Awd Code:
# AdwCleaner v3.001 - Report created 30/08/2013 at 11:21:20
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Frank - SIGRID
# Running from : C:\Users\Frank\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : Web Assistant
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Program Files (x86)\Ask.com
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\ConduitEngine
Folder Deleted : C:\Program Files (x86)\IncrediMail_MediaBar_2
Folder Deleted : C:\Program Files (x86)\Incredibar-Games_EN
Folder Deleted : C:\Program Files\Web Assistant
Folder Deleted : C:\Users\Frank\AppData\Local\AskToolbar
Folder Deleted : C:\Users\Frank\AppData\Local\Conduit
Folder Deleted : C:\Users\Frank\AppData\Local\Temp\AskSearch
Folder Deleted : C:\Users\Frank\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Frank\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Frank\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\Frank\AppData\LocalLow\IncrediMail_MediaBar_2
Folder Deleted : C:\Users\Frank\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Frank\AppData\LocalLow\Incredibar-Games_EN
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\Conduit
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\ConduitCommon
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\ConduitEngine
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\Smartbar
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\CT3158970
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\CT2724407
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\Extensions\engine@conduit.com
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\Extensions\toolbar@ask.com
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\Extensions\{238d4b4c-d63c-42a7-b6d8-dc96c8c0f5b9}
Folder Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\Extensions\{990af1c2-5a27-4460-8149-ecc6bc122af3}
File Deleted : C:\END
File Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\searchplugins\MyStart Search.xml
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{322F82C7-DE90-4579-93AA-971DCF45B5E9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69B4CCC9-C895-4BC0-8245-1433C31B7854}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{69B4CCC9-C895-4BC0-8245-1433C31B7854}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD235EBB-2808-433D-B947-58C1C39500BB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{77B5A2F4-14E1-4B95-9B05-B61D991E5575}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7B8F6FE7-7FD9-4924-9E5E-98CF75ED6AB9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CB4BE463-BFEA-4359-AE40-A03B1FCA6BA0}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\incredibar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine
Key Deleted : HKCU\Software\AppDataLow\Software\IncrediMail_MediaBar_2
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Incredibar-Games_EN
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\conduitEngine
Key Deleted : HKLM\Software\ImInstaller
Key Deleted : HKLM\Software\IncrediMail_MediaBar_2
Key Deleted : HKLM\Software\Web Assistant
Key Deleted : HKLM\Software\Incredibar-Games_EN
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IncrediMail_MediaBar_2 Toolbar
Key Deleted : [x64] HKLM\SOFTWARE\Web Assistant
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v23.0 (de)
[ File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default\prefs.js ]
Line Deleted : user_pref("CT2724386.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2724386.CTID", "ct2724407");
Line Deleted : user_pref("CT2724386.CommunitiesChangesLastCheckTime", "Wed Dec 01 2010 16:26:32 GMT+0100");
Line Deleted : user_pref("CT2724386.CommunityChanged", true);
Line Deleted : user_pref("CT2724386.CurrentServerDate", "1-12-2010");
Line Deleted : user_pref("CT2724386.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2724386.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2724386.FirstServerDate", "1-12-2010");
Line Deleted : user_pref("CT2724386.FirstTime", true);
Line Deleted : user_pref("CT2724386.FirstTimeFF3", true);
Line Deleted : user_pref("CT2724386.FirstTimeSettingsDone", true);
Line Deleted : user_pref("CT2724386.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2724386.GroupingLastCheckTime", "Wed Dec 01 2010 16:26:32 GMT+0100");
Line Deleted : user_pref("CT2724386.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2724386.GroupingLastResponse", true);
Line Deleted : user_pref("CT2724386.GroupingLastServerUpdateTime", "129356960539570000");
Line Deleted : user_pref("CT2724386.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2724386.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2724386.Initialize", true);
Line Deleted : user_pref("CT2724386.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2724386.InstallationAndCookieDataSentCount", 3);
Line Deleted : user_pref("CT2724386.InstallationId", "IncrediMail_MediaBar_2.exe");
Line Deleted : user_pref("CT2724386.InstallationType", "ConduitIntegration");
Line Deleted : user_pref("CT2724386.InstalledDate", "Wed Dec 01 2010 16:26:32 GMT+0100");
Line Deleted : user_pref("CT2724386.IsGrouping", true);
Line Deleted : user_pref("CT2724386.IsMulticommunity", false);
Line Deleted : user_pref("CT2724386.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2724386.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2724386.LanguagePackLastCheckTime", "Wed Dec 01 2010 16:26:33 GMT+0100");
Line Deleted : user_pref("CT2724386.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2724386.LastLogin_2.7.2.0", "Wed Dec 01 2010 16:26:33 GMT+0100");
Line Deleted : user_pref("CT2724386.LatestVersion", "2.7.2.0");
Line Deleted : user_pref("CT2724386.Locale", "en");
Line Deleted : user_pref("CT2724386.LoginCache", 4);
Line Deleted : user_pref("CT2724386.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2724386.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2724386.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2724386.RadioIsPodcast", false);
Line Deleted : user_pref("CT2724386.RadioMediaID", "21080119");
Line Deleted : user_pref("CT2724386.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2724386.RadioMenuSelectedID", "EBRadioMenu_CT272438621080119");
Line Deleted : user_pref("CT2724386.RadioStationName", "Royal-Radio%20");
Line Deleted : user_pref("CT2724386.RadioStationURL", "");
Line Deleted : user_pref("CT2724386.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2724386&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2724386.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2724386.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2724386&q=");
Line Deleted : user_pref("CT2724386.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2724386.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.SearchInNewTabLastCheckTime", "Wed Dec 01 2010 16:26:33 GMT+0100");
Line Deleted : user_pref("CT2724386.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2724386.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2724386.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2724386.SettingsLastCheckTime", "Wed Dec 01 2010 16:26:32 GMT+0100");
Line Deleted : user_pref("CT2724386.SettingsLastUpdate", "1291215253");
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsLastCheck", "Wed Dec 01 2010 16:26:32 GMT+0100");
Line Deleted : user_pref("CT2724386.ThirdPartyComponentsLastUpdate", "1246790578");
Line Deleted : user_pref("CT2724386.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
Line Deleted : user_pref("CT2724386.UserID", "UN59744799287370333");
Line Deleted : user_pref("CT2724386.WeatherNetwork", "");
Line Deleted : user_pref("CT2724386.WeatherPollDate", "Wed Dec 01 2010 16:26:33 GMT+0100");
Line Deleted : user_pref("CT2724386.WeatherUnit", "C");
Line Deleted : user_pref("CT2724386.clientLogIsEnabled", true);
Line Deleted : user_pref("CT2724386.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2724386.ct2724407.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2724386.ct2724407.FirstTimeSettingsDone", true);
Line Deleted : user_pref("CT2724386.ct2724407.GroupingInvalidateCache", false);
Line Deleted : user_pref("CT2724386.ct2724407.GroupingLastCheckTime", "Wed Dec 01 2010 16:26:32 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2724386.ct2724407.GroupingLastResponse", true);
Line Deleted : user_pref("CT2724386.ct2724407.GroupingLastServerUpdateTime", "129356104284470000");
Line Deleted : user_pref("CT2724386.ct2724407.InvalidateCache", false);
Line Deleted : user_pref("CT2724386.ct2724407.LanguagePackLastCheckTime", "Wed Dec 01 2010 16:26:34 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.Locale", "de");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastCheckTime", "Wed Dec 01 2010 16:26:33 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2724386.ct2724407.RadioLastUpdateServer", "129249047784100000");
Line Deleted : user_pref("CT2724386.ct2724407.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2724407&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2724386.ct2724407.SearchInNewTabLastCheckTime", "Wed Dec 01 2010 16:27:19 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2724386.ct2724407.SettingsLastCheckTime", "Wed Dec 01 2010 16:26:32 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.SettingsLastUpdate", "1291129628");
Line Deleted : user_pref("CT2724386.ct2724407.ThirdPartyComponentsLastCheck", "Wed Dec 01 2010 16:26:32 GMT+0100");
Line Deleted : user_pref("CT2724386.ct2724407.ThirdPartyComponentsLastUpdate", "1255348257");
Line Deleted : user_pref("CT2724386.myStuffEnabled", true);
Line Deleted : user_pref("CT2724386.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2724386.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2724386.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2724386.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2724386.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2724407..clientLogIsEnabled", false);
Line Deleted : user_pref("CT2724407..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2724407..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2724407.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Line Deleted : user_pref("CT2724407.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2724407.BrowserCompStateIsOpen_129626311033612748", true);
Line Deleted : user_pref("CT2724407.BrowserCompStateIsOpen_129723003199914047", true);
Line Deleted : user_pref("CT2724407.BrowserCompStateIsOpen_129847484448267081", true);
Line Deleted : user_pref("CT2724407.BrowserCompStateIsOpen_129851872283658385", true);
Line Deleted : user_pref("CT2724407.BrowserCompStateIsOpen_129904362619180486", true);
Line Deleted : user_pref("CT2724407.BrowserCompStateIsOpen_130040907554784951", true);
Line Deleted : user_pref("CT2724407.BrowserCompStateIsOpen_1367226373000", true);
Line Deleted : user_pref("CT2724407.CTID", "ct2724407");
Line Deleted : user_pref("CT2724407.CurrentServerDate", "30-8-2013");
Line Deleted : user_pref("CT2724407.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2724407.DialogsGetterLastCheckTime", "Fri Aug 30 2013 08:36:38 GMT+0200");
Line Deleted : user_pref("CT2724407.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2724407.FirstServerDate", "20-7-2011");
Line Deleted : user_pref("CT2724407.FirstTime", true);
Line Deleted : user_pref("CT2724407.FirstTimeFF3", true);
Line Deleted : user_pref("CT2724407.FixPageNotFoundErrors", false);
Line Deleted : user_pref("CT2724407.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2724407.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2724407.HasUserGlobalKeys", true);
Line Deleted : user_pref("CT2724407.Initialize", true);
Line Deleted : user_pref("CT2724407.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2724407.InstallationAndCookieDataSentCount", 3);
Line Deleted : user_pref("CT2724407.InstallationId", "ConduitStubGeneric");
Line Deleted : user_pref("CT2724407.InstallationType", "ConduitStubIntegration");
Line Deleted : user_pref("CT2724407.InstalledDate", "Wed Jul 20 2011 20:29:31 GMT+0200");
Line Deleted : user_pref("CT2724407.InvalidateCache", false);
Line Deleted : user_pref("CT2724407.IsAlertDBUpdated", true);
Line Deleted : user_pref("CT2724407.IsGrouping", false);
Line Deleted : user_pref("CT2724407.IsInitSetupIni", true);
Line Deleted : user_pref("CT2724407.IsMulticommunity", false);
Line Deleted : user_pref("CT2724407.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2724407.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2724407.LanguagePackLastCheckTime", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT2724407.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2724407.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2724407.LastLogin_3.12.2.3", "Fri Jun 01 2012 20:46:18 GMT+0200");
Line Deleted : user_pref("CT2724407.LastLogin_3.13.0.6", "Tue Jul 17 2012 17:57:34 GMT+0200");
Line Deleted : user_pref("CT2724407.LastLogin_3.14.1.0", "Sun Aug 26 2012 11:55:48 GMT+0200");
Line Deleted : user_pref("CT2724407.LastLogin_3.15.1.0", "Wed Mar 06 2013 18:08:06 GMT+0100");
Line Deleted : user_pref("CT2724407.LastLogin_3.18.0.7", "Fri Jul 26 2013 15:40:22 GMT+0200");
Line Deleted : user_pref("CT2724407.LastLogin_3.19.0.3", "Fri Aug 30 2013 08:36:38 GMT+0200");
Line Deleted : user_pref("CT2724407.LastLogin_3.5.0.12", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT2724407.LatestVersion", "3.19.0.3");
Line Deleted : user_pref("CT2724407.Locale", "de");
Line Deleted : user_pref("CT2724407.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2724407.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2724407.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2724407.MyStuffEnabledAtInstallation", true);
Line Deleted : user_pref("CT2724407.OriginalFirstVersion", "3.5.0.12");
Line Deleted : user_pref("CT2724407.RadioIsPodcast", false);
Line Deleted : user_pref("CT2724407.RadioLastCheckTime", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT2724407.RadioLastUpdateIPServer", "0");
Line Deleted : user_pref("CT2724407.RadioMediaID", "21080119");
Line Deleted : user_pref("CT2724407.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2724407.RadioMenuSelectedID", "EBRadioMenu_CT272440721080119");
Line Deleted : user_pref("CT2724407.RadioShrinkedFromSetup", false);
Line Deleted : user_pref("CT2724407.RadioStationName", "Royal-Radio%20");
Line Deleted : user_pref("CT2724407.RadioStationURL", "");
Line Deleted : user_pref("CT2724407.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2724407.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2724407&q=");
Line Deleted : user_pref("CT2724407.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2724407.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2724407.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID&UM=UM_ID");
Line Deleted : user_pref("CT2724407.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2724407.ServiceMapLastCheckTime", "Fri Aug 30 2013 11:13:33 GMT+0200");
Line Deleted : user_pref("CT2724407.SettingsLastCheckTime", "Wed Jul 20 2011 20:29:31 GMT+0200");
Line Deleted : user_pref("CT2724407.SettingsLastUpdate", "1311168846");
Line Deleted : user_pref("CT2724407.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2724407.ThirdPartyComponentsLastCheck", "Wed Jul 20 2011 20:29:31 GMT+0200");
Line Deleted : user_pref("CT2724407.ThirdPartyComponentsLastUpdate", "1255344657");
Line Deleted : user_pref("CT2724407.ToolbarShrinkedFromSetup", false);
Line Deleted : user_pref("CT2724407.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2724407");
Line Deleted : user_pref("CT2724407.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
Line Deleted : user_pref("CT2724407.UserID", "UN36928324977727917");
Line Deleted : user_pref("CT2724407.WeatherNetwork", "");
Line Deleted : user_pref("CT2724407.WeatherPollDate", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT2724407.WeatherUnit", "C");
Line Deleted : user_pref("CT2724407.alertChannelId", "1116673");
Line Deleted : user_pref("CT2724407.ct2724407.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2724407.ct2724407.InvalidateCache", false);
Line Deleted : user_pref("CT2724407.ct2724407.LanguagePackLastCheckTime", "Fri Aug 30 2013 08:36:38 GMT+0200");
Line Deleted : user_pref("CT2724407.ct2724407.Locale", "de");
Line Deleted : user_pref("CT2724407.ct2724407.RadioLastCheckTime", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT2724407.ct2724407.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2724407.ct2724407.RadioLastUpdateServer", "129249047784100000");
Line Deleted : user_pref("CT2724407.ct2724407.SearchInNewTabLastCheckTime", "Fri Aug 30 2013 08:36:37 GMT+0200");
Line Deleted : user_pref("CT2724407.ct2724407.SettingsLastCheckTime", "Fri Aug 30 2013 08:36:37 GMT+0200");
Line Deleted : user_pref("CT2724407.ct2724407.SettingsLastUpdate", "1377832320");
Line Deleted : user_pref("CT2724407.ct2724407.ThirdPartyComponentsLastCheck", "Wed Jul 20 2011 20:29:31 GMT+0200");
Line Deleted : user_pref("CT2724407.ct2724407.ThirdPartyComponentsLastUpdate", "1255344657");
Line Deleted : user_pref("CT2724407.ct2724407.globalFirstTimeInfoLastCheckTime", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT2724407.ct2724407.toolbarAppMetaDataLastCheckTime", "Fri Aug 30 2013 08:36:38 GMT+0200");
Line Deleted : user_pref("CT2724407.ct2724407.toolbarContextMenuLastCheckTime", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT2724407.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...]
Line Deleted : user_pref("CT2724407.globalFirstTimeInfoLastCheckTime", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT2724407.homepageProtectorEnableByLogin", true);
Line Deleted : user_pref("CT2724407.initDone", true);
Line Deleted : user_pref("CT2724407.isAppTrackingManagerOn", true);
Line Deleted : user_pref("CT2724407.isFirstRadioInstallation", false);
Line Deleted : user_pref("CT2724407.myStuffEnabled", true);
Line Deleted : user_pref("CT2724407.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2724407.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2724407.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2724407.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2724407.revertSettingsEnabled", true);
Line Deleted : user_pref("CT2724407.searchProtectorDialogDelayInSec", 10);
Line Deleted : user_pref("CT2724407.searchProtectorEnableByLogin", true);
Line Deleted : user_pref("CT2724407.testingCtid", "");
Line Deleted : user_pref("CT2724407.toolbarAppMetaDataLastCheckTime", "Wed Jul 20 2011 20:29:31 GMT+0200");
Line Deleted : user_pref("CT2724407.toolbarContextMenuLastCheckTime", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CT3158970.1000082.isPlayDisplay", "true");
Line Deleted : user_pref("CT3158970.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock\",\"url\":\"hxxp://feedlive.net/california.asx\"}");
Line Deleted : user_pref("CT3158970.1000234.TWC_TMP_city", "BERLIN");
Line Deleted : user_pref("CT3158970.1000234.TWC_TMP_country", "DE");
Line Deleted : user_pref("CT3158970.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3158970.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3158970.FirstTime", "true");
Line Deleted : user_pref("CT3158970.FirstTimeFF3", "true");
Line Deleted : user_pref("CT3158970.UserID", "UN42859699251814711");
Line Deleted : user_pref("CT3158970.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT3158970.autoDisableScopes", 0);
Line Deleted : user_pref("CT3158970.countryCode", "DE");
Line Deleted : user_pref("CT3158970.defaultSearch", "false");
Line Deleted : user_pref("CT3158970.enableAlerts", "always");
Line Deleted : user_pref("CT3158970.enableFix404ByUser", "TRUE");
Line Deleted : user_pref("CT3158970.enableSearchFromAddressBar", "false");
Line Deleted : user_pref("CT3158970.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT3158970.fixPageNotFoundError", "false");
Line Deleted : user_pref("CT3158970.fixPageNotFoundErrorByUser", "false");
Line Deleted : user_pref("CT3158970.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT3158970.fixUrls", true);
Line Deleted : user_pref("CT3158970.fullUserID", "UN42859699251814711.UP.20130630194427");
Line Deleted : user_pref("CT3158970.hxxp___api19_thetrafficstat_net.pid2", "c65d81f5f6f91936");
Line Deleted : user_pref("CT3158970.hxxp___api20_thetrafficstat_net.pid2", "5a4b521207132107");
Line Deleted : user_pref("CT3158970.hxxp___api29_thetrafficstat_net.pid2", "ef3fc61244a825e7");
Line Deleted : user_pref("CT3158970.hxxp___api31_thetrafficstat_net.pid2", "e4584e30a5198491");
Line Deleted : user_pref("CT3158970.installId", "ConduitNSISIntegration");
Line Deleted : user_pref("CT3158970.installType", "ConduitNSISIntegration");
Line Deleted : user_pref("CT3158970.isCheckedStartAsHidden", true);
Line Deleted : user_pref("CT3158970.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3158970.isFirstTimeToolbarLoading", "false");
Line Deleted : user_pref("CT3158970.isNewTabEnabled", true);
Line Deleted : user_pref("CT3158970.isPerformedSmartBarTransition", "true");
Line Deleted : user_pref("CT3158970.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT3158970.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3158970&octid=CT3158970&SearchSource=15&CUI=UN42859699251814711&SSPV=&Lay=1&UM=\"}");
Line Deleted : user_pref("CT3158970.lastVersion", "10.16.70.505");
Line Deleted : user_pref("CT3158970.migrateAppsAndComponents", true);
Line Deleted : user_pref("CT3158970.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.google.de%2F\",\"EB_MAIN_FRAME_TITLE\":\"Google\",\"EB_SEARCH_TERM\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://Inc[...]
Line Deleted : user_pref("CT3158970.openThankYouPage", "false");
Line Deleted : user_pref("CT3158970.openUninstallPage", "true");
Line Deleted : user_pref("CT3158970.search.searchAppId", "129675591388832722");
Line Deleted : user_pref("CT3158970.search.searchCount", "0");
Line Deleted : user_pref("CT3158970.searchInNewTabEnabledByUser", "true");
Line Deleted : user_pref("CT3158970.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT3158970.searchSuggestEnabledByUser", "false");
Line Deleted : user_pref("CT3158970.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3158970.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3158970.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3158970\"}");
Line Deleted : user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://IncredibarGamesEN.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Incredibar-Games EN\"}");
Line Deleted : user_pref("CT3158970.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3158970.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3158970.serviceLayer_services_Configuration_lastUpdate", "1376850107858");
Line Deleted : user_pref("CT3158970.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1352480839171");
Line Deleted : user_pref("CT3158970.serviceLayer_services_appsMetadata_lastUpdate", "1352480838800");
Line Deleted : user_pref("CT3158970.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1352480839291");
Line Deleted : user_pref("CT3158970.serviceLayer_services_location_lastUpdate", "1372613956540");
Line Deleted : user_pref("CT3158970.serviceLayer_services_login_10.10.27.6_lastUpdate", "1352663853696");
Line Deleted : user_pref("CT3158970.serviceLayer_services_login_10.14.65.43_lastUpdate", "1365074574327");
Line Deleted : user_pref("CT3158970.serviceLayer_services_login_10.15.0.562_lastUpdate", "1370364532707");
Line Deleted : user_pref("CT3158970.serviceLayer_services_login_10.15.2.523_lastUpdate", "1372613956659");
Line Deleted : user_pref("CT3158970.serviceLayer_services_login_10.16.4.519_lastUpdate", "1374846143157");
Line Deleted : user_pref("CT3158970.serviceLayer_services_login_10.16.70.505_lastUpdate", "1376850108158");
Line Deleted : user_pref("CT3158970.serviceLayer_services_optimizer_lastUpdate", "1352480839466");
Line Deleted : user_pref("CT3158970.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1352480839598");
Line Deleted : user_pref("CT3158970.serviceLayer_services_searchAPI_lastUpdate", "1376850107878");
Line Deleted : user_pref("CT3158970.serviceLayer_services_serviceMap_lastUpdate", "1376850107718");
Line Deleted : user_pref("CT3158970.serviceLayer_services_toolbarContextMenu_lastUpdate", "1352480839257");
Line Deleted : user_pref("CT3158970.serviceLayer_services_toolbarSettings_lastUpdate", "1376850108278");
Line Deleted : user_pref("CT3158970.serviceLayer_services_translation_lastUpdate", "1376850107958");
Line Deleted : user_pref("CT3158970.settingsINI", true);
Line Deleted : user_pref("CT3158970.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT3158970.showToolbarPermission", "false");
Line Deleted : user_pref("CT3158970.smartbar.CTID", "CT3158970");
Line Deleted : user_pref("CT3158970.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT3158970.smartbar.isHidden", true);
Line Deleted : user_pref("CT3158970.smartbar.toolbarName", "Incredibar-Games EN ");
Line Deleted : user_pref("CT3158970.startPage", "false");
Line Deleted : user_pref("CT3158970.toolbarBornServerTime", "9-11-2012");
Line Deleted : user_pref("CT3158970.toolbarCurrentServerTime", "18-8-2013");
Line Deleted : user_pref("CT3158970.toolbarLoginClientTime", "Sat Apr 06 2013 17:54:13 GMT+0200");
Line Deleted : user_pref("CT3158970.upgradeFromClearSBVersion", true);
Line Deleted : user_pref("CT3158970_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1377854013135,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/ct2724407/CT2724407", "\"6e1e9a01d2266339556cb9c58271e41b3\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2724407", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=ct2724407", "\"1367226872\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=de", "hrY3aRo68pvVAKwJTjMFmA==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=de", "uwY9T5AsudBxjradvWCAOA==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=de", "D/tN3YiKFksK+RjZytPhIA==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=de", "ZdrYrsEQox0wVf3yXX8zTQ==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"07879643d3acc1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"8028f138140cc1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.2.3", "\"4ead38b3e6bcd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0e0a4327275cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.1.0", "\"0343677cfb1cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18.0.7", "\"97e416bb586ce1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.19.0.3", "\"2a1a0d7b586ce1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.0.12", "\"8028f138140cc1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2724407", "\"9971ee9815a5fc569766cf6ddcaaca8e\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634303635100000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/2011 5:25:10 PM", "634335443890000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/17/2011 12:59:49 PM", "634339976460000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/22/2011 6:54:06 PM", "634356118310000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2724407/CT2724407", "\"1311168846\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/ct2724407/CT2724407", "\"1311168846\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"c46fa7f9435738b1f1731ba199dd66f2\"");
Line Deleted : user_pref("CommunityToolbar.EngineHiddenByUser", true);
Line Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Line Deleted : user_pref("CommunityToolbar.IsEngineShown", false);
Line Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Line Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Frank\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8te5n404.default\\conduitCommon\\modules\\3.5.0.12");
Line Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.5.0.12");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2724386,ConduitEngine,CT2724407");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2724386,CT2724407");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2724407");
Line Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Wed May 11 2011 15:32:35 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Mon Oct 03 2011 08:44:18 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Line Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Line Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Mon Oct 03 2011 08:44:10 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Line Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Line Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Line Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Line Deleted : user_pref("CommunityToolbar.alert.userId", "48a6c3d0-ddc2-46d6-9461-bac803aa28b5");
Line Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Wed Dec 01 2010 16:26:33 GMT+0100");
Line Deleted : user_pref("CommunityToolbar.globalUserId", "cf861039-4ddf-402e-8169-448233e30aa2");
Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jul 20 2011 20:29:33 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Line Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Line Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jul 20 2011 20:29:32 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1305622559");
Line Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Line Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Line Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Line Deleted : user_pref("CommunityToolbar.notifications.userId", "1b3ca98e-3820-4fad-9eec-190a90cfa2d7");
Line Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sat Oct 01 2011 10:23:29 GMT+0200");
Line Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Line Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Fri Jul 15 2011 14:22:18 GMT+0200");
Line Deleted : user_pref("ConduitEngine.FirstServerDate", "01/12/2011 16");
Line Deleted : user_pref("ConduitEngine.FirstTime", true);
Line Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Line Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Line Deleted : user_pref("ConduitEngine.Initialize", true);
Line Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Line Deleted : user_pref("ConduitEngine.InstalledDate", "Wed Jan 12 2011 14:52:26 GMT+0100");
Line Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Line Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Line Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Line Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Jul 18 2011 13:56:08 GMT+0200");
Line Deleted : user_pref("ConduitEngine.LastLogin_3.2.5.2", "Tue May 10 2011 06:23:09 GMT+0200");
Line Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Mon Jul 18 2011 13:56:09 GMT+0200");
Line Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Jul 18 2011 13:56:08 GMT+0200");
Line Deleted : user_pref("ConduitEngine.UserID", "UN98332057071285168");
Line Deleted : user_pref("ConduitEngine.componentAlertEnabled", true);
Line Deleted : user_pref("ConduitEngine.engineLocale", "de");
Line Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Jul 18 2011 13:56:08 GMT+0200");
Line Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Mon Jul 18 2011 13:56:09 GMT+0200");
Line Deleted : user_pref("ConduitEngine.initDone", true);
Line Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Line Deleted : user_pref("ConduitEngine.usagesFlag", 1);
Line Deleted : user_pref("browser.search.defaultenginename", "MyStart Search");
Line Deleted : user_pref("browser.search.selectedEngine", "MyStart Search");
Line Deleted : user_pref("extensions.enabledAddons", "toolbar%40ask.com:3.15.24.42066,%7B8E9E3331-D360-4f87-8803-52DE43566502%7D:2.0.0.611,%7B990af1c2-5a27-4460-8149-ecc6bc122af3%7D:3.19.0.3,%7B238d4b4c-d63c-42a7-b6[...]
Line Deleted : user_pref("extensions.enabledItems", "engine@conduit.com:3.2.5.2,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17");
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{8E9E3331-D360-4f87-8803-52DE43566502}\":{\"descriptor\":\"C:\\\\Program Files\\\\Web Assistant\\\\Firefox\",\"mtim[...]
Line Deleted : user_pref("smartbar.machineId", "GTSCAWQL1RFMTD8/2EWJ7LEUYO/ASDG1RZQ3VPQNATWME93ZEVAGKWYJLF1ATGP/RQ/C3E96GFGFOXPN3IPSTG");
Line Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.mywebsearch.com\":\"searc[...]
Line Deleted : user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=toolbar|babsrc=tb_ss|invocationType=tb50-ie-aolsoftonic-tbsbox-en-us|invocationType=tb50-ff-aolsoftonic[...]
Line Deleted : user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.mywebsearch.com\":\"searc[...]
*************************
AdwCleaner[R0].txt - [53792 octets] - [30/08/2013 11:20:26]
AdwCleaner[S0].txt - [49630 octets] - [30/08/2013 11:21:20]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [49691 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Windows 7 Home Premium x64
Ran by Frank on 30.08.2013 at 13:03:34,42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\im
Successfully deleted: [Registry Key] "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2453639657-2932101560-2309690496-1001\Software\web assistant"
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2724386
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3158970
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Frank\AppData\Roaming\incredibar"
~~~ FireFox
Emptied folder: C:\Users\Frank\AppData\Roaming\mozilla\firefox\profiles\8te5n404.default\minidumps [90 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.08.2013 at 13:07:08,34
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ TFC
hier gab es Probleme, die ausgelesene Datei hat sich nicht selbst, wie die anderen auf meinem Laptop gespeichert, er hat auch keinen Neustart gefordert, so das ich diesen selbst gamcht habe. Er ist aber auch nach mehreren Minuten nicht aus gegangen, somit habe ich nachgeholfen, im abgesicherten Modus wieder hoch gefahren und einen Neustart gemacht, ich hoffe das war richtig.
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Frank (administrator) on 30-08-2013 13:24:16
Running from C:\Users\Frank\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9913376 2009-12-29] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [832544 2010-01-18] (Acer Incorporated)
HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [17398376 2010-01-25] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated)
MountPoints2: {d8b38a40-9381-11e0-9c0c-705ab63b216a} - E:\pushinst.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-24] (Intel Corporation)
HKLM-x32\...\Run: [EgisTecLiveUpdate] - C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-04] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-01-13] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1287760 2010-01-22] (Dritek System Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2009-12-24] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2009-12-24] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5741g&r=27360510j345l04h4z1k5t44n2k91p
SearchScopes: HKLM - DefaultScope value is missing.
Handler: msdaipp - No CLSID Value -
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default
FF Homepage: hxxp://www.google.de/
FF Keyword.URL: chrome://browser-region/locale/region.properties
FF NetworkProxy: "backup.ftp", "178.217.14.33"
FF NetworkProxy: "backup.ftp_port", 9090
FF NetworkProxy: "backup.gopher", "212.91.180.250"
FF NetworkProxy: "backup.gopher_port", 8080
FF NetworkProxy: "backup.socks", "178.217.14.33"
FF NetworkProxy: "backup.socks_port", 9090
FF NetworkProxy: "backup.ssl", "178.217.14.33"
FF NetworkProxy: "backup.ssl_port", 9090
FF NetworkProxy: "ftp", "178.217.14.33"
FF NetworkProxy: "ftp_port", 9090
FF NetworkProxy: "gopher", "212.91.180.250"
FF NetworkProxy: "gopher_port", 8080
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "178.217.14.33"
FF NetworkProxy: "socks_port", 9090
FF NetworkProxy: "ssl", "178.217.14.33"
FF NetworkProxy: "ssl_port", 9090
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Frank\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG)
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
S3 gusvc; "C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe" [x]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-05-06] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-05-06] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-05-06] (Avira Operations GmbH & Co. KG)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-30 13:07 - 2013-08-30 13:07 - 00001285 _____ C:\Users\Frank\Desktop\JRT.txt
2013-08-30 13:03 - 2013-08-30 13:03 - 00000000 ____D C:\Windows\ERUNT
2013-08-30 11:23 - 2013-08-30 11:23 - 00049848 _____ C:\Users\Frank\Desktop\AdwCleaner[S0].txt
2013-08-30 11:20 - 2013-08-30 11:21 - 00000000 ____D C:\AdwCleaner
2013-08-30 11:16 - 2013-08-30 11:16 - 01023533 _____ (Thisisu) C:\Users\Frank\Desktop\JRT.exe
2013-08-30 11:16 - 2013-08-30 11:16 - 00448512 _____ (OldTimer Tools) C:\Users\Frank\Desktop\TFC.exe
2013-08-30 11:15 - 2013-08-30 11:15 - 00994642 _____ C:\Users\Frank\Desktop\adwcleaner.exe
2013-08-30 10:18 - 2013-08-30 10:18 - 00029648 _____ C:\Users\Frank\Desktop\1FRST1.txt
2013-08-30 10:18 - 2013-08-30 10:18 - 00018939 _____ C:\Users\Frank\Desktop\2Addition1.txt
2013-08-30 10:17 - 2013-08-30 10:17 - 00000000 ____D C:\FRST
2013-08-30 10:15 - 2013-08-30 10:15 - 01579080 _____ (Farbar) C:\Users\Frank\Desktop\FRST64.exe
2013-08-30 08:39 - 2013-08-30 08:39 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-08-30 08:39 - 2013-08-30 08:39 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-08-30 08:36 - 2013-08-30 08:36 - 00000000 ____D C:\Users\Frank\AppData\Local\Secunia PSI
2013-08-30 08:35 - 2013-08-30 08:35 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-08-30 08:32 - 2013-08-30 08:32 - 00000000 ____D C:\Windows\Sun
2013-08-30 08:31 - 2013-08-30 08:31 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00000000 ____D C:\ProgramData\Sun
2013-08-30 08:30 - 2013-08-30 08:30 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-30 08:29 - 2013-08-30 08:29 - 00903080 _____ (Oracle Corporation) C:\Users\Frank\Downloads\JavaSetup7u25.exe
2013-08-30 06:54 - 2013-08-30 06:54 - 00000000 ____D C:\Users\Frank\AppData\Roaming\SumatraPDF
2013-08-30 06:54 - 2013-08-30 06:54 - 00000000 ____D C:\Program Files (x86)\SumatraPDF
2013-08-14 17:24 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 17:24 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 17:24 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 17:24 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 17:24 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 17:24 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 17:24 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 17:24 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 17:24 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 17:23 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 17:23 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 17:23 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 17:23 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 17:23 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 17:23 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 17:23 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 17:23 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 17:15 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 17:15 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 17:15 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 17:15 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 17:15 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 17:15 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 17:15 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 17:15 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 17:15 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 17:15 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 17:15 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 17:15 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 17:15 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 17:15 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 17:15 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 17:15 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 17:15 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 17:15 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 17:15 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 17:15 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 17:15 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 17:15 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 17:15 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 17:15 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 17:15 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 17:14 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 17:14 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-08-30 13:23 - 2012-11-27 12:43 - 00023979 _____ C:\Windows\setupact.log
2013-08-30 13:23 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-30 13:07 - 2013-08-30 13:07 - 00001285 _____ C:\Users\Frank\Desktop\JRT.txt
2013-08-30 13:03 - 2013-08-30 13:03 - 00000000 ____D C:\Windows\ERUNT
2013-08-30 13:00 - 2010-06-05 07:03 - 00000344 _____ C:\Windows\Tasks\Acer Registration Reminder.job
2013-08-30 12:35 - 2013-06-29 09:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-30 12:32 - 2010-03-06 20:31 - 01182366 _____ C:\Windows\WindowsUpdate.log
2013-08-30 12:12 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-30 12:12 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-30 11:28 - 2010-05-03 13:55 - 00000000 ___RD C:\Users\Frank\Desktop\Verknüpfungen
2013-08-30 11:23 - 2013-08-30 11:23 - 00049848 _____ C:\Users\Frank\Desktop\AdwCleaner[S0].txt
2013-08-30 11:22 - 2012-09-23 16:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-30 11:21 - 2013-08-30 11:20 - 00000000 ____D C:\AdwCleaner
2013-08-30 11:16 - 2013-08-30 11:16 - 01023533 _____ (Thisisu) C:\Users\Frank\Desktop\JRT.exe
2013-08-30 11:16 - 2013-08-30 11:16 - 00448512 _____ (OldTimer Tools) C:\Users\Frank\Desktop\TFC.exe
2013-08-30 11:15 - 2013-08-30 11:15 - 00994642 _____ C:\Users\Frank\Desktop\adwcleaner.exe
2013-08-30 10:18 - 2013-08-30 10:18 - 00029648 _____ C:\Users\Frank\Desktop\1FRST1.txt
2013-08-30 10:18 - 2013-08-30 10:18 - 00018939 _____ C:\Users\Frank\Desktop\2Addition1.txt
2013-08-30 10:17 - 2013-08-30 10:17 - 00000000 ____D C:\FRST
2013-08-30 10:15 - 2013-08-30 10:15 - 01579080 _____ (Farbar) C:\Users\Frank\Desktop\FRST64.exe
2013-08-30 09:03 - 2010-03-07 05:22 - 00654166 _____ C:\Windows\system32\perfh007.dat
2013-08-30 09:03 - 2010-03-07 05:22 - 00130006 _____ C:\Windows\system32\perfc007.dat
2013-08-30 09:03 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-30 08:40 - 2013-07-09 16:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-30 08:39 - 2013-08-30 08:39 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-08-30 08:39 - 2013-08-30 08:39 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-08-30 08:39 - 2010-01-16 05:56 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-08-30 08:36 - 2013-08-30 08:36 - 00000000 ____D C:\Users\Frank\AppData\Local\Secunia PSI
2013-08-30 08:35 - 2013-08-30 08:35 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-08-30 08:32 - 2013-08-30 08:32 - 00000000 ____D C:\Windows\Sun
2013-08-30 08:31 - 2013-08-30 08:31 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00000000 ____D C:\ProgramData\Sun
2013-08-30 08:30 - 2013-08-30 08:30 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-30 08:29 - 2013-08-30 08:29 - 00903080 _____ (Oracle Corporation) C:\Users\Frank\Downloads\JavaSetup7u25.exe
2013-08-30 08:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-30 07:03 - 2010-01-16 05:59 - 00779712 _____ C:\Windows\PFRO.log
2013-08-30 06:54 - 2013-08-30 06:54 - 00000000 ____D C:\Users\Frank\AppData\Roaming\SumatraPDF
2013-08-30 06:54 - 2013-08-30 06:54 - 00000000 ____D C:\Program Files (x86)\SumatraPDF
2013-08-30 06:46 - 2010-01-16 05:50 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-30 06:28 - 2010-05-03 13:53 - 00003922 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{36545382-2CEB-4C97-A122-8D258D63D623}
2013-08-28 17:08 - 2010-05-18 11:41 - 00000000 ____D C:\Users\Frank\AppData\Local\PokerStars.EU
2013-08-26 17:38 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-23 15:35 - 2013-06-29 09:47 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-23 15:35 - 2012-04-02 15:01 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-23 15:35 - 2011-06-18 07:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-23 15:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-14 17:18 - 2013-07-29 17:38 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 17:17 - 2010-05-06 18:53 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-30 08:04
==================== End Of Log ============================ --- --- ---
--- --- ---
FRST
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Frank (administrator) on 30-08-2013 13:24:16
Running from C:\Users\Frank\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9913376 2009-12-29] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [832544 2010-01-18] (Acer Incorporated)
HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [17398376 2010-01-25] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated)
MountPoints2: {d8b38a40-9381-11e0-9c0c-705ab63b216a} - E:\pushinst.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-24] (Intel Corporation)
HKLM-x32\...\Run: [EgisTecLiveUpdate] - C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-04] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-01-13] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1287760 2010-01-22] (Dritek System Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2009-12-24] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2009-12-24] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_5741g&r=27360510j345l04h4z1k5t44n2k91p
SearchScopes: HKLM - DefaultScope value is missing.
Handler: msdaipp - No CLSID Value -
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8te5n404.default
FF Homepage: hxxp://www.google.de/
FF Keyword.URL: chrome://browser-region/locale/region.properties
FF NetworkProxy: "backup.ftp", "178.217.14.33"
FF NetworkProxy: "backup.ftp_port", 9090
FF NetworkProxy: "backup.gopher", "212.91.180.250"
FF NetworkProxy: "backup.gopher_port", 8080
FF NetworkProxy: "backup.socks", "178.217.14.33"
FF NetworkProxy: "backup.socks_port", 9090
FF NetworkProxy: "backup.ssl", "178.217.14.33"
FF NetworkProxy: "backup.ssl_port", 9090
FF NetworkProxy: "ftp", "178.217.14.33"
FF NetworkProxy: "ftp_port", 9090
FF NetworkProxy: "gopher", "212.91.180.250"
FF NetworkProxy: "gopher_port", 8080
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "178.217.14.33"
FF NetworkProxy: "socks_port", 9090
FF NetworkProxy: "ssl", "178.217.14.33"
FF NetworkProxy: "ssl_port", 9090
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Frank\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG)
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
S3 gusvc; "C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe" [x]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-05-06] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-05-06] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-05-06] (Avira Operations GmbH & Co. KG)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-30 13:07 - 2013-08-30 13:07 - 00001285 _____ C:\Users\Frank\Desktop\JRT.txt
2013-08-30 13:03 - 2013-08-30 13:03 - 00000000 ____D C:\Windows\ERUNT
2013-08-30 11:23 - 2013-08-30 11:23 - 00049848 _____ C:\Users\Frank\Desktop\AdwCleaner[S0].txt
2013-08-30 11:20 - 2013-08-30 11:21 - 00000000 ____D C:\AdwCleaner
2013-08-30 11:16 - 2013-08-30 11:16 - 01023533 _____ (Thisisu) C:\Users\Frank\Desktop\JRT.exe
2013-08-30 11:16 - 2013-08-30 11:16 - 00448512 _____ (OldTimer Tools) C:\Users\Frank\Desktop\TFC.exe
2013-08-30 11:15 - 2013-08-30 11:15 - 00994642 _____ C:\Users\Frank\Desktop\adwcleaner.exe
2013-08-30 10:18 - 2013-08-30 10:18 - 00029648 _____ C:\Users\Frank\Desktop\1FRST1.txt
2013-08-30 10:18 - 2013-08-30 10:18 - 00018939 _____ C:\Users\Frank\Desktop\2Addition1.txt
2013-08-30 10:17 - 2013-08-30 10:17 - 00000000 ____D C:\FRST
2013-08-30 10:15 - 2013-08-30 10:15 - 01579080 _____ (Farbar) C:\Users\Frank\Desktop\FRST64.exe
2013-08-30 08:39 - 2013-08-30 08:39 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-08-30 08:39 - 2013-08-30 08:39 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-08-30 08:36 - 2013-08-30 08:36 - 00000000 ____D C:\Users\Frank\AppData\Local\Secunia PSI
2013-08-30 08:35 - 2013-08-30 08:35 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-08-30 08:32 - 2013-08-30 08:32 - 00000000 ____D C:\Windows\Sun
2013-08-30 08:31 - 2013-08-30 08:31 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00000000 ____D C:\ProgramData\Sun
2013-08-30 08:30 - 2013-08-30 08:30 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-30 08:29 - 2013-08-30 08:29 - 00903080 _____ (Oracle Corporation) C:\Users\Frank\Downloads\JavaSetup7u25.exe
2013-08-30 06:54 - 2013-08-30 06:54 - 00000000 ____D C:\Users\Frank\AppData\Roaming\SumatraPDF
2013-08-30 06:54 - 2013-08-30 06:54 - 00000000 ____D C:\Program Files (x86)\SumatraPDF
2013-08-14 17:24 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 17:24 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 17:24 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 17:24 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 17:24 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 17:24 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 17:24 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 17:24 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 17:24 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 17:24 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 17:24 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 17:23 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 17:23 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 17:23 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 17:23 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 17:23 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 17:23 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 17:23 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 17:23 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 17:15 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 17:15 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 17:15 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 17:15 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 17:15 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 17:15 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 17:15 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 17:15 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 17:15 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 17:15 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 17:15 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 17:15 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 17:15 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 17:15 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 17:15 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 17:15 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 17:15 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 17:15 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 17:15 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 17:15 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 17:15 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 17:15 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 17:15 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 17:15 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 17:15 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 17:14 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 17:14 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-08-30 13:23 - 2012-11-27 12:43 - 00023979 _____ C:\Windows\setupact.log
2013-08-30 13:23 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-30 13:07 - 2013-08-30 13:07 - 00001285 _____ C:\Users\Frank\Desktop\JRT.txt
2013-08-30 13:03 - 2013-08-30 13:03 - 00000000 ____D C:\Windows\ERUNT
2013-08-30 13:00 - 2010-06-05 07:03 - 00000344 _____ C:\Windows\Tasks\Acer Registration Reminder.job
2013-08-30 12:35 - 2013-06-29 09:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-30 12:32 - 2010-03-06 20:31 - 01182366 _____ C:\Windows\WindowsUpdate.log
2013-08-30 12:12 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-30 12:12 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-30 11:28 - 2010-05-03 13:55 - 00000000 ___RD C:\Users\Frank\Desktop\Verknüpfungen
2013-08-30 11:23 - 2013-08-30 11:23 - 00049848 _____ C:\Users\Frank\Desktop\AdwCleaner[S0].txt
2013-08-30 11:22 - 2012-09-23 16:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-30 11:21 - 2013-08-30 11:20 - 00000000 ____D C:\AdwCleaner
2013-08-30 11:16 - 2013-08-30 11:16 - 01023533 _____ (Thisisu) C:\Users\Frank\Desktop\JRT.exe
2013-08-30 11:16 - 2013-08-30 11:16 - 00448512 _____ (OldTimer Tools) C:\Users\Frank\Desktop\TFC.exe
2013-08-30 11:15 - 2013-08-30 11:15 - 00994642 _____ C:\Users\Frank\Desktop\adwcleaner.exe
2013-08-30 10:18 - 2013-08-30 10:18 - 00029648 _____ C:\Users\Frank\Desktop\1FRST1.txt
2013-08-30 10:18 - 2013-08-30 10:18 - 00018939 _____ C:\Users\Frank\Desktop\2Addition1.txt
2013-08-30 10:17 - 2013-08-30 10:17 - 00000000 ____D C:\FRST
2013-08-30 10:15 - 2013-08-30 10:15 - 01579080 _____ (Farbar) C:\Users\Frank\Desktop\FRST64.exe
2013-08-30 09:03 - 2010-03-07 05:22 - 00654166 _____ C:\Windows\system32\perfh007.dat
2013-08-30 09:03 - 2010-03-07 05:22 - 00130006 _____ C:\Windows\system32\perfc007.dat
2013-08-30 09:03 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-30 08:40 - 2013-07-09 16:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-30 08:39 - 2013-08-30 08:39 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-08-30 08:39 - 2013-08-30 08:39 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-08-30 08:39 - 2010-01-16 05:56 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-08-30 08:36 - 2013-08-30 08:36 - 00000000 ____D C:\Users\Frank\AppData\Local\Secunia PSI
2013-08-30 08:35 - 2013-08-30 08:35 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-08-30 08:32 - 2013-08-30 08:32 - 00000000 ____D C:\Windows\Sun
2013-08-30 08:31 - 2013-08-30 08:31 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-08-30 08:31 - 2013-08-30 08:31 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-08-30 08:31 - 2013-08-30 08:31 - 00000000 ____D C:\ProgramData\Sun
2013-08-30 08:30 - 2013-08-30 08:30 - 00000000 ____D C:\Program Files (x86)\Java
2013-08-30 08:29 - 2013-08-30 08:29 - 00903080 _____ (Oracle Corporation) C:\Users\Frank\Downloads\JavaSetup7u25.exe
2013-08-30 08:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-30 07:03 - 2010-01-16 05:59 - 00779712 _____ C:\Windows\PFRO.log
2013-08-30 06:54 - 2013-08-30 06:54 - 00000000 ____D C:\Users\Frank\AppData\Roaming\SumatraPDF
2013-08-30 06:54 - 2013-08-30 06:54 - 00000000 ____D C:\Program Files (x86)\SumatraPDF
2013-08-30 06:46 - 2010-01-16 05:50 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-30 06:28 - 2010-05-03 13:53 - 00003922 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{36545382-2CEB-4C97-A122-8D258D63D623}
2013-08-28 17:08 - 2010-05-18 11:41 - 00000000 ____D C:\Users\Frank\AppData\Local\PokerStars.EU
2013-08-26 17:38 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-23 15:35 - 2013-06-29 09:47 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-23 15:35 - 2012-04-02 15:01 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-23 15:35 - 2011-06-18 07:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-23 15:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-14 17:18 - 2013-07-29 17:38 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 17:17 - 2010-05-06 18:53 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-30 08:04
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- Code:
Getting user folders.
Stopping running processes.
Emptying Temp folders.
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Frank
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 128 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
Emptying RecycleBin. Do not interrupt.
RecycleBin emptied: 0 bytes
Process complete!
Total Files Cleaned = 0,00 mb --- --- --- |