unknownname | 20.06.2013 19:02 | Hallo schrauber,
hier die AdwCleaner[S1].txt: Code:
# AdwCleaner v2.303 - Datei am 20/06/2013 um 19:30:03 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzer : unknownname
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\unknownname\Desktop\adwcleaner(1).exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla FireFox\searchplugins\Search_Results.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchTheWeb.xml
Datei Gelöscht : C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml
Datei Gelöscht : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\searchplugins\delta.xml
Datei Gelöscht : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\searchplugins\Search_Results.xml
Datei Gelöscht : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\searchplugins\Web Search.xml
Ordner Gelöscht : C:\Program Files (x86)\Covus Freemium
Ordner Gelöscht : C:\Program Files (x86)\HomeTab
Ordner Gelöscht : C:\Program Files\Covus Freemium
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\FreeRIP
Ordner Gelöscht : C:\ProgramData\IBUpdaterService
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Covus Freemium
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Users\unknownname\AppData\Local\Google\Chrome\unknownname Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl
Ordner Gelöscht : C:\Users\unknownname\AppData\LocalLow\HomeTab
Ordner Gelöscht : C:\Users\unknownname\AppData\LocalLow\SimplyTech
Ordner Gelöscht : C:\Users\unknownname\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\unknownname\AppData\Roaming\HomeTab
Ordner Gelöscht : C:\Users\unknownname\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\unknownname\AppData\Roaming\SimplyTech
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\BabylonToolbar
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\HomeTab
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.Band
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.Band.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.NotificationSource
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.NotificationSource.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cfd485f0-96bd-47cd-bb6d-cd7dda95f102}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DA17D5A-5718-4130-A605-FC316C827836}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16611
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&q=%s --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&q=%s --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=1370195759890&tguid=46364-3869-1370195759890-1CFE39B8643B5F17705E04C8A33208DB&st=chrome&q= --> hxxp://www.google.com
-\\ Mozilla Firefox v21.0 (de)
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\user.js ... Gelöscht !
Gelöscht : user_pref("browser.search.defaultengine", "Web Search");
Gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
Gelöscht : user_pref("browser.search.order.1", "Web Search");
Gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Gelöscht : user_pref("extensions.delta.admin", false);
Gelöscht : user_pref("extensions.delta.aflt", "babsst");
Gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Gelöscht : user_pref("extensions.delta.dfltLng", "en");
Gelöscht : user_pref("extensions.delta.excTlbr", false);
Gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Gelöscht : user_pref("extensions.delta.id", "1ab0e937000000000000001cc08255de");
Gelöscht : user_pref("extensions.delta.instlDay", "15826");
Gelöscht : user_pref("extensions.delta.instlRef", "sst");
Gelöscht : user_pref("extensions.delta.newTab", false);
Gelöscht : user_pref("extensions.delta.prdct", "delta");
Gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Gelöscht : user_pref("extensions.delta.rvrt", "false");
Gelöscht : user_pref("extensions.delta.smplGrp", "none");
Gelöscht : user_pref("extensions.delta.tlbrId", "base");
Gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Gelöscht : user_pref("extensions.delta.vrsn", "1.8.16.16");
Gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.16.1618:52:04");
Gelöscht : user_pref("extensions.delta.vrsni", "1.8.16.16");
Gelöscht : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=46364&tid=3869&ver=3.2&ts=137019575[...]
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\prefs.js
[OK] Die Datei ist sauber.
-\\ Google Chrome v [Version kann nicht ermittelt werden]
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
Datei : C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [22747 octets] - [20/06/2013 19:30:03]
########## EOF - C:\AdwCleaner[S1].txt - [22808 octets] ########## Nun die JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Professional x64
Ran by unknownname on 20.06.2013 at 19:37:42,56
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\unknownname\appdata\local\{00CA716B-B893-48A6-BA8F-610A348FFF8F}
Successfully deleted: [Empty Folder] C:\Users\unknownname\appdata\local\{5B6E749D-E825-445A-B9EB-733637DD4F90}
Successfully deleted: [Empty Folder] C:\Users\unknownname\appdata\local\{96F94195-47E8-4CFD-8D2F-5186995A7F56}
Successfully deleted: [Empty Folder] C:\Users\unknownname\appdata\local\{BC22B6F4-1D86-4277-BE81-CD27571E9044}
Successfully deleted: [Empty Folder] C:\Users\unknownname\appdata\local\{D2089F23-A5F5-4EF9-8A04-4D78EC3CA75E}
Successfully deleted: [Empty Folder] C:\Users\unknownname\appdata\local\{DD475EF3-88C5-429F-90DD-B71DBA3886D0}
~~~ FireFox
Successfully deleted: [File] C:\Users\unknownname\AppData\Roaming\mozilla\firefox\profiles\vs1ebs2d.default\invalidprefs.js
Emptied folder: C:\Users\unknownname\AppData\Roaming\mozilla\firefox\profiles\vs1ebs2d.default\minidumps [4 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.06.2013 at 19:42:50,27
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und zum Abschluss die FRST.txt:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-06-2013 01
Ran by unknownname (administrator) on 20-06-2013 19:45:49
Running from C:\Users\unknownname\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlX64.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
() C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
(Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Team Foundation Server 11.0\Application Tier\TfsJobAgent\TfsJobAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1832760 2012-09-20] (Logitech, Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKCU\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3672640 2013-03-14] (Disc Soft Ltd)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [GDFirewallTray] C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1854928 2013-03-22] (G Data Software AG)
HKLM-x32\...\Run: [ADSK DLMSession] C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1632216 2012-07-23] (Autodesk, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [G Data AntiVirus Tray] C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe [1444304 2013-03-22] (G Data Software AG)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized [703888 2013-03-26] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKU\unknownname\...\Run: [PureSync] "C:\Program Files (x86)\PureSync\PureSyncTray.exe" [x]
Startup: C:\Users\unknownname\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk
ShortcutTarget: Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Startup: C:\Users\unknownname\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk
ShortcutTarget: Mozilla Thunderbird.lnk -> C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Startup: C:\Users\unknownname\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
SearchScopes: HKCU - {5BCCD8D7-E3F3-4411-8E95-6DA19C170DB1} URL = hxxp://www.google.de/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Agent Ransack Keyboard Hook - {B23EDAE2-2A36-4c87-AEFD-B6801B6C6584} - C:\Program Files\Mythicsoft\Agent Ransack\ShellExt.dll (Mythicsoft Ltd)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: HomeTab - {ba696155-d96e-4281-b467-0367a0456474} - C:\Users\unknownname\AppData\Roaming\HomeTab\HomeTab.dll No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - HomeTab - {ba696155-d96e-4281-b467-0367a0456474} - C:\Users\unknownname\AppData\Roaming\HomeTab\HomeTab.dll No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Tcpip\..\Interfaces\{8F511CA4-930F-47CA-9326-B3A0CB101CDA}: [NameServer]192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: HomeTab - C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\Extensions\{24532715-4abc-47ee-bd4f-a6774d0723d2}
FF Extension: No Name - C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\Extensions\WTB_GLOBAL.sqlite
FF Extension: No Name - C:\Users\unknownname\AppData\Roaming\Mozilla\Firefox\Profiles\vs1ebs2d.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
Chrome:
=======
CHR HomePage: about:newtab?source=home
CHR RestoreOnStartup: "about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Plugin: ({"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"}) - {"extensions":{"settings":{"fgibjgmnimooanbagcfpnkmngejcojaf":{"ack_external":true}, "hcemhggbahmlmhgnbpbbdaklcojhbecn":{"from_bookmark":false, "location":1, "state":0, "was_installed_by_default":false, "install_time":"12997874066957085", "manifest":{"update_url":"hxxp://vz.iminent.com/vz/2FE796A5-06CC-48F6-8C8F-BDCC0ABB0D92/100/update.xml", "manifest_version":2, "description":"Iminent Toolbar", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqN+f19a393XEPY3ZeszTI4akZ3kSyfXNUW/EBCi17jWnQx4XusqnyllCnGfXP/cvCrW+yLW0ls0rpBYfv9PPsG8Vg8wF+XyHLZRzwxApKg4IZSMQcsTmkyHp0r544yw5gpXxas3iVkEfajt7/is0glbc2N3QTg03nFXb9n/9O3QIDAQAB", "name":"Iminent Toolbar", "version":"2.0.0.0"}, "from_webstore":false, "path":"hcemhggbahmlmhgnbpbbdaklcojhbecn\2.0.0.0_0", "disable_reason":1}}}, "browser":{"show_home_button":true}, "homepage":"about:newtab?source=home", "session":{"urls_to_restore_on_startup":["about:newtab?source=home"], "restore_on_startup":4}, "homepage_is_newtabpage":"true"} No File
CHR Extension: () - C:\Users\unknownname\AppData\Local\Google\Chrome\User Data\Default\Extensions\2.0.0.0_0\manifest.json
==================== Services (Whitelisted) =================
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [1957840 2013-03-22] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [635344 2013-02-25] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlX64.exe [2556896 2013-04-24] (G Data Software AG)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation)
R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2926672 2013-03-22] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [696808 2013-02-25] (G Data Software AG)
R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [192000 2012-12-29] (Microsoft Corporation)
R2 MySQL55; C:\ProgramData\MySQL\MySQL Server 5.5\my.ini [9171 2012-05-14] ()
S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [612864 2012-12-29] (Microsoft Corporation)
S2 SystemStoreService; C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [296448 2013-06-02] ()
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation)
R2 TFSJobAgent; C:\Program Files\Microsoft Team Foundation Server 11.0\Application Tier\TfsJobAgent\TfsJobAgent.exe [41432 2012-11-06] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S3 WMSVC; C:\Windows\system32\inetsrv\wmsvc.exe [10752 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-05-12] (DT Soft Ltd)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [60248 2013-06-12] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [130392 2013-06-12] (G Data Software AG)
S3 GdNetMon; C:\Windows\system32\drivers\GdNetMon64.sys [31448 2011-12-10] (G Data Software AG)
S3 GdNetMon; C:\Windows\system32\drivers\GdNetMon64.sys [31448 2011-12-10] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [62808 2013-05-01] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64856 2013-06-12] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2013-05-01] (G Data Software)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2013-05-01] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65368 2013-06-12] (G Data Software AG)
R0 mv61xx; C:\Windows\System32\DRIVERS\mv61xx.sys [183144 2012-05-23] (Marvell Semiconductor, Inc.)
S3 NAL; C:\Windows\system32\Drivers\iqvw64e.sys [34472 2010-03-24] (Intel Corporation )
S4 RsFx0201; C:\Windows\System32\DRIVERS\RsFx0201.sys [336880 2012-10-20] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U3 DfSdkS;
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-20 19:44 - 2013-06-20 19:44 - 01929538 ____A (Farbar) C:\Users\unknownname\Desktop\FRST64.exe
2013-06-20 19:42 - 2013-06-20 19:42 - 00001509 ____A C:\Users\unknownname\Desktop\JRT.txt
2013-06-20 19:37 - 2013-06-20 19:37 - 00000000 ____D C:\Windows\ERUNT
2013-06-20 19:36 - 2013-06-20 19:36 - 00000000 ____D C:\JRT
2013-06-20 19:30 - 2013-06-20 19:30 - 00022772 ____A C:\AdwCleaner[S1].txt
2013-06-20 19:24 - 2013-06-20 19:24 - 00648201 ____A C:\Users\unknownname\Desktop\adwcleaner(1).exe
2013-06-20 19:24 - 2013-06-20 19:24 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\unknownname\Desktop\JRT.exe
2013-06-20 18:10 - 2013-06-20 18:10 - 00041947 ____A C:\Users\unknownname\Desktop\ComboFixCorrected.txt
2013-06-20 15:17 - 2013-06-20 15:17 - 00041790 ____A C:\ComboFix.txt
2013-06-20 13:04 - 2013-06-20 15:17 - 00000000 ____D C:\Qoobox
2013-06-20 13:04 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-06-20 13:04 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-06-20 13:04 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-06-20 13:04 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-06-20 13:04 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-06-20 13:04 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-06-20 13:04 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-06-20 13:04 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-06-20 13:03 - 2013-06-20 15:14 - 00000000 ____D C:\Windows\erdnt
2013-06-20 12:59 - 2013-06-20 12:59 - 05081021 ____R (Swearware) C:\Users\unknownname\Desktop\ComboFix.exe
2013-06-19 20:00 - 2013-06-19 20:06 - 00032226 ____A C:\Users\unknownname\Desktop\Addition.txt
2013-06-19 20:00 - 2013-06-19 20:03 - 00035914 ____A C:\Users\unknownname\Desktop\FRST.txt
2013-06-19 19:58 - 2013-06-19 19:58 - 00000000 ____D C:\FRST
2013-06-19 19:14 - 2013-06-19 19:14 - 00700783 ____A (Swearware) C:\Users\unknownname\Downloads\dds+.exe
2013-06-19 19:13 - 2013-06-19 19:13 - 00648201 ____A C:\Users\unknownname\Downloads\adwcleaner.exe
2013-06-18 13:01 - 2013-06-18 13:02 - 00000000 ____D C:\Users\unknownname\AppData\Local\{920A4F92-FDED-4C94-85F6-F4A5245C10F3}
2013-06-16 14:56 - 2013-06-16 14:56 - 00000000 ____D C:\Users\unknownname\AppData\Local\{E9F722AC-2DA3-427D-A9E7-10EFAECB1649}
2013-06-12 21:03 - 2013-06-12 21:03 - 00000000 ____D C:\Program Files (x86)\Team Tools
2013-06-12 21:03 - 2013-06-12 21:03 - 00000000 ____D C:\Program Files (x86)\Common7
2013-06-12 20:14 - 2013-06-12 20:14 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-12 20:14 - 2013-06-12 20:14 - 00000000 ____D C:\Program Files\iTunes
2013-06-12 20:14 - 2013-06-12 20:14 - 00000000 ____D C:\Program Files\iPod
2013-06-12 20:14 - 2013-06-12 20:14 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-12 20:06 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 20:06 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 20:06 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 20:06 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 20:06 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 20:06 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 20:06 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 20:06 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 20:06 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 20:06 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 20:06 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 20:06 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 20:06 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 20:06 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-12 20:06 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-12 20:06 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 20:06 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-12 20:06 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-12 20:06 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 20:05 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 20:05 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 20:05 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 20:05 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 20:05 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-12 20:05 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 20:05 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 20:05 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 20:05 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 20:05 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 20:05 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-12 20:05 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 19:52 - 2013-06-12 19:52 - 00000000 ____D C:\Users\unknownname\AppData\Local\{CA05EF1B-FD3C-4EB6-A7C4-861A3E7F8B55}
2013-06-12 19:50 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 19:50 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 19:50 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 19:50 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 19:50 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 19:50 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 19:50 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 19:50 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 19:50 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 19:50 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 19:50 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 19:50 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 19:50 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 19:50 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 19:50 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 19:50 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 19:50 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 19:50 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 19:50 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-11 16:06 - 2013-06-11 16:06 - 00000000 ____D C:\Users\unknownname\AppData\Local\{930DE47D-4A74-4C04-B572-2B6946B93C02}
2013-06-10 17:05 - 2013-06-10 17:05 - 00000000 ____D C:\Users\unknownname\AppData\Local\{3F15F85A-C5DF-4E83-B3EF-E02B026A0201}
2013-06-03 11:22 - 2013-06-03 11:22 - 00000000 ____D C:\Users\unknownname\AppData\Roaming\OpenOffice.org
2013-06-03 11:06 - 2013-06-03 11:08 - 152249762 ____A C:\Users\unknownname\Downloads\Apache_OpenOffice_incubating_3.4.1_Win_x86_install_de.exe
2013-06-03 10:57 - 2013-06-03 10:57 - 06529210 ____A C:\Users\unknownname\Downloads\dict-en.oxt
2013-06-03 10:42 - 2012-05-23 11:57 - 00183144 ___AT (Marvell Semiconductor, Inc.) C:\Windows\System32\Drivers\mv61xx.sys
2013-06-03 10:42 - 2012-05-23 11:57 - 00014696 ___AT (Marvell Semiconductor Inc.) C:\Windows\System32\Drivers\mv61xxmm.sys
2013-06-03 10:42 - 2009-09-14 19:14 - 00041984 ___AT (<Marvell>) C:\Windows\System32\mvcoinst.dll
2013-06-03 10:27 - 2013-06-03 10:27 - 21151576 ____A (Mozilla) C:\Users\unknownname\Downloads\Firefox Setup 21.0.exe
2013-06-03 09:39 - 2013-06-03 09:39 - 03234774 ____A C:\Users\unknownname\Downloads\dict-de_DE-igerman98_2011-06-21.oxt
2013-06-03 09:38 - 2013-06-03 09:38 - 04606812 ____A C:\Users\unknownname\Downloads\dict-de_DE-frami_2012-06-17.oxt
2013-06-02 20:40 - 2013-06-02 20:40 - 00000000 ____D C:\Program Files\IDT
2013-06-02 20:20 - 2013-06-03 10:02 - 00000000 ____D C:\ProgramData\FreeDriverScout
2013-06-02 20:20 - 2013-06-02 20:20 - 00000000 ____D C:\Users\unknownname\Documents\Freemium Driver Utilities
2013-06-02 20:17 - 2013-06-02 20:17 - 00000000 ____D C:\Users\unknownname\AppData\Local\DownloadGuide
2013-06-02 20:07 - 2013-06-02 20:07 - 00000000 ____D C:\Users\unknownname\AppData\Local\Freemium
2013-06-02 19:56 - 2013-06-13 05:58 - 00031816 ____A C:\Windows\Launcher.exe
2013-06-02 19:53 - 2013-06-03 10:02 - 00000000 ____D C:\Program Files (x86)\SoftwareUpdater
2013-06-02 19:53 - 2013-06-02 19:53 - 00000000 ____D C:\ProgramData\FreeSystemUtilities
2013-05-31 22:08 - 2013-05-31 22:08 - 00000435 ____A C:\Users\unknownname\Desktop\vgn.txt
2013-05-31 16:05 - 2013-05-31 16:05 - 00000000 ____D C:\Users\unknownname\AppData\Local\{BBC3CC0C-FFC6-41A9-B899-4AC1FC856DCF}
2013-05-29 21:17 - 2013-05-29 21:17 - 00000000 ____D C:\Program Files (x86)\Coq
2013-05-29 21:15 - 2013-05-29 21:15 - 53693262 ____A C:\Users\unknownname\Downloads\coq-installer-8.4pl2-win-0.exe
2013-05-27 13:11 - 2013-05-27 13:11 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-05-22 20:31 - 2013-05-22 21:19 - 2772063031 ____A C:\Users\unknownname\Downloads\20130515-Gorin-SemProg-VL-07-1080p.mkv
2013-05-22 20:31 - 2013-05-22 21:09 - 1795801630 ____A C:\Users\unknownname\Downloads\20130515-Gorin-SemProg-VL-06-1080p.mkv
2013-05-21 10:10 - 2013-05-21 10:10 - 00000000 ____D C:\Users\unknownname\AppData\Local\{16105CC8-4F50-4EFC-A427-B197597BADAC}
==================== One Month Modified Files and Folders =======
2013-06-20 19:44 - 2013-06-20 19:44 - 01929538 ____A (Farbar) C:\Users\unknownname\Desktop\FRST64.exe
2013-06-20 19:42 - 2013-06-20 19:42 - 00001509 ____A C:\Users\unknownname\Desktop\JRT.txt
2013-06-20 19:40 - 2009-07-14 06:45 - 00014944 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-20 19:40 - 2009-07-14 06:45 - 00014944 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-20 19:37 - 2013-06-20 19:37 - 00000000 ____D C:\Windows\ERUNT
2013-06-20 19:37 - 2011-12-08 16:25 - 01709028 ____A C:\Windows\WindowsUpdate.log
2013-06-20 19:36 - 2013-06-20 19:36 - 00000000 ____D C:\JRT
2013-06-20 19:33 - 2012-02-19 19:12 - 00001102 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-20 19:32 - 2012-05-14 13:21 - 00353402 ____A C:\Windows\PFRO.log
2013-06-20 19:32 - 2012-02-16 15:15 - 00054541 ____A C:\Windows\setupact.log
2013-06-20 19:32 - 2011-12-08 16:57 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-20 19:32 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-20 19:30 - 2013-06-20 19:30 - 00022772 ____A C:\AdwCleaner[S1].txt
2013-06-20 19:24 - 2013-06-20 19:24 - 00648201 ____A C:\Users\unknownname\Desktop\adwcleaner(1).exe
2013-06-20 19:24 - 2013-06-20 19:24 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\unknownname\Desktop\JRT.exe
2013-06-20 19:21 - 2012-04-02 09:24 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-20 19:21 - 2012-02-19 19:12 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-20 18:10 - 2013-06-20 18:10 - 00041947 ____A C:\Users\unknownname\Desktop\ComboFixCorrected.txt
2013-06-20 15:17 - 2013-06-20 15:17 - 00041790 ____A C:\ComboFix.txt
2013-06-20 15:17 - 2013-06-20 13:04 - 00000000 ____D C:\Qoobox
2013-06-20 15:17 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-06-20 15:14 - 2013-06-20 13:03 - 00000000 ____D C:\Windows\erdnt
2013-06-20 15:12 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-06-20 12:59 - 2013-06-20 12:59 - 05081021 ____R (Swearware) C:\Users\unknownname\Desktop\ComboFix.exe
2013-06-20 12:56 - 2013-04-27 09:57 - 00000000 ___RD C:\Users\unknownname\Dropbox
2013-06-20 12:56 - 2013-04-27 09:49 - 00000000 ____D C:\Users\unknownname\AppData\Roaming\Dropbox
2013-06-19 20:06 - 2013-06-19 20:00 - 00032226 ____A C:\Users\unknownname\Desktop\Addition.txt
2013-06-19 20:03 - 2013-06-19 20:00 - 00035914 ____A C:\Users\unknownname\Desktop\FRST.txt
2013-06-19 19:58 - 2013-06-19 19:58 - 00000000 ____D C:\FRST
2013-06-19 19:14 - 2013-06-19 19:14 - 00700783 ____A (Swearware) C:\Users\unknownname\Downloads\dds+.exe
2013-06-19 19:13 - 2013-06-19 19:13 - 00648201 ____A C:\Users\unknownname\Downloads\adwcleaner.exe
2013-06-18 13:02 - 2013-06-18 13:01 - 00000000 ____D C:\Users\unknownname\AppData\Local\{920A4F92-FDED-4C94-85F6-F4A5245C10F3}
2013-06-16 14:56 - 2013-06-16 14:56 - 00000000 ____D C:\Users\unknownname\AppData\Local\{E9F722AC-2DA3-427D-A9E7-10EFAECB1649}
2013-06-14 20:25 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-06-13 05:58 - 2013-06-02 19:56 - 00031816 ____A C:\Windows\Launcher.exe
2013-06-12 21:25 - 2012-11-19 21:47 - 00000000 ____D C:\ProgramData\Package Cache
2013-06-12 21:07 - 2012-12-03 15:13 - 00000000 ____D C:\ProgramData\Apple Computer
2013-06-12 21:03 - 2013-06-12 21:03 - 00000000 ____D C:\Program Files (x86)\Team Tools
2013-06-12 21:03 - 2013-06-12 21:03 - 00000000 ____D C:\Program Files (x86)\Common7
2013-06-12 21:03 - 2013-05-12 19:12 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-06-12 21:02 - 2013-05-12 18:55 - 00000000 ____D C:\Windows\SysWOW64\1033
2013-06-12 20:57 - 2013-05-12 18:55 - 00000000 ____D C:\Windows\System32\1033
2013-06-12 20:57 - 2012-04-02 09:24 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 20:57 - 2011-12-11 11:46 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 20:55 - 2013-05-12 19:17 - 00000000 ____D C:\Users\unknownname\Documents\Visual Studio 2012
2013-06-12 20:46 - 2011-12-08 20:57 - 00094832 ____A C:\Users\unknownname\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-12 20:45 - 2011-12-08 22:13 - 00000000 ____D C:\Users\unknownname\AppData\Roaming\Notepad++
2013-06-12 20:45 - 2011-12-08 22:13 - 00000000 ____D C:\Program Files (x86)\Notepad++
2013-06-12 20:40 - 2011-12-10 15:39 - 00065368 ____A (G Data Software AG) C:\Windows\System32\Drivers\HookCentre.sys
2013-06-12 20:24 - 2011-12-10 15:39 - 00130392 ____A (G Data Software AG) C:\Windows\System32\Drivers\MiniIcpt.sys
2013-06-12 20:24 - 2011-12-10 15:39 - 00060248 ____A (G Data Software AG) C:\Windows\System32\Drivers\GDBehave.sys
2013-06-12 20:14 - 2013-06-12 20:14 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-12 20:14 - 2013-06-12 20:14 - 00000000 ____D C:\Program Files\iTunes
2013-06-12 20:14 - 2013-06-12 20:14 - 00000000 ____D C:\Program Files\iPod
2013-06-12 20:14 - 2013-06-12 20:14 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-12 20:10 - 2011-12-10 15:39 - 00064856 ____A (G Data Software AG) C:\Windows\System32\Drivers\gdwfpcd64.sys
2013-06-12 20:07 - 2011-12-08 21:13 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 20:03 - 2012-12-30 19:06 - 00000000 ____D C:\Users\unknownname\AppData\Local\Apple Computer
2013-06-12 20:02 - 2011-12-09 16:16 - 02041226 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-12 20:02 - 2009-07-14 19:58 - 00877286 ____A C:\Windows\System32\perfh007.dat
2013-06-12 20:02 - 2009-07-14 19:58 - 00209618 ____A C:\Windows\System32\perfc007.dat
2013-06-12 20:02 - 2009-07-14 07:13 - 02041226 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-12 19:59 - 2012-01-01 23:01 - 00000000 ____D C:\Users\unknownname\AppData\Roaming\Apple Computer
2013-06-12 19:52 - 2013-06-12 19:52 - 00000000 ____D C:\Users\unknownname\AppData\Local\{CA05EF1B-FD3C-4EB6-A7C4-861A3E7F8B55}
2013-06-11 16:06 - 2013-06-11 16:06 - 00000000 ____D C:\Users\unknownname\AppData\Local\{930DE47D-4A74-4C04-B572-2B6946B93C02}
2013-06-10 17:05 - 2013-06-10 17:05 - 00000000 ____D C:\Users\unknownname\AppData\Local\{3F15F85A-C5DF-4E83-B3EF-E02B026A0201}
2013-06-10 17:04 - 2011-12-11 16:21 - 00094832 ____A C:\Users\unknownname\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-09 12:08 - 2013-04-26 18:19 - 00000000 ____D C:\Users\unknownname\Desktop\physik
2013-06-08 16:08 - 2013-06-12 20:05 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-12 20:05 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-12 20:05 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-12 20:05 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-12 20:05 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-12 20:05 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-12 20:05 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-12 20:05 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-12 20:05 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-12 20:05 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-12 20:05 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-12 20:05 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-04 18:09 - 2013-04-26 18:19 - 00000000 ____D C:\Users\unknownname\Desktop\kommpar
2013-06-04 17:56 - 2011-12-10 11:35 - 00094832 ____A C:\Users\unknownname\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-04 17:52 - 2009-07-14 07:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-04 17:40 - 2009-07-14 06:45 - 00373072 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-03 11:22 - 2013-06-03 11:22 - 00000000 ____D C:\Users\unknownname\AppData\Roaming\OpenOffice.org
2013-06-03 11:14 - 2011-12-08 22:11 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-06-03 11:08 - 2013-06-03 11:06 - 152249762 ____A C:\Users\unknownname\Downloads\Apache_OpenOffice_incubating_3.4.1_Win_x86_install_de.exe
2013-06-03 10:57 - 2013-06-03 10:57 - 06529210 ____A C:\Users\unknownname\Downloads\dict-en.oxt
2013-06-03 10:34 - 2012-06-02 22:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-03 10:32 - 2011-12-10 11:34 - 00000000 ____D C:\users\unknownname
2013-06-03 10:28 - 2013-05-13 22:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-03 10:27 - 2013-06-03 10:27 - 21151576 ____A (Mozilla) C:\Users\unknownname\Downloads\Firefox Setup 21.0.exe
2013-06-03 10:03 - 2013-05-01 18:36 - 00000000 ____D C:\users\DefaultAppPool
2013-06-03 10:03 - 2012-11-19 22:19 - 00000000 ____D C:\users\Classic .NET AppPool
2013-06-03 10:03 - 2011-12-10 11:36 - 00000000 ____D C:\users\unknownname
2013-06-03 10:02 - 2013-06-02 20:20 - 00000000 ____D C:\ProgramData\FreeDriverScout
2013-06-03 10:02 - 2013-06-02 19:53 - 00000000 ____D C:\Program Files (x86)\SoftwareUpdater
2013-06-03 10:02 - 2009-07-14 20:18 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-06-03 10:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-06-03 09:39 - 2013-06-03 09:39 - 03234774 ____A C:\Users\unknownname\Downloads\dict-de_DE-igerman98_2011-06-21.oxt
2013-06-03 09:38 - 2013-06-03 09:38 - 04606812 ____A C:\Users\unknownname\Downloads\dict-de_DE-frami_2012-06-17.oxt
2013-06-02 20:40 - 2013-06-02 20:40 - 00000000 ____D C:\Program Files\IDT
2013-06-02 20:20 - 2013-06-02 20:20 - 00000000 ____D C:\Users\unknownname\Documents\Freemium Driver Utilities
2013-06-02 20:17 - 2013-06-02 20:17 - 00000000 ____D C:\Users\unknownname\AppData\Local\DownloadGuide
2013-06-02 20:07 - 2013-06-02 20:07 - 00000000 ____D C:\Users\unknownname\AppData\Local\Freemium
2013-06-02 19:53 - 2013-06-02 19:53 - 00000000 ____D C:\ProgramData\FreeSystemUtilities
2013-05-31 22:08 - 2013-05-31 22:08 - 00000435 ____A C:\Users\unknownname\Desktop\vgn.txt
2013-05-31 16:05 - 2013-05-31 16:05 - 00000000 ____D C:\Users\unknownname\AppData\Local\{BBC3CC0C-FFC6-41A9-B899-4AC1FC856DCF}
2013-05-30 11:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-05-29 22:54 - 2013-04-26 18:19 - 00000000 ____D C:\Users\unknownname\Desktop\semprog
2013-05-29 21:17 - 2013-05-29 21:17 - 00000000 ____D C:\Program Files (x86)\Coq
2013-05-29 21:15 - 2013-05-29 21:15 - 53693262 ____A C:\Users\unknownname\Downloads\coq-installer-8.4pl2-win-0.exe
2013-05-27 13:11 - 2013-05-27 13:11 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-05-22 22:39 - 2013-05-19 10:53 - 00000000 ____D C:\Users\unknownname\AppData\Roaming\vlc
2013-05-22 21:19 - 2013-05-22 20:31 - 2772063031 ____A C:\Users\unknownname\Downloads\20130515-Gorin-SemProg-VL-07-1080p.mkv
2013-05-22 21:09 - 2013-05-22 20:31 - 1795801630 ____A C:\Users\unknownname\Downloads\20130515-Gorin-SemProg-VL-06-1080p.mkv
2013-05-21 10:10 - 2013-05-21 10:10 - 00000000 ____D C:\Users\unknownname\AppData\Local\{16105CC8-4F50-4EFC-A427-B197597BADAC}
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-05-30 11:25
==================== End Of Log ============================ --- --- ---
Schöne Grüße
unknownname |