6-A66D05DA9AB3}\{D9461574-5FC0-4641-BBDC-D1038B196F55}\Brmfcmon\BrMfcMon.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{2321DF80-8D24-40E0-B7A6-A66D05DA9AB3}\{D9461574-5FC0-4641-BBDC-D1038B196F55}\Brmfcmon\BrMfimon.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\{20eec29f-979e-4792-8283-83cc63c57b0a}\isrt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{20eec29f-979e-4792-8283-83cc63c57b0a}\_IsRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{1986171A-1303-486A-8441-525B393C6C11}\ISSetup.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{1986171A-1303-486A-8441-525B393C6C11}\_Setup.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{0d6c4a58-a878-4315-9657-d2381006dcf8}\isrt.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\{0d6c4a58-a878-4315-9657-d2381006dcf8}\_IsRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_Desktop.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_Resource_de.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_Resource_en.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_Service.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_StaticRes.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\tv_w32.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\tv_w32.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\tv_x64.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\tv_x64.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\uninstall.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\x86\Teamviewer_PrintProcessor.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\TeamViewer\Version8\outlook\TeamViewerMeetingAddIn.dll
C:\DOKUME~1\Plank\LOKALE~1\Temp\pft4.tmp\Disk1\Setup.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\D.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\B.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\8.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\6.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\5.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\4.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\35.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\3.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\21.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\1F.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\1E.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\1A.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\19.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\14.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\13.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\11.dir\InstallFlashPlayer.exe
C:\DOKUME~1\Plank\LOKALE~1\Temp\10.dir\InstallFlashPlayer.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2008-04-14 14:00] - [2009-02-09 13:14] - 0111104 ____A (Microsoft Corporation) f0a7d59af279326528715b206669b86c
C:\Windows\System32\User32.dll
[2008-04-14 14:00] - [2008-04-14 14:00] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 14:00] - [2008-04-14 14:00] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================ OTL Code:
OTL logfile created on: 26.08.2013 20:26:38 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Plank\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,75 Gb Total Physical Memory | 0,87 Gb Available Physical Memory | 49,86% Memory free
3,60 Gb Paging File | 2,78 Gb Available in Paging File | 77,26% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 232,88 Gb Total Space | 207,62 Gb Free Space | 89,15% Space Free | Partition Type: NTFS
Computer Name: NABO-KARLSFELD | User Name: Plank | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\Plank\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Dokumente und Einstellungen\Plank\Eigene Dateien\Downloads\adwcleaner.exe ()
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - c:\Dokumente und Einstellungen\Plank\Lokale Einstellungen\Temp\TeamViewer\Version8\TeamViewer_Desktop.exe (TeamViewer GmbH)
PRC - C:\Dokumente und Einstellungen\Plank\Lokale Einstellungen\Temp\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Dokumente und Einstellungen\Plank\Lokale Einstellungen\Temp\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Programme\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Programme\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Programme\Ask.com\Updater\Updater.exe ({StringFileInfo_CompanyName})
PRC - C:\Programme\Brother\Brmfcmon\BrMfcMon.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Programme\InterBase Corp\InterBase\Bin\ibserver.exe (Inprise Corporation)
PRC - C:\Programme\InterBase Corp\InterBase\Bin\ibguard.exe (Inprise Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Dokumente und Einstellungen\Plank\Eigene Dateien\Downloads\adwcleaner.exe ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\Programme\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Programme\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Programme\Brother\BrUtilities\BrLogAPI.dll ()
MOD - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\cl31cl3.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) -- File not found
DRV - (SSPORT) -- C:\WINDOWS\system32\Drivers\SSPORT.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\WINDOWS\system32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (VIAHdAudAddService) -- C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (monfilt) -- C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\WINDOWS\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (DgiVecp) -- C:\WINDOWS\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3433501987-3011716872-2427280945-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKU\S-1-5-21-3433501987-3011716872-2427280945-1007\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3433501987-3011716872-2427280945-1007\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-3433501987-3011716872-2427280945-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2013.08.24 21:06:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2013.07.29 20:02:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
[2013.08.24 22:19:52 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla\Extensions
[2013.08.26 20:02:54 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla\Firefox\Profiles\8n1stvgc.default\extensions
[2013.08.26 20:02:54 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla\Firefox\Profiles\8n1stvgc.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2013.08.26 20:01:17 | 000,010,316 | ---- | M] () -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla\Firefox\Profiles\8n1stvgc.default\searchplugins\duckduckgo.xml
[2013.08.24 22:19:18 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\browser\extensions
[2013.08.24 22:19:18 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2008.04.14 14:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3433501987-3011716872-2427280945-1007\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] C:\Programme\Ask.com\Updater\Updater.exe ({StringFileInfo_CompanyName})
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [ControlCenter3] C:\Programme\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [EPSON Stylus D88 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE /P23 "EPSON Stylus D88 Series" /O6 "USB002" /M "Stylus D88" File not found
O4 - HKLM..\Run: [InterBase Guardian] C:\Programme\InterBase Corp\InterBase\Bin\ibguard.exe (Inprise Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PaperPort PTD] "C:\Programme\ScanSoft\PaperPort\pptd40nt.exe" File not found
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKU\S-1-5-21-3433501987-3011716872-2427280945-1007..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\VR-NetWorld Auftragsprüfung.lnk = C:\Programme\VR-NetWorld\VRToolCheckOrder.exe (VR-NetWorld Software)
O4 - Startup: C:\Dokumente und Einstellungen\Plank\Startmenü\Programme\Autostart\OpenOffice.org 3.4.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3433501987-3011716872-2427280945-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{946D1AA9-F229-45B8-8F30-840DB0B025E2}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Plank\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Plank\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.19 11:40:31 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.08.26 20:12:53 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.08.26 20:02:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\QuickScan
[2013.08.26 19:21:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Malwarebytes
[2013.08.26 19:20:51 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2013.08.26 19:20:50 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2013.08.26 19:20:49 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013.08.26 19:20:49 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2013.08.26 19:04:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\TeamViewer
[2013.08.26 19:00:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2013.08.26 18:55:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2013.08.24 22:19:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla
[2013.08.24 20:01:01 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2013.07.29 20:02:24 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Thunderbird
========== Files - Modified Within 30 Days ==========
[2013.08.26 20:31:00 | 000,000,226 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2013.08.26 19:46:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.08.26 19:20:51 | 000,000,756 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.08.26 19:13:54 | 000,449,532 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2013.08.26 19:13:54 | 000,433,412 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013.08.26 19:13:54 | 000,080,772 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2013.08.26 19:13:54 | 000,067,984 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013.08.26 19:09:57 | 000,182,038 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2013.08.26 19:09:56 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.08.26 19:09:52 | 000,000,300 | ---- | M] () -- C:\WINDOWS\tasks\XRGFRW.job
[2013.08.26 19:09:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.08.26 19:09:49 | 1878,249,472 | -HS- | M] () -- C:\hiberfil.sys
[2013.08.24 22:21:09 | 000,000,104 | ---- | M] () -- C:\Dokumente und Einstellungen\Plank\Desktop\Internet.lnk
[2013.08.24 22:19:19 | 000,000,696 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2013.08.21 13:46:28 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013.08.21 13:46:28 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013.08.18 22:15:30 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013.08.05 19:54:07 | 000,002,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Plank\Desktop\Microsoft Word (2).lnk
========== Files Created - No Company Name ==========
[2013.08.26 19:20:51 | 000,000,756 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.08.26 19:09:49 | 1878,249,472 | -HS- | C] () -- C:\hiberfil.sys
[2013.08.24 22:21:09 | 000,000,104 | ---- | C] () -- C:\Dokumente und Einstellungen\Plank\Desktop\Internet.lnk
[2013.08.24 22:19:19 | 000,000,702 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk
[2013.08.24 22:19:19 | 000,000,696 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2012.12.29 21:13:14 | 000,000,234 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2012.12.29 21:13:14 | 000,000,093 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2012.12.29 21:13:01 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2012.12.29 21:11:14 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2012.12.29 21:11:14 | 000,000,091 | ---- | C] () -- C:\WINDOWS\Brfaxrx.ini
[2012.12.29 21:11:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brdfxspd.dat
[2012.12.14 14:31:08 | 000,118,784 | RHS- | C] () -- C:\WINDOWS\System32\c_8749.dll
[2012.11.28 18:39:06 | 000,000,032 | ---- | C] () -- C:\WINDOWS\Menu.INI
[2012.05.05 11:41:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.02.15 09:15:16 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.01.30 14:50:07 | 000,000,425 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2012.01.30 14:49:21 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\bridf08b.dat
[2010.11.11 15:17:30 | 000,000,103 | ---- | C] () -- C:\Dokumente und Einstellungen\Plank\default.pls
========== ZeroAccess Check ==========
[2009.06.19 12:03:36 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2009.07.18 18:03:13 | 001,509,888 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 12:54:49 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2009.09.25 16:31:43 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ
[2012.01.30 14:48:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft
[2011.07.09 09:43:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\AskToolbar
[2012.12.29 22:35:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\OpenOffice.org
[2013.08.26 20:03:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\QuickScan
[2013.08.26 19:04:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\TeamViewer
[2012.12.29 22:21:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Thunderbird
========== Purity Check ==========
< End of report > ADW Code:
# AdwCleaner v3.001 - Report created 26/08/2013 at 20:13:26
# Updated 24/08/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Plank - NABO-KARLSFELD
# Running from : C:\Dokumente und Einstellungen\Plank\Eigene Dateien\Downloads\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Dokumente und Einstellungen\user\Anwendungsdaten\Mozilla\Firefox\Profiles\9olqapgt.default\.autoreg
File Found : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
Folder Found C:\DOKUME~1\Plank\LOKALE~1\Temp\AskSearch
Folder Found C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\AskToolbar
Folder Found C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\AskToolbar
Folder Found C:\Dokumente und Einstellungen\Plank\Lokale Einstellungen\Anwendungsdaten\AskToolbar
Folder Found C:\Programme\Ask.com
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\APN
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\AskToolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\Software\APN
Key Found : HKLM\Software\AskToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Product Found : Ask Toolbar
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
***** [ Browsers ] *****
-\\ Internet Explorer v7.0.6000.21348
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Dokumente und Einstellungen\user\Anwendungsdaten\Mozilla\Firefox\Profiles\9olqapgt.default\prefs.js ]
[ File : C:\Dokumente und Einstellungen\Plank\Anwendungsdaten\Mozilla\Firefox\Profiles\8n1stvgc.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [3359 octets] - [26/08/2013 20:13:26]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3419 octets] ########## |