Code:
Zoek.exe v5.0.0.0 Updated 21-09-2014
Tool run by Spieler on 23.09.2014 at 16:58:40,13.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Spieler.HeikeHarder-HP\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
23.09.2014 17:02:21 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{bd7c9b62-a7d9-4405-be51-7fd633f08791} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A0442EE1-D2E7-44C0-B4A5-8C4E6B035787} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A0442EE1-D2E7-44C0-B4A5-8C4E6B035787} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD8812D4-E5B8-41C6-94D4-59872A484BF1} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32B29DF0-2237-4370-9A29-37CEBB730E9B} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901108} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901108} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{bd7c9b62-a7d9-4405-be51-7fd633f08791} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bd7c9b62-a7d9-4405-be51-7fd633f08791} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411901108} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901108} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{164E93C4-09BF-4647-9E0B-D5FBB1D35E63} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{5CFCAFF6-5BB0-4864-B626-021C99ED82E5} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{26647CA4-A2A7-4EAC-8A72-761AA9141DE7} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{99079A25-328F-4BD4-BE04-00955ACAA0A7} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{9D717F81-9148-4F12-8568-69135F087DB0} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{A0442EE1-D2E7-44C0-B4A5-8C4E6B035787} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{CD8812D4-E5B8-41C6-94D4-59872A484BF1} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{32B29DF0-2237-4370-9A29-37CEBB730E9B} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{32B29DF0-2237-4370-9A29-37CEBB730E9B} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{77BEC163-D389-42c1-91A4-C758846296A5} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{F9639E4A-801B-4843-AEE3-03D9DA199E77} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\!{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\!{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{A0442EE1-D2E7-44C0-B4A5-8C4E6B035787} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\!{A0442EE1-D2E7-44C0-B4A5-8C4E6B035787} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\!{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\!{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\!{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{F9639E4A-801B-4843-AEE3-03D9DA199E77} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\!{F9639E4A-801B-4843-AEE3-03D9DA199E77} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\virtualKeyboard@kaspersky.ru deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\FFSodaPDFConverter2012@sodapdf.com deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaPlayerV1alpha718.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewerV1alpha1479.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha3700.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha9390.net deleted successfully
==== Deleting Services ======================
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater15.0.0 deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vToolbarUpdater15.0.0 deleted successfully
==== FireFox Fix ======================
ProfilePath: C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default
---- Lines BabylonToolbar removed from prefs.js ----
user_pref("extensions.BabylonToolbar.babExt", "");
user_pref("extensions.BabylonToolbar.babTrack", "affID=101365");
user_pref("extensions.BabylonToolbar.dfltSrch", true);
user_pref("extensions.BabylonToolbar.hmpg", false);
user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1720:37:12");
user_pref("extensions.BabylonToolbar.newTab", false);
user_pref("extensions.BabylonToolbar.smplGrp", "none");
user_pref("extensions.BabylonToolbar.srcExt", "ss");
user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1720:37:12");
user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=101365");
user_pref("extensions.BabylonToolbar_i.hardId", "ecc3245c0000000000006c626d9ce7a5");
user_pref("extensions.BabylonToolbar_i.id", "ecc3245c0000000000006c626d9ce7a5");
user_pref("extensions.BabylonToolbar_i.instlDay", "15391");
user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
user_pref("extensions.BabylonToolbar_i.newTab", false);
user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1720:37:12");
user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
---- Lines BabylonToolbar removed from user.js ----
user_pref("extensions.BabylonToolbar_i.id", "ecc3245c0000000000006c626d9ce7a5");
user_pref("extensions.BabylonToolbar_i.hardId", "ecc3245c0000000000006c626d9ce7a5");
user_pref("extensions.BabylonToolbar_i.instlDay", "15391");
user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1720:37:12");
user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
user_pref("extensions.BabylonToolbar_i.newTab", false);
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=101365");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
---- Lines Softonic removed from user.js ----
user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search settings, Click No to restore original settings");
user_pref("extensions.Softonic.autoRvrt", "false");
user_pref("extensions.Softonic_i.hmpg", true);
user_pref("extensions.Softonic_i.hmpgUrl", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=13&cc=");
user_pref("extensions.Softonic.hpOld", "hxxp://www.searchqu.com/406");
user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=13&cc=");
user_pref("extensions.Softonic_i.dfltSrch", true);
user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=2&cc=&q=");
user_pref("extensions.Softonic.dspOld", "Search Results");
user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)");
user_pref("extensions.Softonic_i.dnsErr", true);
user_pref("extensions.Softonic_i.newTab", true);
user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=15&cc=");
user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=1&cc=&q=");
user_pref("extensions.Softonic.id", "ecc3245c0000000000006c626d9ce7a5");
user_pref("extensions.Softonic.instlDay", "15440");
user_pref("extensions.Softonic.vrsn", "1.5.21.0");
user_pref("extensions.Softonic.vrsni", "1.5.21.0");
user_pref("extensions.Softonic_i.vrsnTs", "1.5.21.00:13:27");
user_pref("extensions.Softonic.prtnrId", "softonic");
user_pref("extensions.Softonic.prdct", "Softonic");
user_pref("extensions.Softonic.aflt", "SD");
user_pref("extensions.Softonic_i.smplGrp", "none");
user_pref("extensions.Softonic.tlbrId", "base");
user_pref("extensions.Softonic.instlRef", "MON00016");
user_pref("extensions.Softonic.dfltLng", "de");
user_pref("extensions.Softonic.excTlbr", false);
user_pref("extensions.Softonic.admin", false);
---- Lines y2layers removed from user.js ----
user_pref("extentions.y2layers.installId", "7e587973-110f-448c-ab39-76706f0febac");
---- FireFox user.js and prefs.js backups ----
user__1715_.backup
prefs__1715_.backup
ProfilePath: C:\Users\HEIKEH~1\AppData\Roaming\Thunderbird\Profiles\yfa13q6e.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1715_.backup
ProfilePath: C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default
---- Lines BabylonToolbar removed from prefs.js ----
user_pref("extensions.BabylonToolbar.pnu_base", "{\"newVrsn\":\"76\",\"lastVrsn\":\"76\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true
---- FireFox user.js and prefs.js backups ----
user__1715_.backup
prefs__1715_.backup
ProfilePath: C:\Users\SPIELE~1.HEI\AppData\Roaming\Thunderbird\Profiles\rvweewm9.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1715_.backup
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Opera\shell\open\command]
@="C:\\Program Files (x86)\\Opera\\Opera.exe"
==== Deleting Files \ Folders ======================
C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} not found
C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} not found
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\toolbar_AVIRA-V7@apn.ask.com.xpi not found
C:\Program Files (x86)\SuperLyrics\FF not found
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\ffxtlbr@funmoods.com not found
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi not found
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Packages\windows_ie_ac_001\AC\{8D29679C-9757-6367-1362-24EF70A8A6E5} deleted
C:\Users\Heike Harder\daemonprocess.txt deleted
C:\Users\Spieler.HeikeHarder-HP\daemonprocess.txt deleted
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\install.exe deleted
C:\found.000 deleted
C:\found.001 deleted
C:\Users\Heike Harder\AppData\Roaming\BrowserCompanion deleted
C:\Users\Heike Harder\AppData\Roaming\Babylon deleted
C:\Users\Heike Harder\AppData\Roaming\GetRightToGo deleted
C:\Users\Heike Harder\AppData\Roaming\Systweak deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Uniblue deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\0F1F1C2Y1H1P1C0I0T deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\aps.uninstall.scan.results deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\systweak deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\OpenCandy deleted
C:\Users\Heike Harder\AppData\Local\AVG Secure Search deleted
C:\Users\Heike Harder\AppData\Local\blekkotb_020 deleted
C:\Users\Heike Harder\AppData\Local\PackageAware deleted
C:\Users\Heike Harder\AppData\Local\Babylon deleted
C:\Users\Heike Harder\AppData\Local\Conduit deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\nspA788.tmp deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\nszD8AD.tmp deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\newplayer deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\LPT deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\AVG Secure Search deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\blekkotb_020 deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\cache deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\PackageAware deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Smartbar deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\conduit deleted
C:\Users\wangzhisong\AppData\Local\Mobogenie deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Uncompressor deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\Public\CommonRTP.exe deleted
C:\Users\Spieler.HeikeHarder-HP\Downloads\FreeYouTubeToMP3Converter (1).exe deleted
C:\Users\Spieler.HeikeHarder-HP\Downloads\FreeYouTubeToMP3Converter.exe deleted
C:\Users\Spieler.HeikeHarder-HP\Downloads\SoftonicDownloader_fuer_minecraft-forge.exe deleted
C:\Users\Heike Harder\AppData\LocalLow\bbrs_002.tb deleted
C:\Users\Heike Harder\AppData\LocalLow\DVDVideoSoftTB deleted
C:\Users\Heike Harder\AppData\LocalLow\searchresultstb deleted
C:\Users\Heike Harder\AppData\LocalLow\SweetIM deleted
C:\Users\Heike Harder\AppData\LocalLow\AVG Secure Search deleted
C:\Users\Heike Harder\AppData\LocalLow\BabylonToolbar deleted
C:\Users\Heike Harder\AppData\LocalLow\dvdvideosofttoolbar deleted
C:\Users\Heike Harder\AppData\LocalLow\searchqutoolbar deleted
C:\Users\Heike Harder\AppData\LocalLow\searchquband deleted
C:\Users\Heike Harder\AppData\LocalLow\facemoods.com deleted
C:\Users\Heike Harder\AppData\LocalLow\Funmoods deleted
C:\Users\Heike Harder\AppData\LocalLow\Softonic deleted
C:\Users\Heike Harder\AppData\LocalLow\DataMngr deleted
C:\Users\Heike Harder\AppData\LocalLow\Incredibar.com deleted
C:\Users\Heike Harder\AppData\LocalLow\PriceGong deleted
C:\Users\Heike Harder\AppData\LocalLow\Conduit deleted
C:\Users\Heike Harder\AppData\LocalLow\ConduitEngine deleted
C:\Users\Heike Harder\AppData\LocalLow\Toolbar4 deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\LocalLow\AskToolbar deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\LocalLow\dvdvideosofttoolbar deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\LocalLow\wincorebsband deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\LocalLow\mediabarbs deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\LocalLow\Softonic_Deutsch deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\LocalLow\Smartbar deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\bbrs_002.tb deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\DVDVideoSoftTB deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\searchresultstb deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\blekkotb_019 deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\blekkotb_020 deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\dvdvideosofttoolbar deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\searchqutoolbar deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\searchquband deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Funmoods deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Softonic deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Incredibar.com deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\PriceGong deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Conduit deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Toolbar4 deleted
C:\windows\SysNative\tasks\Feven 2.5-chromeinstaller deleted
C:\windows\SysNative\tasks\Feven 2.5-codedownloader deleted
C:\windows\SysNative\tasks\Feven 2.5-enabler deleted
C:\windows\SysNative\tasks\Feven 2.5-firefoxinstaller deleted
C:\windows\SysNative\tasks\Feven 2.5-updater deleted
C:\Windows\tasks\Feven 2.5-chromeinstaller.job deleted
C:\Windows\tasks\Feven 2.5-codedownloader.job deleted
C:\Windows\tasks\Feven 2.5-enabler.job deleted
C:\Windows\tasks\Feven 2.5-firefoxinstaller.job deleted
C:\Windows\tasks\Feven 2.5-updater.job deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Users\wangzhisong deleted
C:\Windows\Syswow64\sho22A4.tmp deleted
C:\Windows\Syswow64\sho664.tmp deleted
C:\Windows\Syswow64\sho7B13.tmp deleted
C:\Windows\Syswow64\InstallUtil.InstallLog deleted
C:\Windows\SysWow64\Extensions deleted
C:\Users\Heike Harder\Documents\Updater deleted
C:\Users\Spieler.HeikeHarder-HP\Documents\Mobogenie deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\searchplugins\askcom.xml deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\searchplugins\search-results.xml deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\searchplugins\SearchResults.xml deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\searchplugins\Search_Results.xml deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\ffxtlbr@babylon.com deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\bprotector_extensions.rdf deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\bProtector_extensions.sqlite deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\dvdvideosofttoolbar deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\SweetIMToolbarData deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\staged deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\CT2269050 deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\CT2704262 deleted
C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\CT2319825 deleted
C:\Users\Spieler.HeikeHarder-HP\Desktop\Search.lnk deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\4433da5b-eb52-495d-8865-b2a7468567f6@927544a3-fdfb-4485-a78b-21e1113eee35.com deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\crossriderapp2258@crossrider.com deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{32b29df0-2237-4370-9a29-37cebb730e9b} deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{cd8812d4-e5b8-41c6-94d4-59872a484bf1} deleted
C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com deleted
C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\4433da5b-eb52-495d-8865-b2a7468567f6@927544a3-fdfb-4485-a78b-21e1113eee35.com deleted
C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\crossriderapp2258@crossrider.com deleted
C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\jid0-O6MIff3eO5dIGf5Tcv8RsJDKxrs@jetpack deleted
C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\lvgnow@dnhktwg.co.uk deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\ffxtlbra@softonic.com deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\conduitCommon deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\ffox@bandoo.com deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\toolbar@ask.com deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\plugin@yontoo.com deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} deleted
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\bbrs_002@blabbers.com deleted
"C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\searchplugins\softonic.xml" deleted
"C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\searchplugins\conduit.xml" deleted
"C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\searchplugins\sweetim.xml" deleted
"C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}" deleted
"C:\PROGRA~2\TermTutor\Service\ttsvc.exe" deleted
"C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\ap_logs" deleted
"C:\PROGRA~2\TermTutor" not deleted
"C:\PROGRA~2\TermTutor\Service" not deleted
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\SPIELE~1.HEI\AppData\Local\Temp ====
2014-09-23 13:03:55 4E566FEA83FCEEAF2873702806B55006 43008 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpccntno.dll
2014-09-23 12:53:07 26EE807E54B8C30D215A4E039B160651 40960 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\is45637729\308276872_stp.EXE
2014-09-23 10:35:26 89B461FBDD425AAC0FF7C763925AD71B 173481 ------w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\is45637729\308276442_stp\Generic_vo.exe
2014-09-21 18:47:06 D6C776643BD04F945A821F96271E1EEF 86528 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\ttap2.dll
2014-09-21 18:47:06 8C1144BC03FFA0E57FB9263CC473F052 98304 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\ttap2.exe
2014-09-21 18:47:06 18AA44B12D0A65A7B00C6714BBA1EBB8 408576 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\uoEK5.exe
2014-09-21 18:35:28 1AC42FF41023CE239929989FC4CFB96B 2270880 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\n5414\WIE_2.14.1.82.exe
2014-09-21 18:35:24 75171125AE047C62724A13E5782BF8A0 74675720 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\tmd_34015938.exe
2014-09-21 18:35:20 A234FB2C87F1C72A2C7416B01313D632 2099173 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\n5414\FLVMPlayerSetup.exe
2014-09-21 18:34:44 9D4AC4ABB121001E753AC334ABD87EB6 285209 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\n5414\VOPackage.exe
2014-09-21 18:34:12 0E88682AEBA4D7EF923B316F97F990BA 347552 ----atw- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\n5414\s5414.exe
2014-09-21 18:32:10 75171125AE047C62724A13E5782BF8A0 74675720 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\tmd_34015466.exe
2014-09-21 16:48:40 ACE58E99A13BB9E34A9095F7EAC106AC 173663 ------w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\is45637729\159752500_stp\Generic_vo.exe
2014-09-21 15:17:12 CD7F6178B6AB601F566961570802A0C2 173330 ------w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\is45637729\156681032_stp\Generic_vo.exe
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2014-09-23 12:56:33 0DC5AF80D059DEC792B665ED598C6567 536576 ----a-w- C:\Windows\SysWOW64\sqlite3.dll
2014-09-11 01:15:47 E3D7B3F64C30994409BDF8E48048A854 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 01:15:47 6DD476318F524D2DCB73AFEB2EE27B4A 61952 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 01:15:47 297EF1AB73B8FCE76BCA1365C2E49AFC 440320 ----a-w- C:\Windows\SysWOW64\ieui.dll
2014-09-11 01:15:46 CC8F34B345DA638D77BB48C035DA628D 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll
2014-09-11 01:15:46 84E96F4AF8A7748A3DE7C3EBBC6768E5 365056 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 01:15:46 4F2EDC301EC63F803C0FDB6CC87EDA24 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll
2014-09-11 01:15:46 42F6F28D4885505F687CAF0459FF9F90 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 01:15:46 010DFAF3EF93994B805BAA1493D47973 243200 ----a-w- C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 01:15:45 D603AC77E17E5B9583E382F2EE0381A7 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 01:15:45 AA595171932ACC79DA9851067DCBDABF 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll
2014-09-11 01:15:45 8D4FCAB2643DFEF68040B70F1EDCCBC5 327872 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 01:15:45 7C3D593AB1E2F5E5687D97772EF99AC7 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll
2014-09-11 01:15:45 13C2C87C35E52AAB1B439FB2E26DF2DE 69632 ----a-w- C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 01:15:45 074646C5A979DE79133DE4A8530A9C5D 603136 ----a-w- C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 01:15:44 77F79126444896B5867E6761490735B8 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 01:15:44 2E2E40E5D92EEA979548E307C5781038 597504 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 01:15:43 88EBB8526981D03C5777AB0A4AEBA8B4 1068032 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 01:15:43 5074835337862817DB3726558D0908DE 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 01:15:43 1D8C086A39B9794D7131384586811B25 678400 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 01:15:41 FD96C05DE700F5FD26273D6DDB6495A7 2185728 ----a-w- C:\Windows\SysWOW64\iertutil.dll
2014-09-11 01:15:40 D58988722C72D265B51A54103DFC2C6F 1812992 ----a-w- C:\Windows\SysWOW64\wininet.dll
2014-09-11 01:15:40 77B7DDF91F3ED2CDB6CF60224EE13433 4232704 ----a-w- C:\Windows\SysWOW64\jscript9.dll
2014-09-11 01:15:39 6A3A809CA7A8F40C89E6F1D301898A66 2014208 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 01:15:39 41010A88B70A2168F801DC19EBD4CB4F 1190400 ----a-w- C:\Windows\SysWOW64\urlmon.dll
2014-09-11 01:15:38 7BF1CE9240CB9DD27C3E30733176EB8E 17455104 ----a-w- C:\Windows\SysWOW64\mshtml.dll
2014-09-11 01:15:37 A3560FAFC1686D5EE9830B33B5C74B66 11769856 ----a-w- C:\Windows\SysWOW64\ieframe.dll
2014-09-11 01:02:47 2413D2216D08FAF7D7178D9E0B481AEB 2285056 ----a-w- C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-10 07:39:48 A8DDB7ACB122FC36FF0D7C9B3099A380 793600 ----a-w- C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-10 06:34:25 B094390B6B2D0456821384771020870B 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll
2014-09-10 06:34:25 1B85FA0D0A93C011B76678733F39DB6C 550912 ----a-w- C:\Windows\SysWOW64\kerberos.dll
2014-09-10 06:34:25 10826DA2FC073702AEAB93AF3D73B066 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll
2014-09-10 05:37:41 79896A78039C9A63C56197843CFBAD0B 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2014-09-11 01:15:48 9EFF09364ABDC86770FA0B1BCC9CA3C3 596480 ----a-w- C:\Windows\Sysnative\ieui.dll
2014-09-11 01:15:47 EF79F0B9E0F277F5797C475DF4248B97 83968 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll
2014-09-11 01:15:47 A0600300428AB73664050659E738F11F 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll
2014-09-11 01:15:47 1BE1D1942825BE2146941DA274D2B92F 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb
2014-09-11 01:15:46 EE6B22396FA99639A163B1B7E9736669 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll
2014-09-11 01:15:46 786ECD92C9D77F571134283E0FABAF1A 289280 ----a-w- C:\Windows\Sysnative\dxtrans.dll
2014-09-11 01:15:46 641068C626DE3AD348871D0D7931A3FA 547328 ----a-w- C:\Windows\Sysnative\vbscript.dll
2014-09-11 01:15:46 4CF33E458BAEDA917CAE9F2E8338479C 446464 ----a-w- C:\Windows\Sysnative\dxtmsft.dll
2014-09-11 01:15:46 305D5395A65D00C74A94AEA40E9909E9 758272 ----a-w- C:\Windows\Sysnative\jscript9diag.dll
2014-09-11 01:15:46 2D95BDB699FA1D531B642EA18464FE05 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe
2014-09-11 01:15:46 0113777A28BEC88A50C2566F346E4B58 72704 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll
2014-09-11 01:15:45 E76C23C71345ACBC65ED8F6E87AD01D1 195584 ----a-w- C:\Windows\Sysnative\msrating.dll
2014-09-11 01:15:45 C07D636B0237172345E68AE8B70A2984 51200 ----a-w- C:\Windows\Sysnative\jsproxy.dll
2014-09-11 01:15:45 C067D863FCD53B91A5BF78AE1CE88E54 85504 ----a-w- C:\Windows\Sysnative\mshtmled.dll
2014-09-11 01:15:45 A1BB4CFB25F7CE1D4F67DD71111823AA 374968 ----a-w- C:\Windows\Sysnative\iedkcs32.dll
2014-09-11 01:15:45 68B0077C0D09D1B669A260F2921FD6B9 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll
2014-09-11 01:15:45 33BAC6F66DB5FE5F7E20D41B025F490E 707072 ----a-w- C:\Windows\Sysnative\ie4uinit.exe
2014-09-11 01:15:45 2AEFBA4339A34C8EF021B49D23D1F1DF 727040 ----a-w- C:\Windows\Sysnative\msfeeds.dll
2014-09-11 01:15:44 920BD93A0B64657A20CA66C2EBB167EA 23591424 ----a-w- C:\Windows\Sysnative\mshtml.dll
2014-09-11 01:15:43 698C19E198F832E071778A1427E942C8 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe
2014-09-11 01:15:43 5A0C72B9D3CCA42D8AB74890C19443B2 940032 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe
2014-09-11 01:15:43 4C8838D7C13E9080AF4B548CA791896B 1249280 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll
2014-09-11 01:15:43 227303FC6E95547EA274F4337BBC7278 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll
2014-09-11 01:15:43 1439630B47D717960D59423958754394 775168 ----a-w- C:\Windows\Sysnative\ieapfltr.dll
2014-09-11 01:15:41 75498A52C2AE248DEE5BDF5209768963 2793984 ----a-w- C:\Windows\Sysnative\iertutil.dll
2014-09-11 01:15:40 F6304AACC5744016770C8C797CAA2AF7 5833728 ----a-w- C:\Windows\Sysnative\jscript9.dll
2014-09-11 01:15:40 39EBB9708453036A74C30C9A294023FF 2310656 ----a-w- C:\Windows\Sysnative\wininet.dll
2014-09-11 01:15:39 FECA80905D551074E1A9298BD98103B7 1447424 ----a-w- C:\Windows\Sysnative\urlmon.dll
2014-09-11 01:15:39 97752927B6E2401011A96E0D6082E403 2104832 ----a-w- C:\Windows\Sysnative\inetcpl.cpl
2014-09-11 01:15:37 BA56C68CCB912C4C08C97DD32C47AD31 13588480 ----a-w- C:\Windows\Sysnative\ieframe.dll
2014-09-11 01:02:47 3469B9FAE899139FEE7356E91693376A 2777088 ----a-w- C:\Windows\Sysnative\msmpeg2vdec.dll
2014-09-10 07:39:48 EFF3FF9D9E5BFD2A05390D959A1C3AD0 1031168 ----a-w- C:\Windows\Sysnative\TSWorkspace.dll
2014-09-10 06:34:25 EE4B105F1DBE1E864AFC72E7F0315432 1460736 ----a-w- C:\Windows\Sysnative\lsasrv.dll
2014-09-10 06:34:25 33EF550DCCC58C93F5B65FD75BAD9832 728064 ----a-w- C:\Windows\Sysnative\kerberos.dll
2014-09-10 05:37:41 224C2EEBAAF39CD93DE5332DBE5E5A95 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll
2014-09-10 05:14:22 E2BCB58869598B392D6A78953F61A2D9 578048 ----a-w- C:\Windows\Sysnative\aepdu.dll
2014-09-10 05:14:21 88BC88D0BDFB6BBE5765D5ABB233C110 424448 ----a-w- C:\Windows\Sysnative\aeinv.dll
====== C:\Windows\Sysnative\drivers =====
2014-09-23 14:21:22 8A50D5304E6AE48664CF5838EC32F647 122584 ----a-w- C:\Windows\Sysnative\drivers\MBAMSwissArmy.sys
2014-09-23 14:21:07 F92B0E478C0FAA6D6661E6E977247E60 25816 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys
2014-09-23 14:21:07 9D9ED48F841EA37AA5310D54B9E5D3C7 91352 ----a-w- C:\Windows\Sysnative\drivers\mbamchameleon.sys
2014-09-23 14:21:07 15E8ABC06843672955CE26A009533BAD 63704 ----a-w- C:\Windows\Sysnative\drivers\mwac.sys
2014-09-21 18:47:10 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_Kernel_webinstr_01009.Wdf
2014-09-04 17:22:34 4501E093B242532C5B677DC52614D6EB 58232 ----a-w- C:\Windows\Sysnative\drivers\ttnfd.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-09-23 12:53:21 -------- d-----w- C:\Program Files\TermTutor
======= C:\PROGRA~2 =====
2014-09-23 12:53:19 -------- d-----w- C:\PROGRA~2\TermTutor
2014-09-21 18:49:09 -------- d-----w- C:\PROGRA~2\DVDVideoSoft
======= C: =====
====== C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming ======
2014-09-21 18:48:00 -------- d-----w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
2014-09-21 18:47:59 -------- d-----w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\InetStat
2014-09-21 18:47:49 -------- d-----w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\LookThisUp
2014-08-28 11:41:54 -------- d-----w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperCam 2
====== C:\Users\Spieler.HeikeHarder-HP ======
2014-09-23 14:20:30 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\mbam-setup-2.0.2.1012 (3).exe
2014-09-23 12:55:15 1B151CCE618BE06C22B55FD4B502B75E 1373475 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\AdwCleaner_3.310.exe
2014-09-23 12:21:28 3898339E870EDE8F50036C6E463198A4 2105856 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\FRST64.exe
2014-09-23 11:15:36 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-09-23 11:15:07 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-09-21 18:49:41 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-09-21 18:41:06 75171125AE047C62724A13E5782BF8A0 74675720 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\FreeStudio.exe
====== C: exe-files ==
2014-09-23 14:20:30 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\mbam-setup-2.0.2.1012 (3).exe
2014-09-23 13:03:10 9DF4EB707D8FA2C6F93C08C435E39CEF 48521944 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Raptr\raptr-4.1.0-r86354-release.exe
2014-09-23 12:55:15 1B151CCE618BE06C22B55FD4B502B75E 1373475 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\AdwCleaner_3.310.exe
2014-09-23 12:53:07 26EE807E54B8C30D215A4E039B160651 40960 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\is45637729\308276872_stp.EXE
2014-09-23 12:52:45 612F9A64E1C050345825131AEFB0A5E8 592353 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLQ455BR\Setup[1].exe
2014-09-23 12:21:28 3898339E870EDE8F50036C6E463198A4 2105856 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\FRST64.exe
2014-09-23 11:15:36 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-09-23 11:15:07 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-09-23 11:07:32 4C8C0B0340C6234649C7F91FB5E89A54 571272 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\recovery\101.3.21.141\ChromeRecovery.exe
2014-09-23 11:07:31 984CC93BB0EF86A0B4825269D8379D81 774424 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\recovery\101.3.21.141\GoogleUpdateSetup.exe
2014-09-23 10:35:26 89B461FBDD425AAC0FF7C763925AD71B 173481 ------w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\is45637729\308276442_stp\Generic_vo.exe
2014-09-22 12:13:54 2941120388D052BFB27F8EC78EDA9F54 150214592 ----a-w- C:\ProgramData\Overwolf\Setup\0.80.20.0\OverwolfSetup.exe
2014-09-21 18:49:40 B2D5EE8DAB72DFEB5A68A9317F04A3EE 2796544 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Instagram Download\FreeInstagramDownload.exe
2014-09-21 18:49:39 A7B188FE47718D4B5766EA331DBBDE75 2786472 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Dailymotion Download\FreeDailymotionDownload.exe
2014-09-21 18:49:39 A76489AE142B61E7F3233AE6928B6171 1489576 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Video to DVD Converter\FreeDVDVideoBurner.exe
2014-09-21 18:49:39 A76489AE142B61E7F3233AE6928B6171 1489576 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free DVD Video Burner\FreeDVDVideoBurner.exe
2014-09-21 18:49:38 B12129ED81350F7AEE5B25DC544A479D 7969960 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Image Convert And Resize\FreeImageConvertAndResize.exe
2014-09-21 18:49:37 E870F7828E24A1474E2617610ECB7FF7 1777320 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Screen Video Recorder\FreeScreenVideoRecorder.exe
2014-09-21 18:49:37 CD8956CD7703B6E230FAB7683CAFAD22 6050472 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe
2014-09-21 18:49:37 838E0690A62236F93ED11FC184F116FC 1958568 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Uploader for Facebook\FreeUploaderForFacebook.exe
2014-09-21 18:49:37 375E8A8366DFE6E9B45095B49FEE1422 574120 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Uploader for Facebook\FreeUploaderForFacebookStub.exe
2014-09-21 18:49:34 4D76C8C5A3B975B5E8E0631AC6390943 2398720 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free YouTube Uploader\FreeYouTubeUploader.exe
2014-09-21 18:49:33 CAFB615041C9A98BFC14BBA98859BD2F 1588736 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Video Flip and Rotate\FreeVideoFlipAndRotate.exe
2014-09-21 18:49:33 C8C5E771F703D548AE6016336E397380 1768616 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free DVD Video Converter\FreeDVDVideoConverter.exe
2014-09-21 18:49:32 E27BF18FE2FA3825E8096742570BC15B 874664 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Audio Editor\FreeAudioEditor.exe
2014-09-21 18:49:32 2343BBA26FCA6DAF16B0C384803A9AE8 901800 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Video Editor\FreeVideoEditor.exe
2014-09-21 18:49:31 D2D6C75BA62099C936B2EEDBDEC508A3 85672 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free YouTube to DVD Converter\ytgroovlc.exe
2014-09-21 18:49:31 ABEE199287E4756C207A7073A905A9D9 85672 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\ytgroovlc.exe
2014-09-21 18:49:31 9992E0234E390B8C7CA13B3BF4E06AD6 2790568 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free YouTube to DVD Converter\FreeYouTubeToDVDConverter.exe
2014-09-21 18:49:30 A6BA764B254EABD910CAFD8B4A099C95 85672 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free YouTube Download\ytgroovlc.exe
2014-09-21 18:49:30 863E08B68F2413035BBBC11911D21265 2785960 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe
2014-09-21 18:49:29 3C502FA97C0DB042AAEF1832FA0BEC4B 2783400 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe
2014-09-21 18:49:29 099736B65B312C83180535CAF806D4EF 2280448 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Video to MP3 Converter\FreeVideoToMP3Converter.exe
2014-09-21 18:49:29 099736B65B312C83180535CAF806D4EF 2280448 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Video to JPG Converter\FreeVideoToJPGConverter.exe
2014-09-21 18:49:29 099736B65B312C83180535CAF806D4EF 2280448 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Video to DVD Converter\FreeVideoToDVDConverter.exe
2014-09-21 18:49:29 099736B65B312C83180535CAF806D4EF 2280448 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free MP4 Video Converter\FreeMP4VideoConverter.exe
2014-09-21 18:49:29 099736B65B312C83180535CAF806D4EF 2280448 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Audio Converter\FreeAudioConverter.exe
2014-09-21 18:49:26 8835B57F7E822F586B9404792D346BFD 112296 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\facebook_auth.exe
2014-09-21 18:49:25 F378DDD2C53ACB621CDBAAB6739D535D 19393395 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free DVD Video Converter\HandBrakeCLI.exe
2014-09-21 18:49:24 8B89DBE1A968EAA3A4918333C76CB29C 541600 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\dvdauthor.exe
2014-09-21 18:49:24 4CD5DB20E5CC3C0C2CA1D7237E2FED4E 285184 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Video Flip and Rotate\ffmpeg.exe
2014-09-21 18:49:24 0E42A6F5616BB6D755628FE17F4D2599 406072 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\spumux.exe
2014-09-21 18:49:24 04F0EBD84546546E1EFCF50B34F26E95 319144 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free YouTube Uploader\ffmpeg.exe
2014-09-21 18:49:22 04F0EBD84546546E1EFCF50B34F26E95 319144 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Video Editor\ffmpeg.exe
2014-09-21 18:49:22 04F0EBD84546546E1EFCF50B34F26E95 319144 ----a-w- C:\Program Files (x86)\DVDVideoSoft\Free Audio Editor\ffmpeg.exe
2014-09-21 18:49:19 C21E3E21923419EC1495B11F9E08F75A 186536 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\updhelper.exe
2014-09-21 18:49:16 4BD42E764A7DBF39348A01A18FBD0CC1 359080 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\Uninstall.exe
2014-09-21 18:49:11 2B5C5346B4BC8AFA7383DC3076D67BDA 523944 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\FreeStudioManager.exe
2014-09-21 18:49:11 04F0EBD84546546E1EFCF50B34F26E95 319144 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\ffmpeg.exe
2014-09-21 18:49:09 6BB10735FB90613EDB503945DB9F3375 1174520 ----a-w- C:\Program Files (x86)\DVDVideoSoft\unins000.exe
2014-09-21 18:48:00 43A792989D6E34C307068F09A04E95FD 700430 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\InetStat\inetstat.exe
2014-09-21 18:47:54 CF5F4FFBEA3BF2A667AAA66BB7946B49 206480 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\LookThisUp\LookThisUpUninstall.exe
2014-09-21 18:47:50 3F48839ED5C8EF49DEE94ED82A2AE97F 1848976 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\LookThisUp\LookThisUp.exe
2014-09-21 18:47:06 8C1144BC03FFA0E57FB9263CC473F052 98304 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\ttap2.exe
2014-09-21 18:47:06 18AA44B12D0A65A7B00C6714BBA1EBB8 408576 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\uoEK5.exe
2014-09-21 18:41:06 75171125AE047C62724A13E5782BF8A0 74675720 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\FreeStudio.exe
2014-09-21 18:35:28 1AC42FF41023CE239929989FC4CFB96B 2270880 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\n5414\WIE_2.14.1.82.exe
2014-09-21 18:35:24 75171125AE047C62724A13E5782BF8A0 74675720 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\tmd_34015938.exe
2014-09-21 18:35:20 A234FB2C87F1C72A2C7416B01313D632 2099173 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\n5414\FLVMPlayerSetup.exe
2014-09-21 18:34:44 9D4AC4ABB121001E753AC334ABD87EB6 285209 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\n5414\VOPackage.exe
2014-09-21 18:34:12 0E88682AEBA4D7EF923B316F97F990BA 347552 ----atw- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\n5414\s5414.exe
2014-09-21 18:32:10 75171125AE047C62724A13E5782BF8A0 74675720 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\tmd_34015466.exe
2014-09-21 16:48:40 ACE58E99A13BB9E34A9095F7EAC106AC 173663 ------w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\is45637729\159752500_stp\Generic_vo.exe
2014-09-21 15:17:12 CD7F6178B6AB601F566961570802A0C2 173330 ------w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp\is45637729\156681032_stp\Generic_vo.exe
2014-09-21 08:59:30 2BCE940645009F66760BAFD979AD1488 111168 ----a-w- C:\Program Files (x86)\Overwolf\OWUninstaller.exe
2014-09-21 08:59:28 67FF06D9E8049C398F1970AD9A6686A6 54048 ----a-w- C:\Program Files (x86)\Overwolf\0.80.20.0\OverwolfCrashHandler.exe
2014-09-21 08:59:28 1B5D06E953620CB844A9337DCC855218 74528 ----a-w- C:\Program Files (x86)\Overwolf\0.80.20.0\OverwolfBrowser.exe
2014-09-21 08:59:26 F7B3E91854DE6B39FFB21204840033A2 54048 ----a-w- C:\Program Files (x86)\Common Files\Overwolf\0.80.20.0\OverwolfHelper.exe
2014-09-21 08:59:26 E7ED1EF09C668A99714998F535F12A87 87840 ----a-w- C:\Program Files (x86)\Common Files\Overwolf\0.80.20.0\OverwolfHelper64.exe
2014-09-21 08:59:26 7497B153228715C9BB65A086BB297E45 181536 ----a-w- C:\Program Files (x86)\Overwolf\0.80.20.0\Purplizer\Purplizer.exe
2014-09-21 08:59:26 525BCBD5BC2365FDD438FE389D896A55 39712 ----a-w- C:\Program Files (x86)\Overwolf\Overwolf.exe
2014-09-21 08:59:24 419B46AEF57049CAB061E39F06BE4C5E 998176 ----a-w- C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
2014-09-21 08:59:24 352BD8B0AF75FBC0287F06A0FDE65EFA 66336 ----a-w- C:\Program Files (x86)\Overwolf\0.80.20.0\OWCleanup.exe
2014-09-21 08:59:24 28A1DC17AF38BCD336D219E00701B77C 519456 ----a-w- C:\Program Files (x86)\Overwolf\0.80.20.0\OWUninstallMenu.exe
2014-09-21 08:57:12 74C2E79D7B2AEA127725301C474690F2 1356544 ----a-w- C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe
2014-09-21 08:57:12 3943CCFD25474EFDB59D5851CA501F24 439552 ----a-w- C:\Program Files (x86)\Overwolf\0.80.20.0\OverwolfTSHelper.exe
2014-09-21 08:57:10 FE5C1F193F36449F154A1A7AE99E565E 531712 ----a-w- C:\Program Files (x86)\Overwolf\0.80.20.0\OverwolfOverlayHelper.exe
2014-09-20 22:00:05 C55A40E86096B2C417D21D38A933175F 267264 ----a-r- C:\Program Files (x86)\Glyph\Games\ArcheAge\Live\bin32\hshield\Update\autoup.exe
2014-09-20 22:00:05 C55A40E86096B2C417D21D38A933175F 267264 ----a-r- C:\ArcheAge\Working\bin32\hshield\Update\autoup.exe
2014-09-20 17:54:30 7BE039B2BFD4099FEA12FC23A2349B8E 717665 ----a-w- C:\Program Files (x86)\Klebezettel NG\unins000.exe
2014-09-20 17:54:09 EB1D4248589AE34D078A9C8371099943 3542792 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\KlebezettelNG\LiveUpdate\klebe.exe
2014-09-18 12:13:59 DCEBC24BBA306D6E04FA067CC950BD2E 150214080 ----a-w- C:\ProgramData\Overwolf\Setup\0.80.13.0\OverwolfSetup.exe
2014-09-17 18:46:20 663540F61B79B50495531C31656A866D 54048 ----a-w- C:\Program Files (x86)\Overwolf\0.80.13.0\OverwolfCrashHandler.exe
2014-09-17 18:46:18 A62C2674344A0FAE9991A6311919D0C9 87840 ----a-w- C:\Program Files (x86)\Common Files\Overwolf\0.80.13.0\OverwolfHelper64.exe
2014-09-17 18:46:18 3705C69743C01DA801628D2858EA49EE 54048 ----a-w- C:\Program Files (x86)\Common Files\Overwolf\0.80.13.0\OverwolfHelper.exe
2014-09-17 18:46:18 257B5239EABDFEC0D82681640371FA67 74528 ----a-w- C:\Program Files (x86)\Overwolf\0.80.13.0\OverwolfBrowser.exe
2014-09-17 18:46:16 E716B56581330F94CF912766DA7E4C16 66336 ----a-w- C:\Program Files (x86)\Overwolf\0.80.13.0\OWCleanup.exe
2014-09-17 18:46:16 375D09AFE4564ED60A5BC62DC46EE1D2 519456 ----a-w- C:\Program Files (x86)\Overwolf\0.80.13.0\OWUninstallMenu.exe
2014-09-17 18:46:16 10301A84C688D06F7CBB5308B0F73E93 181536 ----a-w- C:\Program Files (x86)\Overwolf\0.80.13.0\Purplizer\Purplizer.exe
2014-09-17 18:44:02 3943CCFD25474EFDB59D5851CA501F24 439552 ----a-w- C:\Program Files (x86)\Overwolf\0.80.13.0\OverwolfTSHelper.exe
2014-09-17 18:44:00 FE5C1F193F36449F154A1A7AE99E565E 531712 ----a-w- C:\Program Files (x86)\Overwolf\0.80.13.0\OverwolfOverlayHelper.exe
2014-09-17 17:05:26 9238F082257E2A7CC7BA92DAE489880E 1208295 ----a-w- C:\Program Files (x86)\Action Replay PowerSaves 3DS\unins000.exe
2014-09-17 17:05:11 AC06EB6C9E952E93A770799E0DD66C26 3894853 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Desktop\powersave\powersaves_setup_v1.21.exe
2014-09-17 08:31:53 F955D214F78F7DE28977F35F9D947348 48069240 ----a-w- C:\Program Files (x86)\Opera\24.0.1558.61\opera.exe
2014-09-17 08:31:53 E4C77B94735CE5C0636C657D6255E381 3180152 ----a-w- C:\Program Files (x86)\Opera\24.0.1558.61\opera_autoupdate.exe
2014-09-17 08:31:53 A2BD280F1EF5A3E8B6AB36412FEFC2A8 73336 ----a-w- C:\Program Files (x86)\Opera\24.0.1558.61\wow_helper.exe
2014-09-17 08:31:53 983C641D1CEAC68B224615770F56E395 3537016 ----a-w- C:\Program Files (x86)\Opera\24.0.1558.61\installer.exe
2014-09-17 08:31:53 2CEF0826198AFD0975B580D5801202AE 1372280 ----a-w- C:\Program Files (x86)\Opera\24.0.1558.61\opera_crashreporter.exe
=== C: other files ==
2014-09-23 14:21:22 8A50D5304E6AE48664CF5838EC32F647 122584 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-23 14:21:07 F92B0E478C0FAA6D6661E6E977247E60 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-09-23 14:21:07 9D9ED48F841EA37AA5310D54B9E5D3C7 91352 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-09-23 14:21:07 15E8ABC06843672955CE26A009533BAD 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-09-23 12:49:03 8A80554C91D9FCA8ACB82F023DE02F11 3 ----a-w- C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8K1ZA6L\world-333[1].com
2014-09-17 17:02:24 DCAA0AF50292BBE8D0A590E14893EE68 3817601 ----a-w- C:\Users\Spieler.HeikeHarder-HP\Downloads\powersaves3ds-software-121.zip
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}"="C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext" [11.05.2012 11:54]
==== Firefox Extensions ======================
ProfilePath: C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default
- Plasmoo Search Engine - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\engine@plasmoo.com
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\ffox@bandoo.com
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\toolbar@ask.com
- WEB.DE MailCheck - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\toolbar@web.de
- Undetermined - C:\ProgramData\AVG Secure Search\12.2.5.32
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\4433da5b-eb52-495d-8865-b2a7468567f6@927544a3-fdfb-4485-a78b-21e1113eee35.com
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\ffxtlbr@babylon.com
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\ffxtlbra@softonic.com
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\plugin@yontoo.com
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{32b29df0-2237-4370-9a29-37cebb730e9b}
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{cd8812d4-e5b8-41c6-94d4-59872a484bf1}
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
- Undetermined - C:\Users\Heike Harder\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\bbrs_002@blabbers.com
- Plasmoo Search Engine - %ProfilePath%\extensions\engine@plasmoo.com
- WEB.DE MailCheck - %ProfilePath%\extensions\toolbar@web.de
- Wincore Mediabar - %ProfilePath%\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}
ProfilePath: C:\Users\HEIKEH~1\AppData\Roaming\Thunderbird\Profiles\yfa13q6e.default
- Undetermined - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 11\THBExt_3_1_x
ProfilePath: C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default
- Undetermined - C:\Program Files (x86)\Better-Surf\ff
- Undetermined - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff
- Undetermined - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
- Undetermined - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha718\ff
- Undetermined - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1479\ff
- Undetermined - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3700\ff
- Undetermined - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha9390\ff
- Undetermined - C:\Program Files (x86)\SuperLyrics\FF
- Undetermined - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta541\ff
- Undetermined - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha701\ff
- Undetermined - C:\Program Files\Video downloader\Firefox
- Undetermined - C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\4433da5b-eb52-495d-8865-b2a7468567f6@927544a3-fdfb-4485-a78b-21e1113eee35.com
- Undetermined - C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\crossriderapp2258@crossrider.com
- Undetermined - C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\e46480cf-7cf6-495e-af69-573053f52c72@b33ab36d-5952-49aa-adb2-a41b3dbe51a5.com
- Undetermined - C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\ffxtlbr@babylon.com
- Undetermined - C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\ffxtlbr@funmoods.com
- Internet Turbo - C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\{17372c46-39f1-4c28-8f8c-b25d9b57d042}
- Wincore Mediabar - C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}
- Internet Turbo - %ProfilePath%\extensions\{17372c46-39f1-4c28-8f8c-b25d9b57d042}
- Wincore Mediabar - %ProfilePath%\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}
- Lightning Speed Dial - %ProfilePath%\extensions\lightningnewtab@gmail.com.xpi
- WEB.DE MailCheck - %ProfilePath%\extensions\toolbar@web.de.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default
6D657ABADF217DBB17CF0A0AF44A7E29 - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll - Nexon Game Controller
6A8A6B3C42CA4D1403C8FEA50BACEC63 - C:\Users\Spieler.HeikeHarder-HP\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
10737B44923217BC0E67D26A9FC1F0AA - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll - RealNetworks(tm) Chrome Background Extension Plug-In (32-bit)
2645990C521342DCD08963D2DF6CD0D2 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll - RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)
==== Deleted Firefox Extensions ======================
C:\Users\HEIKEH~1\AppData\Roaming\Mozilla\Firefox\Profiles\e7puc2qc.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} deleted
C:\Users\SPIELE~1.HEI\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\lightningnewtab@gmail.com.xpi deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} deleted
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Mozilla\Firefox\Profiles\6q039lkv.default\extensions\{17372c46-39f1-4c28-8f8c-b25d9b57d042} deleted
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
fcaiicgcjkjiagjocmccmcmncckndcmh - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3700\ch\MediaViewV1alpha3700.crx[]
flliilndjeohchalpbbcdekjklbdgfkk - No path found[]
jfmjfhklogoienhpfnppmbcbjfjnkonk - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx[11.05.2012 11:54]
laaciepchcabcfgpniblbiecldehkbae - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha9390\ch\MediaViewV1alpha9390.crx[]
mlnobaakadehgcjbhieegodlndablmao - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1479\ch\MediaViewerV1alpha1479.crx[]
RealPlayer HTML5Video Downloader Extension - Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk
media enhance - Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
==== Chromium Startpages ======================
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "hxxp://www.trovi.com/?gd=&ctid=CT3325578&octid=EB_ORIGINAL_CTID&ISID=MD15F8B10-3BB8-4EB0-ABDF-66BCF70295B7&SearchSource=55&CUI=&UM=2&UP=SP50F30F4C-32BB-47E8-8B88-21A74C21ACB9&SSPV=",
"startup_urls": [ "hxxp://www.trovi.com/?gd=&ctid=CT3325578&octid=EB_ORIGINAL_CTID&ISID=MD15F8B10-3BB8-4EB0-ABDF-66BCF70295B7&SearchSource=55&CUI=&UM=2&UP=SP50F30F4C-32BB-47E8-8B88-21A74C21ACB9&SSPV=" ],
==== Chromium Fix ======================
C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_static.livelyrics00.live-lyrics.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_static.livelyrics00.live-lyrics.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_ciuvo.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_ciuvo.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_api.ciuvo.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_api.ciuvo.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.superfish.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_static.boostsaves.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_static.boostsaves.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_static.boostsaves.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_static.boostsaves.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.wajam.com_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.wajam.com_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_flliilndjeohchalpbbcdekjklbdgfkk_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_flliilndjeohchalpbbcdekjklbdgfkk_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\flliilndjeohchalpbbcdekjklbdgfkk deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0.localstorage deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0.localstorage-journal deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\databases\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0 deleted successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="hxxp://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Unknown Url="Not_Found"
{d944bb61-2e34-4dbf-a683-47e505c587dc} Unknown Url="Not_Found"
==== Reset Google Chrome ======================
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Heike Harder\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Heike Harder\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} deleted successfully
HKEY_USERS\S-1-5-21-2355925718-3238339638-3018866954-1007\Software\Microsoft\Internet Explorer\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6CB99040-7828-4C37-AC01-F15758F43E4D} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6CB99040-7828-4C37-AC01-F15758F43E4D} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CB99040-7828-4C37-AC01-F15758F43E4D} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CB99040-7828-4C37-AC01-F15758F43E4D} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\fcaiicgcjkjiagjocmccmcmncckndcmh deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\laaciepchcabcfgpniblbiecldehkbae deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mlnobaakadehgcjbhieegodlndablmao deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iminent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IminentMessenger deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Heike Harder\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\Heike Harder\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=7875 folders=992 231417633 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Gast\AppData\Local\Temp emptied successfully
C:\Users\Heike Harder\AppData\Local\Temp emptied successfully
C:\Users\Spieler.HeikeHarder-HP\AppData\Local\Temp will be emptied at reboot
C:\Users\SPIELE~1~HEI\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\SPIELE~1.HEI\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\PROGRA~2\TermTutor" not found
==== EOF on 23.09.2014 at 17:28:53,00 ====================== |