achschneider | 27.08.2013 06:37 | Hallo Schrauber,
danke für die rasche Antwort.
Sorry, wenn es dir die Arbeit erleichtert, werde ich die log-files von nun an wie beschrieben im Thread einfügen.
Anbei die entsprechenden drei logfiles von
AdwCleaner: Code:
# AdwCleaner v3.001 - Report created 27/08/2013 at 06:55:11
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Achim - ACHIM-THINK
# Running from : C:\Users\Achim\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\SweetIM
Folder Deleted : C:\Users\Achim\AppData\Local\apn
Folder Deleted : C:\Users\Achim\AppData\Local\Conduit
Folder Deleted : C:\Users\Achim\AppData\Local\Temp\boost_interprocess
Folder Deleted : C:\Users\Achim\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Achim\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Achim\AppData\Roaming\DSite
Folder Deleted : C:\Users\Achim\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Conduit
Folder Deleted : C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\ConduitEngine
Folder Deleted : C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Smartbar
Folder Deleted : C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default_backup\Smartbar
File Deleted : C:\END
File Deleted : C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\user.js
File Deleted : C:\Windows\Tasks\DSite.job
File Deleted : C:\Windows\System32\Tasks\DSite
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{40C3CC16-7269-4B32-9531-17F2950FB06F}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\dsiteproducts
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\Conduit
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\prefs.js ]
Line Deleted : user_pref("CT502842.CTID", "CT502842");
Line Deleted : user_pref("CT502842.EMailNotifierCheckInterval", "5");
Line Deleted : user_pref("CT502842.EMailNotifierPollDate", "Wed Nov :02:27 GMT+0100");
Line Deleted : user_pref("CT502842.EMailNotifierSound", "NONE");
Line Deleted : user_pref("CT502842.Initialize", true);
Line Deleted : user_pref("CT502842.LastLogin", "Tue Dec :25:29 GMT+0100");
Line Deleted : user_pref("CT502842.LoginCache", "3");
Line Deleted : user_pref("CT502842.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT502842.SearchBoxWidth", 152);
Line Deleted : user_pref("CT502842.SearchEngine", "Search||hxxp://www.google.com/search?hl=en&q=UCM_SEARCH_TERM");
Line Deleted : user_pref("CT502842.Server", "hxxp://users.conduit.com");
Line Deleted : user_pref("CT502842.SettingsLastUpdate", "1195658142");
Line Deleted : user_pref("CT502842.ThirdPartyComponentsInterval", "24");
Line Deleted : user_pref("CT502842.ThirdPartyComponentsLastCheck", "Wed Nov :00:36 GMT+0100");
Line Deleted : user_pref("CT502842.ThirdPartyComponentsLastUpdate", "1162825956");
Line Deleted : user_pref("CT502842.UserID", "UN20061108110035796");
Line Deleted : user_pref("CT502842.WeatherNetwork", "");
Line Deleted : user_pref("CT502842.WeatherPollDate", "Tue Dec :25:30 GMT+0100");
Line Deleted : user_pref("CT502842.WeatherUnit", "C");
Line Deleted : user_pref("CT502842.components.1000", false);
Line Deleted : user_pref("CT502842.components.1001", false);
Line Deleted : user_pref("CT502842.components.1002", false);
Line Deleted : user_pref("CT502842.components.1003", false);
Line Deleted : user_pref("CT502842.components.1004", false);
Line Deleted : user_pref("CT502842.components.1006", false);
Line Deleted : user_pref("CT502842.components.1008", false);
Line Deleted : user_pref("CT502842.components.1009", false);
Line Deleted : user_pref("CT502842.components.1010", false);
Line Deleted : user_pref("CT502842.components.1012", false);
Line Deleted : user_pref("CT502842.components.102", false);
Line Deleted : user_pref("CT502842.components.103", false);
Line Deleted : user_pref("CT502842.components.104", true);
Line Deleted : user_pref("CT502842.components.105", true);
Line Deleted : user_pref("CT502842.components.128070027375882165", false);
Line Deleted : user_pref("CT502842.components.128073065400700904", false);
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT65619/CT65619", "\"46ee611e9a0fe93f55af7750803aba0f3\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT65619", "\"1367218526\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"01ffa8b1cc6cb1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"807dc126dd28cc1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.2.3", "\"4ead38b3e6bcd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0e0a4327275cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.1.0", "\"0343677cfb1cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18.0.7", "\"0343677cfb1cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.19.0.3", "\"23c5489aa686ce1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT65619", "\"9971ee9815a5fc569766cf6ddcaaca8e\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-US", "\"ac6547200eccf72d3c751805a83c1597\"");
Line Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Line Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Line Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList4", "");
Line Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sat Mar 26 2011 22:49:00 GMT+0100");
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 60);
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Fri Jun 17 2011 20:43:33 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Line Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Line Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Jun 22 2011 21:47:59 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Line Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Line Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Line Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Line Deleted : user_pref("CommunityToolbar.alert.userId", "29a1eb3b-bfbf-4447-8a8d-c10a479db17e");
Line Deleted : user_pref("CommunityToolbar.globalUserId", "89be37ff-88c8-4afa-8d70-351916f7de5d");
Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Mon Jun :40:53 GMT+0200");
Line Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Line Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Tue Jun 21 2011 17:50:02 GMT+0200");
Line Deleted : user_pref("ConduitEngine.FirstServerDate", "03/27/2011 00");
Line Deleted : user_pref("ConduitEngine.FirstTime", true);
Line Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Line Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Line Deleted : user_pref("ConduitEngine.Initialize", true);
Line Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Line Deleted : user_pref("ConduitEngine.InstalledDate", "Sat Mar 26 2011 22:49:01 GMT+0100");
Line Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Line Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Line Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Line Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Jun 22 2011 21:48:02 GMT+0200");
Line Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Jun 22 2011 21:48:02 GMT+0200");
Line Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Jun 22 2011 21:48:02 GMT+0200");
Line Deleted : user_pref("ConduitEngine.UserID", "UN39269095980423774");
Line Deleted : user_pref("ConduitEngine.componentAlertEnabled", false);
Line Deleted : user_pref("ConduitEngine.engineLocale", "de");
Line Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Jun 22 2011 21:48:02 GMT+0200");
Line Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Jun 22 2011 21:48:03 GMT+0200");
Line Deleted : user_pref("ConduitEngine.initDone", true);
Line Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Line Deleted : user_pref("ConduitEngine.usagesFlag", 2);
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Line Deleted : user_pref("extensions.toolbar@ask.com.install-event-fired", true);
[ File : C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default_backup\prefs.js ]
Line Deleted : user_pref("CT2319825.1000082.isPlayDisplay", "true");
Line Deleted : user_pref("CT2319825.1000082.state", "{\"state\":\"stopped\",\"text\":\"1Live\",\"description\":\"1Live\",\"url\":\"hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_einslive_a\"}");
Line Deleted : user_pref("CT2319825.1000234.TWC_TMP_city", "BERLIN");
Line Deleted : user_pref("CT2319825.1000234.TWC_TMP_country", "DE");
Line Deleted : user_pref("CT2319825.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2319825.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2319825.FirstTime", "true");
Line Deleted : user_pref("CT2319825.FirstTimeFF3", "true");
Line Deleted : user_pref("CT2319825.ID", "50925059");
Line Deleted : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=2&q=");
Line Deleted : user_pref("CT2319825.UserID", "UN84015805479879887");
Line Deleted : user_pref("CT2319825.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT2319825.autoDisableScopes", -1);
Line Deleted : user_pref("CT2319825.browser.search.defaultthis.engineName", true);
Line Deleted : user_pref("CT2319825.defaultSearch", "true");
Line Deleted : user_pref("CT2319825.embeddedsData", "[{\"appId\":\"128898076802619666\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Line Deleted : user_pref("CT2319825.enableAlerts", "always");
Line Deleted : user_pref("CT2319825.enableSearchFromAddressBar", "true");
Line Deleted : user_pref("CT2319825.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT2319825.fixPageNotFoundError", "true");
Line Deleted : user_pref("CT2319825.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT2319825.fixUrls", true);
Line Deleted : user_pref("CT2319825.installId", "ConduitNSISIntegration");
Line Deleted : user_pref("CT2319825.installType", "ConduitNSISIntegration");
Line Deleted : user_pref("CT2319825.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2319825.isNewTabEnabled", true);
Line Deleted : user_pref("CT2319825.isPerformedSmartBarTransition", "true");
Line Deleted : user_pref("CT2319825.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT2319825.keyword", true);
Line Deleted : user_pref("CT2319825.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Aaddons\",\"EB_MAIN_FRAME_TITLE\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://Winload.OurToolbar.com/\[...]
Line Deleted : user_pref("CT2319825.openThankYouPage", "false");
Line Deleted : user_pref("CT2319825.openUninstallPage", "true");
Line Deleted : user_pref("CT2319825.search.searchAppId", "128898076802619666");
Line Deleted : user_pref("CT2319825.search.searchCount", "0");
Line Deleted : user_pref("CT2319825.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT2319825.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2319825.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2319825.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT2319825.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2319825\"}");
Line Deleted : user_pref("CT2319825.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://Winload.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT2319825.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Winload\"}");
Line Deleted : user_pref("CT2319825.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2319825.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT2319825.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1349280608902");
Line Deleted : user_pref("CT2319825.serviceLayer_services_appsMetadata_lastUpdate", "1349280608876");
Line Deleted : user_pref("CT2319825.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1349280609473");
Line Deleted : user_pref("CT2319825.serviceLayer_services_login_10.10.27.6_lastUpdate", "1349280609867");
Line Deleted : user_pref("CT2319825.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1349280609451");
Line Deleted : user_pref("CT2319825.serviceLayer_services_searchAPI_lastUpdate", "1349280608481");
Line Deleted : user_pref("CT2319825.serviceLayer_services_serviceMap_lastUpdate", "1349280608217");
Line Deleted : user_pref("CT2319825.serviceLayer_services_toolbarContextMenu_lastUpdate", "1349280609500");
Line Deleted : user_pref("CT2319825.serviceLayer_services_toolbarSettings_lastUpdate", "1349280608505");
Line Deleted : user_pref("CT2319825.serviceLayer_services_translation_lastUpdate", "1349280608878");
Line Deleted : user_pref("CT2319825.settingsINI", true);
Line Deleted : user_pref("CT2319825.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT2319825.smartbar.CTID", "CT2319825");
Line Deleted : user_pref("CT2319825.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT2319825.smartbar.homepage", true);
Line Deleted : user_pref("CT2319825.smartbar.toolbarName", "Winload ");
Line Deleted : user_pref("CT2319825.startPage", "userChanged");
Line Deleted : user_pref("CT2319825.toolbarBornServerTime", "3-10-2012");
Line Deleted : user_pref("CT2319825.toolbarCurrentServerTime", "3-10-2012");
Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "");
Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", "Winload Customized Web Search");
Line Deleted : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=2&q=");
Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT2319825");
Line Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=2&q=");
-\\ Google Chrome v29.0.1547.57
[ File : C:\Users\Achim\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [19199 octets] - [27/08/2013 06:53:29]
AdwCleaner[S0].txt - [19158 octets] - [27/08/2013 06:55:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19219 octets] ########## Junkware Removal Tool: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.4 (08.22.2013:1)
OS: Windows 7 Professional x64
Ran by Achim on 27.08.2013 at 7:03:44,41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2319825
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{71588120-FC17-4463-B07D-2C71FE6E057B}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{7D6DE346-CAAA-4CC8-A6E3-CD6998109B05}
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Achim\AppData\Roaming\mozilla\firefox\profiles\ggmtit2u.default\prefs.js
user_pref("adblock.patterns", "hxxp://www.de.map24.com/source/advertisement/v3.0.1/map24_rectangle.php?lang=de-de&map24_sid=26e2a4302a0d41cdcecc7f3ed5293ee7_MTAuMzkuOS4yNQ htt
user_pref("fgupdater.patterns", "!Filterset.G[hxxp://www.pierceive.com/]=2008-03-08a-MERGED .adquest.nl .adreporting.com .geldrace.nl .site-id.nl /(\\Wadv|banner|promo)s?(\\.(
user_pref("google.toolbar.button_option.cached.gtbSearchBlogs", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchBlogs\" t
user_pref("google.toolbar.button_option.cached.gtbSearchPhotos", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchPhotos\"
user_pref("google.toolbar.button_option.cached.gtbSearchScholar", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchScholar
user_pref("google.toolbar.button_option.cached.gtbstoolbar-google-com_CTK0Y7F4MTG6NKYH03WT-xml", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.o
user_pref("google.toolbar.button_option.cached.gtbstoolbar-google-com_J66T77NJDBMW4FEUU7FA-xml", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.o
user_pref("google.toolbar.search-icon", "data:image/x-icon;base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7PT7/3zF6/9Ptu//RbHx/
Emptied folder: C:\Users\Achim\AppData\Roaming\mozilla\firefox\profiles\ggmtit2u.default\minidumps [153 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.08.2013 at 7:07:43,75
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und ein neu erstelltes FRST Logfile
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-08-2013
Ran by Achim (administrator) on 27-08-2013 07:16:55
Running from C:\Users\Achim\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Lenovo.) C:\Windows\system32\ibmpmsvc.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(Authentec Inc.) C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Nenad Hrg SoftwareOK) D:\Dokumente\Backup\DesktopOK_x64.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
() C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
(SB-AW) C:\Program Files (x86)\VersionBackup\VBackDisplay.exe
(SB-AW) C:\Program Files (x86)\VersionBackup\VBackRun.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Lenovo Group Limited) C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Lenovo) C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\avcenter.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE
(Microsoft Corporation) C:\Windows\system32\PrintIsolationHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ismagent.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-20] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-17] (Realtek Semiconductor)
HKLM\...\Run: [TpShocks] - C:\Windows\SYSTEM32\TpShocks.exe [382248 2013-02-12] (Lenovo.)
HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [293672 2013-01-28] (Lenovo Group Limited)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-24] (CANON INC.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-17] (Synaptics Incorporated)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Transcode Engine\plugins\mc_demux_mp2_ds.ax",DllRegisterServer [45568 2009-07-14] (Microsoft Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.)
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-06-22] (Google Inc.)
HKCU\...\Run: [DesktopOK] - D:\Dokumente\Backup\DesktopOK_x64.exe [378368 2012-09-30] (Nenad Hrg SoftwareOK)
HKCU\...\Run: [Nero MediaHome 4] - C:\Program Files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe [5178664 2012-02-28] (Nero AG)
MountPoints2: {5142ea1a-02ff-11e2-899f-806e6f6e6963} - Q:\LenovoQDrive.exe
HKLM-x32\...\Run: [RotateImage] - C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-02-28] (Intel Corporation)
HKLM-x32\...\Run: [PWMTRV] - C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL [6002984 2013-04-23] (Lenovo Group Limited)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Fastboot] - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo)
HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2010-03-02] (CANON INC.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-20] (Microsoft Corp.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM-x32\...\Run: [Nero MediaHome 4] - C:\Program Files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe [5178664 2012-02-28] (Nero AG)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKU\Default\...\RunOnce: [Lenovo.ShowBand] - c:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-05-17] (Lenovo)
HKU\Default\...\RunOnce: [] - [x]
HKU\Default\...\RunOnce: [Lenovoautoqdrive] - C:\PROGRA~2\Common~1\Lenovo\Lenovo~1\LenovoAutorunreg.exe [159744 2011-12-15] ()
Lsa: [Notification Packages] scecli C:\Program Files\ThinkPad\Bluetooth Software\BtwProximityCP.dll C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Spyder3Utility.lnk
ShortcutTarget: Spyder3Utility.lnk -> C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VersionBackup.lnk
ShortcutTarget: VersionBackup.lnk -> C:\Program Files (x86)\VersionBackup\VersionBackup.exe (SB-AW)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad
SearchScopes: HKLM - DefaultScope {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF SearchPlugin: C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\searchplugins\dictcc.xml
FF SearchPlugin: C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\searchplugins\wie-sagt-man-noch---suche.xml
FF Extension: Deutsches Wörterbuch - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: No Name - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\fb_add_on@avm.de
FF Extension: Flagfox - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: No Name - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{BE2100B3-1D80-48eb-ACCF-D26750644378}
FF Extension: Flash and Video Download - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
FF Extension: iPox - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66}(2)
FF Extension: Download Statusbar - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}(2)
FF Extension: Bitdefender QuickScan - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF Extension: elemhidehelper - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\elemhidehelper@adblockplus.org.xpi
FF Extension: firegestures - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\firegestures@xuldev.org.xpi
FF Extension: tabscope - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\tabscope@xuldev.org.xpi
FF Extension: No Name - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{0fa2149e-bb2c-4ac2-a8d3-479599819475}.xpi
FF Extension: No Name - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF Extension: No Name - C:\Users\Achim\AppData\Roaming\Mozilla\Firefox\Profiles\ggmtit2u.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [VIP1X@verisign.com] C:\Program Files (x86)\Symantec\VIP Access Client\
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.de/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (PDF-XChange Viewer) - C:\Program Files (x86)\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility) - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Chrome In-App Payments service) - C:\Users\Achim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Achim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-01] (Adobe Systems Incorporated)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [371768 2013-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-03] (Avira Operations GmbH & Co. KG)
R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.)
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [8447848 2011-11-09] (DisplayLink Corp.)
S3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [320576 2013-04-23] (Lenovo.)
R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation)
R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [188200 2013-01-28] (Lenovo Group Limited)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-10] (Lenovo Group Limited)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-08-23] ()
R2 NeroMediaHomeService.4; C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe [517416 2012-02-28] (Nero AG)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] ()
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-04-11] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-27] (Avira Operations GmbH & Co. KG)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [165688 2012-09-25] (Broadcom Corporation.)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider)
R3 LenovoRd; C:\Windows\System32\Drivers\LenovoRd.sys [118016 2009-05-11] (Lenovo)
S3 mod7700; C:\Windows\System32\DRIVERS\dvb7700all.sys [866600 2012-08-09] (DiBcom)
R1 PHCORE; C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [33344 2012-03-26] (Lenovo Group Limited)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [44784 2013-04-17] (Synaptics Incorporated)
R2 smihlp2; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13128 2011-05-30] (Authentec Inc.)
S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2010-03-30] ()
S3 STIrUsb; C:\Windows\System32\DRIVERS\irstusb.sys [33792 2008-01-19] (SigmaTel, Inc.)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.)
R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility)
R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [48024 2013-01-28] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\DRIVERS\XHCIPort.sys [194456 2013-01-28] (Windows (R) Win 7 DDK provider)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-27 07:: _____ C:\Users\Achim\Desktop\JRT.txt
2013-08-27 07:: ____D C:\Windows\ERUNT
2013-08-27 07:: _____ C:\Users\Achim\Desktop\AdwCleaner[S0].txt
2013-08-27 06:53 - 2013-08-27 07: ____D C:\AdwCleaner
2013-08-27 06:53 - 2013-08-27 06:51 - 01021434 _____ (Thisisu) C:\Users\Achim\Desktop\JRT.exe
2013-08-27 06:53 - 2013-08-27 06:49 - 00994642 _____ C:\Users\Achim\Desktop\adwcleaner.exe
2013-08-26 18:50 - 2013-08-26 18:49 - 00377856 _____ C:\Users\Achim\Desktop\gmer_2.1.19163.exe
2013-08-26 18:42 - 2013-08-26 18:42 - 00000000 ____D C:\FRST
2013-08-26 18:41 - 2013-08-26 18:41 - 01577068 _____ (Farbar) C:\Users\Achim\Desktop\FRST64.exe
2013-08-26 18:39 - 2013-08-26 18:39 - 00000000 _____ C:\Users\Achim\defogger_reenable
2013-08-26 18:38 - 2013-08-26 18:37 - 00050477 _____ C:\Users\Achim\Desktop\Defogger.exe
2013-08-26 17:50 - 2013-08-26 17:58 - 00000045 _____ C:\Users\Achim\AppData\Roaming\mbam.context.scan
2013-08-26 07:: ____D C:\Users\Achim\AppData\Roaming\Malwarebytes
2013-08-26 07:: ____D C:\ProgramData\Malwarebytes
2013-08-26 07:: ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-26 07::50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-26 07:: _____ (OldTimer Tools) C:\Users\Achim\Desktop\OTL.exe
2013-08-19 19:: ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-19 13:50 - 2013-08-19 13:50 - 14551000 _____ C:\Users\Achim\boot_BASE+CSWITCH_1.cab
2013-08-19 13:49 - 2013-08-19 13:49 - 192937984 _____ C:\Users\Achim\boot_BASE+CSWITCH_1.etl
2013-08-19 13:45 - 2013-08-19 13:45 - 14392835 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_6.cab
2013-08-19 13:43 - 2013-08-19 13:44 - 197132288 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_6.etl
2013-08-19 13:40 - 2013-08-19 13:40 - 14216496 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_5.cab
2013-08-19 13:39 - 2013-08-19 13:39 - 242221056 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_5.etl
2013-08-19 13:34 - 2013-08-19 13:34 - 14169403 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_4.cab
2013-08-19 13:33 - 2013-08-19 13:34 - 189792256 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_4.etl
2013-08-19 13:29 - 2013-08-19 13:29 - 14049388 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_3.cab
2013-08-19 13:27 - 2013-08-19 13:28 - 178257920 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_3.etl
2013-08-19 13:19 - 2013-08-19 13:19 - 13655002 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_2.cab
2013-08-19 13:17 - 2013-08-19 13:18 - 192937984 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_2.etl
2013-08-19 13:13 - 2013-08-19 13:13 - 12626656 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_1.cab
2013-08-19 13:12 - 2013-08-19 13:13 - 184549376 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_1.etl
2013-08-19 13::50 - 00011389 _____ C:\Users\Achim\xbootmgr.log
2013-08-19 12:13 - 2013-08-19 12:29 - 372244480 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_4_km_premerge.etl
2013-08-19 12:13 - 2013-08-19 12:17 - 104857600 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_4_um_premerge.etl
2013-08-19 11:49 - 2013-08-19 11:54 - 190840832 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_1_km_premerge.etl
2013-08-19 11:49 - 2013-08-19 11:54 - 104857600 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_1_um_premerge.etl
2013-08-19 10:52 - 2013-08-19 10:57 - 197132288 _____ C:\Windows\system32\boot_BASE+CSWITCH_1_km_premerge.etl
2013-08-19 10:52 - 2013-08-19 10:56 - 104857600 _____ C:\Windows\system32\boot_BASE+CSWITCH_1_um_premerge.etl
2013-08-19 10:45 - 2013-08-19 10:51 - 198180864 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_6_km_premerge.etl
2013-08-19 10:45 - 2013-08-19 10:49 - 104857600 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_6_um_premerge.etl
2013-08-19 10:39 - 2013-08-19 13: _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_5_km_premerge.etl
2013-08-19 10:39 - 2013-08-19 13: _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_5_um_premerge.etl
2013-08-19 10:31 - 2013-08-19 12:11 - 186646528 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_3.etl
2013-08-13 20:40 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-13 20:40 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-13 20:40 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-13 20:40 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-13 20:40 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-13 20:40 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-13 20:40 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-13 20:40 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-13 20:40 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-13 20:40 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-13 20:40 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-13 20:40 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-13 20:40 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-13 20:40 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-13 20:33 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-13 20:33 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-13 20:33 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-13 20:33 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-13 20:33 - 2013-07-09 08: _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-13 20:33 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-13 20:33 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-13 20:33 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-13 20:33 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-13 20:33 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-13 20:33 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-13 20:33 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-13 20:33 - 2013-07-09 07: _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-13 20:33 - 2013-07-09 07: _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-13 20:33 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-13 20:33 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-13 20:33 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-13 20:33 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-13 20:33 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-13 20:33 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-13 20:33 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-13 20:33 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-13 20:33 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-13 20:33 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-13 20:33 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-13 20:33 - 2013-07-06 08: _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-13 20:32 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-08 20:21 - 2013-08-20 21:50 - 00000000 ____D D:\Dokumente\Eigene Logbücher
2013-08-08 20:16 - 2013-08-08 20:17 - 00000000 ____D C:\Program Files (x86)\SmartTRAK
2013-08-08 20:16 - 2013-08-08 20:16 - 00000988 _____ C:\Users\Public\Desktop\SmartTRAK.lnk
2013-08-08 20:16 - 2012-05-24 15:16 - 01025536 _____ (Uwatec AG) C:\Windows\SysWOW64\Calculate.dll
2013-08-08 20:16 - 2012-01-25 12: _____ (Uwatec AG) C:\Windows\SysWOW64\Old.dll
2013-08-08 20:16 - 2012-01-25 12: _____ C:\Windows\SysWOW64\compress.exe
2013-08-06 18:31 - 2013-08-25 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-07-28 16:21 - 2013-08-02 18:38 - 00000075 _____ C:\Users\Achim\AppData\Roaming\WB.CFG
==================== One Month Modified Files and Folders =======
2013-08-27 07:16 - 2012-06-22 09:59 - 00711662 _____ C:\Windows\system32\perfh007.dat
2013-08-27 07:16 - 2012-06-22 09:59 - 00152870 _____ C:\Windows\system32\perfc007.dat
2013-08-27 07:16 - 2009-07-14 07:13 - 01632372 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-27 07:12 - 2012-06-22 00:27 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-27 07:10 - 2012-06-22 00: _____ C:\Windows\WindowsUpdate.log
2013-08-27 07:10 - 2009-07-14 07: ____H C:\Windows\Tasks\SA.DAT
2013-08-27 07:10 - 2009-07-14 06:51 - 00101613 _____ C:\Windows\setupact.log
2013-08-27 07:: _____ C:\Users\Achim\Desktop\JRT.txt
2013-08-27 07::45 - 00034208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-27 07::45 - 00034208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-27 07:: ____D C:\Windows\ERUNT
2013-08-27 07::53 - 00000000 ____D C:\AdwCleaner
2013-08-27 07:: _____ C:\Users\Achim\Desktop\AdwCleaner[S0].txt
2013-08-27 06:54 - 2012-09-23 14:36 - 00000000 ____D C:\Users\Achim\AppData\Local\Adobe
2013-08-27 06:51 - 2013-08-27 06:53 - 01021434 _____ (Thisisu) C:\Users\Achim\Desktop\JRT.exe
2013-08-27 06:49 - 2013-08-27 06:53 - 00994642 _____ C:\Users\Achim\Desktop\adwcleaner.exe
2013-08-26 23:48 - 2012-10-03 01:11 - 00000000 ____D D:\Dokumente\Bedienungsanleitungen und co
2013-08-26 23:44 - 2013-01-13 14:46 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-26 23:26 - 2012-06-22 00:27 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-26 20:54 - 2012-10-04 21:13 - 00000000 ____D D:\Dokumente\Backup
2013-08-26 18:49 - 2013-08-26 18:50 - 00377856 _____ C:\Users\Achim\Desktop\gmer_2.1.19163.exe
2013-08-26 18:42 - 2013-08-26 18:42 - 00000000 ____D C:\FRST
2013-08-26 18:41 - 2013-08-26 18:41 - 01577068 _____ (Farbar) C:\Users\Achim\Desktop\FRST64.exe
2013-08-26 18:39 - 2013-08-26 18:39 - 00000000 _____ C:\Users\Achim\defogger_reenable
2013-08-26 18:39 - 2012-09-23 14:25 - 00000000 ____D C:\Users\Achim
2013-08-26 18:37 - 2013-08-26 18:38 - 00050477 _____ C:\Users\Achim\Desktop\Defogger.exe
2013-08-26 18::47 - 00746278 _____ C:\Windows\PFRO.log
2013-08-26 17:58 - 2013-08-26 17:50 - 00000045 _____ C:\Users\Achim\AppData\Roaming\mbam.context.scan
2013-08-26 07:22 - 2012-10-03 00:21 - 00000000 ___RD D:\Dokumente\Musik
2013-08-26 07:: ____D C:\Users\Achim\AppData\Roaming\Malwarebytes
2013-08-26 07:: ____D C:\ProgramData\Malwarebytes
2013-08-26 07:: ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-26 07:: _____ (OldTimer Tools) C:\Users\Achim\Desktop\OTL.exe
2013-08-25 20:35 - 2012-10-08 09:58 - 00000000 ____D C:\Users\Achim\AppData\Roaming\MyPhoneExplorer
2013-08-25 20:12 - 2013-08-06 18:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-25 20:12 - 2013-03-24 17:42 - 00000000 ____D C:\Program Files\DivX
2013-08-25 20:12 - 2013-03-24 17:40 - 00000000 ____D C:\Program Files (x86)\DivX
2013-08-25 20:12 - 2013-03-24 17:26 - 00000000 ____D C:\ProgramData\DivX
2013-08-25 19:21 - 2013-07-04 15:21 - 00000005 _____ C:\Users\Achim\AppData\Roaming\WBPU-TTL.DAT
2013-08-24 17:24 - 2012-09-23 18: ____D C:\ldiag
2013-08-22 18:29 - 2012-10-03 20:11 - 00000000 ____D C:\Users\Achim\AppData\Roaming\vlc
2013-08-21 21:53 - 2012-09-30 16:27 - 00000000 ____D D:\Dokumente\Finanzen
2013-08-20 22:12 - 2012-10-03 15:47 - 00000000 ____D D:\Dokumente\Screenshots
2013-08-20 21:50 - 2013-08-08 20:21 - 00000000 ____D D:\Dokumente\Eigene Logbücher
2013-08-19 21:36 - 2012-10-14 17: ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-19 19:: ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-19 13:50 - 2013-08-19 13:50 - 14551000 _____ C:\Users\Achim\boot_BASE+CSWITCH_1.cab
2013-08-19 13:50 - 2013-08-19 13: _____ C:\Users\Achim\xbootmgr.log
2013-08-19 13:49 - 2013-08-19 13:49 - 192937984 _____ C:\Users\Achim\boot_BASE+CSWITCH_1.etl
2013-08-19 13:45 - 2013-08-19 13:45 - 14392835 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_6.cab
2013-08-19 13:44 - 2013-08-19 13:43 - 197132288 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_6.etl
2013-08-19 13:40 - 2013-08-19 13:40 - 14216496 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_5.cab
2013-08-19 13:39 - 2013-08-19 13:39 - 242221056 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_5.etl
2013-08-19 13:34 - 2013-08-19 13:34 - 14169403 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_4.cab
2013-08-19 13:34 - 2013-08-19 13:33 - 189792256 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_4.etl
2013-08-19 13:29 - 2013-08-19 13:29 - 14049388 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_3.cab
2013-08-19 13:28 - 2013-08-19 13:27 - 178257920 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_3.etl
2013-08-19 13:19 - 2013-08-19 13:19 - 13655002 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_2.cab
2013-08-19 13:18 - 2013-08-19 13:17 - 192937984 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_2.etl
2013-08-19 13:13 - 2013-08-19 13:13 - 12626656 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_1.cab
2013-08-19 13:13 - 2013-08-19 13:12 - 184549376 _____ C:\Users\Achim\bootPrep_BASE+CSWITCH_1.etl
2013-08-19 13::39 - 277872640 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_5_km_premerge.etl
2013-08-19 13::39 - 104857600 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_5_um_premerge.etl
2013-08-19 12:29 - 2013-08-19 12:13 - 372244480 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_4_km_premerge.etl
2013-08-19 12:29 - 2012-12-09 22:49 - 13928638 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_4.cab
2013-08-19 12:29 - 2012-12-09 22:28 - 00034837 _____ C:\Windows\system32\xbootmgr.log
2013-08-19 12:17 - 2013-08-19 12:13 - 104857600 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_4_um_premerge.etl
2013-08-19 12:12 - 2012-12-09 22:43 - 13930024 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_3.cab
2013-08-19 12:11 - 2013-08-19 10:31 - 186646528 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_3.etl
2013-08-19 12:: _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_2.etl
2013-08-19 12::35 - 13381407 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_2.cab
2013-08-19 11:55 - 2012-12-09 22:32 - 12390145 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_1.cab
2013-08-19 11:54 - 2013-08-19 11:49 - 190840832 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_1_km_premerge.etl
2013-08-19 11:54 - 2013-08-19 11:49 - 104857600 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_1_um_premerge.etl
2013-08-19 10:57 - 2013-08-19 10:52 - 197132288 _____ C:\Windows\system32\boot_BASE+CSWITCH_1_km_premerge.etl
2013-08-19 10:56 - 2013-08-19 10:52 - 104857600 _____ C:\Windows\system32\boot_BASE+CSWITCH_1_um_premerge.etl
2013-08-19 10:51 - 2013-08-19 10:45 - 198180864 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_6_km_premerge.etl
2013-08-19 10:51 - 2012-12-09 22:57 - 16360860 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_6.cab
2013-08-19 10:49 - 2013-08-19 10:45 - 104857600 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_6_um_premerge.etl
2013-08-19 10:45 - 2012-12-09 22:53 - 16690882 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_5.cab
2013-08-19 10:37 - 2013-05-08 21:24 - 211812352 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_4.etl
2013-08-19 10:10 - 2013-05-08 20:59 - 187695104 _____ C:\Windows\system32\bootPrep_BASE+CSWITCH_1.etl
2013-08-19 00:37 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-18 21:58 - 2012-10-03 19:19 - 00000000 ____D C:\Program Files (x86)\The GodFather
2013-08-13 20:42 - 2012-10-14 20:35 - 00000000 ____D C:\Users\Achim\AppData\Roaming\QuickScan
2013-08-13 20:37 - 2013-07-11 07:33 - 00000000 ____D C:\Windows\system32\MRT
2013-08-13 20:35 - 2012-09-23 16:25 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-13 20:26 - 2013-01-13 14:46 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-13 20:26 - 2012-10-08 13: _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-13 20:26 - 2012-10-08 13: _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-13 08::29 - 00000000 ____D C:\Users\Achim\AppData\Local\Google
2013-08-13 08::27 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-08 20:19 - 2009-07-14 06:45 - 00384696 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-08 20:17 - 2013-08-08 20:16 - 00000000 ____D C:\Program Files (x86)\SmartTRAK
2013-08-08 20:17 - 2012-09-23 14:27 - 00100560 _____ C:\Users\Achim\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-08 20:16 - 2013-08-08 20:16 - 00000988 _____ C:\Users\Public\Desktop\SmartTRAK.lnk
2013-08-05 21::34 - 00000000 ____D C:\Users\Achim\AppData\Roaming\Intel WiDi
2013-08-02 18:38 - 2013-07-28 16:21 - 00000075 _____ C:\Users\Achim\AppData\Roaming\WB.CFG
2013-08-02 18:13 - 2009-07-14 07: _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-29 20:54 - 2012-09-30 17:19 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-28 20:47 - 2012-12-09 12:13 - 00001132 ____H C:\Windows\EPMBatch.ept
Files to move or delete:
====================
C:\Users\Achim\AppData\Local\Temp\DivXSetup.exe
C:\Users\Achim\AppData\Local\Temp\npp.6.3.2.Installer.exe
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\GoogleCrashHandler.exe
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\GoogleCrashHandler64.exe
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\GoogleUpdate.exe
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\GoogleUpdateBroker.exe
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\GoogleUpdateOnDemand.exe
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\GoogleUpdateSetup.exe
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdate.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_am.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ar.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_bg.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_bn.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ca.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_cs.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_da.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_de.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_el.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_en-GB.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_en.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_es-419.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_es.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_et.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_fa.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_fi.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_fil.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_fr.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_gu.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_hi.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_hr.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_hu.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_id.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_is.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_it.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_iw.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ja.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_kn.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ko.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_lt.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_lv.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ml.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_mr.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ms.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_nl.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_no.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_pl.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_pt-BR.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_pt-PT.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ro.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ru.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_sk.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_sl.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_sr.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_sv.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_sw.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ta.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_te.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_th.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_tr.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_uk.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_ur.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_vi.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_zh-CN.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\goopdateres_zh-TW.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\npGoogleUpdate3.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\psmachine.dll
C:\Users\Achim\AppData\Local\Temp\{90BA7495-AF18-4ACE-92C6-A522ADABCFF2}\psuser.dll
C:\Users\Achim\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\Achim\AppData\Local\Temp\fla1335.tmp\LSCSetup64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-22 00:48
==================== End Of Log ============================ --- --- ---
--- --- ---
Wie geht es weiter?
Danke und Grüße
Achim |