patch2308 | 12.08.2012 20:00 | Ok, hier ist es:
OTL Logfile: Code:
OTL logfile created on: 12.08.2012 20:35:43 - Run 2
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Users\***\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,98 Gb Total Physical Memory | 6,83 Gb Available Physical Memory | 85,60% Memory free
15,96 Gb Paging File | 13,79 Gb Available in Paging File | 86,38% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 365,00 Gb Total Space | 307,00 Gb Free Space | 84,11% Space Free | Partition Type: NTFS
Drive D: | 544,44 Gb Total Space | 513,44 Gb Free Space | 94,31% Space Free | Partition Type: NTFS
Drive F: | 12,04 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: ***-PC | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.08.12 20:32:31 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\***\Downloads\OTL.exe
PRC - [2012.08.11 20:49:03 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.06.01 17:33:28 | 002,446,392 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2012.06.01 17:03:22 | 000,073,392 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.09.16 10:48:54 | 001,623,920 | ---- | M] (Lexware GmbH & Co. KG) -- C:\Program Files (x86)\Common Files\Lexware\LxWebAccess\LxWebAccess.exe
PRC - [2011.07.31 14:07:18 | 000,189,808 | ---- | M] (Haufe-Lexware GmbH & Co. KG) -- C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe
PRC - [2011.02.25 03:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2011.02.07 11:55:24 | 001,757,264 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2011.01.04 15:06:42 | 007,060,560 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
PRC - [2010.12.23 08:07:58 | 000,945,232 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2010.11.29 07:42:38 | 000,775,848 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
PRC - [2010.11.17 10:24:54 | 004,387,632 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
PRC - [2010.09.20 05:24:42 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
PRC - [2010.08.27 03:52:12 | 002,782,064 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
PRC - [2010.02.10 16:29:52 | 000,719,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2009.11.02 07:21:26 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
========== Modules (No Company Name) ==========
MOD - [2012.06.20 23:19:41 | 013,198,336 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
MOD - [2012.06.20 23:19:18 | 001,666,048 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
MOD - [2012.05.11 17:52:31 | 000,194,048 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\f11d5fea7ded12068e8cdb8b2f1bdbd9\CustomMarshalers.ni.dll
MOD - [2012.05.10 22:08:01 | 005,617,664 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
MOD - [2012.05.10 22:07:48 | 000,982,528 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll
MOD - [2012.05.10 22:07:15 | 009,091,584 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
MOD - [2012.05.10 21:57:53 | 014,412,800 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2012.02.20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012.02.20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010.07.05 12:42:58 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll
MOD - [2010.05.07 16:22:18 | 001,636,864 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
MOD - [2009.11.02 07:23:36 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
MOD - [2009.11.02 07:20:10 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012.04.30 21:08:10 | 000,827,520 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe -- (IswSvc)
SRV:64bit: - [2011.02.27 21:48:28 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.09.22 11:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010.08.09 21:04:12 | 000,166,704 | ---- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc.exe -- (Samsung UPD Service)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2012.08.04 22:01:42 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.27 08:48:49 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.01 17:33:28 | 002,446,392 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.03.01 14:23:36 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.02.25 03:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010.06.01 08:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.05.02 15:24:12 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.04.30 21:08:32 | 000,033,672 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV:64bit: - [2012.04.27 10:20:04 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.04.25 00:32:27 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.12.13 03:32:22 | 002,797,056 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2011.05.07 17:51:32 | 000,454,232 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vsdatant.sys -- (Vsdatant)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.02.27 23:07:40 | 009,079,808 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011.02.27 21:11:30 | 000,299,520 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011.01.27 07:35:26 | 000,425,064 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.12.16 22:06:46 | 000,047,232 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.11.18 07:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010.11.13 00:23:38 | 000,138,024 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2010.11.12 16:16:00 | 000,037,504 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2010.11.12 16:15:58 | 000,077,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2010.11.10 01:04:14 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010.10.07 04:59:00 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2007.08.24 19:44:24 | 000,112,512 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2012.01.11 22:09:55 | 000,015,144 | ---- | M] (Windows (R) 2003 DDK 3790 provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\rtport.sys -- (rtport)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
IE - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\..\URLSearchHook: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - No CLSID value found
IE - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\..\SearchScopes\{61A1485A-6063-45CD-9205-1153F6031718}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=9246A60B-F8BA-407B-8828-F37D9BC501A3&apn_sauid=63DBB5D6-0FD1-4464-9DD9-D11E0FFE1F51
IE - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Ixquick HTTPS"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.freenet.de/"
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_270.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2012.06.19 22:58:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2012.06.19 20:57:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.27 08:48:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.27 08:48:49 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012.03.27 14:58:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions
[2012.08.11 01:53:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\31rcb8o0.default\extensions
[2012.08.11 01:53:06 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\31rcb8o0.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012.03.29 20:40:59 | 000,002,492 | ---- | M] () -- C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\31rcb8o0.default\searchplugins\ixquick-https.xml
[2012.07.27 08:48:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.07.27 08:48:49 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.03.13 07:23:34 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.03.13 07:06:36 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.03.13 07:23:34 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.03.13 07:23:34 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.03.13 07:23:34 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.03.13 07:23:34 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Samsung BHO Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\S-1-5-21-1335839233-2991384071-368375801-1000\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Device Detector] DevDetect.exe -autorun File not found
O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 1.7.0_04)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.5.1)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.) - F:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008.01.15 17:17:16 | 000,025,214 | R--- | M] () - F:\AutoRun.ico -- [ CDFS ]
O32 - AutoRun File - [2007.08.23 19:04:06 | 000,000,047 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{05530b08-8486-11e1-b4d1-e8039a2778f6}\Shell - "" = AutoRun
O33 - MountPoints2\{05530b08-8486-11e1-b4d1-e8039a2778f6}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{078bd028-796e-11e1-abe2-e8039a2778f6}\Shell - "" = AutoRun
O33 - MountPoints2\{078bd028-796e-11e1-abe2-e8039a2778f6}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{078bd0ee-796e-11e1-abe2-e8039a2778f6}\Shell - "" = AutoRun
O33 - MountPoints2\{078bd0ee-796e-11e1-abe2-e8039a2778f6}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{0ff7e861-7c97-11e1-967a-e8039a2778f6}\Shell - "" = AutoRun
O33 - MountPoints2\{0ff7e861-7c97-11e1-967a-e8039a2778f6}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{a15499bb-7848-11e1-a7f6-e8039a2778f6}\Shell - "" = AutoRun
O33 - MountPoints2\{a15499bb-7848-11e1-a7f6-e8039a2778f6}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{b93497f7-776f-11e1-863f-e8039a2778f6}\Shell - "" = AutoRun
O33 - MountPoints2\{b93497f7-776f-11e1-863f-e8039a2778f6}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{b9349801-776f-11e1-863f-e8039a2778f6}\Shell - "" = AutoRun
O33 - MountPoints2\{b9349801-776f-11e1-863f-e8039a2778f6}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007.07.03 22:04:10 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.08.11 20:57:39 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Windows Live Writer
[2012.08.11 20:57:39 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Windows Live Writer
[2012.08.11 01:34:00 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Garmin
[2012.08.05 23:40:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.08.05 08:09:26 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\{A76581E6-1819-4CA7-BDE9-8CCE54E69F50}
[2012.08.03 19:10:27 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Buhl
[2012.08.03 19:09:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO Fahrtenbuch 2012
[2012.08.03 19:07:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WISO
[2012.08.03 19:06:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Buhl Data Service GmbH
[2012.08.02 00:02:59 | 000,000,000 | ---D | C] -- C:\Users\***\Documents\Trojaner
[2012.08.02 00:00:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.08.02 00:00:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
[2012.08.01 23:15:03 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2012.08.01 23:05:01 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes
[2012.08.01 23:04:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.08.01 23:04:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.08.01 23:04:49 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012.08.01 23:04:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.07.26 19:02:58 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Ugoe
[2012.07.16 15:48:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DownloadManager
========== Files - Modified Within 30 Days ==========
[2012.08.12 20:26:33 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012.08.12 20:26:16 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012.08.11 01:36:47 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012.08.10 23:31:43 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.10 23:31:43 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.09 17:04:45 | 4274,053,119 | -HS- | M] () -- C:\hiberfil.sys
[2012.08.07 16:10:03 | 001,498,506 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012.08.07 16:10:03 | 000,654,166 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2012.08.07 16:10:03 | 000,616,008 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012.08.07 16:10:03 | 000,130,006 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2012.08.07 16:10:03 | 000,106,388 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012.08.03 19:09:54 | 000,002,068 | ---- | M] () -- C:\Users\Public\Desktop\WISO Fahrtenbuch 2012.lnk
[2012.08.02 00:20:29 | 000,021,438 | ---- | M] () -- C:\Users\***\Desktop\Logfiles.7z
[2012.08.01 23:15:08 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe
[2012.08.01 23:14:36 | 000,000,000 | ---- | M] () -- C:\Users\***\defogger_reenable
[2012.08.01 23:04:51 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.25 08:39:01 | 000,428,144 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012.07.16 16:01:58 | 000,000,474 | ---- | M] () -- C:\user.js
[2012.07.16 15:49:18 | 000,002,073 | ---- | M] () -- C:\Users\***\Desktop\JDownloader.lnk
========== Files Created - No Company Name ==========
[2012.08.11 01:36:47 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012.08.03 19:09:54 | 000,002,068 | ---- | C] () -- C:\Users\Public\Desktop\WISO Fahrtenbuch 2012.lnk
[2012.08.02 00:10:19 | 000,021,438 | ---- | C] () -- C:\Users\***\Desktop\Logfiles.7z
[2012.08.01 23:14:36 | 000,000,000 | ---- | C] () -- C:\Users\***\defogger_reenable
[2012.08.01 23:04:51 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.16 15:49:18 | 000,002,073 | ---- | C] () -- C:\Users\***\Desktop\JDownloader.lnk
[2012.07.16 15:49:06 | 000,002,037 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.07.16 15:49:06 | 000,001,981 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.07.16 15:49:06 | 000,001,960 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.07.16 15:43:15 | 000,000,474 | ---- | C] () -- C:\user.js
[2012.05.10 19:58:26 | 000,038,383 | ---- | C] () -- C:\Users\***\AppData\Roaming\Microsoft Excel 97-2003.ADR
[2012.04.17 15:58:12 | 000,138,608 | ---- | C] () -- C:\windows\SysWow64\LxDNTvmc100.dll
[2012.04.17 15:58:10 | 000,074,608 | ---- | C] () -- C:\windows\SysWow64\LxDNTvm100.dll
[2012.04.17 15:58:08 | 000,309,616 | ---- | C] () -- C:\windows\SysWow64\LxDNT100.dll
[2012.02.27 10:41:52 | 000,202,240 | ---- | C] () -- C:\windows\SysWow64\LXPrnUtil10.dll
[2011.10.20 00:34:15 | 000,258,864 | ---- | C] () -- C:\windows\SUPDRun.exe
[2011.10.20 00:33:34 | 000,003,143 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2011.10.19 11:49:54 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2011.10.19 11:33:20 | 000,001,156 | ---- | C] () -- C:\windows\HotFixList.ini
[2011.10.19 10:50:09 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2011.10.19 10:05:05 | 000,142,128 | ---- | C] () -- C:\windows\wiainst64.exe
========== LOP Check ==========
[2012.04.12 18:40:58 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\ACD Systems
[2012.06.19 21:43:41 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\CheckPoint
[2012.07.05 21:03:24 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\FileZilla
[2012.08.11 01:53:26 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Garmin
[2012.05.21 21:40:06 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Lexware
[2012.07.26 19:02:58 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Ugoe
[2012.03.26 22:40:31 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\WildTangent
[2012.08.11 20:57:39 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Windows Live Writer
[2009.07.14 07:08:49 | 000,017,264 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< # AdwCleaner v1.800 - Logfile created 08/09/2012 at 17:03:04 >
Invalid Switch: 2012 at 17:03:04
< # Updated 01/08/2012 by Xplode >
Invalid Switch: 2012 by Xplode
< # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) >
< # User : *** - ***-PC >
< # Running from : C:\Users\***\Downloads\adwcleaner.exe >
< # Option [Delete] >
< >
< >
< ***** [Services] ***** >
< >
< >
< ***** [Files / Folders] ***** >
Invalid Switch: Folders] *****
< >
< Folder Deleted : C:\Users\***\AppData\Local\Conduit >
< Folder Deleted : C:\Users\***\AppData\Local\Temp\BabylonToolbar >
< Folder Deleted : C:\Users\***\AppData\LocalLow\AskToolbar >
< Folder Deleted : C:\Users\***\AppData\LocalLow\Conduit >
< Folder Deleted : C:\Users\***\AppData\Roaming\Babylon >
< Folder Deleted : C:\Users\***\AppData\Roaming\BabylonToolbar >
< Folder Deleted : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\31rcb8o0.default\ConduitCommon >
< Folder Deleted : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\31rcb8o0.default\extensions\toolbar@ask.com >
< Folder Deleted : C:\ProgramData\Ask >
< Folder Deleted : C:\ProgramData\Babylon >
< Folder Deleted : C:\ProgramData\Trymedia >
< Folder Deleted : C:\Program Files (x86)\Ask.com >
< Folder Deleted : C:\Program Files (x86)\BabylonToolbar >
< Folder Deleted : C:\Program Files (x86)\Conduit >
< Folder Deleted : C:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} >
< File Deleted : C:\Users\***\AppData\Local\Temp\Uninstall.exe >
< File Deleted : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\31rcb8o0.default\searchplugins\Askcom.xml >
< File Deleted : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\31rcb8o0.default\searchplugins\Conduit.xml >
< File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml >
< >
< ***** [Registry] ***** >
< >
<[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 >
< Key Deleted : HKCU\Software\APN >
< Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar >
< Key Deleted : HKCU\Software\AppDataLow\Software\Conduit >
< Key Deleted : HKCU\Software\Ask.com >
< Key Deleted : HKCU\Software\BabylonToolbar >
< Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} >
< Key Deleted : HKLM\SOFTWARE\APN >
< Key Deleted : HKLM\SOFTWARE\AskToolbar >
< Key Deleted : HKLM\SOFTWARE\Babylon >
< Key Deleted : HKLM\SOFTWARE\BabylonToolbar >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL >
< Key Deleted : HKLM\SOFTWARE\Classes\b >
< Key Deleted : HKLM\SOFTWARE\Classes\Babylon.dskBnd >
< Key Deleted : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1 >
< Key Deleted : HKLM\SOFTWARE\Classes\bbylnApp.appCore >
< Key Deleted : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 >
< Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane >
< Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 >
< Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 >
< Key Deleted : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc >
< Key Deleted : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1 >
< Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd >
< Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 >
< Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF >
< Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF >
< Key Deleted : HKLM\SOFTWARE\Conduit >
< Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb >
< Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83AA2913-C123-4146-85BD-AD8F93971D39} >
< Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} >
< Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar >
< Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] >
< [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF >
< >
< ***** [Registre - GUID] ***** >
< >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} >
< Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} >
< Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} >
< Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} >
< Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} >
< Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} >
< Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} >
< Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70} >
< Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} >
< Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} >
< Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} >
< Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} >
< Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} >
< Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B} >
< Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} >
< Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] >
< Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] >
< Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}] >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} >
< [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} >
< >
< ***** [Internet Browsers] ***** >
< >
< -\\ Internet Explorer v9.0.8112.16421 >
< >
< Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.babylon.com/?affID=110819&babsrc=HP_ss&mntrId=2ed6f590000000000000000000000000 --> hxxp://www.google.com >
Invalid Switch: www.google.com
< >
< -\\ Mozilla Firefox v14.0.1 (de) >
< >
< Profile name : default >
< File : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\31rcb8o0.default\prefs.js >
< >
< C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\31rcb8o0.default\user.js ... Deleted ! >
< >
< Deleted : user_pref("CT2613550..clientLogIsEnabled", false); >
< Deleted : user_pref("CT2613550..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] >
< Deleted : user_pref("CT2613550..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] >
< Deleted : user_pref("CT2613550.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); >
< Deleted : user_pref("CT2613550.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); >
< Deleted : user_pref("CT2613550.CTID", "CT2613550"); >
< Deleted : user_pref("CT2613550.CurrentServerDate", "18-6-2012"); >
< Deleted : user_pref("CT2613550.DSChangedManually", true); >
< Deleted : user_pref("CT2613550.DSInstall", true); >
< Deleted : user_pref("CT2613550.DialogsAlignMode", "LTR"); >
< Deleted : user_pref("CT2613550.DialogsGetterLastCheckTime", "Mon Jun 18 2012 09:35:00 GMT+0200"); >
< Deleted : user_pref("CT2613550.DownloadReferralCookieData", ""); >
< Deleted : user_pref("CT2613550.EMailNotifierPollDate", "Mon Jun 18 2012 12:35:04 GMT+0200"); >
< Deleted : user_pref("CT2613550.FirstServerDate", "30-3-2012"); >
< Deleted : user_pref("CT2613550.FirstTime", true); >
< Deleted : user_pref("CT2613550.FirstTimeFF3", true); >
< Deleted : user_pref("CT2613550.FixPageNotFoundErrors", true); >
< Deleted : user_pref("CT2613550.GroupingServerCheckInterval", 1440); >
< Deleted : user_pref("CT2613550.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); >
< Deleted : user_pref("CT2613550.HPInstall", true); >
< Deleted : user_pref("CT2613550.HasUserGlobalKeys", true); >
< Deleted : user_pref("CT2613550.HomePageProtectorEnabled", false); >
< Deleted : user_pref("CT2613550.HomepageBeforeUnload", "hxxp://www.freenet.de/"); >
< Deleted : user_pref("CT2613550.Initialize", true); >
< Deleted : user_pref("CT2613550.InitializeCommonPrefs", true); >
< Deleted : user_pref("CT2613550.InstallationAndCookieDataSentCount", 3); >
< Deleted : user_pref("CT2613550.InstallationType", "Unknown"); >
< Deleted : user_pref("CT2613550.InstalledDate", "Fri Mar 30 2012 13:10:29 GMT+0200"); >
< Deleted : user_pref("CT2613550.IsAlertDBUpdated", true); >
< Deleted : user_pref("CT2613550.IsGrouping", false); >
< Deleted : user_pref("CT2613550.IsInitSetupIni", true); >
< Deleted : user_pref("CT2613550.IsMulticommunity", false); >
< Deleted : user_pref("CT2613550.IsOpenThankYouPage", true); >
< Deleted : user_pref("CT2613550.IsOpenUninstallPage", true); >
< Deleted : user_pref("CT2613550.IsProtectorsInit", true); >
< Deleted : user_pref("CT2613550.LanguagePackLastCheckTime", "Mon Jun 18 2012 08:51:02 GMT+0200"); >
< Deleted : user_pref("CT2613550.LanguagePackReloadIntervalMM", 1440); >
< Deleted : user_pref("CT2613550.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] >
< Deleted : user_pref("CT2613550.LastLogin_3.10.0.1", "Wed Apr 18 2012 21:27:12 GMT+0200"); >
< Deleted : user_pref("CT2613550.LastLogin_3.12.0.7", "Fri Apr 27 2012 08:49:33 GMT+0200"); >
< Deleted : user_pref("CT2613550.LastLogin_3.12.2.3", "Mon Jun 18 2012 08:51:02 GMT+0200"); >
< Deleted : user_pref("CT2613550.LastLogin_3.13.0.6", "Mon Jun 18 2012 09:40:39 GMT+0200"); >
< Deleted : user_pref("CT2613550.LatestVersion", "3.13.0.6"); >
< Deleted : user_pref("CT2613550.Locale", "de-de"); >
< Deleted : user_pref("CT2613550.MCDetectTooltipHeight", "83"); >
< Deleted : user_pref("CT2613550.MCDetectTooltipShow", false); >
< Deleted : user_pref("CT2613550.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); >
< Deleted : user_pref("CT2613550.MCDetectTooltipWidth", "295"); >
< Deleted : user_pref("CT2613550.MyStuffEnabledAtInstallation", true); >
< Deleted : user_pref("CT2613550.OriginalFirstVersion", "3.10.0.1"); >
< Deleted : user_pref("CT2613550.SHRINK_TOOLBAR", 1); >
< Deleted : user_pref("CT2613550.SavedHomepage", "hxxp://www.web.de/"); >
< Deleted : user_pref("CT2613550.SearchBoxWidth", 172); >
< Deleted : user_pref("CT2613550.SearchCaption", "ZoneAlarm-Sicherheit Customized Web Search"); >
< Deleted : user_pref("CT2613550.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties"); >
< Deleted : user_pref("CT2613550.SearchFromAddressBarIsInit", true); >
< Deleted : user_pref("CT2613550.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT261[...] >
< Deleted : user_pref("CT2613550.SearchInNewTabEnabled", true); >
< Deleted : user_pref("CT2613550.SearchInNewTabIntervalMM", 1440); >
< Deleted : user_pref("CT2613550.SearchInNewTabLastCheckTime", "Mon Jun 18 2012 09:40:40 GMT+0200"); >
< Deleted : user_pref("CT2613550.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] >
< Deleted : user_pref("CT2613550.SearchProtectorEnabled", false); >
< Deleted : user_pref("CT2613550.SearchProtectorToolbarDisabled", false); >
< Deleted : user_pref("CT2613550.SendProtectorDataViaLogin", true); >
< Deleted : user_pref("CT2613550.ServiceMapLastCheckTime", "Mon Jun 18 2012 09:35:00 GMT+0200"); >
< Deleted : user_pref("CT2613550.SettingsLastCheckTime", "Mon Jun 18 2012 11:54:39 GMT+0200"); >
< Deleted : user_pref("CT2613550.SettingsLastUpdate", "1337169810"); >
< Deleted : user_pref("CT2613550.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2613550&SearchSource=13"); >
< Deleted : user_pref("CT2613550.ThirdPartyComponentsInterval", 504); >
< Deleted : user_pref("CT2613550.ThirdPartyComponentsLastCheck", "Mon Jun 18 2012 09:35:00 GMT+0200"); >
< Deleted : user_pref("CT2613550.ThirdPartyComponentsLastUpdate", "1255344657"); >
< Deleted : user_pref("CT2613550.ToolbarShrinkedFromSetup", false); >
< Deleted : user_pref("CT2613550.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2613550"); >
< Deleted : user_pref("CT2613550.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] >
< Deleted : user_pref("CT2613550.UserID", "UN39870640524348155"); >
< Deleted : user_pref("CT2613550.ValidationData_Search", 2); >
< Deleted : user_pref("CT2613550.ValidationData_Toolbar", 2); >
< Deleted : user_pref("CT2613550.alertChannelId", "1006347"); >
< Deleted : user_pref("CT2613550.approveUntrustedApps", true); >
< Deleted : user_pref("CT2613550.autoDisableScopes", -1); >
< Deleted : user_pref("CT2613550.components.129171076489169448", false); >
< Deleted : user_pref("CT2613550.components.129539182460150402", false); >
< Deleted : user_pref("CT2613550.components.129791240633491387", false); >
< Deleted : user_pref("CT2613550.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] >
< Deleted : user_pref("CT2613550.globalFirstTimeInfoLastCheckTime", "Mon Jun 18 2012 09:35:00 GMT+0200"); >
< Deleted : user_pref("CT2613550.homepageProtectorEnableByLogin", true); >
< Deleted : user_pref("CT2613550.initDone", true); >
< Deleted : user_pref("CT2613550.isAppTrackingManagerOn", true); >
< Deleted : user_pref("CT2613550.myStuffEnabled", true); >
< Deleted : user_pref("CT2613550.myStuffPublihserMinWidth", 400); >
< Deleted : user_pref("CT2613550.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] >
< Deleted : user_pref("CT2613550.myStuffServiceIntervalMM", 1440); >
< Deleted : user_pref("CT2613550.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] >
< Deleted : user_pref("CT2613550.navigateToUrlOnSearch", false); >
< Deleted : user_pref("CT2613550.oldAppsList", "129171076488700693,129171076488856944,111,129171076488856945,129[...] >
< Deleted : user_pref("CT2613550.revertSettingsEnabled", true); >
< Deleted : user_pref("CT2613550.searchProtectorDialogDelayInSec", 10); >
< Deleted : user_pref("CT2613550.searchProtectorEnableByLogin", true); >
< Deleted : user_pref("CT2613550.testingCtid", ""); >
< Deleted : user_pref("CT2613550.toolbarAppMetaDataLastCheckTime", "Mon Jun 18 2012 08:51:02 GMT+0200"); >
< Deleted : user_pref("CT2613550.toolbarContextMenuLastCheckTime", "Mon Jun 18 2012 09:35:00 GMT+0200"); >
< Deleted : user_pref("CT2613550.usagesFlag", 2); >
< Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2613550&Search[...] >
< Deleted : user_pref("CommunityToolbar.ConduitSearchList", "ZoneAlarm-Sicherheit Customized Web Search"); >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2613550/CT2613550[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1006347/1002062/DE", "\"0\"[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2613550", [...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2613550",[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/50/261/CT2613550/Images/6340849712463612[...] >
< Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...] >
< Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\***\\AppData\\Roaming\\Mozilla[...] >
< Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6"); >
< Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", ""); >
< Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2613550"); >
< Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2613550"); >
< Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2613550"); >
< Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Apr 12 2012 00:27:31 GMT+0200"); >
< Deleted : user_pref("CommunityToolbar.globalUserId", "4d862513-6a0f-4900-a0d7-6764d0a40c11"); >
< Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); >
< Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); >
< Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2613550"); >
< Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Mon Jun 18 2012 09:35:0[...] >
< Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); >
< Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Mon Jun 18 2012 09:51:30 GMT+020[...] >
< Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); >
< Deleted : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); >
< Deleted : user_pref("CommunityToolbar.notifications.locale", ""); >
< Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 0); >
< Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Mon Jun 18 2012 09:35:02 GMT+0200"); >
< Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", ""); >
< Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); >
< Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); >
< Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false); >
< Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); >
< Deleted : user_pref("CommunityToolbar.notifications.userId", "eb851fa8-efc8-44b9-bb9b-bc18764a17ad"); >
< Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.web.de/"); >
< Deleted : user_pref("CommunityToolbar.originalSearchEngine", "Ixquick hxxpS"); >
< Deleted : user_pref("browser.search.defaultengine", "Ask.com"); >
< Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); >
< Deleted : user_pref("browser.search.defaultthis.engineName", "ZoneAlarm-Sicherheit Customized Web Search"); >
< Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2613550&Sea[...] >
< Deleted : user_pref("browser.search.order.1", "Ask.com"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.babExt", ""); >
< Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "2ed6f590000000000000000000000000"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.id", "2ed6f590000000000000000000000000"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15537"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1716:01:56"); >
< Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); >
< Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://search.conduit.com/ResultsExt.aspx?cti[...] >
< Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=&locale=&apn_u[...] >
< >
< ************************* >
[2012.08.08 20:23:21 | 000,027,019 | ---- | M] () -- \AdwCleaner[R1].txt
[2012.08.09 17:03:19 | 000,024,633 | ---- | M] () -- \AdwCleaner[S1].txt
[2012.08.09 17:04:45 | 4274,053,119 | -HS- | M] () -- \hiberfil.sys
[2012.08.09 17:04:49 | 4274,053,119 | -HS- | M] () -- \pagefile.sys
[2011.10.19 09:59:52 | 000,002,184 | ---- | M] () -- \RHDSetup.log
[2011.10.19 10:35:25 | 000,000,163 | ---- | M] () -- \Setup.log
[2012.07.16 16:01:58 | 000,000,474 | ---- | M] () -- \user.js
< >
< AdwCleaner[R1].txt - [27019 octets] - [08/08/2012 20:23:09] >
Invalid Switch: 2012 20:23:09]
< AdwCleaner[S1].txt - [24540 octets] - [09/08/2012 17:03:04] >
Invalid Switch: 2012 17:03:04]
< >
< ########## EOF - C:\AdwCleaner[S1].txt - [24669 octets] ########## >
< End of report > --- --- ---
Viele Grüße
Petra |