Schattenlord | 28.03.2014 20:10 | Hallo Matthias,
anbei die gewünschten Log Dateien :)
adwCleaner[S1]: Code:
# AdwCleaner v3.022 - Bericht erstellt am 27/03/2014 um 23:37:07
# Aktualisiert 13/03/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Björn - BJOERN-PC
# Gestartet von : C:\Users\Björn\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Splashtop
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\1ClicktorrentFile
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\1ClicktorrentFile1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\oneclick
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\oneclickmg
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dealplylive.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\5b6d9deb668b915
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2928751
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF65FDBC-5683-4DFD-9113-1FCB5B0A3447}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A85489D8-9FB7-4AD9-93EE-CD7E5B3B15C2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE93F30A-4DCE-4FA3-9D01-6941E7EF07D0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E567812A-BD95-494A-AE1A-66BF953152FB}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FF65FDBC-5683-4DFD-9113-1FCB5B0A3447}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FF65FDBC-5683-4DFD-9113-1FCB5B0A3447}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FF65FDBC-5683-4DFD-9113-1FCB5B0A3447}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\Splashtop Inc.
Schlüssel Gelöscht : HKCU\Software\TENCENT
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyricsparty
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Icy_Tower
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKLM\Software\Splashtop Inc.
Schlüssel Gelöscht : HKLM\Software\Icy_Tower
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B7C5EA94-B96A-41F5-BE95-25D78B486678}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Splashtop Software Updater
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Icy_Tower Toolbar
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Speedchecker Limited
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\49AE5C7BA69B5F14EB59527DB8846687
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\49AE5C7BA69B5F14EB59527DB8846687
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v24.0 (en-US)
[ Datei : C:\Users\Björn\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default\prefs.js ]
Zeile gelöscht : user_pref("CT2832595.FirstTime", "true");
Zeile gelöscht : user_pref("CT2832595.FirstTimeFF3", "true");
Zeile gelöscht : user_pref("CT2832595.LoginRevertSettingsEnabled", true);
Zeile gelöscht : user_pref("CT2832595.RevertSettingsEnabled", true);
Zeile gelöscht : user_pref("CT2832595.UserID", "UN52039384870627798");
Zeile gelöscht : user_pref("CT2832595.activeToolbar.enc", "c3RhZW1tZQ==");
Zeile gelöscht : user_pref("CT2832595.addressBarTakeOverEnabledInHidden", "true");
Zeile gelöscht : user_pref("CT2832595.countryCode", "DE");
Zeile gelöscht : user_pref("CT2832595.enableAlerts", "never");
Zeile gelöscht : user_pref("CT2832595.enableFix404ByUser", "FALSE");
Zeile gelöscht : user_pref("CT2832595.firstTimeDialogOpened", "true");
Zeile gelöscht : user_pref("CT2832595.fixPageNotFoundErrorByUser", "TRUE");
Zeile gelöscht : user_pref("CT2832595.fixPageNotFoundErrorInHidden", "true");
Zeile gelöscht : user_pref("CT2832595.fixUrls", true);
Zeile gelöscht : user_pref("CT2832595.fullUserID", "UN52039384870627798.UP.20130728130217");
Zeile gelöscht : user_pref("CT2832595.homepageuserchanged", true);
Zeile gelöscht : user_pref("CT2832595.hxxp___toolbar_innogames_de_toolbars_flags.APP_WIN_FEATURES", "cmVzaXphYmxlPW5vLCBzYXZlcmVzaXplZHNpemU9bm8sIGhzY3JvbGw9bm8sIHZzY3JvbGw9bm8sIHRpdGxlYmFyPW5vLCBjbG9zZWJ1dHRvbj1ubywg[...]
Zeile gelöscht : user_pref("CT2832595.hxxp___toolbar_innogames_de_toolbars_staemme.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPW5vLCBzYXZlcmVzaXplZHNpemU9bm8sIGhzY3JvbGw9bm8sIHZzY3JvbGw9bm8sIHRpdGxlYmFyPW5vLCBjbG9zZWJ1dHRvbj[...]
Zeile gelöscht : user_pref("CT2832595.hxxp___toolbar_innogames_de_toolbars_switch.APP_WIN_FEATURES", "cmVzaXphYmxlPW5vLCBzYXZlcmVzaXplZHNpemU9bm8sIGhzY3JvbGw9bm8sIHZzY3JvbGw9bm8sIHRpdGxlYmFyPW5vLCBjbG9zZW9uZXh0ZXJuYWx[...]
Zeile gelöscht : user_pref("CT2832595.installType", "DirectDownload");
Zeile gelöscht : user_pref("CT2832595.isCheckedStartAsHidden", true);
Zeile gelöscht : user_pref("CT2832595.isFirstTimeToolbarLoading", "false");
Zeile gelöscht : user_pref("CT2832595.isNewTabEnabled", false);
Zeile gelöscht : user_pref("CT2832595.isPerformedSmartBarTransition", "true");
Zeile gelöscht : user_pref("CT2832595.lastVersion", "10.16.9.506");
Zeile gelöscht : user_pref("CT2832595.migrateAppsAndComponents", true);
Zeile gelöscht : user_pref("CT2832595.search.searchAppId", "129333561190981396");
Zeile gelöscht : user_pref("CT2832595.search.searchCount", "0");
Zeile gelöscht : user_pref("CT2832595.searchInNewTabEnabled", "false");
Zeile gelöscht : user_pref("CT2832595.searchInNewTabEnabledByUser", "false");
Zeile gelöscht : user_pref("CT2832595.searchInNewTabEnabledInHidden", "true");
Zeile gelöscht : user_pref("CT2832595.searchSuggestEnabledByUser", "false");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_Configuration_lastUpdate", "1375206499459");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1375009458381");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_appsMetadata_lastUpdate", "1375206499112");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1375009458311");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_location_lastUpdate", "1373412345753");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_login_10.13.1.89_lastUpdate", "1352675538999");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_login_10.13.40.15_lastUpdate", "1359439471849");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_login_10.14.370.524_lastUpdate", "1370971764622");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_login_10.14.40.128_lastUpdate", "1362905432637");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_login_10.16.2.509_lastUpdate", "1373412345590");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_login_10.16.7.524_lastUpdate", "1375206499186");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_login_lastUpdate", "1352754988964");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1375009458353");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_searchAPI_lastUpdate", "1375206499135");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_serviceMap_lastUpdate", "1375206499061");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_toolbarContextMenu_lastUpdate", "1375009458226");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_toolbarSettings_lastUpdate", "1375213699262");
Zeile gelöscht : user_pref("CT2832595.serviceLayer_services_translation_lastUpdate", "1375206499365");
Zeile gelöscht : user_pref("CT2832595.settingsINI", true);
Zeile gelöscht : user_pref("CT2832595.showToolbarPermission", "false");
Zeile gelöscht : user_pref("CT2832595.smartbar.CTID", "CT2832595");
Zeile gelöscht : user_pref("CT2832595.smartbar.Uninstall", "0");
Zeile gelöscht : user_pref("CT2832595.smartbar.toolbarName", "InnoGames International ");
Zeile gelöscht : user_pref("CT2832595.staemme_market.enc", "ZGU=");
Zeile gelöscht : user_pref("CT2832595.staemme_username_en", "VTJOb1lYUjBaVzVzYjNKa09UST0=");
Zeile gelöscht : user_pref("CT2832595.staemme_village_de84.enc", "MTEyMTI2");
Zeile gelöscht : user_pref("CT2832595.toolbarBornServerTime", "7-9-2012");
Zeile gelöscht : user_pref("CT2832595.toolbarCurrentServerTime", "30-7-2013");
Zeile gelöscht : user_pref("CT2832595.toolbarLoginClientTime", "Thu Mar 14 2013 17:12:08 GMT+0100");
Zeile gelöscht : user_pref("CT2832595.toolbarUrl.enc", "aHR0cDovL3Rvb2xiYXIuaW5ub2dhbWVzLmRlL3Rvb2xiYXJzL3N0YWVtbWUvdG9vbGJhci5waHA=");
Zeile gelöscht : user_pref("CT2832595.toolbar_market.enc", "ZGU=");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true);
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de");
Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "yahoooc");
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "e9086af4-978d-4bd1-a786-e7f8b82eccb6");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "31/05/2013");
Zeile gelöscht : user_pref("extensions.helperbar.publisher", "yahoooc");
Zeile gelöscht : user_pref("extensions.helperbar.type", "hp1000");
Zeile gelöscht : user_pref("smartbar.machineId", "NVVZX4IJEC5ZWH3T8KARERQVVTS0SURDNJ7T/YXT3U7WP3+XWNV+IKZWBABIFNFF4W2ZB0NG8S7EJH/ZHKTVLG");
-\\ Google Chrome v
[ Datei : C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [19163 octets] - [27/03/2014 23:35:16]
AdwCleaner[R1].txt - [16391 octets] - [27/03/2014 23:36:32]
AdwCleaner[S0].txt - [2843 octets] - [27/03/2014 23:35:57]
AdwCleaner[S1].txt - [15591 octets] - [27/03/2014 23:37:07]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [15652 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Professional x64
Ran by Bj”rn on 27.03.2014 at 23:40:52,79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3093385529-1678394880-1889526415-1001\Software\sweetim
~~~ Files
Successfully deleted: [File] "C:\Users\Bj”rn\appdata\local\google\chrome\user data\default\local storage\http_start.iminent.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Bj”rn\appdata\local\google\chrome\user data\default\local storage\http_start.iminent.com_0.localstorage-journal"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Bj”rn\appdata\local\cre"
~~~ FireFox
Successfully deleted the following from C:\Users\Bj”rn\AppData\Roaming\mozilla\firefox\profiles\53h5f9ae.default\prefs.js
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.name", "HDvid-Codec V9.0");
Emptied folder: C:\Users\Bj”rn\AppData\Roaming\mozilla\firefox\profiles\53h5f9ae.default\minidumps [63 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.03.2014 at 23:46:24,46
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.03.2014
Suchlauf-Zeit: 19:48:03
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.03.28.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Björn
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 323389
Verstrichene Zeit: 8 Min, 25 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end) zoek-result: Code:
Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by Bj”rn on 28.03.2014 at 19:50:37,50.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\BJRN~1\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
28.03.2014 19:51:28 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-3093385529-1678394880-1889526415-1001\Software\Mozilla\Firefox\Extensions\{ca101f1f-097d-4e2b-939a-b3b54b675d22} deleted successfully
HKEY_USERS\S-1-5-21-3093385529-1678394880-1889526415-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Mozilla\Firefox\Extensions\{ca101f1f-097d-4e2b-939a-b3b54b675d22} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\BJRN~1\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default\prefs.js:
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.order.1", "Google");
Added to C:\Users\BJRN~1\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\BJRN~1\AppData\Roaming\Thunderbird\Profiles\bzawikeo.default\prefs.js:
Added to C:\Users\BJRN~1\AppData\Roaming\Thunderbird\Profiles\bzawikeo.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\BJRN~1\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default
user.js not found
---- Lines OneClickDownload removed from prefs.js ----
user_pref("extensions.bootstrappedAddons", "{\"OneClickDownload@OneClickDownload.com\":{\"version\":\"1.3\",\"type\":\"extension\",\"descriptor\":\"C:
user_pref("extensions.OneClickDownload.filter", "filter:1,3");
---- Lines OneClickDownload modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}\":{\"descriptor\":\"C:\\\\
---- Lines afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356 removed from prefs.js ----
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.active", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.addressbar", "NA");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.addressbarenhanced", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncdb.was_copied", "true");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncdb_dbWasSet", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncinternaldb.was_copied", "true");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncinternaldb_dbWasSet", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.backgroundver", 2);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.certdomaininstaller", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.changeprevious", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.au.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.au.value", "%222014-3-23%22");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.cnt.expiration", "Fri Feb 01 2030 00:00:0
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.cnt.value", "%22DE%22");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.first_run.expiration", "Fri Feb 01 2030 0
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.first_run.value", "%221%22");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.install.expiration", "Fri Feb 01 2030 00:
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.install.value", "%222014-3-23%22");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.InstallationTime.value", "%221394294937%2
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.testingGaq.expiration", "Fri Feb 01 2030
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.testingGaq.value", "%22http%3A//extclickm
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.description", "HDVid Codec - Enjoy the future of
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.domain", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.enablesearch", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.homepage", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.iframe", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.InstallationThankYouPage", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.InstallationTime", 1394294937);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.__defualt_browser__.value", "%22ch%22
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_bundledUrls.value
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_appVer.value", "26");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_nextCheck.expiration", "Mon
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.lastDailyReport", "1395598950651");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.lastUpdate", "1395598949597");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.manifesturl", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.newtab", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.opensearch", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.pluginsurl", "https://w9u6a2p6.ssl.hwcdn.net/plu
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.pluginsversion", 22);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.publisher", "installdaddy");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.searchstatus", 0);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.setnewtab", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.thankyou", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.updateinterval", 360);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.ver", 26);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.apps", "51356");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.bic", "144f02df54969c62d8158517ecc1b61b");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.cid", 51356);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.FilesValidatorDueTime", "1395599007128");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.firstrun", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.hadappinstalled", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.installationdate", 1395598948);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.modetype", "production");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.reportInstall", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.statsDailyCounter", 1);
---- FireFox user.js and prefs.js backups ----
prefs__2000_.backup
ProfilePath: C:\Users\BJRN~1\AppData\Roaming\Thunderbird\Profiles\bzawikeo.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__2000_.backup
==== Deleting Files \ Folders ======================
C:\Users\Björn\AppData\Local\avgchrome not found
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\Users\BJRN~1\Downloads\SideKickSetup (1).exe deleted
C:\Users\BJRN~1\Downloads\SideKickSetup.exe deleted
C:\Users\BJRN~1\Downloads\FreeYouTubeToMP3Converter31126.exe deleted
C:\Windows\wininit.ini deleted
C:\Users\BJRN~1\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default\jetpack deleted
C:\Users\BJRN~1\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default\CT2832595 deleted
C:\Users\BJRN~1\limboole.exe deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"="C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5" [04.03.2013 15:08]
==== Firefox Extensions ======================
ProfilePath: C:\Users\BJRN~1\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default
- DivX Plus Web Player HTML5 lt;videogt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
- Undetermined - C:\Users\Björn\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default\extensions\{e9086af4-978d-4bd1-a786-e7f8b82eccb6}
- Undetermined - C:\Users\Björn\AppData\Roaming\Mozilla\Firefox\Profiles\53h5f9ae.default\extensions\fca3238e-0f52-4634-8e93-c36d211b2ea9@c1c012cf-93b0-488e-a2c5-453d23bec199.com
- Yahoo Community Smartbar - %ProfilePath%\extensions\{e9086af4-978d-4bd1-a786-e7f8b82eccb6}
- Greasemonkey - %ProfilePath%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
ProfilePath: C:\Users\BJRN~1\AppData\Roaming\Thunderbird\Profiles\bzawikeo.default
- Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi
- Zindus - %ProfilePath%\extensions\{ad7d8a66-253b-11dc-977c-000c29a3126e}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
lmhcioafdnaphcmlajkgbnghloomafka - C:\Program Files (x86)\LyricsParty\133.crx[]
nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[07.02.2013 06:47]
obilhkhfmlggcoildcnoeknaghkiiclj - C:\Users\Bj”rn\AppData\Local\CRE\obilhkhfmlggcoildcnoeknaghkiiclj.crx[]
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
obilhkhfmlggcoildcnoeknaghkiiclj - C:\Users\Bj”rn\AppData\Local\CRE\obilhkhfmlggcoildcnoeknaghkiiclj.crx[]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
==== Reset Google Chrome ======================
C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Default User\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lmhcioafdnaphcmlajkgbnghloomafka deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\obilhkhfmlggcoildcnoeknaghkiiclj deleted successfully
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\obilhkhfmlggcoildcnoeknaghkiiclj deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Björn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Björn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Björn\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Björn\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
No Chrome Cache found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=194 folders=20 52028644 bytes)
==== Empty Temp Folders ======================
C:\Users\Björn\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\postgres\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\BJRN~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 28.03.2014 at 20:07:05,16 ====================== LG,
Björn |