Hi Schrauber,
- Funde mit MBAM entfernt
-Adw Code:
# AdwCleaner v3.001 - Report created 29/08/2013 at 14:36:03
# Updated 24/08/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Günter - NAME-GISELA
# Running from : C:\Dokumente und Einstellungen\Günter\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Viewpoint
Folder Deleted : C:\Programme\Conduit
Folder Deleted : C:\Programme\Viewpoint
Folder Deleted : C:\Programme\FileConverter_1.3
Folder Deleted : C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\AskToolbar
Folder Deleted : C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Conduit
Folder Deleted : C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FileConverter_1.3
Folder Deleted : C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\AskSearch
Folder Deleted : C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Softonic
Folder Deleted : C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Toolbar4
Folder Deleted : C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\IncrediMail_MediaBar_2
Folder Deleted : C:\Dokumente und Einstellungen\Günter\IECompatCache
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Anwendungsdaten\apn
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Anwendungsdaten\Conduit
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Anwendungsdaten\ConduitEngine
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Anwendungsdaten\PackageAware
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Anwendungsdaten\FileConverter_1.3
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Systweak
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\IECompatCache
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\Lokale Einstellungen\Anwendungsdaten\Conduit
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\Lokale Einstellungen\Anwendungsdaten\ConduitEngine
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\Lokale Einstellungen\Anwendungsdaten\IncrediMail_MediaBar_2
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\Lokale Einstellungen\Anwendungsdaten\FileConverter_1.3
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\Anwendungsdaten\AskToolbar
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\Anwendungsdaten\PriceGong
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\Anwendungsdaten\Softonic
Folder Deleted : C:\Dokumente und Einstellungen\Gisela\Anwendungsdaten\Toolbar4
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\CT2724386
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\Extensions\ffxtlbra@softonic.com
Folder Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\Extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}
[!] Folder Deleted : C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\dnpmlnedpdikbgdghljdepnljfpkhccn
[!] Folder Deleted : C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\jbpcjmidkkgldeplajgnbpjkfpmpeepb
File Deleted : C:\chatzum_nt.exe
File Deleted : C:\WINDOWS\system32\conduitEngine.tmp
File Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\searchplugins\Askcom.xml
File Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\searchplugins\ChatZum.xml
File Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\searchplugins\MyStart Search.xml
File Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\searchplugins\softonic.xml
File Deleted : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\user.js
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{78E516EF-11DE-47A1-8364-A99B917EC5EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{153D7D79-706C-443D-BA98-41CA86982C9D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{78E516EF-11DE-47A1-8364-A99B917EC5EE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{153D7D79-706C-443D-BA98-41CA86982C9D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{153D7D79-706C-443D-BA98-41CA86982C9D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E8EE31C-11EA-4E54-A130-A611DCEEE5C6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B19E6B3E-5659-44EB-AA10-5F788A5507A1}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{78E516EF-11DE-47A1-8364-A99B917EC5EE}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{78E516EF-11DE-47A1-8364-A99B917EC5EE}]
Key Deleted : HKCU\Software\Babylon
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\PriceGong
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\FileConverter_1.3
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\IncrediMail_MediaBar_2
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\MetaStream
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\Software\Uniblue\DriverScanner
Key Deleted : HKLM\Software\Viewpoint
Key Deleted : HKLM\Software\FileConverter_1.3
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileConverter_1.3 Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FileConverter_1.3 Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v3.5.2 (de)
[ File : C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\prefs.js ]
Line Deleted : user_pref("CT2724386.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2724386.CTID", "ct2724407");
Line Deleted : user_pref("CT2724386.CurrentServerDate", "8-1-2013");
Line Deleted : user_pref("CT2724386.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2724386.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2724386.FirstServerDate", "15-7-2012");
Line Deleted : user_pref("CT2724386.FirstTime", true);
Line Deleted : user_pref("CT2724386.FirstTimeFF3", true);
Line Deleted : user_pref("CT2724386.FirstTimeSettingsDone", true);
Line Deleted : user_pref("CT2724386.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2724386.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2724386.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2724386.Initialize", true);
Line Deleted : user_pref("CT2724386.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2724386.InstallationAndCookieDataSentCount", 3);
Line Deleted : user_pref("CT2724386.InstallationId", "IncrediMail_MediaBar_2.exe");
Line Deleted : user_pref("CT2724386.InstallationType", "ConduitIntegration");
Line Deleted : user_pref("CT2724386.InstalledDate", "Sun Jul 15 2012 20:50:00 GMT+0200");
Line Deleted : user_pref("CT2724386.IsGrouping", false);
Line Deleted : user_pref("CT2724386.IsMulticommunity", false);
Line Deleted : user_pref("CT2724386.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2724386.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2724386.LanguagePackLastCheckTime", "Sun Jul 15 2012 20:50:03 GMT+0200");
Line Deleted : user_pref("CT2724386.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2724386.LastLogin_2.7.2.0", "Tue Jan 08 2013 16:34:28 GMT+0100");
Line Deleted : user_pref("CT2724386.LatestVersion", "3.16.0.3");
Line Deleted : user_pref("CT2724386.Locale", "en");
Line Deleted : user_pref("CT2724386.LoginCache", 4);
Line Deleted : user_pref("CT2724386.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2724386.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2724386.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2724386.RadioIsPodcast", false);
Line Deleted : user_pref("CT2724386.RadioMediaID", "21080119");
Line Deleted : user_pref("CT2724386.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2724386.RadioMenuSelectedID", "EBRadioMenu_CT272438621080119");
Line Deleted : user_pref("CT2724386.RadioStationName", "Royal-Radio%20");
Line Deleted : user_pref("CT2724386.RadioStationURL", "");
Line Deleted : user_pref("CT2724386.SearchEngine", "Web%20Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2724386&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2724386.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2724386.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2724386&q=");
Line Deleted : user_pref("CT2724386.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2724386.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.SearchInNewTabLastCheckTime", "Sun Jul 15 2012 20:50:01 GMT+0200");
Line Deleted : user_pref("CT2724386.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2724386.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2724386.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2724386.SettingsLastCheckTime", "Sun Jul 15 2012 20:50:00 GMT+0200");
Line Deleted : user_pref("CT2724386.SettingsLastUpdate", "1340713604");
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsLastCheck", "Sun Jul 15 2012 20:50:00 GMT+0200");
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsLastUpdate", "1331805997");
Line Deleted : user_pref("CT2724386.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2724386.UserID", "UN40008733009874228");
Line Deleted : user_pref("CT2724386.WeatherNetwork", "");
Line Deleted : user_pref("CT2724386.WeatherPollDate", "Tue Jan 08 2013 16:34:29 GMT+0100");
Line Deleted : user_pref("CT2724386.WeatherUnit", "C");
Line Deleted : user_pref("CT2724386.alertChannelId", "1116652");
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B474953462D584D503D263F2D2E3135443B464E4F5B565E695B426D6265523B544243464959505B637D737B6E55217578654E675[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C4748402C574C4F3C253E2C2E2B2F433A454E59505B57676A66426D62455E69543D56444643465B525D66716C216E6B587D73675[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462B554A4D4B4749594D33535D4F432C45333439344A414C565B5E6C656E706C7164736D4D786D705D465F4D4E534D645B66705[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e.:2z527", "2423");
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F564654524C474A595A4851505E51523964595C49324B393C3B3E5047525D6C6A6B6F786D68506A6F7171742256227679664F6[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C4343534E2D585B3C253E2C302E34433A45515862695E675A416C6164513A5341454348584F5A666D7B7C7174726E702174745B2[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e06cg5el8:", "6E6D6C6B6D6F6C75706F");
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A747372717375727B7675242F4B49474F42357D5D5C3D");
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E41295547484D515A4E5A59325D5255422B443237303749404B585E685E706E6E6674626E696B4D786D705D465F4D524B51645B66732[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473E454745482F5A4F523F2841302D2F33463D48566265685C6B675F6D70604873686B58415A4946484B5F56616F7C217D74747[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D3229344356554E472E594E51325E4F412A4335373231483F4A59655F5F626C5B717369756975744D786D70517E6B60496252505451675[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352C37474B59574B4A4858584E5E3762573A535E49324B3A3D3F3B504752626C625D75786D766A7C517C7174614A63525557526[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A522B55553A233C2B2F282941384354515E5D56615F56685C426D6265523B544346494A59505B6C697A7E21702370765925797[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D49564A50592E594E314A55402942322E332F473E495B5D595A6A5E58707262674974696C59425B4B474B51605762747C2473737[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B364953545259585A5A50524E36615659462F4838353D3C4D444F626C6D6B72716A77614D786D705D465F4F4C5451645B66797[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347513F445559424C5A315C5154412A4333323037483F4A5E68565B5970606E6C666164734C776C6F5C455E4E4D4B51635A6579247[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E782332293449565540472E594E513E274030323533453C475C5558636A656E625E6C616B7068734B766B6E5B445D4D4F524F6259647927767[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4F44504C4754585C5048345F5457442D46373135344B424D636B5D5F5F73696B4A756A6D5A435C4D474B4961586379226F742[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A30273249485545442C574C4F3C253E2F2A2D2D433A455C67555B5E3F6A5F624F3851423D403F564D586F7A68786C717154207477644D66575[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354D462C574C4F3C253E2F2B2B31433A455D6356575C5C5A416C6164513A5344404045584F5A7273717A786D2256227679664F6[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352C37502E4F4747315C5154412A4334313738483F4A635F5A6A645E625A4772676A5740594A474D4D5E55607971246E7778257[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B36505459574C554F515B345F5457442D46373637384B424D676B706E606F61666B63664D786D705D465F504F5050645B66212[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A35504F5346482F5A4F523F28413233342F463D48635C5D66626A436E6366533C55464748425A515C77707773202371215925797[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3652504C5249555256525C35605558452E47383B38364C434E6A706F5F65635D736F677578684C65706B54207477644D66575[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2A554A2D46513C253E302B332C433A45626756516259655F5F436E63465F6A553E5749444C445C535E7B21747C7821745A267[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A52404548564F58315C5154412A4335342F37483F4A68646B645D5E626462616D6971726B6C786A517C7174614A6355544F566[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57");
Line Deleted : user_pref("CT2724386.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352C37565949484E4F51525C4E4C55535B54605A5A3E695E614E37503B3D41544B567575656D7367796D6D7C55217578654E675[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E3128335351565551575A4F584C5E335E5356432C4534383649404B6B59566C686B46716669563F58474B485C535E7E6C6956227679664F6[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C484A2C574C2F48533E27403233433A45665B68505C5E406B6E4F38514343544B56776C79616D6F517C71547873634C6557566[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C32293423524C5457474A4E50565D4A61515F5D575255643D685D604D364F3D3E3E3D544B5645486A736D696F527D7275624B645253535[...]
Line Deleted : user_pref("CT2724386.backendstorage./9b-0?3g>d", "3A6D406E736B6F407A71457948204C78777D257E7C4E542A2123255959585A5C5D2B5D60");
Line Deleted : user_pref("CT2724386.backendstorage./9b-0?3g@6:5;", "");
Line Deleted : user_pref("CT2724386.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332A354448584C3A232E333E58604F6456604F6852645858635E604E376B7167617059");
Line Deleted : user_pref("CT2724386.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Line Deleted : user_pref("CT2724386.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484779213F3E484F4E4D4648502B564B4E2E5959595F4C564F3764535750");
Line Deleted : user_pref("CT2724386.backendstorage./9b5ba==9cjag", "6C67716F72746E6D7A4478714A78777A797C4D7D20");
Line Deleted : user_pref("CT2724386.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6C6B6D6F6C746E7178777B");
Line Deleted : user_pref("CT2724386.backendstorage./9b9643g3/9e", "6A");
Line Deleted : user_pref("CT2724386.backendstorage./9b<:222h64<", "393F352F3E");
Line Deleted : user_pref("CT2724386.backendstorage./9b=+03eh8h8j?:", "4443");
Line Deleted : user_pref("CT2724386.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
Line Deleted : user_pref("CT2724386.backendstorage./9b?b0d:8aj62<h", "6D");
Line Deleted : user_pref("CT2724386.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Line Deleted : user_pref("CT2724386.backendstorage.hxxp://api26_thetrafficstat_net.pid2", "33666161376436626236613030636639");
Line Deleted : user_pref("CT2724386.backendstorage.hxxp://api29_thetrafficstat_net.pid2", "61666136616263656435663864316231");
Line Deleted : user_pref("CT2724386.backendstorage.shoppingapp.gk.exipres", "53756E204A616E20313320323031332031363A33343A343620474D542B30313030");
Line Deleted : user_pref("CT2724386.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79");
Line Deleted : user_pref("CT2724386.clientLogIsEnabled", false);
Line Deleted : user_pref("CT2724386.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2724386.ct2724407.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2724386.ct2724407.FirstTimeSettingsDone", true);
Line Deleted : user_pref("CT2724386.ct2724407.InvalidateCache", false);
Line Deleted : user_pref("CT2724386.ct2724407.LanguagePackLastCheckTime", "Tue Jan 08 2013 16:34:36 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.Locale", "de");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastCheckTime", "Tue Jan 08 2013 16:34:28 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastUpdateServer", "129249047784100000");
Line Deleted : user_pref("CT2724386.ct2724407.SearchEngine", "Web%20Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2724407&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2724386.ct2724407.SearchInNewTabLastCheckTime", "Tue Jan 08 2013 16:34:27 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2724386.ct2724407.SettingsLastCheckTime", "Tue Jan 08 2013 16:34:27 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.SettingsLastUpdate", "1340713641");
Line Deleted : user_pref("CT2724386.ct2724407.ThirdPartyComponentsLastCheck", "Tue Jan 08 2013 16:34:27 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.ThirdPartyComponentsLastUpdate", "1331806000");
Line Deleted : user_pref("CT2724386.myStuffEnabled", true);
Line Deleted : user_pref("CT2724386.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2724386.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2724386.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2724386.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=2&cc=&q=");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2724386");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2724386");
Line Deleted : user_pref("browser.newtab.url", "search.chatzum.com");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("extensions.Softonic.admin", false);
Line Deleted : user_pref("extensions.Softonic.aflt", "orgnl");
Line Deleted : user_pref("extensions.Softonic.autoRvrt", "false");
Line Deleted : user_pref("extensions.Softonic.cntry", "DE");
Line Deleted : user_pref("extensions.Softonic.cv", "cv5");
Line Deleted : user_pref("extensions.Softonic.dfltLng", "");
Line Deleted : user_pref("extensions.Softonic.dfltSrch", true);
Line Deleted : user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)");
Line Deleted : user_pref("extensions.Softonic.dspOld", "MyStart Suche");
Line Deleted : user_pref("extensions.Softonic.envrmnt", "production");
Line Deleted : user_pref("extensions.Softonic.excTlbr", false);
Line Deleted : user_pref("extensions.Softonic.hdrMd5", "4FDE5D7C95462D770E8625B8F124E0C2");
Line Deleted : user_pref("extensions.Softonic.hmpg", true);
Line Deleted : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=13&cc=");
Line Deleted : user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=13&cc=");
Line Deleted : user_pref("extensions.Softonic.hpOld", "hxxp://mystart.incredimail.com/");
Line Deleted : user_pref("extensions.Softonic.id", "54170f89000000000000001d195b2ddc");
Line Deleted : user_pref("extensions.Softonic.instlDay", "15496");
Line Deleted : user_pref("extensions.Softonic.instlRef", "MON00001");
Line Deleted : user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=2&cc=&q=");
Line Deleted : user_pref("extensions.Softonic.lastVrsnTs", "1.5.24.321:21:20");
Line Deleted : user_pref("extensions.Softonic.mntrvrsn", "1.3.0");
Line Deleted : user_pref("extensions.Softonic.newTab", false);
Line Deleted : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=15&cc=");
Line Deleted : user_pref("extensions.Softonic.prdct", "Softonic");
Line Deleted : user_pref("extensions.Softonic.prtnrId", "softonic");
Line Deleted : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search settings, Click No to restore original settings");
Line Deleted : user_pref("extensions.Softonic.sg", "az");
Line Deleted : user_pref("extensions.Softonic.smplGrp", "none");
Line Deleted : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
Line Deleted : user_pref("extensions.Softonic.tlbrId", "base");
Line Deleted : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource=1&cc=&q=");
Line Deleted : user_pref("extensions.Softonic.vrsn", "1.5.24.3");
Line Deleted : user_pref("extensions.Softonic.vrsnTs", "1.5.24.321:21:20");
Line Deleted : user_pref("extensions.Softonic.vrsni", "1.5.24.3");
Line Deleted : user_pref("extensions.Softonic_i.dnsErr", true);
Line Deleted : user_pref("extensions.Softonic_i.hmpg", true);
Line Deleted : user_pref("extensions.Softonic_i.newTab", false);
Line Deleted : user_pref("extensions.Softonic_i.smplGrp", "none");
Line Deleted : user_pref("extensions.Softonic_i.vrsnTs", "1.5.24.321:21:20");
Line Deleted : user_pref("extensions.enabledItems", "{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}:2.7.2.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,ffxtlbra@softonic.com:1.5.0,toolbar@ask.com:3.15.10.29781,{ADFA33FD-16F5[...]
Line Deleted : user_pref("id_chatzum.firstlaunch", "0");
Line Deleted : user_pref("id_chatzum.guid", "%7B89BB7698-D6ED-745A-9042-0CD71483C2DD%7D");
Line Deleted : user_pref("id_chatzum.hiddenvisual", 0);
Line Deleted : user_pref("id_chatzum.openSearchEngineName", "Ask.com");
Line Deleted : user_pref("id_chatzum.searchengine", "Ask.com");
Line Deleted : user_pref("id_chatzum.variables.SVar1", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar10", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar2", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar3", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar4", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar5", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar6", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar7", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar8", "%13");
Line Deleted : user_pref("id_chatzum.variables.SVar9", "%13");
Line Deleted : user_pref("id_chatzum.variables.Var1", "0");
Line Deleted : user_pref("id_chatzum.variables.Var10", "0");
Line Deleted : user_pref("id_chatzum.variables.Var2", "0");
Line Deleted : user_pref("id_chatzum.variables.Var3", "0");
Line Deleted : user_pref("id_chatzum.variables.Var4", "0");
Line Deleted : user_pref("id_chatzum.variables.Var5", "0");
Line Deleted : user_pref("id_chatzum.variables.Var6", "0");
Line Deleted : user_pref("id_chatzum.variables.Var7", "0");
Line Deleted : user_pref("id_chatzum.variables.Var8", "0");
Line Deleted : user_pref("id_chatzum.variables.Var9", "0");
Line Deleted : user_pref("id_chatzum_installed_version", "1.0.17");
Line Deleted : user_pref("id_chatzum_tabpage", "hxxp%3A//searchsafer.com/");
Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
-\\ Google Chrome v29.0.1547.57
[ File : C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Dokumente und Einstellungen\Gisela\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [31230 octets] - [29/08/2013 14:32:19]
AdwCleaner[S0].txt - [31562 octets] - [29/08/2013 14:36:03]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [31623 octets] ########## - JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Microsoft Windows XP x86
Ran by Gnter on 29.08.2013 at 14:42:47,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2724386
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3241949
Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{102FA9D5-638B-49D3-AD0C-9FDFB8242AD1}
~~~ Files
Successfully deleted: [File] C:\WINDOWS\Tasks\registrybooster.job
~~~ Folders
~~~ FireFox
Successfully deleted: [File] C:\user.js
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.08.2013 at 14:47:24,96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - Frst
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-08-2013
Ran by Günter (administrator) on 29-08-2013 14:49:38
Running from C:\Dokumente und Einstellungen\Günter\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\sched.exe
(SEIKO EPSON CORPORATION) C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\eEBSVC.exe
() C:\Programme\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Programme\Microsoft LifeCam\MSCamS32.exe
() C:\Programme\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
(Skype Technologies S.A.) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(SEIKO EPSON CORPORATION) C:\WINDOWS\system32\SAgent4.exe
(TomTom) C:\Programme\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corporation) C:\Programme\Windows Media Player\WMPNetwk.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(ATI Technologies, Inc.) C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
(ICSI Technology Ltd.) C:\WINDOWS\Dit.exe
(Agere Systems) C:\WINDOWS\AGRSMMSG.exe
(CyberLink Corp.) C:\Programme\Home Cinema\PowerCinema\PCMService.exe
(Chicony) C:\WINDOWS\mHotkey.exe
(Chicony) C:\WINDOWS\CNYHKey.exe
(Microsoft Corporation) C:\WINDOWS\vVX1000.exe
(NewSoft Technology Corporation) C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
(NewSoft Technology Corporation) C:\Programme\NewSoft\Presto! PageManager 9 for EP\PMSpeed.EXE
(SEIKO EPSON CORPORATION) C:\Programme\Epson Software\FAX Utility\FUFAXSTM.exe
(SEIKO EPSON CORPORATION) C:\Programme\Epson Software\Event Manager\EEventManager.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avgnt.exe
(SEIKO EPSON CORPORATION) C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIGBU.EXE
(Google Inc.) C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Programme\Windows Media Player\WMPNSCFG.exe
(TomTom) C:\Programme\TomTom HOME 2\TomTomHOMERunner.exe
(NewSoft Technology Corporation) C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
(Arcor AG & Co. KG) C:\Programme\Arcor\Arcor Wlan-Monitor 1.0\ArcorWlanUtility.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avshadow.exe
(X10) C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
(Google Inc.) C:\Programme\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Programme\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Programme\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Cmaudio] - RunDll32 cmicnfg.cpl,CMICtrlWnd [x]
HKLM\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [ATIPTA] - C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe [344064 2004-11-24] (ATI Technologies, Inc.)
HKLM\...\Run: [Dit] - C:\Windows\Dit.exe [90112 2004-07-20] (ICSI Technology Ltd.)
HKLM\...\Run: [AGRSMMSG] - C:\Windows\AGRSMMSG.exe [88209 2005-03-04] (Agere Systems)
HKLM\...\Run: [PCMService] - C:\Programme\Home Cinema\PowerCinema\PCMService.exe [81920 2004-11-09] (CyberLink Corp.)
HKLM\...\Run: [CHotkey] - C:\Windows\mHotkey.exe [508416 2004-02-24] (Chicony)
HKLM\...\Run: [ledpointer] - C:\Windows\CNYHKey.exe [5794816 2004-02-03] (Chicony)
HKLM\...\Run: [HPDJ Taskbar Utility] - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe [176128 2004-01-05] (HP)
HKLM\...\Run: [DXDllRegExe] - dxdllreg.exe [x]
HKLM\...\Run: [VX1000] - C:\WINDOWS\vVX1000.exe [709992 2007-04-10] (Microsoft Corporation)
HKLM\...\Run: [LifeCam] - C:\Programme\Microsoft LifeCam\LifeExp.exe [279912 2007-05-17] (Microsoft Corporation)
HKLM\...\Run: [WrtMon.exe] - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe [26448 2008-05-24] (NewSoft Technology Corporation)
HKLM\...\Run: [PMSpeed] - C:\Programme\NewSoft\Presto! PageManager 9 for EP\PMSpeed.EXE [112464 2009-12-04] (NewSoft Technology Corporation)
HKLM\...\Run: [FUFAXSTM] - C:\Programme\Epson Software\FAX Utility\FUFAXSTM.exe [847872 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [EEventManager] - C:\Programme\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [avgnt] - C:\Programme\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-01] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
HKCU\...\Run: [NBJ] - C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe [1916928 2004-09-24] (Ahead Software AG)
HKCU\...\Run: [Epson Stylus Office BX620FWD(Netzwerk)] - C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\E_S93.tmp [242 2013-06-04] ()
HKCU\...\Run: [Skype] - C:\Programme\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [swg] - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2007-08-30] (Google Inc.)
HKCU\...\Run: [WMPNSCFG] - C:\Programme\Windows Media Player\WMPNSCFG.exe [204288 2006-11-03] (Microsoft Corporation)
HKCU\...\Run: [TomTomHOME.exe] - C:\Programme\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-07-02] (TomTom)
MountPoints2: J - J:\LaunchU3.exe -a
MountPoints2: {8a00127b-ae70-11e1-8c7b-0011090568c9} - LaunchU3.exe -a
MountPoints2: {d623abd2-52ab-11d9-aff1-806d6172696f} - @%systemroot%\explorer.exe /e,.
HKU\Gisela\...\Run: [swg] - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2007-08-30] (Google Inc.)
HKU\Gisela\...\Run: [WMPNSCFG] - C:\Programme\Windows Media Player\WMPNSCFG.exe [ 2006-11-03] (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Arcor Wlan-Monitor 1.0.lnk
ShortcutTarget: Arcor Wlan-Monitor 1.0.lnk -> C:\Programme\Arcor\Arcor Wlan-Monitor 1.0\ArcorWlanUtility.exe (Arcor AG & Co. KG)
SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search
SearchScopes: HKCU - 76E6670DDA62406CBE00199F1164292A URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3241949
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU -No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103478587671
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - No File
Handler: ipp - No CLSID Value -
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
Tcpip\..\Interfaces\{DC932E0B-E9F5-44BA-83E0-55B93DD869B4}: [NameServer]192.168.178.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default
FF SelectedSearchEngine: Bing
FF Homepage: hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP
FF Keyword.URL: hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&q=
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Programme\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Programme\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Programme\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @real.com/nppl3260;version=6.0.11.2061 - C:\Programme\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.2.2122 - C:\Programme\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.1059 - C:\Programme\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\searchplugins\bingp.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Extensions\home2@tomtom.com
FF Extension: No Name - C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Microsoft .NET Framework Assistant - C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Mozilla\Firefox\Profiles\rs2v0vef.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: Skype Click to Call - C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.de/ig?hl=de"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Programme\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Programme\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Programme\Google\Chrome\Application\29.0.1547.57\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Dokumente und Einstellungen\G\u00FCnter\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll No File
CHR Plugin: (Skype Click to Call) - C:\Dokumente und Einstellungen\G\u00FCnter\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10201_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Programme\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (QuickTime Plug-in 6.5) - C:\Programme\Mozilla Firefox\plugins\npqtplugin.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 6.5) - C:\Programme\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 6.5) - C:\Programme\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 6.5) - C:\Programme\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 6.5) - C:\Programme\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 6.5) - C:\Programme\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Computer, Inc.)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Programme\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Programme\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Programme\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Earth Plugin) - C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Updater) - C:\Programme\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
CHR Plugin: (Picasa) - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Programme\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Programme\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Programme\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Programme\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Programme\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (MetaStream 3 Plugin) - C:\Programme\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll No File
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Programme\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Skype Click to Call) - C:\DOKUME~1\GNTER~1\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10201_0
CHR Extension: (Chrome In-App Payments service) - C:\DOKUME~1\GNTER~1\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR HKLM\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Anwendungsdaten\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.8.0.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Programme\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
========================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor; C:\Programme\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [98304 2004-10-12] ()
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [84024 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-01] (Avira Operations GmbH & Co. KG)
R2 EpsonBidirectionalService; C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION)
S3 fsssvc; C:\Programme\Windows Live\Family Safety\fsssvc.exe [704864 2009-08-05] (Microsoft Corporation)
S2 gupdate1c98ae5ffb1b530; C:\Programme\Google\Update\GoogleUpdate.exe [133104 2009-02-09] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [133104 2009-02-09] (Google Inc.)
S2 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [194032 2012-08-30] (Google)
R2 MSCamSvc; C:\Programme\Microsoft LifeCam\MSCamS32.exe [271720 2007-05-17] (Microsoft Corporation)
R2 PhotoshopElementsDeviceConnect; C:\Programme\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [118784 2004-10-12] ()
R2 Skype C2C Service; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3048136 2012-05-30] (Skype Technologies S.A.)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [162408 2013-06-21] (Skype Technologies)
R2 StatusAgent4; C:\WINDOWS\system32\SAgent4.exe [131072 2006-12-20] (SEIKO EPSON CORPORATION)
R2 TomTomHOMEService; C:\Programme\TomTom HOME 2\TomTomHOMEService.exe [93072 2013-07-02] (TomTom)
R2 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation)
R3 x10nets; C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe [20480 2001-11-12] (X10)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
==================== Drivers (Whitelisted) ====================
R3 3xHybrid; C:\Windows\System32\DRIVERS\3xHybrid.sys [945152 2004-10-06] (Philips Semiconductors GmbH)
R1 AFS2K; C:\Windows\System32\Drivers\AFS2K.sys [43672 2006-05-22] (Oak Technology Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-03-20] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-03-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-20] (Avira Operations GmbH & Co. KG)
R2 AWISp50; C:\Windows\System32\Drivers\AWISp50.sys [17664 2006-03-15] (Printing Communications Assoc., Inc. (PCAUSA))
S3 BRGSp50; C:\Windows\System32\Drivers\BRGSp50.sys [20608 2005-06-08] (Printing Communications Assoc., Inc. (PCAUSA))
S3 CardReaderFilter; C:\WINDOWS\system32\Drivers\USBCRFT.SYS [17408 2013-08-29] (ICSI Technology Ltd.)
R3 cmudax; C:\Windows\System32\drivers\cmudax.sys [1272000 2004-10-01] (C-Media Inc.)
S3 EL90XBC; C:\Windows\System32\DRIVERS\el90xbc5.sys [66591 2001-08-17] (3Com Corporation)
R3 FETNDISB; C:\Windows\System32\DRIVERS\fetnd5b.sys [42496 2004-04-15] (VIA Technologies, Inc. )
R2 fssfltr; C:\Windows\System32\DRIVERS\fssfltr_tdi.sys [54752 2009-08-05] (Microsoft Corporation)
S3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [113664 2004-03-17] (Windows (R) Server 2003 DDK provider)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51056 2004-01-05] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-01-05] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21488 2004-01-05] (HP)
S3 MPE; C:\Windows\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
R3 MxlW2k; C:\Windows\System32\Drivers\MxlW2k.sys [28352 2004-12-19] (MusicMatch, Inc.)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [9856 2002-10-01] (Padus, Inc.)
S3 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
S3 UKBFLT; C:\Windows\System32\DRIVERS\UKBFLT.sys [11672 2003-12-19] (Chicony)
S3 usbsermptxp; C:\Windows\System32\DRIVERS\usbsermptxp.sys [25600 2007-11-10] (Microsoft Corporation)
S3 VX1000; C:\Windows\System32\DRIVERS\VX1000.sys [1966312 2007-04-10] (Microsoft Corporation)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2003-01-10] (America Online, Inc.)
S3 WN4501HLFIR(Arcor); C:\Windows\System32\DRIVERS\ARWUSB.sys [489472 2006-12-04] (Arcor)
S3 X10UIF; C:\Windows\System32\Drivers\x10uif.sys [10761 2001-11-14] (X10 Wireless Technology, Inc.)
S3 ZDPSp50; C:\Windows\System32\Drivers\ZDPSp50.sys [17664 2004-10-25] (Printing Communications Assoc., Inc. (PCAUSA))
S3 btaudio; system32\drivers\btaudio.sys [x]
S3 BTDriver; system32\DRIVERS\btport.sys [x]
S3 BTWDNDIS; system32\DRIVERS\btwdndis.sys [x]
S3 BTWUSB; System32\Drivers\btwusb.sys [x]
S3 WINFLASH; \??\K:\Win Flash\WinFlash.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-29 14:42 - 2013-08-29 14:42 - 00000000 ____D C:\WINDOWS\ERUNT
2013-08-29 14:31 - 2013-08-29 14:37 - 00000000 ____D C:\AdwCleaner
2013-08-29 14:30 - 2013-08-29 14:30 - 01023533 _____ (Thisisu) C:\Dokumente und Einstellungen\Günter\Desktop\JRT.exe
2013-08-29 14:29 - 2013-08-29 14:29 - 00994642 _____ C:\Dokumente und Einstellungen\Günter\Desktop\adwcleaner.exe
2013-08-29 13:22 - 2013-08-29 13:22 - 00001772 _____ C:\Dokumente und Einstellungen\Günter\Desktop\gmer290813.log
2013-08-29 12:58 - 2013-08-29 14:48 - 00001423 _____ C:\WINDOWS\setupapi.log
2013-08-29 12:57 - 2013-08-29 12:57 - 00377856 _____ C:\Dokumente und Einstellungen\Günter\Desktop\gmer_2.1.19163.exe
2013-08-29 12:48 - 2013-08-29 12:49 - 00039038 _____ C:\Dokumente und Einstellungen\Günter\Desktop\Addition.txt
2013-08-29 12:47 - 2013-08-29 12:47 - 00000000 ____D C:\FRST
2013-08-29 12:44 - 2013-08-29 12:44 - 01072975 _____ (Farbar) C:\Dokumente und Einstellungen\Günter\Desktop\FRST.exe
2013-08-28 21:49 - 2013-08-28 21:49 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-28 18:43 - 2013-08-28 18:55 - 00000000 ____D C:\PapierkorbBkp
2013-08-14 19:43 - 2013-08-14 19:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 19:43 - 2013-08-14 19:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 19:43 - 2013-08-14 19:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 19:43 - 2013-08-14 19:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-06 17:35 - 2013-08-06 17:35 - 00000000 ____D C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\TeamViewer
2013-08-06 17:12 - 2013-08-06 17:12 - 00001891 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Google Earth.lnk
==================== One Month Modified Files and Folders =======
2013-08-29 14:48 - 2013-08-29 12:58 - 00001423 _____ C:\WINDOWS\setupapi.log
2013-08-29 14:47 - 2013-08-29 14:47 - 00001358 _____ C:\Dokumente und Einstellungen\Günter\Desktop\JRT.txt
2013-08-29 14:44 - 2009-07-16 19:33 - 00000000 ____D C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\Skype
2013-08-29 14:42 - 2013-08-29 14:42 - 00000000 ____D C:\WINDOWS\ERUNT
2013-08-29 14:42 - 2012-10-18 14:09 - 00000420 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{3F7DF3EC-8ACC-4300-9C49-69B95BE14457}.job
2013-08-29 14:41 - 2004-12-19 15:59 - 01453158 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-29 14:39 - 2011-03-19 14:08 - 00000000 ____D C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\.oit
2013-08-29 14:39 - 2009-07-03 09:30 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-29 14:39 - 2005-04-26 11:30 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-08-29 14:39 - 2005-04-26 11:30 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-08-29 14:39 - 2004-12-19 16:03 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-29 14:38 - 2005-04-25 16:12 - 00000300 ___SH C:\Dokumente und Einstellungen\Günter\ntuser.ini
2013-08-29 14:38 - 2005-04-25 16:12 - 00000000 ____D C:\Dokumente und Einstellungen\Günter
2013-08-29 14:38 - 2004-12-19 16:03 - 00032610 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-29 14:37 - 2013-08-29 14:31 - 00000000 ____D C:\AdwCleaner
2013-08-29 14:36 - 2004-12-19 15:54 - 00000000 ___RD C:\Programme
2013-08-29 14:30 - 2013-08-29 14:30 - 01023533 _____ (Thisisu) C:\Dokumente und Einstellungen\Günter\Desktop\JRT.exe
2013-08-29 14:29 - 2013-08-29 14:29 - 00994642 _____ C:\Dokumente und Einstellungen\Günter\Desktop\adwcleaner.exe
2013-08-29 14:08 - 2009-07-03 09:30 - 00001090 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-29 14:01 - 2012-04-19 10:55 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-08-29 13:22 - 2013-08-29 13:22 - 00001772 _____ C:\Dokumente und Einstellungen\Günter\Desktop\gmer290813.log
2013-08-29 12:57 - 2013-08-29 12:57 - 00377856 _____ C:\Dokumente und Einstellungen\Günter\Desktop\gmer_2.1.19163.exe
2013-08-29 12:49 - 2013-08-29 12:48 - 00039038 _____ C:\Dokumente und Einstellungen\Günter\Desktop\Addition.txt
2013-08-29 12:47 - 2013-08-29 12:47 - 00000000 ____D C:\FRST
2013-08-29 12:44 - 2013-08-29 12:44 - 01072975 _____ (Farbar) C:\Dokumente und Einstellungen\Günter\Desktop\FRST.exe
2013-08-29 12:40 - 2005-03-01 14:04 - 00017408 _____ (ICSI Technology Ltd.) C:\WINDOWS\system32\Drivers\USBCRFT.SYS
2013-08-29 12:39 - 2005-04-30 11:33 - 00000190 ___SH C:\Dokumente und Einstellungen\Gisela\ntuser.ini
2013-08-29 12:39 - 2005-04-30 11:33 - 00000000 ____D C:\Dokumente und Einstellungen\Gisela
2013-08-29 12:39 - 2004-12-19 18:34 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2013-08-29 12:36 - 2004-12-20 14:37 - 00000000 ____D C:\WINDOWS\pss
2013-08-29 12:32 - 2005-05-03 20:51 - 00000000 ____D C:\WINDOWS\Minidump
2013-08-29 12:32 - 2005-04-30 11:33 - 00000000 __SHD C:\Dokumente und Einstellungen\Gisela\UserData
2013-08-29 12:24 - 2013-02-06 18:04 - 00001781 _____ C:\Dokumente und Einstellungen\Gisela\Desktop\Google Chrome.lnk
2013-08-29 12:22 - 2010-04-14 13:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB978338$
2013-08-29 11:59 - 2009-03-30 17:47 - 00000000 ____D C:\Programme\Malwarebytes' Anti-Malware
2013-08-29 11:59 - 2006-12-16 17:52 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB923980$
2013-08-28 21:49 - 2013-08-28 21:49 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-28 18:55 - 2013-08-28 18:43 - 00000000 ____D C:\PapierkorbBkp
2013-08-28 18:39 - 2004-12-19 15:46 - 00000721 _____ C:\WINDOWS\win.ini
2013-08-28 18:39 - 2004-12-19 15:46 - 00000227 _____ C:\WINDOWS\system.ini
2013-08-28 18:39 - 2004-12-19 15:46 - 00000211 __RSH C:\boot.ini
2013-08-28 18:20 - 2011-05-29 10:45 - 00000000 ____D C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\go
2013-08-28 18:20 - 2004-12-19 20:53 - 00000000 ____D C:\Programme\Google
2013-08-28 18:06 - 2005-04-25 16:12 - 00000000 ___RD C:\Dokumente und Einstellungen\Günter\Startmenü\Programme\Autostart
2013-08-28 14:02 - 2012-11-13 18:50 - 97222656 _____ C:\Dokumente und Einstellungen\Günter\Eigene Dateien\Unsere Kohlmeisen.psa
2013-08-28 13:55 - 2005-04-25 16:12 - 00000000 ___RD C:\Dokumente und Einstellungen\Günter\Eigene Dateien\Eigene Musik
2013-08-27 18:36 - 2009-03-27 16:53 - 00000000 ____D C:\Programme\TomTom HOME 2
2013-08-27 10:07 - 2009-03-26 13:13 - 00000966 _____ C:\WINDOWS\Tasks\Google Software Updater.job
2013-08-27 08:12 - 2012-10-17 14:24 - 00000000 ____D C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\CallingID
2013-08-27 08:12 - 2005-04-25 16:12 - 00000000 __SHD C:\Dokumente und Einstellungen\Günter\UserData
2013-08-27 08:00 - 2004-12-19 15:46 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-23 09:50 - 2011-04-27 14:25 - 00000000 ____D C:\Dokumente und Einstellungen\Günter\Eigene Dateien\Berlin 2011
2013-08-21 11:06 - 2012-04-19 10:55 - 00692104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-08-21 11:06 - 2011-09-03 16:05 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-08-15 18:06 - 2004-12-19 18:35 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-08-14 19:55 - 2013-07-16 16:25 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-08-14 19:55 - 2009-06-17 18:04 - 00000000 ____D C:\WINDOWS\ie8updates
2013-08-14 19:49 - 2005-05-14 09:07 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-08-14 19:46 - 2004-12-19 15:54 - 01172388 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-14 19:43 - 2013-08-14 19:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 19:43 - 2013-08-14 19:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 19:43 - 2013-08-14 19:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 19:43 - 2013-08-14 19:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-14 19:43 - 2007-03-06 18:40 - 00892046 _____ C:\WINDOWS\system32\TZLog.log
2013-08-14 19:29 - 2011-01-23 18:47 - 00000000 ____D C:\Dokumente und Einstellungen\Günter\Eigene Dateien\Gisela 65 Geburtstag
2013-08-14 15:11 - 2005-09-17 18:41 - 00002477 _____ C:\Dokumente und Einstellungen\Günter\Desktop\Microsoft Word.lnk
2013-08-12 19:05 - 2005-03-01 14:48 - 00000116 _____ C:\WINDOWS\NeroDigital.ini
2013-08-12 18:55 - 2005-04-25 16:12 - 00000000 ___RD C:\Dokumente und Einstellungen\Günter\Eigene Dateien\Eigene Bilder
2013-08-12 12:32 - 2012-12-25 13:08 - 00002243 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Skype.lnk
2013-08-11 10:57 - 2009-07-16 19:32 - 00000000 ___RD C:\Programme\Skype
2013-08-06 17:35 - 2013-08-06 17:35 - 00000000 ____D C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\TeamViewer
2013-08-06 17:12 - 2013-08-06 17:12 - 00001891 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Google Earth.lnk
2013-08-03 01:48 - 2006-10-18 21:47 - 01543680 ____N (Microsoft Corporation) C:\WINDOWS\system32\wmvdecod.dll
Files to move or delete:
====================
C:\Dokumente und Einstellungen\Günter\getfile.dat
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\Quarantine.exe
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\setup.exe
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\SkypeSetup.exe
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\tbInc1.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_Desktop.exe
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_Resource_de.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_Service.exe
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\TeamViewer\Version8\TeamViewer_StaticRes.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\TeamViewer\Version8\tv_w32.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\TeamViewer\Version8\tv_w32.exe
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\TeamViewer\Version8\tv_x64.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\TeamViewer\Version8\tv_x64.exe
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\MSS\3.0.318.3\mcbrwsr2.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\MSS\3.0.318.3\McInstallerRes.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\MSS\3.0.318.3\McInstallerRes_LD.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\MSS\3.0.318.3\McInstallerStartup.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\MSS\3.0.318.3\McUICnt.exe
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\MSS\3.0.318.3\SecurityScanner.dll
C:\DOKUME~1\GNTER~1\LOKALE~1\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2004-12-19 15:46] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2004-12-19 15:46] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2004-12-19 15:46] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2004-12-19 15:46] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2004-12-19 15:46] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2004-12-19 15:46] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2004-12-19 15:46] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================ --- --- --- |