Mailin-He | 28.07.2014 14:52 | So, diesmal lief nicht alles so problemlos :/
Bei mbam konnte zwar alles in Quarantäne gesetzt werden, aber es war nicht möglich die .txt Datei zu exportieren, da jedesmal nur 'keine Rückmeldung' kam.
Bei Adwcleaner trat einmal ein Error auf, aber es konnte trotzdem alles entfernt werden.
Der Rest ging soweit gut.
adwcleaner: Code:
# AdwCleaner v3.300 - Bericht erstellt am 28/07/2014 um 15:32:48
# Aktualisiert 27/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Holger - HOLGER-PC
# Gestartet von : C:\Users\Holger\Desktop\adwcleaner_3.300.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Tâches planifiées ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\DVDVideoSoftTBToolbarHelper_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\DVDVideoSoftTBToolbarHelper_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IMBooster_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IMBooster_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKCU\Software\a08ddce135ec44
Schlüssel Gelöscht : HKLM\SOFTWARE\a08ddce135ec44
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_autostitch_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_autostitch_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_camstudio_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_camstudio_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_comic-life[1]_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_comic-life[1]_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hugin_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hugin_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_painttool-sai_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_painttool-sai_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_windows-movie-maker_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_windows-movie-maker_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_winrar-unplugged_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_winrar-unplugged_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DVDVideoSoftTB
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Vittalia
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledThirdPartyPrograms
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\3p0r3j7a.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent109", "1318787118930");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent111", "1318787118928");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent112", "1318787118932");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent127", "1327839282779");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent134", "1329037644596");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=dbe82248-dcdd-4bd7-a2d6-90ca7403b564&apn_ptnrs=%5EABT&apn_sauid=CB70FDF0-74A5-4B9A[...]
[ Datei : C:\Users\Holger\AppData\Roaming\Mozilla\Firefox\Profiles\jf81ljrp.default\prefs.js ]
Zeile gelöscht : user_pref("CT2625848.1000082.isDisplayHidden", "true");
Zeile gelöscht : user_pref("CT2625848.1000082.isPlayDisplay", "true");
Zeile gelöscht : user_pref("CT2625848.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock\",\"url\":\"hxxp://feedlive.net/california.asx\"}");
Zeile gelöscht : user_pref("CT2625848.2625848a129894023611240511000000paramsGK1.enc", "eyJ1cGRhdGVSZXFUaW1lIjoxMzY0NTc2Nzk1NTQxLCJ1cGRhdGVSZXNwVGltZSI6MTM2NDU3Njc5NjEwNCwiZGF0YSI6eyJzZXR0aW5ncyI6eyJpY29uIjoiaHR0cDovL3[...]
Zeile gelöscht : user_pref("CT2625848.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2625848.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2625848.FirstTime", "true");
Zeile gelöscht : user_pref("CT2625848.FirstTimeFF3", "true");
Zeile gelöscht : user_pref("CT2625848.LoginRevertSettingsEnabled", true);
Zeile gelöscht : user_pref("CT2625848.PG_ENABLE", "dHJ1ZQ==");
Zeile gelöscht : user_pref("CT2625848.RevertSettingsEnabled", true);
Zeile gelöscht : user_pref("CT2625848.SearchAppState.enc", "Mw==");
Zeile gelöscht : user_pref("CT2625848.SearchAppTracking.enc", "c2VudA==");
Zeile gelöscht : user_pref("CT2625848.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2625848&SearchSource=2&q=");
Zeile gelöscht : user_pref("CT2625848.UserID", "UN39682148491682667");
Zeile gelöscht : user_pref("CT2625848.addressBarTakeOverEnabledInHidden", "true");
Zeile gelöscht : user_pref("CT2625848.autoDisableScopes", 0);
Zeile gelöscht : user_pref("CT2625848.browser.search.defaultthis.engineName", true);
Zeile gelöscht : user_pref("CT2625848.defaultSearch", "true");
Zeile gelöscht : user_pref("CT2625848.embeddedsData", "[{\"appId\":\"129181467799155027\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Zeile gelöscht : user_pref("CT2625848.enableAlerts", "false");
Zeile gelöscht : user_pref("CT2625848.enableFix404ByUser", "TRUE");
Zeile gelöscht : user_pref("CT2625848.enableSearchFromAddressBar", "true");
Zeile gelöscht : user_pref("CT2625848.firstTimeDialogOpened", "true");
Zeile gelöscht : user_pref("CT2625848.fixPageNotFoundError", "true");
Zeile gelöscht : user_pref("CT2625848.fixPageNotFoundErrorByUser", "true");
Zeile gelöscht : user_pref("CT2625848.fixPageNotFoundErrorInHidden", "true");
Zeile gelöscht : user_pref("CT2625848.fixUrls", true);
Zeile gelöscht : user_pref("CT2625848.installId", "ConduitNSISIntegration");
Zeile gelöscht : user_pref("CT2625848.installType", "ConduitNSISIntegration");
Zeile gelöscht : user_pref("CT2625848.isCheckedStartAsHidden", true);
Zeile gelöscht : user_pref("CT2625848.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2625848.isFirstTimeToolbarLoading", "false");
Zeile gelöscht : user_pref("CT2625848.isNewTabEnabled", true);
Zeile gelöscht : user_pref("CT2625848.isPerformedSmartBarTransition", "true");
Zeile gelöscht : user_pref("CT2625848.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("CT2625848.keyword", true);
Zeile gelöscht : user_pref("CT2625848.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT2625848&octid=CT2625848&SearchSource=15&CUI=UN39682148491682667&SSPV=EB_SSPV&Lay=1&UM=\[...]
Zeile gelöscht : user_pref("CT2625848.lastVersion", "10.15.0.562");
Zeile gelöscht : user_pref("CT2625848.migrateAppsAndComponents", true);
Zeile gelöscht : user_pref("CT2625848.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"Wieso sind deaktivierte Toolbars immer wieder im Browser?\",\"EB_MAIN_FRAME_URL\":\"about%3Aaddons\",\"EB_MAIN_FRAME_TITLE\":\"\",\"[...]
Zeile gelöscht : user_pref("CT2625848.openThankYouPage", "false");
Zeile gelöscht : user_pref("CT2625848.openUninstallPage", "true");
Zeile gelöscht : user_pref("CT2625848.search.searchAppId", "129181467799155027");
Zeile gelöscht : user_pref("CT2625848.search.searchCount", "0");
Zeile gelöscht : user_pref("CT2625848.searchInNewTabEnabledByUser", "true");
Zeile gelöscht : user_pref("CT2625848.searchInNewTabEnabledInHidden", "true");
Zeile gelöscht : user_pref("CT2625848.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2625848\"}");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DVDVideoSoftTBDE.OurToolbar.com//xpi\"}");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DVDVideoSoftTB DE\"}");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1364560662534");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_appsMetadata_lastUpdate", "1364576800455");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1364560662451");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_location_lastUpdate", "1364560662134");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_login_10.13.1.89_lastUpdate", "1352655465765");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_login_10.13.40.15_lastUpdate", "1358437688602");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_login_10.14.40.128_lastUpdate", "1359389978630");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_login_10.14.42.7_lastUpdate", "1360852667945");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_login_10.14.65.43_lastUpdate", "1364246616274");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_login_10.15.0.562_lastUpdate", "1364560662296");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_optimizer_lastUpdate", "1347700747707");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1364560662486");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_searchAPI_lastUpdate", "1364560662228");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_serviceMap_lastUpdate", "1364560662046");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_toolbarContextMenu_lastUpdate", "1364560662418");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_toolbarSettings_lastUpdate", "1364576800176");
Zeile gelöscht : user_pref("CT2625848.serviceLayer_services_translation_lastUpdate", "1364560662516");
Zeile gelöscht : user_pref("CT2625848.settingsINI", true);
Zeile gelöscht : user_pref("CT2625848.shouldFirstTimeDialog", "false");
Zeile gelöscht : user_pref("CT2625848.showToolbarPermission", "false");
Zeile gelöscht : user_pref("CT2625848.smartbar.CTID", "CT2625848");
Zeile gelöscht : user_pref("CT2625848.smartbar.Uninstall", "0");
Zeile gelöscht : user_pref("CT2625848.smartbar.homepage", true);
Zeile gelöscht : user_pref("CT2625848.smartbar.toolbarName", "DVDVideoSoftTB DE ");
Zeile gelöscht : user_pref("CT2625848.startPage", "userChanged");
Zeile gelöscht : user_pref("CT2625848.toolbarBornServerTime", "15-9-2012");
Zeile gelöscht : user_pref("CT2625848.toolbarCurrentServerTime", "29-3-2013");
Zeile gelöscht : user_pref("CT2625848.toolbarDisabled", "true");
Zeile gelöscht : user_pref("CT2625848.toolbarLoginClientTime", "Tue Mar 26 2013 16:40:25 GMT+0100");
Zeile gelöscht : user_pref("CT2625848.url_history0001.enc", "amF2YXNjcmlwdDp2b2lkKDApOjo6Y2xpY2toYW5kbGVyOjo6MTM2NDM4ODI1NzU4NiwsLGphdmFzY3JpcHQ6dm9pZCgwKTo6OmNsaWNraGFuZGxlcjo6OjEzNjQzODgyNTc1ODgsLCxqYXZhc2NyaXB0OnZv[...]
Zeile gelöscht : user_pref("CT2625848_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1364576785749,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Zeile gelöscht : user_pref("CT2851647_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1362062851440,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Zeile gelöscht : user_pref("Smartbar.ConduitHomepagesList", "");
Zeile gelöscht : user_pref("Smartbar.ConduitSearchEngineList", "uTorrentBar_DE Customized Web Search");
Zeile gelöscht : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2851647&SearchSource=2&q=");
Zeile gelöscht : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=");
Zeile gelöscht : user_pref("Smartbar.keywordURLSelectedCTID", "CT2851647");
Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Zeile gelöscht : user_pref("browser.search.defaultthis.engineName", "DVDVideoSoftTB Customized Web Search");
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.babTrack", "affID=100842");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.bbDpng", 21);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.hmpg", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.id", "a6c5e9050000000000004c0f6e2b8fa3");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.instlDay", "15264");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=a6c5e9050000000000004c0f6e2b8fa3&tlver=1.4.35.10&affID=100842");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.lastDP", 21);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.4.35.1010:41:27");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "7.0");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.newTab", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.propectorlck", 60423049);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.ptch_0717", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.srcExt", "ss");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.srchPrvdr", "Search the web (Babylon)");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.vrsn", "1.4.35.10");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.vrsnTs", "1.4.35.1010:41:27");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=112049&tt=050412_30b&babsrc=NT_ss&mntrId=a6c5e9050000000000004c0f6e2b8fa3");
Zeile gelöscht : user_pref("extensions.crossrider.bic", "14163e3490f204646740dc5ae3540ea5");
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.id", "a6c5e9050000000000004c0f6e2b8fa3");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15976");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.611:22:02");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=124780&tsp=5019");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gelöscht : user_pref("extentions.y2layers.installId", "6482EB53-51A6-199F-6266-F4C7734AFCF1");
Zeile gelöscht : user_pref("extentions.y2layers.lastDnsTest", 371918);
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent0", "1319458270159");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent101", "1323713542517");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent109", "1328631010492");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent111", "1328631010491");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent112", "1328631010493");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent127", "1329054287809");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent134", "1329054731688");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent140", "1328200329582");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=Vittalia&dpid=Vittalia&co=DE&userid=2df5a0cd-ce56-5b10-4b34-f0dd46ab459a&searchtype=ds&installDate={installDate}&q=");
Zeile gelöscht : user_pref("smartBar.searchInNewTabOwner", "CT2625848");
Zeile gelöscht : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT2851647&SearchSource=13&CUI=SB_CUI");
Zeile gelöscht : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2625848&SearchSource=2&q=,hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2851647&SearchSource=2&q=[...]
Zeile gelöscht : user_pref("smartbar.machineId", "1IM3EC/NVX9IE1RYWWRGUC67HIOMYYROD6THNTCG8HIYRA9YYGQM1J6HJ4PLKBKN+WQBA5WNTRKGW2CGASHC2G");
Zeile gelöscht : user_pref("smartbar.originalHomepage", "www.google.de");
Zeile gelöscht : user_pref("smartbar.originalSearchEngine", "Ask.com");
*************************
AdwCleaner[R0].txt - [26527 octets] - [28/07/2014 15:30:11]
AdwCleaner[R1].txt - [25104 octets] - [28/07/2014 15:32:08]
AdwCleaner[S0].txt - [1725 octets] - [28/07/2014 15:31:25]
AdwCleaner[S1].txt - [24680 octets] - [28/07/2014 15:32:48]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [24741 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Holger on 28.07.2014 at 15:36:34,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3604521320-3577530394-489880924-1000\Software\sweetim
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{01565EFE-EB44-4FAA-A8BD-C857F170A660}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{01BE70D0-005F-4B62-AF78-E2DEFA8EED03}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{0428D7C6-E2D4-4E33-989D-10771F3719FD}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{0809C499-D873-4EE2-B7BA-8F9D546252B6}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{11AAECFD-1836-47F9-A4FB-B02316B7AA2F}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{1C0DCBC2-C9D7-41CA-85A7-428ADFA659F7}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{1E6ACE4C-2775-4936-AC01-CFDF90D92DE6}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{21C59432-B233-40D2-8FFF-EE59B32696C2}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{21FD0A9B-82E8-4E69-893E-81DEC6E7F4C5}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{24D39BCA-01E1-4B01-B1CC-722460D90314}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{26A0A02E-C3CC-4B10-A515-CA52BDF9BD49}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{28F5F431-A360-42FD-BA92-EF6F602FFE55}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{2C230626-C093-43A0-A175-5D6AD4211D30}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{2CC3C8E9-B997-4AF6-8DC1-E32BB880719D}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{31E4052D-46AF-4CC0-9F1C-C2CC194C8A74}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{33031516-4C53-4084-9716-332D85D0C036}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{337FF9D5-77E8-4655-87E7-376D3369B998}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{381F769B-0E8A-4011-B4B9-31546D29E7F6}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{3AF79C37-F22B-4D84-84AF-7C139DC92FF7}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{3B530061-64BA-4629-B262-FE8A16AC3E69}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{3CA83F1E-D837-4EEF-BDC7-D91A814C71E0}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{3E632890-C55C-417F-930F-4BDDFC099A67}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{408CA24C-0146-47BC-95CD-AEF91A9A23EB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{40A9ABB1-A535-4B8C-83B7-4703F7276AEB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{4158E540-9DF1-49AE-B49A-66B98F245FBA}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{429B45D5-3C26-448F-88B5-1FD23215A5EA}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{4377057D-E91C-4D50-ABF3-581B62DA1BD0}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{45846A98-8424-4D9D-9801-78E4072166B9}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{45CC0887-BECF-4856-8E0B-A394A6241336}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{480506A4-FF70-4A17-81BA-FB61F18C21F6}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{48BE01B9-3702-4410-AE28-1994D2DD7455}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{49A84547-0B1F-42C4-A1E0-9A126D0CBCCB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{4B3DCEB6-19AA-4C16-98D2-B94D51A88B6A}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{4D002A56-F1DB-4239-831A-A5D37CF0D02C}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{4D3DCBC6-5563-49C6-BC2C-F11D97D63D78}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{4DD4C709-6E49-4191-B366-69320247F788}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{4F54684D-D6E2-41BB-B3B2-04F2DFF50A9A}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{520BB7AE-02C1-45B1-91D4-80819010A97D}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{520DB73F-4422-4892-88AD-E1BD1FC1E228}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{52EDA39A-614C-4EC3-B304-2F3589425BDB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{5378A4FB-2BF6-4E24-8FA9-A7EC6BE1026B}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{555D736E-92A6-4B31-BD22-41D843062FFA}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{58FE6189-549C-4167-9BCF-98F49266C552}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{59D39A3E-99F6-4764-BD8B-8D82C5754A55}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{5BA4A5D2-FCFD-4966-8912-DFA4E3E5767E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{623310D4-5C3E-4A23-9889-6F354DEF5044}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{62BB5A16-FF4E-4205-8BE8-F8CD75AA568E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{638FCE35-81D7-4F9D-A624-C5983448433E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{64F0EECC-C7A6-4054-A3A7-6743906EF07F}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{65351C58-DBBF-4ADC-9E8D-BE098DA5B74F}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{6586E092-9780-4BDC-B20D-4C477C392169}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{674C62C8-1DB8-4D13-A2FA-A27B00AD5E5E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{68278B58-9780-4CCA-A5BB-CDC23DF32273}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{6A7214BA-D52A-41E7-95E8-411CB1212221}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{6BD5F74B-0268-4D0C-AD48-E4862874676B}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{6C7EA29E-2590-4732-A4B4-43745A45B714}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{6EBA9794-B73F-4A1D-96BC-CEF74CF04378}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{6F183289-7DC0-4799-9C21-8F0E2F0049CB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{72220E2C-F394-484D-97F2-0F6144716E6F}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{725B9B76-58E9-4413-AD97-4A832563FC67}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{7381589D-9FE7-4628-879D-966DF96BC4AD}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{73885FF6-77F8-404B-A5EB-B9303AF6341D}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{74CF624A-332E-40D3-9EE8-9D15CA37D9ED}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{760D3C7B-C26E-469E-BA84-A7C935632216}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{780FBBE5-4107-4AF4-A3CB-969630522871}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{7A524B56-C006-4D2A-BFBB-A92D6C8B88C4}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{7D309C3F-2745-4E3B-8136-15E6D798C370}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{7EAC9E0E-1F69-44BA-8460-FC2CFEB89B0E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{7EB69579-78D4-482B-AB53-4DD9F2010C68}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{7F7DD568-79E1-40C0-9189-AC1D1F7DF9B4}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{806796CA-CF57-44A4-B5CF-46F5444E5865}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{81A8A99E-0D63-4845-B13D-42F2D5765A56}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{82BC236F-0CFC-42C6-AEDC-DDF7FB931F97}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{8501FFD8-E636-454D-B90C-BE2D090D4BA2}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{85E70A22-9096-423F-99A8-1882269F4579}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{86E407FE-1D7F-4B7A-8E85-E0C9F6416BFC}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{88D2783B-10C4-4770-8A60-4A59E0A4E753}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{8C96478D-CB63-47D7-A37C-EAC881C5FF10}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{8D110B5B-31E7-4E42-9FAC-509DBDFCD8AB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{8DF142AC-4CDE-42E5-AE69-C07C0272E8BB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{9194C40C-7F67-4500-934B-9CFA7D790D0E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{9257DB26-F1FD-4D32-8249-5B7DEA5DAAA0}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{96741E6C-1A0C-4D6B-8721-56A1E05328BB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{96C1CC50-24D7-43AB-9F7B-8D49260D69B3}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{982F3FFA-4AD0-4067-9CFF-7239E1C68D24}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{98E7CC73-939C-4EB7-A433-9943EE40CC8A}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{9DF17AEA-7E72-40A8-9CEA-6D9E8DA513FD}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{9E7C1C43-8938-4DA6-8826-0DC65D27D5F9}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{A03F0BD3-3265-4B1D-9634-353B25FA3770}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{A11A54E3-3CEC-4FD3-A3E7-F366A5DB2B86}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{A5ADBCC6-7A93-46C8-B894-0E812B1700B2}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{A86F7BCD-822F-4704-8086-A742E54BDC52}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{A90BE10A-69F2-4C5A-B5CA-21CB069CB0E4}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{ABCD8CD8-2594-4997-904F-5EE99CC9914D}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{AD5EF1AD-93E5-49AE-93D6-379D01DB4771}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{AE05F381-FCDE-4004-9CD8-76DC761B9847}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{B174A958-A40E-40B5-AE99-7BBE3B475555}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{B497F297-9255-4A6D-8D48-46ECD9D9B188}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{B7EA824E-278B-4B99-9789-E5A769491F75}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{B85992D7-2967-440A-B0C3-09078A330C7F}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{B9A84EEB-DC50-4216-9929-1F61CBC7B000}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{B9ACD3AA-96B8-4AE5-A228-EC155FF30372}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{BCBE1EB3-7327-43D4-83FE-773FB541203F}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{BE1D593C-D3D6-4146-BB5E-ED049A832ED6}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C07F4F3F-D0C0-40ED-947F-936F450B13F2}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C1886394-6916-4C5E-AF59-3418EF9013C2}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C2DF65C5-A714-45CC-82BA-75C6645F4CC9}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C5977E90-25E2-47C7-AE3D-76E05777E475}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C5D7CA77-F064-4110-9876-DFA3F3A09C3D}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C74DA569-68ED-43F3-A38E-8F2ED5AC9A2E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C7C10F93-226B-497F-A008-3975CF816181}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C7DBA06F-D63E-4734-8C5A-7EA9E7C08E3A}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C8F08928-1100-4A4D-97D2-4C221D35B6F9}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{C9ACE8FB-65E0-4124-8A21-2D8D5DD8E98B}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{CCC39621-BC82-401D-B6C9-6C3265410F86}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{CED9699C-7C1A-4B0D-BA67-3B72A1C05288}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{CF93FDF9-AA4C-488C-88E5-1278E9905D53}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{D3B97383-E6B3-4072-9D9A-4A0A033EA1BB}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{D5C42A08-B2C1-471F-B843-4F2FF0F6F3D6}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{D5DE0CF1-47B2-4601-B003-DCF6E90081FD}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{D841CDD1-0DF4-45A4-84A9-EF8598E8CE6F}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E0000F2E-9BAF-4B71-9B6A-5693A3C3F51B}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E21E564C-E0FE-45FA-A12F-B265453F52C0}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E3E081AC-BEA9-4F58-AABB-52E528D520BE}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E42FB3EF-A788-4F51-84CF-F459EF1B5670}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E499EFE2-6E50-42E2-A931-BD3765FC2FFE}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E5613018-E5D5-4BB6-AFC9-5A686A9E876B}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E6DDCA77-A9EC-4DA0-82A8-E81882B82232}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E7810551-AEA1-4E9A-A377-339E8CAB640D}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E7A6E675-501B-4341-BE05-ABAF63CB8B7C}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E887F315-66AC-4CEC-B607-609C3C8F6175}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{E9C31863-410E-403D-9DE8-C894AE47D244}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{EE8C62B8-710F-4637-96D6-5E937A508A8D}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{EFB18F23-5508-4003-9DF0-AC3605321AD4}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{F1FCE24F-3140-4F32-8EE1-19DE49F298E8}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{F3019933-0327-4BF3-8039-0402A3BFF20A}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{F49A254B-AB3C-4ABE-8D95-841F818B296E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{F5612853-0408-4766-AB76-360BE8470F36}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{F6375A0E-903E-4D0C-B99B-B37B845F87E6}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{F83B4AB4-483C-46DB-85A9-74835E45B129}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{F8ADF092-CF34-4ABA-B1A9-FC7072C243A4}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{F90CC7D2-B538-443A-98CE-7928B1FFB71D}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{FBAA5B28-4760-4224-93B2-8DBA3B2BC53E}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{FC14201D-C885-42D4-AB3D-34AE458899BA}
Successfully deleted: [Empty Folder] C:\Users\Holger\appdata\local\{FE17EF4A-A86E-4C7A-ABE9-7FEEB7B5BED5}
~~~ FireFox
Emptied folder: C:\Users\Holger\AppData\Roaming\mozilla\firefox\profiles\jf81ljrp.default\minidumps [38 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.07.2014 at 15:42:57,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014
Ran by Holger (administrator) on HOLGER-PC on 28-07-2014 15:43:29
Running from C:\Users\Holger\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Windows\PLFSetI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Spotify Ltd) C:\Users\Holger\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324608 2010-02-05] (Alcor Micro Corp.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2107176 2010-03-11] (Synaptics Incorporated)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [206208 2010-06-09] ()
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [BambooCore] => C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1
HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1
HKU\S-1-5-21-3604521320-3577530394-489880924-1000\...\Run: [Spotify Web Helper] => C:\Users\Holger\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-06-28] (Spotify Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{FD0FA144-5927-43D2-BA07-CB9D67C4FB57}: [NameServer]139.7.30.125 139.7.30.126
FireFox:
========
FF ProfilePath: C:\Users\Holger\AppData\Roaming\Mozilla\Firefox\Profiles\jf81ljrp.default
FF DefaultSearchEngine: Google
FF Homepage: hxxp://www.google.de
FF NetworkProxy: "ftp", "176.31.182.88"
FF NetworkProxy: "ftp_port", 3128
FF NetworkProxy: "http", "176.31.182.88"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "176.31.182.88"
FF NetworkProxy: "socks_port", 3128
FF NetworkProxy: "ssl", "176.31.182.88"
FF NetworkProxy: "ssl_port", 3128
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Garmin Communicator - C:\Users\Holger\AppData\Roaming\Mozilla\Firefox\Profiles\jf81ljrp.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2013-12-15]
FF Extension: Ghostery - C:\Users\Holger\AppData\Roaming\Mozilla\Firefox\Profiles\jf81ljrp.default\Extensions\firefox@ghostery.com.xpi [2014-02-16]
FF Extension: Stealthy - C:\Users\Holger\AppData\Roaming\Mozilla\Firefox\Profiles\jf81ljrp.default\Extensions\stealthyextension@gmail.com.xpi [2013-03-31]
FF Extension: Adblock Plus - C:\Users\Holger\AppData\Roaming\Mozilla\Firefox\Profiles\jf81ljrp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-24]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 12\spmplugin3
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-02] (Avira Operations GmbH & Co. KG)
R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173272 2013-11-01] (Microsoft Corp.)
S4 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [868896 2010-06-11] (Acer Incorporated)
S4 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4121080 2011-06-13] (INCA Internet Co., Ltd.) [File not signed]
S4 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [255744 2010-06-29] (NewTech Infosystems, Inc.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2412344 2014-01-28] (TuneUp Software)
S2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-07-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-07-02] (Avira Operations GmbH & Co. KG)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [212992 2011-11-21] (Huawei Technologies Co., Ltd.)
S3 KovaPlusFltr; C:\Windows\System32\drivers\KovaPlusFltr.sys [15104 2010-01-25] (ROCCAT Development, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) [File not signed]
S3 skfiltv; C:\Windows\System32\drivers\skfiltv.sys [24064 2008-08-14] (Creative Technology Ltd.)
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [129024 2012-06-27] (MCCI Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2013-03-26] (TuneUp Software)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 dump_wmimmc; \??\C:\gPotato\Rappelz\GameGuard\dump_wmimmc.sys [X]
S1 gcnpnhwg; \??\C:\Windows\system32\drivers\gcnpnhwg.sys [X]
S1 grqnpkrp; \??\C:\Windows\system32\drivers\grqnpkrp.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-28 15:43 - 2014-07-28 15:43 - 00015467 _____ () C:\Users\Holger\Desktop\FRST.txt
2014-07-28 15:42 - 2014-07-28 15:42 - 00016465 _____ () C:\Users\Holger\Desktop\JRT.txt
2014-07-28 15:36 - 2014-07-28 15:36 - 00000000 ____D () C:\Windows\ERUNT
2014-07-28 15:35 - 2014-07-28 15:35 - 00024842 _____ () C:\Users\Holger\Desktop\AdwCleaner[S1].txt
2014-07-28 15:30 - 2014-07-28 15:32 - 00000000 ____D () C:\AdwCleaner
2014-07-28 15:15 - 2014-07-28 15:16 - 02093568 _____ (Farbar) C:\Users\Holger\Desktop\FRST64.exe
2014-07-28 15:14 - 2014-07-28 15:14 - 01016261 _____ (Thisisu) C:\Users\Holger\Desktop\JRT.exe
2014-07-28 15:11 - 2014-07-28 15:11 - 01367289 _____ () C:\Users\Holger\Desktop\adwcleaner_3.300.exe
2014-07-28 14:42 - 2014-07-28 15:27 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-28 14:42 - 2014-07-28 14:42 - 00001074 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-28 14:42 - 2014-07-28 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-28 14:42 - 2014-07-28 14:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-28 14:42 - 2014-07-28 14:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-28 14:42 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-28 14:42 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-28 14:42 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-27 18:51 - 2014-07-27 18:51 - 00024078 _____ () C:\ComboFix.txt
2014-07-27 18:32 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-27 18:32 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-27 18:32 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-27 18:32 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-27 18:32 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-27 18:32 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-27 18:32 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-27 18:32 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-27 18:23 - 2014-07-27 18:51 - 00000000 ____D () C:\Qoobox
2014-07-27 18:22 - 2014-07-27 18:48 - 00000000 ____D () C:\Windows\erdnt
2014-07-27 18:18 - 2014-07-27 18:19 - 05563277 ____R (Swearware) C:\Users\Holger\Desktop\ComboFix.exe
2014-07-26 20:55 - 2014-07-26 20:55 - 00001236 _____ () C:\Users\Holger\Desktop\Revo Uninstaller.lnk
2014-07-26 20:55 - 2014-07-26 20:55 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-25 16:50 - 2014-07-25 16:47 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-07-25 16:28 - 2014-07-25 16:28 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\Avira
2014-07-25 16:22 - 2014-07-25 16:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-07-25 16:21 - 2014-07-25 16:21 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-07-25 16:21 - 2014-07-02 13:06 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-07-25 16:21 - 2014-07-02 13:06 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-07-25 16:21 - 2014-07-02 13:06 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-07-23 16:22 - 2014-07-28 15:43 - 00000000 ____D () C:\FRST
2014-07-23 16:21 - 2014-07-23 16:21 - 00000000 _____ () C:\Users\Holger\defogger_reenable
2014-07-23 16:15 - 2014-07-28 15:34 - 00007094 _____ () C:\Windows\setupact.log
2014-07-23 16:15 - 2014-05-01 14:30 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-09 18:28 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 18:28 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 18:28 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 18:28 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 18:28 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 18:28 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 18:28 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 18:28 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 18:28 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 18:28 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 18:28 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 18:28 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 18:28 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 18:28 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 18:28 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 18:28 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 18:28 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 18:28 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 18:28 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 18:28 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 18:28 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 18:28 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 18:28 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 18:28 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 18:28 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 18:28 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 18:28 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 18:28 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 18:28 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 18:28 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 18:28 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 18:28 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 18:28 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 18:28 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 18:28 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 18:28 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 18:28 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 18:28 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 18:28 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 18:28 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 18:28 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 18:28 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 18:28 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 18:28 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 18:28 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 18:28 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 18:28 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 18:28 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 18:28 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 18:28 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 18:28 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 18:28 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 18:28 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 18:28 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 18:28 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 18:28 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 18:28 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 18:28 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 18:28 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 18:28 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 18:28 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 18:28 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 18:28 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 18:28 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 18:28 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 18:28 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 18:28 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 18:28 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 18:28 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 18:28 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 18:28 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 18:28 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 18:28 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 18:28 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 18:28 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 18:28 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 18:28 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 18:28 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 18:26 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 18:26 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 18:26 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-04 06:28 - 2014-07-04 06:28 - 00001545 _____ () C:\Users\Holger\Desktop\Wow - Verknüpfung.lnk
2014-07-03 15:46 - 2014-07-27 19:54 - 00000000 ____D () C:\Program Files (x86)\World_of_Warcraft_WOTLK-RG
2014-07-03 15:44 - 2014-07-03 15:45 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\qBittorrent
2014-07-03 15:44 - 2014-07-03 15:44 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\qBittorrent
2014-07-03 15:44 - 2014-07-03 15:44 - 00000000 ____D () C:\Users\Holger\AppData\Local\qBittorrent
2014-07-03 15:44 - 2014-07-03 15:44 - 00000000 ____D () C:\Program Files (x86)\qBittorrent
2014-06-28 16:15 - 2014-06-28 16:15 - 00001228 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2014-06-28 16:14 - 2014-06-28 16:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2014-06-28 16:08 - 2014-06-29 18:59 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2014-06-28 16:06 - 2014-07-11 17:28 - 00000000 ____D () C:\Users\Holger\AppData\Local\Battle.net
2014-06-28 16:06 - 2014-06-28 17:05 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\Battle.net
2014-06-28 16:05 - 2014-07-11 17:28 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-06-28 16:05 - 2014-06-28 16:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-28 15:44 - 2014-07-28 15:43 - 00015467 _____ () C:\Users\Holger\Desktop\FRST.txt
2014-07-28 15:43 - 2014-07-23 16:22 - 00000000 ____D () C:\FRST
2014-07-28 15:42 - 2014-07-28 15:42 - 00016465 _____ () C:\Users\Holger\Desktop\JRT.txt
2014-07-28 15:42 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-28 15:42 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-28 15:36 - 2014-07-28 15:36 - 00000000 ____D () C:\Windows\ERUNT
2014-07-28 15:35 - 2014-07-28 15:35 - 00024842 _____ () C:\Users\Holger\Desktop\AdwCleaner[S1].txt
2014-07-28 15:35 - 2012-04-08 17:08 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-07-28 15:34 - 2014-07-23 16:15 - 00007094 _____ () C:\Windows\setupact.log
2014-07-28 15:34 - 2014-05-03 10:16 - 00179470 _____ () C:\Windows\PFRO.log
2014-07-28 15:34 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-28 15:33 - 2014-05-01 10:36 - 02058675 _____ () C:\Windows\WindowsUpdate.log
2014-07-28 15:32 - 2014-07-28 15:30 - 00000000 ____D () C:\AdwCleaner
2014-07-28 15:27 - 2014-07-28 14:42 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-28 15:26 - 2010-12-04 23:12 - 00000000 ____D () C:\Users\Holger\AppData\Local\CrashDumps
2014-07-28 15:16 - 2014-07-28 15:15 - 02093568 _____ (Farbar) C:\Users\Holger\Desktop\FRST64.exe
2014-07-28 15:14 - 2014-07-28 15:14 - 01016261 _____ (Thisisu) C:\Users\Holger\Desktop\JRT.exe
2014-07-28 15:11 - 2014-07-28 15:11 - 01367289 _____ () C:\Users\Holger\Desktop\adwcleaner_3.300.exe
2014-07-28 14:52 - 2012-07-16 17:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-28 14:42 - 2014-07-28 14:42 - 00001074 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-28 14:42 - 2014-07-28 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-28 14:42 - 2014-07-28 14:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-28 14:42 - 2014-07-28 14:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-27 19:54 - 2014-07-03 15:46 - 00000000 ____D () C:\Program Files (x86)\World_of_Warcraft_WOTLK-RG
2014-07-27 18:51 - 2014-07-27 18:51 - 00024078 _____ () C:\ComboFix.txt
2014-07-27 18:51 - 2014-07-27 18:23 - 00000000 ____D () C:\Qoobox
2014-07-27 18:51 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-07-27 18:48 - 2014-07-27 18:22 - 00000000 ____D () C:\Windows\erdnt
2014-07-27 18:46 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-27 18:43 - 2010-09-01 10:37 - 00000000 ____D () C:\ProgramData\Temp
2014-07-27 18:30 - 2012-12-31 15:35 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-27 18:19 - 2014-07-27 18:18 - 05563277 ____R (Swearware) C:\Users\Holger\Desktop\ComboFix.exe
2014-07-26 21:31 - 2012-04-29 14:20 - 03065344 ___SH () C:\Users\Holger\Desktop\Thumbs.db
2014-07-26 21:11 - 2013-04-10 18:51 - 00000000 ____D () C:\Users\Holger\Documents\Mailins Ordner
2014-07-26 20:55 - 2014-07-26 20:55 - 00001236 _____ () C:\Users\Holger\Desktop\Revo Uninstaller.lnk
2014-07-26 20:55 - 2014-07-26 20:55 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-26 00:45 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-25 16:47 - 2014-07-25 16:50 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-07-25 16:28 - 2014-07-25 16:28 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\Avira
2014-07-25 16:22 - 2014-07-25 16:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-07-25 16:21 - 2014-07-25 16:21 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-07-25 16:21 - 2012-09-17 19:25 - 00000000 ____D () C:\ProgramData\Avira
2014-07-25 16:17 - 2012-05-12 09:58 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-25 16:17 - 2012-05-12 09:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-25 02:57 - 2010-12-05 00:27 - 00000000 ____D () C:\Users\Gast
2014-07-25 02:56 - 2014-04-21 20:55 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-07-25 02:56 - 2014-02-27 16:08 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-25 02:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-07-24 20:32 - 2012-05-12 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-24 16:58 - 2010-12-03 19:50 - 00000000 ____D () C:\Users\Holger
2014-07-23 16:21 - 2014-07-23 16:21 - 00000000 _____ () C:\Users\Holger\defogger_reenable
2014-07-18 15:49 - 2013-11-27 21:35 - 00000000 ____D () C:\Users\Holger\AppData\Local\Last.fm
2014-07-11 17:28 - 2014-06-28 16:06 - 00000000 ____D () C:\Users\Holger\AppData\Local\Battle.net
2014-07-11 17:28 - 2014-06-28 16:05 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-07-11 17:26 - 2010-12-04 18:51 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\TS3Client
2014-07-11 17:20 - 2010-12-04 18:50 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client
2014-07-10 14:54 - 2014-02-15 12:22 - 00305920 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 14:51 - 2014-05-06 21:29 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-10 14:51 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-10 14:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-10 14:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-09 21:48 - 2013-08-14 19:45 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 21:45 - 2010-12-05 08:29 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 20:53 - 2012-07-16 17:04 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 20:53 - 2012-07-16 17:04 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-09 20:53 - 2011-05-20 15:44 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 16:20 - 2011-10-23 13:00 - 00000000 ____D () C:\Users\Holger\AppData\Local\Paint.NET
2014-07-08 17:37 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-05 23:42 - 2010-12-04 15:48 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\Skype
2014-07-05 20:52 - 2010-10-26 20:40 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-07-05 20:52 - 2010-10-26 20:40 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-07-05 20:52 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-04 06:28 - 2014-07-04 06:28 - 00001545 _____ () C:\Users\Holger\Desktop\Wow - Verknüpfung.lnk
2014-07-03 18:30 - 2013-06-29 17:47 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\Spotify
2014-07-03 17:24 - 2013-06-29 17:49 - 00000000 ____D () C:\Users\Holger\AppData\Local\Spotify
2014-07-03 15:45 - 2014-07-03 15:44 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\qBittorrent
2014-07-03 15:44 - 2014-07-03 15:44 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\qBittorrent
2014-07-03 15:44 - 2014-07-03 15:44 - 00000000 ____D () C:\Users\Holger\AppData\Local\qBittorrent
2014-07-03 15:44 - 2014-07-03 15:44 - 00000000 ____D () C:\Program Files (x86)\qBittorrent
2014-07-02 13:06 - 2014-07-25 16:21 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-07-02 13:06 - 2014-07-25 16:21 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-07-02 13:06 - 2014-07-25 16:21 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-06-30 04:09 - 2014-07-09 18:28 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-09 18:28 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-29 18:59 - 2014-06-28 16:08 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2014-06-28 17:05 - 2014-06-28 16:06 - 00000000 ____D () C:\Users\Holger\AppData\Roaming\Battle.net
2014-06-28 16:15 - 2014-06-28 16:15 - 00001228 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2014-06-28 16:15 - 2014-06-28 16:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2014-06-28 16:15 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-28 16:06 - 2014-06-28 16:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
Files to move or delete:
====================
C:\ProgramData\sysqcl1129139270.dat
Some content of TEMP:
====================
C:\Users\Holger\AppData\Local\Temp\avgnt.exe
C:\Users\Holger\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-19 12:20
==================== End Of Log ============================ --- --- ---
--- --- --- |