MaraMara | 21.12.2013 11:02 | Hi, hier nun die weiteren Logs.
Ich weiß nicht warum die teilweise in einer Box sind und teilweise nicht, habe sie alle mit copy - paste zwischen die Code-Tags gesetzt:
<code>
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.12.20.05
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Admin :: ***** [Administrator]
20.12.2013 18:15:38
mbam-log-2013-12-20 (18-15-38).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 527146
Laufzeit: 2 Stunde(n), 28 Minute(n), 54 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
</code>
<code>AdwCleaner Logfile: Code:
# AdwCleaner v3.015 - Bericht erstellt am 20/12/2013 um 23:49:53
# Updated 10/12/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzername : Admin - *****
# Gestartet von : C:\Firefox Downloads\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eBay.lnk
Datei Gefunden : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\searchplugins\Askcom.xml
Datei Gefunden : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\user.js
Datei Gefunden : C:\Windows\System32\Tasks\NCH Software
Datei Gefunden : C:\Windows\System32\Tasks\PC SpeedUp Service Deactivator
Ordner Gefunden : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ommhmgednjnodcljhlljkaiidghdmikk
Ordner Gefunden : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Ordner Gefunden : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}
Ordner Gefunden : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Ordner Gefunden : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\{b106b661-3e1b-4015-af5c-195e909f35c6}
Ordner Gefunden : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\firejump@firejump.net
Ordner Gefunden : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ommhmgednjnodcljhlljkaiidghdmikk
Ordner Gefunden : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\pddsqboq.default\Extensions\{38542454-dfb6-44f5-b052-d4e071a3d073}
Ordner Gefunden : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\pddsqboq.default\Extensions\engine@conduit.com
Ordner Gefunden C:\Program Files\Conduit
Ordner Gefunden C:\Program Files\FreeRIP3
Ordner Gefunden C:\Program Files\GreenTree Applications
Ordner Gefunden C:\Program Files\myfree codec
Ordner Gefunden C:\Program Files\NCH_DE
Ordner Gefunden C:\Program Files\Winload
Ordner Gefunden C:\ProgramData\FreeRIP
Ordner Gefunden C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeRIP3
Ordner Gefunden C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Ordner Gefunden C:\ProgramData\NCH Software
Ordner Gefunden C:\Users\Admin\AppData\LocalLow\Conduit
Ordner Gefunden C:\Users\Admin\AppData\LocalLow\NCH_DE
Ordner Gefunden C:\Users\Admin\AppData\LocalLow\Winload
Ordner Gefunden C:\Users\Admin\AppData\Roaming\DesktopIconForAmazon
Ordner Gefunden C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeRIP
Ordner Gefunden C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Conduit
Ordner Gefunden C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\CT2319825
Ordner Gefunden C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\CT2801937
Ordner Gefunden C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Smartbar
Ordner Gefunden C:\Users\Gast\AppData\LocalLow\Conduit
Ordner Gefunden C:\Users\Gast\AppData\LocalLow\Winload
Ordner Gefunden C:\Users\Guido\AppData\LocalLow\boost_interprocess
Ordner Gefunden C:\Users\Guido\AppData\LocalLow\Conduit
Ordner Gefunden C:\Users\Guido\AppData\LocalLow\Dealio
Ordner Gefunden C:\Users\Guido\AppData\LocalLow\FreeRIP
Ordner Gefunden C:\Users\Guido\AppData\LocalLow\NCH_DE
Ordner Gefunden C:\Users\Guido\AppData\LocalLow\Search Settings
Ordner Gefunden C:\Users\Guido\AppData\LocalLow\Winload
Ordner Gefunden C:\Users\Guido\AppData\Roaming\Mozilla\Firefox\Profiles\pddsqboq.default\Conduit
Ordner Gefunden C:\Users\Guido\AppData\Roaming\Mozilla\Firefox\Profiles\pddsqboq.default\ConduitEngine
Ordner Gefunden C:\Users\Guido\AppData\Roaming\Mozilla\Firefox\Profiles\pddsqboq.default\CT2857572
Ordner Gefunden C:\Users\Guido\AppData\Roaming\NCH Software
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\APN PIP
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\NCH_DE
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Search Settings
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Winload
Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKCU\Software\Google\Chrome\Extensions\ommhmgednjnodcljhlljkaiidghdmikk
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{501451DE-5808-4599-B544-8BD0915B6B24}_is1
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyFreeCodec
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winload Toolbar
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Schlüssel Gefunden : HKCU\Software\Myfree Codec
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\YahooPartnerToolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{0C81D953-FF93-477D-A248-8ABEFBCA6757}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{8EEB1C24-43B2-4210-B48A-87FE0EAE6267}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2319825
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2801937
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\Software\DivX\Install\Setup\WizardLayout\ConduitToolbar
Schlüssel Gefunden : HKLM\Software\dt soft\daemon tools toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\ommhmgednjnodcljhlljkaiidghdmikk
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B9E96457-2AD3-4C07-943E-F8AA548FB885}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDF5803D-C886-4CCD-9349-C31A63E78D0E}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\PC SpeedUp Service Deactivator
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{209AC4DD-A31C-458F-AF5B-87EDEA8A27BC}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94CD4152-2E72-49EF-B51A-AF3FE73D14A1}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1B48E07-5F90-496E-8A3D-3285F91BE838}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40C3CC16-7269-4B32-9531-17F2950FB06F}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0C81D953-FF93-477D-A248-8ABEFBCA6757}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8EEB1C24-43B2-4210-B48A-87FE0EAE6267}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{501451DE-5808-4599-B544-8BD0915B6B24}_is1
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NCH_DE Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winload Toolbar
Schlüssel Gefunden : HKLM\Software\Myfree Codec
Schlüssel Gefunden : HKLM\Software\NCH_DE
Schlüssel Gefunden : HKLM\Software\PIP
Schlüssel Gefunden : HKLM\Software\Speedchecker Limited
Schlüssel Gefunden : HKLM\Software\Uniblue
Schlüssel Gefunden : HKLM\Software\Uniblue\DriverScanner
Schlüssel Gefunden : HKLM\Software\Winload
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{40C3CC16-7269-4B32-9531-17F2950FB06F}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{40C3CC16-7269-4B32-9531-17F2950FB06F}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{40C3CC16-7269-4B32-9531-17F2950FB06F}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{40C3CC16-7269-4B32-9531-17F2950FB06F}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{40C3CC16-7269-4B32-9531-17F2950FB06F}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{40C3CC16-7269-4B32-9531-17F2950FB06F}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16526
-\\ Mozilla Firefox v11.0 (de)
[ Datei : C:\Users\Guido\AppData\Roaming\Mozilla\Firefox\Profiles\pddsqboq.default\prefs.js ]
Zeile gefunden : user_pref("CT2857572..clientLogIsEnabled", true);
Zeile gefunden : user_pref("CT2857572..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gefunden : user_pref("CT2857572..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gefunden : user_pref("CT2857572.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Zeile gefunden : user_pref("CT2857572.AppTrackingLastCheckTime", "Sat Jan 15 2011 15:49:57 GMT+0100");
Zeile gefunden : user_pref("CT2857572.CT2857572", "CT2857572");
Zeile gefunden : user_pref("CT2857572.CurrentServerDate", "24-3-2011");
Zeile gefunden : user_pref("CT2857572.DialogsAlignMode", "LTR");
Zeile gefunden : user_pref("CT2857572.DialogsGetterLastCheckTime", "Sat Jan 15 2011 15:49:46 GMT+0100");
Zeile gefunden : user_pref("CT2857572.DownloadReferralCookieData", "");
Zeile gefunden : user_pref("CT2857572.ExternalComponentPollDate129356796046694434", "Thu Mar 24 2011 16:44:55 GMT+0100");
Zeile gefunden : user_pref("CT2857572.FirstServerDate", "15-1-2011");
Zeile gefunden : user_pref("CT2857572.FirstTime", true);
Zeile gefunden : user_pref("CT2857572.FirstTimeFF3", true);
Zeile gefunden : user_pref("CT2857572.FixPageNotFoundErrors", false);
Zeile gefunden : user_pref("CT2857572.GroupingServerCheckInterval", 1440);
Zeile gefunden : user_pref("CT2857572.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gefunden : user_pref("CT2857572.HasUserGlobalKeys", true);
Zeile gefunden : user_pref("CT2857572.Initialize", true);
Zeile gefunden : user_pref("CT2857572.InitializeCommonPrefs", true);
Zeile gefunden : user_pref("CT2857572.InstallationAndCookieDataSentCount", 3);
Zeile gefunden : user_pref("CT2857572.InstalledDate", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("CT2857572.InvalidateCache", false);
Zeile gefunden : user_pref("CT2857572.IsGrouping", false);
Zeile gefunden : user_pref("CT2857572.IsMulticommunity", false);
Zeile gefunden : user_pref("CT2857572.IsOpenThankYouPage", true);
Zeile gefunden : user_pref("CT2857572.IsOpenUninstallPage", true);
Zeile gefunden : user_pref("CT2857572.LanguagePackLastCheckTime", "Thu Mar 24 2011 16:44:56 GMT+0100");
Zeile gefunden : user_pref("CT2857572.LanguagePackReloadIntervalMM", 1440);
Zeile gefunden : user_pref("CT2857572.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gefunden : user_pref("CT2857572.LastLogin_3.3.0.19", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("CT2857572.LastLogin_3.3.3.2", "Thu Mar 24 2011 20:44:55 GMT+0100");
Zeile gefunden : user_pref("CT2857572.LatestVersion", "3.2.5.2");
Zeile gefunden : user_pref("CT2857572.Locale", "en");
Zeile gefunden : user_pref("CT2857572.MCDetectTooltipHeight", "83");
Zeile gefunden : user_pref("CT2857572.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gefunden : user_pref("CT2857572.MCDetectTooltipWidth", "295");
Zeile gefunden : user_pref("CT2857572.RadioIsPodcast", false);
Zeile gefunden : user_pref("CT2857572.RadioLastCheckTime", "Thu Mar 24 2011 16:44:56 GMT+0100");
Zeile gefunden : user_pref("CT2857572.RadioLastUpdateIPServer", "3");
Zeile gefunden : user_pref("CT2857572.RadioLastUpdateServer", "129400870958430000");
Zeile gefunden : user_pref("CT2857572.RadioMediaID", "21753723");
Zeile gefunden : user_pref("CT2857572.RadioMediaType", "Media Player");
Zeile gefunden : user_pref("CT2857572.RadioMenuSelectedID", "EBRadioMenu_CT285757221753723");
Zeile gefunden : user_pref("CT2857572.RadioShrinked", "shrinked");
Zeile gefunden : user_pref("CT2857572.RadioStationName", "California%20Rock%20-%20Rock");
Zeile gefunden : user_pref("CT2857572.RadioStationURL", "hxxp://www.feedlive.net/california.asx");
Zeile gefunden : user_pref("CT2857572.SHRINK_TOOLBAR", 1);
Zeile gefunden : user_pref("CT2857572.SavedHomepage", "hxxp://ecosia.org/");
Zeile gefunden : user_pref("CT2857572.SearchBoxWidth", 392);
Zeile gefunden : user_pref("CT2857572.SearchFromAddressBarIsInit", true);
Zeile gefunden : user_pref("CT2857572.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2857572&q=");
Zeile gefunden : user_pref("CT2857572.SearchInNewTabEnabled", true);
Zeile gefunden : user_pref("CT2857572.SearchInNewTabIntervalMM", 1440);
Zeile gefunden : user_pref("CT2857572.SearchInNewTabLastCheckTime", "Thu Mar 24 2011 16:44:56 GMT+0100");
Zeile gefunden : user_pref("CT2857572.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Zeile gefunden : user_pref("CT2857572.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Zeile gefunden : user_pref("CT2857572.ServiceMapLastCheckTime", "Thu Mar 24 2011 16:44:55 GMT+0100");
Zeile gefunden : user_pref("CT2857572.SettingsLastCheckTime", "Thu Mar 24 2011 16:44:54 GMT+0100");
Zeile gefunden : user_pref("CT2857572.SettingsLastUpdate", "1300788505");
Zeile gefunden : user_pref("CT2857572.ThirdPartyComponentsInterval", 504);
Zeile gefunden : user_pref("CT2857572.ThirdPartyComponentsLastCheck", "Thu Mar 24 2011 16:44:54 GMT+0100");
Zeile gefunden : user_pref("CT2857572.ThirdPartyComponentsLastUpdate", "1246790578");
Zeile gefunden : user_pref("CT2857572.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2857572");
Zeile gefunden : user_pref("CT2857572.UserID", "UN03559203793413468");
Zeile gefunden : user_pref("CT2857572.ValidationData_Toolbar", 2);
Zeile gefunden : user_pref("CT2857572.WeatherNetwork", "");
Zeile gefunden : user_pref("CT2857572.WeatherPollDate", "Thu Mar 24 2011 16:44:56 GMT+0100");
Zeile gefunden : user_pref("CT2857572.WeatherUnit", "C");
Zeile gefunden : user_pref("CT2857572.alertChannelId", "1249594");
Zeile gefunden : user_pref("CT2857572.approveUntrustedApps", true);
Zeile gefunden : user_pref("CT2857572.backendstorage._fb_dailyactivity", "31333030393831343936373638");
Zeile gefunden : user_pref("CT2857572.backendstorage._fb_lifetimesent", "54525545");
Zeile gefunden : user_pref("CT2857572.backendstorage.facebook_ctid_connect_send", "73656E646564");
Zeile gefunden : user_pref("CT2857572.components.1000082", false);
Zeile gefunden : user_pref("CT2857572.components.1000234", false);
Zeile gefunden : user_pref("CT2857572.components.129356796046694434", false);
Zeile gefunden : user_pref("CT2857572.components.129356796047006936", false);
Zeile gefunden : user_pref("CT2857572.components.129400803056288017", false);
Zeile gefunden : user_pref("CT2857572.components.129435747711838079", false);
Zeile gefunden : user_pref("CT2857572.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.com\"}");
Zeile gefunden : user_pref("CT2857572.globalFirstTimeInfoLastCheckTime", "Thu Mar 24 2011 20:44:55 GMT+0100");
Zeile gefunden : user_pref("CT2857572.isAppTrackingManagerOn", true);
Zeile gefunden : user_pref("CT2857572.myStuffEnabled", true);
Zeile gefunden : user_pref("CT2857572.myStuffPublihserMinWidth", 400);
Zeile gefunden : user_pref("CT2857572.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Zeile gefunden : user_pref("CT2857572.myStuffServiceIntervalMM", 1440);
Zeile gefunden : user_pref("CT2857572.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gefunden : user_pref("CT2857572.oldAppsList", "129356796045131912,129356796046381930,129356796046694434,1000082,129435747711838079,129400803056288017,1000234,129356796047006936,1000034,1000080,1000,1001,1002,100[...]
Zeile gefunden : user_pref("CT2857572.testingCtid", "");
Zeile gefunden : user_pref("CT2857572.toolbarAppMetaDataLastCheckTime", "Thu Mar 24 2011 16:44:56 GMT+0100");
Zeile gefunden : user_pref("CT2857572.toolbarContextMenuLastCheckTime", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("CT2857572.usagesFlag", 2);
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1249594/1245267/DE", "\"0\"");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2857572", "\"0\"");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "wVmmvqqOMqrv5xct1cJIHg==");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "poKjTfHs0NrVUIalKI8jyg==");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "Dclc8oo4TTv7+mAkSlUSWg==");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "K4Vqu91uAzWURlxJRdXJOg==");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"07879643d3acc1:0\"");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.0.19", "\"8039ce950b0cb1:0\"");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.0.19", "\"8039ce950b0cb1:0\"");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2857572", "\"634333631231730000\"");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634303635100000000");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2857572/CT2857572", "\"1300788505\"");
Zeile gefunden : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634351849102130000\"");
Zeile gefunden : user_pref("CommunityToolbar.EngineOwner", "CT2857572");
Zeile gefunden : user_pref("CommunityToolbar.EngineOwnerGuid", "{38542454-dfb6-44f5-b052-d4e071a3d073}");
Zeile gefunden : user_pref("CommunityToolbar.EngineOwnerToolbarId", "elf_1.12");
Zeile gefunden : user_pref("CommunityToolbar.IsEngineShown", false);
Zeile gefunden : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Zeile gefunden : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2857572");
Zeile gefunden : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{38542454-dfb6-44f5-b052-d4e071a3d073}");
Zeile gefunden : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "elf_1.12");
Zeile gefunden : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=");
Zeile gefunden : user_pref("CommunityToolbar.ToolbarsList", "CT2857572,ConduitEngine");
Zeile gefunden : user_pref("CommunityToolbar.ToolbarsList2", "CT2857572");
Zeile gefunden : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Wed Oct 26 2011 19:46:21 GMT+0200");
Zeile gefunden : user_pref("CommunityToolbar.alert.alertEnabled", true);
Zeile gefunden : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Zeile gefunden : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Mar 04 2012 01:00:49 GMT+0100");
Zeile gefunden : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Zeile gefunden : user_pref("CommunityToolbar.alert.locale", "en");
Zeile gefunden : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Zeile gefunden : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sat Mar 17 2012 04:47:06 GMT+0100");
Zeile gefunden : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Zeile gefunden : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Zeile gefunden : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Zeile gefunden : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Zeile gefunden : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Zeile gefunden : user_pref("CommunityToolbar.alert.userId", "30b2d9ce-5a7f-4fb0-9133-d4961387ed74");
Zeile gefunden : user_pref("CommunityToolbar.globalUserId", "6e615807-1ec5-4543-9233-f9d97716f6b2");
Zeile gefunden : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Zeile gefunden : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Zeile gefunden : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2857572");
Zeile gefunden : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("ConduitEngine.FirstServerDate", "01/15/2011 17");
Zeile gefunden : user_pref("ConduitEngine.FirstTime", true);
Zeile gefunden : user_pref("ConduitEngine.FirstTimeFF3", true);
Zeile gefunden : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Zeile gefunden : user_pref("ConduitEngine.HideEngineAfterRestart", true);
Zeile gefunden : user_pref("ConduitEngine.Initialize", true);
Zeile gefunden : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Zeile gefunden : user_pref("ConduitEngine.InstalledDate", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("ConduitEngine.IsMulticommunity", false);
Zeile gefunden : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Zeile gefunden : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Zeile gefunden : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("ConduitEngine.LastLogin_3.3.0.19", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Zeile gefunden : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Zeile gefunden : user_pref("ConduitEngine.SettingsLastCheckTime", "Sat Jan 15 2011 15:49:46 GMT+0100");
Zeile gefunden : user_pref("ConduitEngine.UserID", "UN00681800113764452");
Zeile gefunden : user_pref("ConduitEngine.engineLocale", "de");
Zeile gefunden : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Sat Jan 15 2011 15:49:47 GMT+0100");
Zeile gefunden : user_pref("ConduitEngine.initDone", true);
Zeile gefunden : user_pref("ConduitEngine.isAppTrackingManagerOn", false);
Zeile gefunden : user_pref("browser.search.defaultthis.engineName", "Elf 1.12 Customized Web Search");
Zeile gefunden : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2857572&SearchSource=3&q={searchTerms}");
Zeile gefunden : user_pref("extensions.enabledItems", "{20a82645-c095-46ed-80e3-08825760534b}:1.1,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}:1.0.5,{D4DD63FA-01E4-46a7-B6B1-EDA[...]
Zeile gefunden : user_pref("extensions.engine@conduit.com.install-event-fired", true);
[ Datei : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\prefs.js ]
Zeile gefunden : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Zeile gefunden : user_pref("CT2319825.CTID", "CT2319825");
Zeile gefunden : user_pref("CT2319825.CurrentServerDate", "27-7-2010");
Zeile gefunden : user_pref("CT2319825.DialogsAlignMode", "LTR");
Zeile gefunden : user_pref("CT2319825.EMailNotifierPollDate", "Tue Jul 27 2010 09:50:10 GMT+0200");
Zeile gefunden : user_pref("CT2319825.FeedLastCount128902288263982011", 77);
Zeile gefunden : user_pref("CT2319825.FeedLastCount129056115025381886", 10);
Zeile gefunden : user_pref("CT2319825.FeedPollDate11908299", "Tue Jul 27 2010 09:50:09 GMT+0200");
Zeile gefunden : user_pref("CT2319825.FeedPollDate128902288263982011", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.FeedPollDate129056115025381886", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.FeedPollDate129228016461601757", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.FeedPollDate129228019840048158", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.FeedPollDate129228021559110981", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.FeedPollDate129228022849107630", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.FirstServerDate", "27-7-2010");
Zeile gefunden : user_pref("CT2319825.FirstTime", true);
Zeile gefunden : user_pref("CT2319825.FirstTimeFF3", true);
Zeile gefunden : user_pref("CT2319825.FixPageNotFoundErrors", true);
Zeile gefunden : user_pref("CT2319825.GroupingServerCheckInterval", 1440);
Zeile gefunden : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gefunden : user_pref("CT2319825.Initialize", true);
Zeile gefunden : user_pref("CT2319825.InitializeCommonPrefs", true);
Zeile gefunden : user_pref("CT2319825.InstalledDate", "Tue Jul 27 2010 09:11:52 GMT+0200");
Zeile gefunden : user_pref("CT2319825.InvalidateCache", false);
Zeile gefunden : user_pref("CT2319825.IsGrouping", false);
Zeile gefunden : user_pref("CT2319825.IsMulticommunity", false);
Zeile gefunden : user_pref("CT2319825.IsOpenThankYouPage", false);
Zeile gefunden : user_pref("CT2319825.IsOpenUninstallPage", true);
Zeile gefunden : user_pref("CT2319825.LanguagePackLastCheckTime", "Tue Jul 27 2010 09:11:54 GMT+0200");
Zeile gefunden : user_pref("CT2319825.LanguagePackReloadIntervalMM", 1440);
Zeile gefunden : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gefunden : user_pref("CT2319825.LastLogin_2.5.8.6", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.LatestVersion", "2.1.0.18");
Zeile gefunden : user_pref("CT2319825.Locale", "de");
Zeile gefunden : user_pref("CT2319825.LoginCache", 4);
Zeile gefunden : user_pref("CT2319825.MCDetectTooltipHeight", "83");
Zeile gefunden : user_pref("CT2319825.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gefunden : user_pref("CT2319825.MCDetectTooltipWidth", "295");
Zeile gefunden : user_pref("CT2319825.RadioIsPodcast", false);
Zeile gefunden : user_pref("CT2319825.RadioLastCheckTime", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.RadioLastUpdateIPServer", "3");
Zeile gefunden : user_pref("CT2319825.RadioLastUpdateServer", "129224641269630000");
Zeile gefunden : user_pref("CT2319825.RadioMediaID", "11949532");
Zeile gefunden : user_pref("CT2319825.RadioMediaType", "Media Player");
Zeile gefunden : user_pref("CT2319825.RadioMenuSelectedID", "EBRadioMenu_CT231982511949532");
Zeile gefunden : user_pref("CT2319825.RadioStationName", "1Live");
Zeile gefunden : user_pref("CT2319825.RadioStationURL", "hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_einslive_a");
Zeile gefunden : user_pref("CT2319825.SHRINK_TOOLBAR", 1);
Zeile gefunden : user_pref("CT2319825.SavedHomepage", "resource:/browserconfig.properties");
Zeile gefunden : user_pref("CT2319825.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2319825&octid=EB_ORIGINAL_CTID&SearchSource=1");
Zeile gefunden : user_pref("CT2319825.SearchFromAddressBarIsInit", true);
Zeile gefunden : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q=");
Zeile gefunden : user_pref("CT2319825.SearchInNewTabEnabled", true);
Zeile gefunden : user_pref("CT2319825.SearchInNewTabIntervalMM", 1440);
Zeile gefunden : user_pref("CT2319825.SearchInNewTabLastCheckTime", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Zeile gefunden : user_pref("CT2319825.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Zeile gefunden : user_pref("CT2319825.SettingsCheckIntervalMin", 120);
Zeile gefunden : user_pref("CT2319825.SettingsLastCheckTime", "Tue Jul 27 2010 09:11:52 GMT+0200");
Zeile gefunden : user_pref("CT2319825.SettingsLastUpdate", "1279443065");
Zeile gefunden : user_pref("CT2319825.ThirdPartyComponentsInterval", 504);
Zeile gefunden : user_pref("CT2319825.ThirdPartyComponentsLastCheck", "Tue Jul 27 2010 09:11:52 GMT+0200");
Zeile gefunden : user_pref("CT2319825.ThirdPartyComponentsLastUpdate", "1255348257");
Zeile gefunden : user_pref("CT2319825.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
Zeile gefunden : user_pref("CT2319825.UserID", "UN10971236462069622");
Zeile gefunden : user_pref("CT2319825.ValidationData_Toolbar", 0);
Zeile gefunden : user_pref("CT2319825.WeatherNetwork", "");
Zeile gefunden : user_pref("CT2319825.WeatherPollDate", "Tue Jul 27 2010 09:50:10 GMT+0200");
Zeile gefunden : user_pref("CT2319825.WeatherUnit", "C");
Zeile gefunden : user_pref("CT2319825.alertChannelId", "715912");
Zeile gefunden : user_pref("CT2319825.backendstorage.shpngrd_evnts", "30");
Zeile gefunden : user_pref("CT2319825.backendstorage.shpngrdglblcfg", "7B202772656627203A2027776E6C64272C2027636E74727927203A20276465272C20276C616E6727203A207B2027636F6D706172655F707269636573273A2027507265697365207665[...]
Zeile gefunden : user_pref("CT2319825.clientLogIsEnabled", true);
Zeile gefunden : user_pref("CT2319825.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gefunden : user_pref("CT2319825.myStuffEnabled", true);
Zeile gefunden : user_pref("CT2319825.myStuffPublihserMinWidth", 400);
Zeile gefunden : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Zeile gefunden : user_pref("CT2319825.myStuffServiceIntervalMM", 1440);
Zeile gefunden : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gefunden : user_pref("CT2319825.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gefunden : user_pref("CT2801937.1000082.isDisplayHidden", "true");
Zeile gefunden : user_pref("CT2801937.1000082.isPlayDisplay", "true");
Zeile gefunden : user_pref("CT2801937.1000082.state", "{\"state\":\"stopped\",\"text\":\"GermanyFM...\",\"description\":\"GermanyFM Info\",\"url\":\"hxxp://www.1000mikes.com/audio/1000mikes.m3u?channelId=6680\"}");
Zeile gefunden : user_pref("CT2801937.1000234.TWC_TMP_city", "BERLIN");
Zeile gefunden : user_pref("CT2801937.1000234.TWC_TMP_country", "DE");
Zeile gefunden : user_pref("CT2801937.1000234.TWC_locId", "GMXX0007");
Zeile gefunden : user_pref("CT2801937.1000234.TWC_location", "Berlin, Deutschland");
Zeile gefunden : user_pref("CT2801937.1000234.TWC_region", "DE");
Zeile gefunden : user_pref("CT2801937.1000234.TWC_temp_dis", "c");
Zeile gefunden : user_pref("CT2801937.1000234.TWC_wind_dis", "kmh");
Zeile gefunden : user_pref("CT2801937.1000234.weatherData", "{\"icon\":\"30.png\",\"temperature\":\"19°C\",\"temperatureClear\":\"19°C\",\"highTemperature\":\"19°C\",\"lowTemperature\":\"9°C\",\"feelsLike\":\"19°[...]
Zeile gefunden : user_pref("CT2801937.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gefunden : user_pref("CT2801937.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gefunden : user_pref("CT2801937.Facebook_Mode.enc", "Mg==");
Zeile gefunden : user_pref("CT2801937.Facebook_User_Locale.enc", "ZW4=");
Zeile gefunden : user_pref("CT2801937.FirstTime", "true");
Zeile gefunden : user_pref("CT2801937.FirstTimeFF3", "true");
Zeile gefunden : user_pref("CT2801937.LoginRevertSettingsEnabled", true);
Zeile gefunden : user_pref("CT2801937.RevertSettingsEnabled", true);
Zeile gefunden : user_pref("CT2801937.UserID", "UN47317047019917092");
Zeile gefunden : user_pref("CT2801937.XING_APP_MARKETPLACE_APP_LANG.enc", "ZW4=");
Zeile gefunden : user_pref("CT2801937.XING_APP_MARKETPLACE_GADGET_HEIGHT_NORMAL.enc", "NTY5");
Zeile gefunden : user_pref("CT2801937.XING_APP_MARKETPLACE_GADGET_HEIGHT_SHORT.enc", "NDE1");
Zeile gefunden : user_pref("CT2801937.XING_APP_MARKETPLACE_GADGET_WIDTH.enc", "MzUz");
Zeile gefunden : user_pref("CT2801937.addressBarTakeOverEnabledInHidden", "true");
Zeile gefunden : user_pref("CT2801937.autoDisableScopes", -1);
Zeile gefunden : user_pref("CT2801937.countryCode", "DE");
Zeile gefunden : user_pref("CT2801937.defaultSearch", "false");
Zeile gefunden : user_pref("CT2801937.embeddedsData", "[{\"appId\":\"129306877457319611\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Zeile gefunden : user_pref("CT2801937.enableAlerts", "always");
Zeile gefunden : user_pref("CT2801937.enableFix404ByUser", "TRUE");
Zeile gefunden : user_pref("CT2801937.enableSearchFromAddressBar", "true");
Zeile gefunden : user_pref("CT2801937.firstTimeDialogOpened", "true");
Zeile gefunden : user_pref("CT2801937.fixPageNotFoundError", "true");
Zeile gefunden : user_pref("CT2801937.fixPageNotFoundErrorByUser", "true");
Zeile gefunden : user_pref("CT2801937.fixPageNotFoundErrorInHidden", "true");
Zeile gefunden : user_pref("CT2801937.fixUrls", true);
Zeile gefunden : user_pref("CT2801937.fullUserID", "UN47317047019917092.UP.20130908215637");
Zeile gefunden : user_pref("CT2801937.hxxp___facebook_conduitapps_com.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPTAsaHNjcm9sbD0wLHZzY3JvbGw9MCx0aXRsZWJhcj0xLGNsb3NlYnV0dG9uPTEsc2F2ZXJlc2l6ZWRzaXplPTAsb3BlbnBvc2l0aW9uPWFsaWd[...]
Zeile gefunden : user_pref("CT2801937.installId", "conduitinstaller.exe");
Zeile gefunden : user_pref("CT2801937.installType", "conduitnsisintegration");
Zeile gefunden : user_pref("CT2801937.isCheckedStartAsHidden", true);
Zeile gefunden : user_pref("CT2801937.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gefunden : user_pref("CT2801937.isFirstTimeToolbarLoading", "false");
Zeile gefunden : user_pref("CT2801937.isNewTabEnabled", false);
Zeile gefunden : user_pref("CT2801937.isPerformedSmartBarTransition", "true");
Zeile gefunden : user_pref("CT2801937.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gefunden : user_pref("CT2801937.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT2801937&octid=CT2801937&SearchSource=15&CUI=UN47317047019917092&SSPV=&Lay=1&UM=\"}");
Zeile gefunden : user_pref("CT2801937.lastVersion", "10.19.2.505");
Zeile gefunden : user_pref("CT2801937.migrateAppsAndComponents", true);
Zeile gefunden : user_pref("CT2801937.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.trojaner-board.de%2F136099-win32-downloader-gen.html\",\"EB_MAIN_FRAME_TITLE\":\"Win32.Downloader.gen%20-%20Troj[...]
Zeile gefunden : user_pref("CT2801937.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gefunden : user_pref("CT2801937.openThankYouPage", "false");
Zeile gefunden : user_pref("CT2801937.openUninstallPage", "true");
Zeile gefunden : user_pref("CT2801937.revertSettingsEnabled", "false");
Zeile gefunden : user_pref("CT2801937.search.searchAppId", "129306877457319611");
Zeile gefunden : user_pref("CT2801937.search.searchCount", "0");
Zeile gefunden : user_pref("CT2801937.searchInNewTabEnabled", "false");
Zeile gefunden : user_pref("CT2801937.searchInNewTabEnabledByUser", "false");
Zeile gefunden : user_pref("CT2801937.searchInNewTabEnabledInHidden", "true");
Zeile gefunden : user_pref("CT2801937.searchSuggestEnabledByUser", "false");
Zeile gefunden : user_pref("CT2801937.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gefunden : user_pref("CT2801937.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gefunden : user_pref("CT2801937.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Zeile gefunden : user_pref("CT2801937.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2801937\"}");
Zeile gefunden : user_pref("CT2801937.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://NCHDE.OurToolbar.com//xpi\"}");
Zeile gefunden : user_pref("CT2801937.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"NCH DE \"}");
Zeile gefunden : user_pref("CT2801937.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gefunden : user_pref("CT2801937.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"1\"}");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_Configuration_lastUpdate", "1387453260266");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1387453263694");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_appsMetadata_lastUpdate", "1387453263602");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1387453263483");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_location_lastUpdate", "1377962394950");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_login_10.13.40.15_lastUpdate", "1363614440753");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_login_10.14.65.43_lastUpdate", "1370091830795");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_login_10.16.2.510_lastUpdate", "1377962395254");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_login_10.19.2.505_lastUpdate", "1387453263730");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1387453263609");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_searchAPI_lastUpdate", "1387453260234");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_serviceMap_lastUpdate", "1387453260142");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_setupAPI_lastUpdate", "1370091831055");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_toolbarContextMenu_lastUpdate", "1387453263553");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_toolbarSettings_lastUpdate", "1387453263641");
Zeile gefunden : user_pref("CT2801937.serviceLayer_services_translation_lastUpdate", "1387453263586");
Zeile gefunden : user_pref("CT2801937.settingsINI", true);
Zeile gefunden : user_pref("CT2801937.shouldFirstTimeDialog", "false");
Zeile gefunden : user_pref("CT2801937.showToolbarPermission", "false");
Zeile gefunden : user_pref("CT2801937.smartbar.CTID", "CT2801937");
Zeile gefunden : user_pref("CT2801937.smartbar.Uninstall", "0");
Zeile gefunden : user_pref("CT2801937.smartbar.toolbarName", "NCH DE ");
Zeile gefunden : user_pref("CT2801937.startPage", "false");
Zeile gefunden : user_pref("CT2801937.toolbarBornServerTime", "18-11-2012");
Zeile gefunden : user_pref("CT2801937.toolbarCurrentServerTime", "19-12-2013");
Zeile gefunden : user_pref("CT2801937.toolbarLoginClientTime", "Sat Jun 01 2013 16:16:03 GMT+0200");
Zeile gefunden : user_pref("CT2801937.twitter_v1.8.0_twitter_app_open_t_f.enc", "ZmFsc2U=");
Zeile gefunden : user_pref("CT2801937_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1387453136389,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Zeile gefunden : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
Zeile gefunden : user_pref("CommunityToolbar.ToolbarsList", "CT2319825");
Zeile gefunden : user_pref("CommunityToolbar.ToolbarsList2", "CT2319825");
Zeile gefunden : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Tue Jul 27 2010 09:11:53 GMT+0200");
Zeile gefunden : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2319825");
Zeile gefunden : user_pref("browser.search.defaultenginename", "NCH DE Customized Web Search");
Zeile gefunden : user_pref("browser.search.defaultthis.engineName", "Winload Customized Web Search");
Zeile gefunden : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}");
Zeile gefunden : user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\");
Zeile gefunden : user_pref("extensions.asktb.abar-war-timeout", "4000");
Zeile gefunden : user_pref("extensions.asktb.cbid", "^AAA");
Zeile gefunden : user_pref("extensions.asktb.config-updated", true);
Zeile gefunden : user_pref("extensions.asktb.crumb", "2011.08.08+01.23.42-toolbar001iad-DE-RXNjaGJvcm4sR2VybWFueQ%3D%3D");
Zeile gefunden : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}&gct=bar");
Zeile gefunden : user_pref("extensions.asktb.dtid", "^YYYYYY^YY^DE");
Zeile gefunden : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
Zeile gefunden : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX3268");
Zeile gefunden : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C");
Zeile gefunden : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q=");
Zeile gefunden : user_pref("extensions.asktb.first-launch-url", "hxxp://www.piriform.com/ccleaner/update?v=2.36.1233&l=1031");
Zeile gefunden : user_pref("extensions.asktb.first-restart-after-config-update", true);
Zeile gefunden : user_pref("extensions.asktb.fresh-install", false);
Zeile gefunden : user_pref("extensions.asktb.guid", "8e284242-30a3-4c3c-b7f3-7774ec3caf3b");
Zeile gefunden : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxps://websearch.ask.com\", [...]
Zeile gefunden : user_pref("extensions.asktb.if", "first");
Zeile gefunden : user_pref("extensions.asktb.l", "dis");
Zeile gefunden : user_pref("extensions.asktb.last-config-req", "1318638129785");
Zeile gefunden : user_pref("extensions.asktb.locale", "de_DE");
Zeile gefunden : user_pref("extensions.asktb.location", "Eschborn,Germany");
Zeile gefunden : user_pref("extensions.asktb.o", "1586");
Zeile gefunden : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Zeile gefunden : user_pref("extensions.asktb.qsrc", "2871");
Zeile gefunden : user_pref("extensions.asktb.r", "4");
Zeile gefunden : user_pref("extensions.asktb.sa", "YES");
Zeile gefunden : user_pref("extensions.asktb.saguid", "4157D447-68F3-482C-A260-D87C26D2C9CF");
Zeile gefunden : user_pref("extensions.asktb.search-suggestions-enabled", true);
Zeile gefunden : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Zeile gefunden : user_pref("extensions.asktb.socialmini-first", true);
Zeile gefunden : user_pref("extensions.asktb.socialmini-interval", "1200000");
Zeile gefunden : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Zeile gefunden : user_pref("extensions.asktb.socialmini-max-items", "30");
Zeile gefunden : user_pref("extensions.asktb.socialmini-native-on", true);
Zeile gefunden : user_pref("extensions.asktb.socialmini-speed", "5000");
Zeile gefunden : user_pref("extensions.asktb.socialmini-transition-first-open", false);
Zeile gefunden : user_pref("extensions.asktb.themeid", "");
Zeile gefunden : user_pref("extensions.asktb.to", "");
Zeile gefunden : user_pref("extensions.asktb.v", "3.12.5.100006");
Zeile gefunden : user_pref("extensions.asktb.version", "5.12.5.17640");
Zeile gefunden : user_pref("smartbar.machineId", "XVWEK0ER2IZ7OOPVXWO8Y2RE6RZ7QDL1XQKVWV07QZW/VV/6VK/RJAR4MGN+RD8IUVFTUWSWOFW+ONZKLBOOEA");
-\\ Google Chrome v31.0.1650.63
[ Datei : C:\Users\Guido\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [50718 octets] - [20/12/2013 23:49:53]
########## EOF - \AdwCleaner\AdwCleaner[R0].txt - [50779 octets] ########## --- --- ---
</code>
<code>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Admin on 21.12.2013 at 10:08:44,04
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DB9733F3-39C3-43BD-A7AA-278EFF59C77F}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\freerip"
Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader"
Successfully deleted: [Folder] "C:\Users\Admin\appdata\local\cre"
Successfully deleted: [Folder] "C:\Program Files\freerip3"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader"
~~~ FireFox
Successfully deleted: [File] C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\a9fjsumn.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Emptied folder: C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\a9fjsumn.default\minidumps [5 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.12.2013 at 10:12:00,08
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
</code>
<code>
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-12-2013 02
Ran by Admin (administrator) on GUIDO-PC on 21-12-2013 10:27:06
Running from C:\Firefox Downloads
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchService.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Acer\Mobility Center\MobilityService.exe
() C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(SafeNet, Inc) C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
() C:\Program Files\1&1 Surf-Stick\AssistantServices.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
() C:\Program Files\1&1 Surf-Stick\UIExec.exe
() C:\Program Files\Bamboo Dock\BambooCore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(CHENGDU YIWO Tech Development Co., Ltd) C:\Users\Admin\Downloads\EaseUS Partition Master 9.2.2\bin\EpmNews.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Tobit.Software) C:\Program Files\Tobit Radio.fx\Client\rfx-tray.exe
(Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(Panasonic Corporation) C:\Program Files\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
(Dropbox, Inc.) C:\Users\Guido\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Realtek Semiconductor Corp.) C:\Users\Guido\AppData\Local\temp\RtkBtMnt.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvSvc] - RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [SynTPStart] - C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2008-01-24] (Synaptics, Inc.)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2007-11-22] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4702208 2008-01-24] (Realtek Semiconductor)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [WarReg_PopUp] - C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe [303104 2008-01-29] (Acer Incorporated)
HKLM\...\Run: [PLFSet] - rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
HKLM\...\Run: [UIExec] - C:\Program Files\1&1 Surf-Stick\UIExec.exe [139088 2010-09-30] ()
HKLM\...\Run: [BambooCore] - C:\Program Files\Bamboo Dock\BambooCore.exe [646232 2011-10-10] ()
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [310128 2013-02-13] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [EaseUS EPM tray] - C:\Users\Admin\Downloads\EaseUS Partition Master 9.2.2\bin\EpmNews.exe [2081792 2013-03-29] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM\...\Run: [Skytel] - C:\Windows\SkyTel.exe [1826816 2008-01-24] (Realtek Semiconductor Corp.)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKCU\...\Run: [ccleaner] - C:\Program Files\CCleaner\CCleaner.exe [4324120 2013-11-22] (Piriform Ltd)
HKCU\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-02-13] (Samsung)
HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1509232 2013-02-13] (Samsung)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-02-13] (Samsung)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default\...\RunOnce: [AcerScrSav] - C:\Windows\ACER\run_NB.exe [ 2007-08-21] ()
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\RunOnce: [AcerScrSav] - C:\Windows\ACER\run_NB.exe [ 2007-08-21] ()
HKU\Gast\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Guido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Guido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Guido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.ask.com/?l=dis&o=1586&gct=hp
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.intl.acer.yahoo.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKCU - {D74A3892-F57E-480B-8501-3A03683A21BD} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=386496&p={searchTerms}
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Google
FF Homepage: www.ecosia.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @wacom.com/wacom-plugin,version=1.1.0.4 - C:\Program Files\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\searchplugins\ixquick---deutsch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Ecosia (eco-friendly search engine) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}
FF Extension: preisspion.de - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\finder@meingutscheincode.de.xpi
FF Extension: Ask Toolbar - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\toolbar_SGT-V7@apn.ask.com.xpi
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\a9fjsumn.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchKeyword: google.com
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0
CHR Extension: (Skype Click to Call) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-11-07] (APN LLC.)
R2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.)
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-11-27] ()
R2 Radio.fx; C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [266343 2007-12-04] ()
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 SentinelProtectionServer; C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [206400 2006-03-14] (SafeNet, Inc)
R2 UI Assistant Service; C:\Program Files\1&1 Surf-Stick\AssistantServices.exe [253264 2010-09-30] ()
S3 de_serv; C:\Program Files\Common Files\AVM\de_serv.exe [x]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-30] (Avira Operations GmbH & Co. KG)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14920 2013-03-07] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9160 2013-03-07] ()
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-02-05] ()
R2 int15; C:\Acer\Empowering Technology\eRecovery\int15.sys [15392 2007-07-03] (Acer, Inc.)
S3 mod7700; C:\Windows\System32\Drivers\mod7700.sys [596352 2008-06-11] (DiBcom SA)
S3 MODRC; C:\Windows\System32\DRIVERS\modrc.sys [13824 2007-10-19] (DiBcom S.A.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1729152 2007-06-12] ()
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-05-17] (Duplex Secure Ltd.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH)
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerflt.sys [8064 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltj.sys [8064 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
R3 winbondcir; C:\Windows\System32\DRIVERS\winbondcir.sys [43008 2008-01-24] (Winbond Electronics Corporation)
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [41456 2008-01-04] (Cyberlink Corp.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Admin\AppData\Local\Temp\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1d\WNt500x86\Sandra.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-21 10:12 - 2013-12-21 10:12 - 00001838 _____ C:\Users\Guido\Desktop\JRT.txt
2013-12-21 10:08 - 2013-12-21 10:08 - 00000000 ____D C:\Windows\ERUNT
2013-12-21 10:06 - 2013-12-21 10:06 - 01034531 _____ (Thisisu) C:\Users\Guido\Desktop\JRT.exe
2013-12-21 00:23 - 2013-12-21 00:23 - 00050858 _____ C:\Users\Guido\Desktop\AdwCleaner[R0].txt
2013-12-21 00:21 - 2013-12-21 00:21 - 00001657 _____ C:\Users\Admin\Desktop\AdwCleaner[R1].txt
2013-12-21 00:16 - 2013-12-21 00:16 - 01226750 _____ C:\Users\Guido\Desktop\adwcleaner.exe
2013-12-21 00:06 - 2013-12-21 00:06 - 00328048 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-20 23:49 - 2013-12-21 00:18 - 00000000 ____D C:\AdwCleaner
2013-12-20 22:33 - 2013-12-20 22:33 - 00059580 _____ C:\Users\Guido\Documents\Trojaner-Board-Anleitung.odt
2013-12-20 18:13 - 2013-12-20 18:13 - 00000910 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-20 14:33 - 2013-12-21 00:12 - 00000000 ____D C:\Users\Guido\AppData\Local\Mozilla Firefox
2013-12-20 09:16 - 2013-12-20 09:16 - 00035521 _____ C:\ComboFix.txt
2013-12-20 08:59 - 2013-12-20 09:16 - 00000000 ____D C:\Qoobox
2013-12-20 08:59 - 2013-12-20 09:16 - 00000000 ____D C:\ComboFix
2013-12-20 08:59 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-12-20 08:59 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-12-20 08:59 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-12-20 08:59 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-12-20 08:59 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-12-20 08:59 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-12-20 08:59 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-12-20 08:59 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-12-20 08:51 - 2013-12-20 08:52 - 05154906 ____R (Swearware) C:\Users\Guido\Desktop\ComboFix.exe
2013-12-19 20:41 - 2013-12-19 20:41 - 00027243 _____ C:\Users\Guido\Desktop\Trojaner-Board.odt
2013-12-19 20:39 - 2013-12-19 20:39 - 00000020 _____ C:\Users\Admin\defogger_reenable
2013-12-19 20:34 - 2013-12-19 20:34 - 00038766 _____ C:\Users\Guido\Desktop\FRST.txt
2013-12-19 20:33 - 2013-12-19 20:33 - 00026151 _____ C:\Users\Guido\Desktop\Addition.txt
2013-12-19 20:32 - 2013-12-21 00:26 - 00038435 _____ C:\Users\Admin\Desktop\FRST.txt
2013-12-19 20:31 - 2013-12-19 20:31 - 00026151 _____ C:\Users\Admin\Desktop\Addition.txt
2013-12-19 20:21 - 2013-12-19 20:21 - 00040404 _____ C:\Users\Guido\Desktop\Gmer.txt
2013-12-19 19:48 - 2013-12-21 00:25 - 00000000 ____D C:\FRST
2013-12-19 11:04 - 2013-12-19 11:04 - 00000000 ____D C:\Users\Admin\AppData\Local\AskPartnerNetwork
2013-12-18 14:14 - 2013-12-19 10:49 - 00009352 _____ C:\Users\Guido\Desktop\Zugangsdaten.odt
2013-12-17 21:26 - 2013-12-18 14:15 - 00008799 _____ C:\Users\Guido\Desktop\Silvester Liederliste.odt
2013-12-15 13:57 - 2013-12-15 13:58 - 555514226 _____ C:\Users\Guido\Desktop\Pascal Schumacher Quartet live - XIX Festiwal Jazz na Starówce 2013.mp4
2013-12-13 08:10 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-13 08:10 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-13 08:10 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-13 08:10 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-13 08:10 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-13 08:10 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-13 08:10 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-13 08:10 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-13 08:10 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-13 08:10 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-13 08:10 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-13 08:10 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-13 08:09 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-13 08:09 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-13 08:09 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-13 08:09 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 08:56 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
2013-12-12 08:56 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 08:56 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-12 08:56 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 08:56 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 08:56 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 08:56 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 08:56 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll
2013-12-12 08:56 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 08:56 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-08 13:51 - 2013-12-08 13:51 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-12-02 09:04 - 2013-12-02 09:04 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-11-29 10:16 - 2013-12-06 10:16 - 00000000 ____D C:\Program Files\McAfee Security Scan
2013-11-29 10:16 - 2013-11-29 10:16 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2013-11-27 11:39 - 2013-11-27 11:39 - 00008988 _____ C:\Users\Guido\Desktop\Adecco.odt
2013-11-24 10:32 - 2013-11-24 10:40 - 00000000 ____D C:\Users\Guido\Desktop\Boney M
2013-11-22 12:39 - 2013-11-22 12:39 - 00000000 ____D C:\ProgramData\Oracle
2013-11-22 12:39 - 2013-11-22 12:39 - 00000000 ____D C:\Program Files\Common Files\Java
2013-11-22 12:39 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-11-22 12:38 - 2013-11-22 12:38 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log
2013-11-22 12:38 - 2013-10-08 07:50 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-11-22 12:38 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-11-22 12:38 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
==================== One Month Modified Files and Folders =======
2013-12-21 10:27 - 2011-07-28 10:50 - 00000000 ___RD C:\Users\Guido\Dropbox
2013-12-21 10:27 - 2011-07-28 10:48 - 00000000 ____D C:\Users\Guido\AppData\Roaming\Dropbox
2013-12-21 10:27 - 2010-01-14 17:19 - 00000000 ____D C:\Users\Guido\AppData\Roaming\Skype
2013-12-21 10:27 - 2008-01-21 08:16 - 00006626 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-21 10:24 - 2012-10-10 14:31 - 01637215 _____ C:\Windows\WindowsUpdate.log
2013-12-21 10:21 - 2010-02-22 09:15 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-21 10:21 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-21 10:21 - 2006-11-02 13:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-21 10:21 - 2006-11-02 13:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-21 10:19 - 2006-11-02 14:01 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-21 10:15 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-21 10:12 - 2013-12-21 10:12 - 00001838 _____ C:\Users\Guido\Desktop\JRT.txt
2013-12-21 10:08 - 2013-12-21 10:08 - 00000000 ____D C:\Windows\ERUNT
2013-12-21 10:06 - 2013-12-21 10:06 - 01034531 _____ (Thisisu) C:\Users\Guido\Desktop\JRT.exe
2013-12-21 00:26 - 2013-12-19 20:32 - 00038435 _____ C:\Users\Admin\Desktop\FRST.txt
2013-12-21 00:25 - 2013-12-19 19:48 - 00000000 ____D C:\FRST
2013-12-21 00:23 - 2013-12-21 00:23 - 00050858 _____ C:\Users\Guido\Desktop\AdwCleaner[R0].txt
2013-12-21 00:21 - 2013-12-21 00:21 - 00001657 _____ C:\Users\Admin\Desktop\AdwCleaner[R1].txt
2013-12-21 00:18 - 2013-12-20 23:49 - 00000000 ____D C:\AdwCleaner
2013-12-21 00:16 - 2013-12-21 00:16 - 01226750 _____ C:\Users\Guido\Desktop\adwcleaner.exe
2013-12-21 00:12 - 2013-12-20 14:33 - 00000000 ____D C:\Users\Guido\AppData\Local\Mozilla Firefox
2013-12-21 00:06 - 2013-12-21 00:06 - 00328048 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-20 23:12 - 2012-04-04 12:25 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-20 23:12 - 2010-02-22 09:15 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-20 22:33 - 2013-12-20 22:33 - 00059580 _____ C:\Users\Guido\Documents\Trojaner-Board-Anleitung.odt
2013-12-20 21:38 - 2013-05-01 14:10 - 00000000 ____D C:\Users\Guido\Documents\Anki
2013-12-20 18:13 - 2013-12-20 18:13 - 00000910 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-20 18:13 - 2010-02-05 17:45 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-20 13:36 - 2010-08-10 11:41 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ghostscript
2013-12-20 13:36 - 2010-01-29 18:34 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-12-20 09:16 - 2013-12-20 09:16 - 00035521 _____ C:\ComboFix.txt
2013-12-20 09:16 - 2013-12-20 08:59 - 00000000 ____D C:\Qoobox
2013-12-20 09:16 - 2013-12-20 08:59 - 00000000 ____D C:\ComboFix
2013-12-20 09:14 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini
2013-12-20 08:59 - 2010-02-24 21:02 - 00000000 ____D C:\Windows\ERDNT
2013-12-20 08:52 - 2013-12-20 08:51 - 05154906 ____R (Swearware) C:\Users\Guido\Desktop\ComboFix.exe
2013-12-19 20:41 - 2013-12-19 20:41 - 00027243 _____ C:\Users\Guido\Desktop\Trojaner-Board.odt
2013-12-19 20:39 - 2013-12-19 20:39 - 00000020 _____ C:\Users\Admin\defogger_reenable
2013-12-19 20:39 - 2010-01-14 22:00 - 00000000 ____D C:\Users\Admin
2013-12-19 20:34 - 2013-12-19 20:34 - 00038766 _____ C:\Users\Guido\Desktop\FRST.txt
2013-12-19 20:33 - 2013-12-19 20:33 - 00026151 _____ C:\Users\Guido\Desktop\Addition.txt
2013-12-19 20:31 - 2013-12-19 20:31 - 00026151 _____ C:\Users\Admin\Desktop\Addition.txt
2013-12-19 20:25 - 2010-01-30 17:29 - 00007620 _____ C:\Users\Admin\AppData\Local\d3d9caps.dat
2013-12-19 20:21 - 2013-12-19 20:21 - 00040404 _____ C:\Users\Guido\Desktop\Gmer.txt
2013-12-19 12:58 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Speech
2013-12-19 12:18 - 2011-01-03 18:04 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2013-12-19 11:09 - 2010-01-14 21:17 - 00000000 ____D C:\Program Files\CCleaner
2013-12-19 11:07 - 2010-01-14 16:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-19 11:04 - 2013-12-19 11:04 - 00000000 ____D C:\Users\Admin\AppData\Local\AskPartnerNetwork
2013-12-19 10:49 - 2013-12-18 14:14 - 00009352 _____ C:\Users\Guido\Desktop\Zugangsdaten.odt
2013-12-18 14:15 - 2013-12-17 21:26 - 00008799 _____ C:\Users\Guido\Desktop\Silvester Liederliste.odt
2013-12-17 18:56 - 2010-04-29 16:25 - 00017408 _____ C:\Users\Guido\AppData\Local\WebpageIcons.db
2013-12-17 13:42 - 2013-08-05 14:21 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-17 13:42 - 2013-08-05 14:21 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-16 03:00 - 2010-02-19 19:05 - 00007620 _____ C:\Users\Guido\AppData\Local\d3d9caps.dat
2013-12-15 13:58 - 2013-12-15 13:57 - 555514226 _____ C:\Users\Guido\Desktop\Pascal Schumacher Quartet live - XIX Festiwal Jazz na Starówce 2013.mp4
2013-12-13 08:23 - 2010-01-11 15:58 - 00000000 ____D C:\Windows\system32\RTCOM
2013-12-13 08:20 - 2008-03-25 15:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-13 08:16 - 2013-08-02 15:12 - 00000000 ____D C:\Windows\system32\MRT
2013-12-13 08:12 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-12-11 19:12 - 2012-04-04 12:25 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-11 19:12 - 2011-05-20 07:48 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-11 18:54 - 2010-01-14 17:35 - 00000000 ____D C:\Program Files\Google
2013-12-09 16:07 - 2011-07-14 16:20 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Foxit Software
2013-12-08 13:53 - 2010-01-14 15:34 - 00000000 ____D C:\Users\Guido\AppData\Roaming\Adobe
2013-12-08 13:52 - 2010-03-24 16:05 - 00000000 ____D C:\Users\Admin\AppData\Local\Adobe
2013-12-08 13:51 - 2013-12-08 13:51 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-12-08 13:51 - 2010-12-20 23:17 - 00000000 ____D C:\Program Files\Adobe
2013-12-08 13:51 - 2008-03-25 15:09 - 00000000 ____D C:\ProgramData\Adobe
2013-12-07 17:32 - 2013-10-13 16:54 - 00000000 ____D C:\Users\Guido\Desktop\Webseite
2013-12-07 17:23 - 2013-09-24 13:21 - 00000000 ____D C:\Users\Guido\AppData\Local\Paint.NET
2013-12-06 10:16 - 2013-11-29 10:16 - 00000000 ____D C:\Program Files\McAfee Security Scan
2013-12-04 13:05 - 2011-07-08 09:38 - 00000000 ____D C:\Users\Guido\AppData\Roaming\Foxit Software
2013-12-02 12:38 - 2010-01-14 17:19 - 00000000 ___RD C:\Program Files\Skype
2013-12-02 12:38 - 2010-01-14 17:19 - 00000000 ____D C:\ProgramData\Skype
2013-12-02 09:04 - 2013-12-02 09:04 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-12-02 08:34 - 2012-05-13 15:16 - 00000000 ____D C:\Users\Guido\Documents\SelfMV
2013-11-30 18:45 - 2013-08-05 14:21 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-29 10:35 - 2013-11-02 14:43 - 00007934 _____ C:\Users\Guido\Desktop\Wohnungsanzeigen.odt
2013-11-29 10:16 - 2013-11-29 10:16 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2013-11-27 11:39 - 2013-11-27 11:39 - 00008988 _____ C:\Users\Guido\Desktop\Adecco.odt
2013-11-24 10:40 - 2013-11-24 10:32 - 00000000 ____D C:\Users\Guido\Desktop\Boney M
2013-11-22 12:39 - 2013-11-22 12:39 - 00000000 ____D C:\ProgramData\Oracle
2013-11-22 12:39 - 2013-11-22 12:39 - 00000000 ____D C:\Program Files\Common Files\Java
2013-11-22 12:38 - 2013-11-22 12:38 - 00004874 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log
2013-11-22 12:38 - 2010-01-14 17:00 - 00000000 ____D C:\Program Files\Java
Files to move or delete:
====================
C:\Users\Admin\BackupResult.DAT
C:\Users\Admin\HiJackThis204.exe
C:\Users\Admin\SCHDLR.DAT
Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\temp\avgnt.exe
C:\Users\Admin\AppData\Local\temp\RtkBtMnt.exe
C:\Users\Guido\AppData\Local\temp\avgnt.exe
C:\Users\Guido\AppData\Local\temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-21 10:27
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
</code> |