SchokoMilch | 11.09.2013 18:20 | Hier ist die ADW Logdatei:
AdwCleaner Logfile: Code:
# AdwCleaner v3.003 - Bericht erstellt am 11/09/2013 um 18:44:15
# Updated 07/09/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : SchokoMilch - SCHOKOMILCH-PC
# Gestartet von : C:\Users\SchokoMilch\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Program Files (x86)\FindLyrics
Ordner Gelöscht : C:\Program Files (x86)\incredibar.com
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Program Files\Web Assistant
Ordner Gelöscht : C:\Users\SchokoMilch\Qtrax
Ordner Gelöscht : C:\Users\SchokoMilch\AppData\Local\Ilivid
Ordner Gelöscht : C:\Users\SchokoMilch\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\SchokoMilch\AppData\Roaming\DealPly
Ordner Gelöscht : C:\Users\SchokoMilch\AppData\Roaming\DSite
Ordner Gelöscht : C:\Users\SchokoMilch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax
Ordner Gelöscht : C:\Users\SchokoMilch\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Ordner Gelöscht : C:\Users\Hubi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\SchokoMilch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk
Datei Gelöscht : C:\Users\SchokoMilch\Desktop\Qtrax Player.lnk
Datei Gelöscht : C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default\searchplugins\11-suche.xml
Datei Gelöscht : C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default\searchplugins\MyStart Search.xml
Datei Gelöscht : C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\Dealply
Datei Gelöscht : C:\Windows\System32\Tasks\DSite
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Wert Gelöscht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\I
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Incredibar.dskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Incredibar.dskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IncredibarApp.appCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IncredibarApp.appCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\DEALPL~1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\DEALPL~1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_htc-sync_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_htc-sync_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C01315C7-B4E2-4864-B43D-5FAFC414D179}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C1545464-C77C-4130-A572-1C619E2895FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EF7FEC6D-451B-4452-9D26-7E10C6B5DB6E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{48C9C8B0-A546-46C1-A81F-47A31E623E9D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C36554-31F0-49DD-8857-ED6A64DF45BE}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{F9639E4A-801B-4843-AEE3-03D9DA199E77}]
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyricsFan
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\incredibar.com
Schlüssel Gelöscht : HKLM\Software\Web Assistant
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\incredibar
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Tarma Installer
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Web Assistant
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16660
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.incredibar.admin", false);
Zeile gelöscht : user_pref("extensions.incredibar.aflt", "orgnl");
Zeile gelöscht : user_pref("extensions.incredibar.cntry", "DE");
Zeile gelöscht : user_pref("extensions.incredibar.dfltLng", "");
Zeile gelöscht : user_pref("extensions.incredibar.dfltSrch", false);
Zeile gelöscht : user_pref("extensions.incredibar.did", "10665");
Zeile gelöscht : user_pref("extensions.incredibar.envrmnt", "production");
Zeile gelöscht : user_pref("extensions.incredibar.excTlbr", false);
Zeile gelöscht : user_pref("extensions.incredibar.hdrMd5", "6AD7FC4A6ECEAAE55EB9E24D68A2B21B");
Zeile gelöscht : user_pref("extensions.incredibar.hmpg", false);
Zeile gelöscht : user_pref("extensions.incredibar.id", "948776190000000000004c80933575dd");
Zeile gelöscht : user_pref("extensions.incredibar.installerproductid", "26");
Zeile gelöscht : user_pref("extensions.incredibar.instlDay", "15542");
Zeile gelöscht : user_pref("extensions.incredibar.instlRef", "");
Zeile gelöscht : user_pref("extensions.incredibar.isDcmntCmplt", true);
Zeile gelöscht : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1422:26:22");
Zeile gelöscht : user_pref("extensions.incredibar.mntrvrsn", "1.2.0");
Zeile gelöscht : user_pref("extensions.incredibar.newTab", false);
Zeile gelöscht : user_pref("extensions.incredibar.noFFXTlbr", false);
Zeile gelöscht : user_pref("extensions.incredibar.ppd", "");
Zeile gelöscht : user_pref("extensions.incredibar.prdct", "incredibar");
Zeile gelöscht : user_pref("extensions.incredibar.productid", "26");
Zeile gelöscht : user_pref("extensions.incredibar.prtnrId", "Incredibar");
Zeile gelöscht : user_pref("extensions.incredibar.sg", "none");
Zeile gelöscht : user_pref("extensions.incredibar.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.incredibar.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQEazn9Kd&loc=IB_TB&i=26&search=");
Zeile gelöscht : user_pref("extensions.incredibar.upn2", "6PQEazn9Kd");
Zeile gelöscht : user_pref("extensions.incredibar.upn2n", "92543270315376269");
Zeile gelöscht : user_pref("extensions.incredibar.vrsn", "1.5.11.14");
Zeile gelöscht : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1422:26:22");
Zeile gelöscht : user_pref("extensions.incredibar.vrsni", "1.5.11.14");
Zeile gelöscht : user_pref("extensions.incredibar_i.aflt", "orgnl");
Zeile gelöscht : user_pref("extensions.incredibar_i.dfltLng", "");
Zeile gelöscht : user_pref("extensions.incredibar_i.did", "10665");
Zeile gelöscht : user_pref("extensions.incredibar_i.excTlbr", false);
Zeile gelöscht : user_pref("extensions.incredibar_i.id", "948776190000000000004c80933575dd");
Zeile gelöscht : user_pref("extensions.incredibar_i.installerproductid", "26");
Zeile gelöscht : user_pref("extensions.incredibar_i.instlDay", "15542");
Zeile gelöscht : user_pref("extensions.incredibar_i.instlRef", "");
Zeile gelöscht : user_pref("extensions.incredibar_i.ms_url_id", "");
Zeile gelöscht : user_pref("extensions.incredibar_i.newTab", false);
Zeile gelöscht : user_pref("extensions.incredibar_i.ppd", "");
Zeile gelöscht : user_pref("extensions.incredibar_i.prdct", "incredibar");
Zeile gelöscht : user_pref("extensions.incredibar_i.productid", "26");
Zeile gelöscht : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Zeile gelöscht : user_pref("extensions.incredibar_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.incredibar_i.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQEazn9Kd&loc=IB_TB&i=26&search=");
Zeile gelöscht : user_pref("extensions.incredibar_i.upn2", "6PQEazn9Kd");
Zeile gelöscht : user_pref("extensions.incredibar_i.upn2n", "92543270315376269");
Zeile gelöscht : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Zeile gelöscht : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1422:26:22");
Zeile gelöscht : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
Zeile gelöscht : user_pref("extensions.wajam.affiliate_id", "6447");
Zeile gelöscht : user_pref("extensions.wajam.firstrun", "false");
Zeile gelöscht : user_pref("extensions.wajam.log_send_info", "false");
Zeile gelöscht : user_pref("extensions.wajam.mappingListJsonString", "{\"version\":\"0.21086\",\"supported_sites\":{\"google\":{\"patterns\":[\"^hxxp\\\\:\\/\\/www\\\\.google\\\\..{2,3}(|\\\\\\/ig|\\\\\\/firefox)\",\"[...]
Zeile gelöscht : user_pref("extensions.wajam.no_trace", "false");
Zeile gelöscht : user_pref("extensions.wajam.server_current_mapping_version", "0.21086");
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.encryptedgoogle.wajam_google_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'W[...]
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.google.wajam_google_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';[...]
Zeile gelöscht : user_pref("extensions.wajam.trace_log", "1365442632410 - processInstallationUpgrade - isFirstTimeInstallation: false\n1365442632410 - processInstallationUpgrade - isUpgrade: false\n1365442632410 - pro[...]
Zeile gelöscht : user_pref("extensions.wajam.unique_id", "3CBAA230519AEF1184F3E838BDFB649F");
Zeile gelöscht : user_pref("extensions.wajam.user_current_mapping_version", "0");
Zeile gelöscht : user_pref("extensions.wajam.version", "1.26");
Zeile gelöscht : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.sweetim.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"h[...]
[ Datei : C:\Users\Hubi\AppData\Roaming\Mozilla\Firefox\Profiles\7bp8bmmh.default\prefs.js ]
Zeile gelöscht : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.sweetim.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"h[...]
-\\ Google Chrome v29.0.1547.66
[ Datei : C:\Users\SchokoMilch\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Hubi\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [17242 octets] - [11/09/2013 18:43:09]
AdwCleaner[S0].txt - [16859 octets] - [11/09/2013 18:44:15]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16920 octets] ########## --- --- ---
[/CODE]
Hier ist die JRT Logdatei:
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.9 (09.07.2013:1)
OS: Windows 7 Home Premium x64
Ran by SchokoMilch on 11.09.2013 at 19:07:46,59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2896008240-3652194997-1925210094-1002\Software\web assistant
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsFanUpdater_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsFanUpdater_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LyricsFanUpdater_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LyricsFanUpdater_RASMANCS
~~~ Files
Successfully deleted: [File] "C:\Users\SchokoMilch\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\SchokoMilch\AppData\Roaming\isafe"
Successfully deleted: [Folder] "C:\Users\SchokoMilch\music\qtrax media library"
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{00AC2972-D920-4F69-81DA-C285D3C71D7B}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{04B7FB89-0257-4A0E-ADF2-730EA524BC8E}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{05186245-6F5D-4608-B2FD-4FA27355F4E5}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{0A898127-F5BB-4204-80A0-57387787CE3D}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{0AA0B518-B666-4B05-A851-99614168A492}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{0B1506AA-C5F9-4FF6-8566-78EC315BC220}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{0B739A71-C761-4D7C-A5E1-D4F892079076}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{0DCED3DF-E0DF-4682-A78D-4A1758C5A7EE}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{0EAE4BA1-0137-4127-ADD1-004C1FB271FA}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{105CB106-A297-4A0D-80DB-434E3E574944}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{12BF69A9-620B-40A7-8D86-4BDD50DFF392}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{135E21CC-C750-4E7E-BDE7-9D13AECBA21C}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{162FBC7B-1AD2-47BB-800F-E2AB426373C4}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{1AB45432-1AC8-4FAB-9E5F-4B66817796B8}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{1AEFEC64-7665-4981-9476-4313345B3E18}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{1B08CDD5-CE0F-4641-AABD-9D4BD1920218}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{1D9078A7-4FE1-48AC-A16C-004876FAB257}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{2002CF45-D98C-4B61-9D59-B8857A3DD1F9}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{218AA9D1-02C9-4246-B7F6-9B97256E2665}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{21A42D57-0BCE-47C7-A4EB-21EBEBE6E2E1}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{267E36DC-D67C-4C4E-AF73-280175955281}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{28AB6582-D7A0-4EA3-A1C9-A99345B04A05}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{2BB5F9BB-9284-4028-B2FF-5390D2D6EF86}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{2D152836-1135-4B35-B873-916617186DD5}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{2DDB42BA-93FE-41F7-9580-420DFB8DA776}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{32658B1F-EBE7-4DFD-A6AD-A6D58272F1A6}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{33CB9E22-A390-4F03-9B53-2F107038CC28}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{340B8958-7E1E-4192-8DB6-E9DDFE412203}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{3539EB42-945D-4FDD-B80A-7D09047CC27E}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{375F3540-0EAD-4005-80A0-164924201589}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{382562E4-CA1E-4570-AA6E-72D3390E27B0}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{394E017D-C625-48C5-9119-70E64FB7237A}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{39858A59-B00F-46E0-A753-132FE9230EAE}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{3A7EB6AF-2204-4C78-9DB4-37F938A7A3E4}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{3BB73639-11C1-489A-8F8D-D7CC456D3CAE}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{3CB6AFC5-EC72-4EA4-AEB4-02403B411478}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{40FCED0C-5272-4361-A34D-BF59720FFA6E}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{411C3698-E4AA-4533-BBB0-C8AF3EDE0F37}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{41FFC6B2-DE41-4113-938D-C6E9BD639208}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{4381C37F-4DBC-4344-925B-93D95B02C6D0}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{44C17442-39E1-4D86-92B8-80EEDFADB4B8}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{46202A91-0F16-4CB7-9985-A9190243DB5A}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{462763A5-A67A-47BA-A901-662AD86EB61E}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{4A1DF858-D08A-4DB8-A7E0-9C38D7FBB884}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{4A45E33C-79E6-48FC-A120-7D1CC8336174}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{4C9B02E1-DC7C-427E-8967-91502C1E0704}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{4CD94562-9A1A-4A2A-A114-8C68CA3B2797}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{4E5EC3BB-E47B-481B-A634-7D18D24FCFC6}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{50E53E15-E38F-4D97-8F31-CB3A18FEB3C7}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{5134E95A-9BF6-4107-BF99-AF8FA8E72EB1}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{52D388FD-0088-46EF-B56C-A4B423FC8752}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{52DA1FFE-B143-4D1F-8AC3-6B4E65B1DA95}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{56E0F4AE-EB3B-4539-B1CF-F5B182F8F999}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{576ABD5F-27B0-4F5F-AACD-2882ACCDFA12}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{5778C2A5-3AD7-41AC-BC31-17FE6E133A66}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{588ACF9C-EB58-401B-B509-EA246D480CB3}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{5AEA3122-560F-4BD1-9B38-734D93AA690D}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{5E2DC559-EF70-4C99-858C-16CDE8EC4796}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{5F3FCBB9-C96D-4E23-BCF4-B319690809BB}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{60290330-55E6-4A40-95E3-733DC672CFA4}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{608A6981-D98C-4B4B-A4F4-997A2FDA8C08}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{6204AF86-F046-4D13-845F-32E94FB91E8C}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{62AA8E73-FBC1-4BF3-A351-A7D588A9F7ED}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{62FBABFA-10FD-4923-897E-43DFEDD2CE8E}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{63944586-4FD5-4B61-A756-218F56D58859}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{69271CBE-0AAA-4400-817D-09A21DA1B3A1}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{6B18BBE3-D92F-48A0-9A2B-A87D2CB3114C}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{6F33CA98-D414-485E-BA23-E98E40B73DE9}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{700C759F-D127-415A-84C7-06BF65D99E32}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{71CEDD3B-B447-4268-90E1-5AC1A4D0D12B}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{723A900E-E3F2-4EA4-ADFB-6F3F33DC92A4}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{72E2D46C-EB43-47E8-ADF4-25377C1507CB}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{74AE5974-CFD8-49E5-A3A8-E867D1FFFA1C}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{74DAEF6E-A6F2-456A-940C-384E722DEFB2}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{767B0647-9C80-4868-A43D-3224AB90E8F4}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{76F32A15-9C19-4035-982C-366FFB36CDA7}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{789755CC-A41B-4336-9C5C-6687C5A2F1B7}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{7B1F13AB-6F1B-4FB5-8A57-D0C866134384}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{7DF71A07-0F74-4815-B158-1E8A5C097ECE}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{80463958-6A89-4441-A1D0-960EDEECF8EB}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{8164FE88-8060-489B-A9C8-FC72F2F21E3E}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{842186DB-EECB-4F1C-8BAF-ADEF99474E9A}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{8BE25EBD-3214-4F12-A908-067C151B5EC1}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{8F7A54FE-EB20-4DA3-A98F-9CDCEAB94C7F}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{9069D2EB-EA6D-4738-85CD-8A3387F40E35}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{91737628-EF27-4F83-8F28-1E03F93A55F7}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{928771B6-5456-417C-9AE9-F514D114DE70}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{960C8852-7098-48F7-B842-27DF5E0AD476}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{9699205E-AA8D-4B2C-A003-4B7B4CC0ED4F}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{98173E89-73A6-4EAD-BE59-68694A3DE8F2}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{9933515A-F600-412D-9595-8B4C4D067118}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{9C42B2AF-923B-43D1-9CFF-A46915081987}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{9DB98327-F4DE-4C93-8547-B6B774E035AF}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{9FD0CD94-3A74-4954-B522-D224B8921620}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{A09588AD-F3EE-4311-9F8C-2839030C7891}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{A1C86D5B-AFAA-4FD2-9F38-2B3745EC092F}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{A3E34946-D180-4E8C-B09F-634CC58A9FC9}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{A425D59B-6C7C-4F46-86C3-B8C281093D15}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{A5457919-3A18-4C65-8202-180BA16DFA53}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{A80E8B98-5122-432C-8157-12AED6748AA8}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{AF98FFAB-4DA7-4C33-8E89-FBFDA0C22189}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{AFCFB35F-6A98-4DEC-B5F2-5521F4E5278D}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{B70F185B-9EFA-417E-87EF-A06F0F9A253C}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{B8098CFF-ACA4-4D10-A657-84782608072D}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{B8366FE2-D8BC-4BF2-A513-FDF880D4F62F}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{BA2C5858-1510-4607-9885-61D54070C77D}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{BCAA3DF1-EC1C-4DA1-A14A-78C34C4D21B0}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{BCFDCD2B-FDAB-46BB-8478-A7144FD32B79}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{BDD2F655-E919-493A-9472-709A0842CBE6}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{C4D91FE0-7899-402E-A765-28AD3D73EDB0}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{C5075F9E-3716-462B-A050-CCC832E68EF2}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{C5C9962E-C3BB-43CE-A69F-BE5EB1CBEC42}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{C69FF28A-630E-4689-9CF5-625E89EA0160}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{C81ACF33-7AD8-4993-8963-A26ECA61EEF6}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{CA1B230F-46E9-431E-8C78-E7D8CA0E79E9}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{CA9F853C-4482-4AF1-BE19-5104FA126131}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{CDBFA3CC-F2EC-4D9D-8865-419B4A4196AC}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{CF631EF5-C29B-445F-8B0E-F4F8770C8B16}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{D0C9E120-6959-4F42-96F1-990F823B8F57}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{D0D2985B-0EEB-4A16-8FC4-9969AD747FB0}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{D52795AE-FBD1-4EED-B0EF-CE8D416C09DF}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{D572E0E6-C714-4B5C-B351-CA1EA9F9F56E}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{D68B31A2-BF2F-4EE7-A3A8-648CFD4993E4}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{D73AFC8C-E246-44D7-A145-8F7F78063893}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{D7C5DF17-7E7D-48DD-8DAC-78DACC737F90}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{D813542E-89F1-42C9-8803-B922B11AC5AD}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{DB0E0C73-AE46-4645-838F-CD6288AE3906}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{DC9EE473-5CC1-4D1E-951B-4A10E3C85483}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{E26C1E0D-1450-423F-B7F9-7DF2568E4EB7}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{E2D84A78-60A6-42E0-834B-55D032269375}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{E3F25FCA-EF95-48E2-A315-E417457DA1B6}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{E5B235DB-F104-4D05-9B9D-0C83CD83FF7F}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{E60DE4CD-51AF-43A4-B12B-775891FB50CB}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{E64CD733-4155-4652-A9A8-4EAB77D53115}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{E7818C35-D64E-4131-89AC-FB974271DCB9}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{E8D7C977-7DF4-4699-8DA7-AB0F23DE7ACB}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{ED4AE371-DE8F-43BE-AB7E-C1067B4802A4}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{EEF37C44-3D75-4299-98D6-20110C694C10}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F0CBD4D7-A73F-47E8-A0B6-9163196F7E0A}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F0FA0C85-0718-45FE-BDD7-281B2238D1B8}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F15299FF-A903-477E-9E77-232691B4CB26}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F4611A3F-4410-450A-A68B-567A514CB963}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F4ABBCC2-A046-4142-A16F-8A33C9F80E6D}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F5282544-F084-4DD1-A8D6-29A0F2C019B5}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F574B946-46E4-4825-987E-BD412D555CFB}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F6B0B0C3-8683-4C57-A9FE-A34303241509}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{F780E87F-CC80-4AC2-9949-A1F39FEDAAA9}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{FBBF42C0-F863-4B84-A9F1-D32B997DF95B}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{FC2717E0-EE79-4843-9796-266944BABF8C}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{FC798F07-A5F8-4BA7-8057-51981DF22ED9}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{FCA5B6EE-7C2F-46D9-BB00-13355CBDD94E}
Successfully deleted: [Empty Folder] C:\Users\SchokoMilch\appdata\local\{FFA95E82-5B58-40D0-B631-71FB34A433EB}
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [Folder] C:\Users\SchokoMilch\AppData\Roaming\mozilla\firefox\profiles\25g5in07.default\extensions\toolbar@web.de
Emptied folder: C:\Users\SchokoMilch\AppData\Roaming\mozilla\firefox\profiles\25g5in07.default\minidumps [51 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\SchokoMilch\appdata\local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.09.2013 at 19:18:10,80
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-09-2013
Ran by SchokoMilch (administrator) on SCHOKOMILCH-PC on 11-09-2013 19:23:01
Running from C:\Users\SchokoMilch\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
() C:\Users\SchokoMilch\AppData\Roaming\Mikogo 4\M4-Service.exe
(Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
() C:\Users\SchokoMilch\AppData\Roaming\Mikogo 4\M4-Capture.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(TomTom) C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
() C:\Users\SchokoMilch\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
() C:\Program Files (x86)\Versandhelfer\Versandhelfer.exe
() C:\Users\SchokoMilch\AppData\Roaming\Mikogo 4\mikogo-host.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
() C:\Program Files (x86)\PHotkey\POSD.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\SchokoMilch\Downloads\FRST64(2).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2832168 2011-09-30] (Synaptics Incorporated)
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-09-16] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-22] (Alcor Micro Corp.)
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
HKCU\...\Run: [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-03-19] (Google Inc.)
HKCU\...\Run: [msnmsgr] - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4280184 2012-03-08] (Microsoft Corporation)
HKCU\...\Run: [MyTomTomSA.exe] - C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [434168 2012-05-18] (TomTom)
HKCU\...\Run: [Facebook Update] - C:\Users\SchokoMilch\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-11-21] (Facebook Inc.)
HKCU\...\Run: [] - [x]
HKCU\...\Run: [NokiaSuite.exe] - C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090040 2012-12-21] (Nokia)
HKCU\...\Run: [Mikogo] - C:\Users\SchokoMilch\AppData\Roaming\Mikogo 4\mikogo-host.exe [6323016 2013-04-10] ()
HKCU\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\SchokoMilch\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20681584 2013-07-25] (Skype Technologies S.A.)
HKCU\...\RunOnce: [Application Restart #2] - C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe "C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe" [383488 2009-07-14] (Microsoft Corporation)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2011-03-31] (CyberLink Corp.)
HKLM-x32\...\Run: [HTC Sync Loader] - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [651264 2012-04-17] ()
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [Nikon Message Center 2] - C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [619008 2010-05-25] (Nikon Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.)
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2013-05-04] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-23] ()
HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-23] ()
HKU\Hubi\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-03-19] (Google Inc.)
HKU\Hubi\...\Run: [TomTomHOME.exe] - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [247768 2012-07-26] (TomTom)
Startup: C:\Users\Hubi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Versandhelfer.lnk
ShortcutTarget: Versandhelfer.lnk -> C:\Program Files (x86)\Versandhelfer\Versandhelfer.exe ()
Startup: C:\Users\SchokoMilch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Versandhelfer.lnk
ShortcutTarget: Versandhelfer.lnk -> C:\Program Files (x86)\Versandhelfer\Versandhelfer.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.1 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.10 - C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.1 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\SchokoMilch\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\SchokoMilch\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF SearchPlugin: C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\SchokoMilch\AppData\Roaming\Mozilla\Firefox\Profiles\25g5in07.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\SCHOKO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\SCHOKO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\SCHOKO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\SCHOKO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Kaspersky URL Advisor) - C:\Users\SCHOKO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_0
CHR Extension: (Virtual Keyboard) - C:\Users\SCHOKO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_0
CHR Extension: (Gmail) - C:\Users\SCHOKO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR Extension: (Anti-Banner) - C:\Users\SCHOKO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx
==================== Services (Whitelisted) =================
R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2009-12-19] ()
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2013-05-04] (Kaspersky Lab ZAO)
R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [70952 2011-04-14] (CyberLink)
R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [312616 2011-04-14] (CyberLink)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [156672 2011-10-14] ()
R2 M4-Service; C:\Users\SchokoMilch\AppData\Roaming\Mikogo 4\M4-Service.exe [1008968 2013-04-10] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-09-16] ()
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2012-03-23] ()
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2012-11-24] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] ()
==================== Drivers (Whitelisted) ====================
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-09-16] ()
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620128 2013-05-04] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29016 2012-10-25] (Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29528 2012-10-25] (Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-20] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-05-04] (Kaspersky Lab ZAO)
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2012-04-22] (hxxp://libusb-win32.sourceforge.net)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-09-16] ()
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-12] (PEGATRON)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-05-04] (Kaspersky Lab ZAO)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-11 19:18 - 2013-09-11 19:18 - 00019290 _____ C:\Users\SchokoMilch\Desktop\JRT.txt
2013-09-11 19:04 - 2013-09-11 19:04 - 01029490 _____ (Thisisu) C:\Users\SchokoMilch\Desktop\JRT.exe
2013-09-11 18:42 - 2013-09-11 18:44 - 00000000 ____D C:\AdwCleaner
2013-09-11 18:42 - 2013-09-11 18:42 - 01037278 _____ C:\Users\SchokoMilch\Downloads\adwcleaner.exe
2013-09-11 13:08 - 2013-09-11 13:46 - 09430408 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-09-11 01:51 - 2013-09-11 01:51 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Neuer Ordner
2013-09-11 01:15 - 2013-09-11 13:44 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-09-11 01:12 - 2013-09-11 01:50 - 00000000 ____D C:\Users\SchokoMilch\Desktop\mbar
2013-09-11 01:11 - 2013-09-11 01:12 - 12907592 _____ (Malwarebytes Corp.) C:\Users\SchokoMilch\Downloads\mbar-1.07.0.1005.exe
2013-09-10 23:35 - 2013-09-11 00:09 - 00038508 _____ C:\Users\SchokoMilch\Downloads\Addition.txt
2013-09-10 23:33 - 2013-09-10 23:33 - 00000000 ____D C:\FRST
2013-09-10 23:32 - 2013-09-10 23:33 - 01949196 _____ (Farbar) C:\Users\SchokoMilch\Downloads\FRST64(1).exe
2013-09-10 23:32 - 2013-09-10 23:32 - 01949196 _____ (Farbar) C:\Users\SchokoMilch\Downloads\FRST64.exe
2013-09-10 23:31 - 2013-09-10 23:31 - 01082349 _____ (Farbar) C:\Users\SchokoMilch\Downloads\FRST.exe
2013-09-10 23:18 - 2013-09-10 23:18 - 00000000 ____D C:\Users\SchokoMilch\AppData\Roaming\Malwarebytes
2013-09-10 23:17 - 2013-09-10 23:17 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-10 23:15 - 2013-09-10 23:15 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\SchokoMilch\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-09-10 23:14 - 2013-09-10 23:14 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\SchokoMilch\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-10 22:33 - 2013-09-10 22:33 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk
2013-09-10 22:33 - 2013-09-10 22:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-09-10 22:31 - 2013-09-10 22:33 - 32782192 _____ (Skype Technologies S.A.) C:\Users\SchokoMilch\Downloads\SkypeSetupFull(1).exe
2013-09-10 22:31 - 2013-09-10 22:31 - 00003148 _____ C:\Windows\System32\Tasks\{922C973C-31F1-410D-B136-2588979BA248}
2013-09-10 22:28 - 2013-09-10 22:29 - 32776560 _____ (Skype Technologies S.A.) C:\Users\SchokoMilch\Downloads\SkypeSetupFull.exe
2013-09-08 22:41 - 2013-09-11 19:05 - 00000000 ____D C:\Windows\ERUNT
2013-09-07 20:27 - 2013-09-07 20:44 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Rüdesheim
2013-09-07 19:40 - 2013-09-11 18:46 - 00000560 _____ C:\Windows\setupact.log
2013-09-07 19:40 - 2013-09-07 19:40 - 00001500 _____ C:\Windows\PFRO.log
2013-09-07 19:40 - 2013-09-07 19:40 - 00000000 _____ C:\Windows\setuperr.log
2013-09-02 19:46 - 2013-09-02 19:46 - 00000000 ____D C:\Users\SchokoMilch\AppData\Roaming\eCyber
2013-09-02 19:45 - 2013-09-02 19:45 - 00000000 ____D C:\Users\Hubi\AppData\Roaming\iSafe
2013-09-02 19:44 - 2013-09-02 19:44 - 00633672 _____ (Woodtale Technology Inc) C:\Users\SchokoMilch\Downloads\iSafedl.exe
2013-09-01 21:12 - 2013-09-01 21:33 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Mit Papa und Iva
2013-08-26 16:29 - 2013-08-26 16:29 - 00000000 ____D C:\Users\SchokoMilch\AppData\Roaming\OpenOffice
2013-08-25 22:00 - 2013-09-03 21:42 - 00000000 ____D C:\Users\Hubi\Desktop\bewerbung-ciba-vision
2013-08-25 21:49 - 2013-08-25 21:49 - 00000000 ____D C:\Users\Hubi\AppData\Roaming\OpenOffice
2013-08-25 21:10 - 2013-08-25 21:49 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-08-25 21:07 - 2013-08-25 21:07 - 00000000 ____D C:\Users\Hubi\Desktop\OpenOffice 4.0.0 (de) Installation Files
2013-08-25 20:02 - 2013-08-25 21:07 - 162401424 _____ C:\Users\Hubi\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de (1).exe
2013-08-25 19:57 - 2013-08-25 19:58 - 05239951 _____ C:\Users\Hubi\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe.part
2013-08-25 19:57 - 2013-08-25 19:57 - 03289915 _____ C:\Users\Hubi\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de(1).exe.part
2013-08-25 19:53 - 2013-08-25 19:53 - 00000000 ____D C:\Users\Hubi\AppData\Local\Microsoft Help
2013-08-19 14:32 - 2012-12-06 13:52 - 00136704 _____ C:\Windows\system32\ZLhp2600.DLL
2013-08-18 00:43 - 2013-08-18 00:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 16:00 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-16 16:00 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-16 16:00 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-16 16:00 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-16 16:00 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-16 16:00 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-16 16:00 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-16 16:00 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-16 16:00 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-16 16:00 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-16 16:00 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-16 16:00 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-16 16:00 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-16 16:00 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-16 16:00 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-16 16:00 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-16 16:00 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-16 16:00 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-16 16:00 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-16 16:00 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-16 15:59 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-16 15:59 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-16 15:59 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-16 15:59 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-16 15:59 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-16 15:59 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-16 15:59 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-16 15:59 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-16 15:59 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-16 15:59 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-16 15:59 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-15 13:45 - 2013-08-15 13:45 - 00003365 _____ C:\Users\SCHOKO~1\AppData\Local\recently-used.xbel
2013-08-15 11:28 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 11:28 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-15 11:28 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-15 11:28 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-15 11:28 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 11:28 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 11:28 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 11:28 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 11:28 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 11:28 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-15 11:28 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-15 11:28 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-15 11:28 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-15 11:28 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-15 11:27 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-15 11:27 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-15 11:27 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-15 11:27 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-15 11:27 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-15 11:27 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-15 11:27 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-15 11:27 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-15 11:27 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-15 11:27 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-15 11:27 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-15 11:27 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 11:27 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-09-11 19:22 - 2013-09-11 19:22 - 01949408 _____ (Farbar) C:\Users\SchokoMilch\Downloads\FRST64(2).exe
2013-09-11 19:18 - 2013-09-11 19:18 - 00019290 _____ C:\Users\SchokoMilch\Desktop\JRT.txt
2013-09-11 19:07 - 2012-03-19 18:58 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-11 19:06 - 2012-04-12 23:19 - 00000000 ____D C:\Users\SchokoMilch\AppData\Roaming\Skype
2013-09-11 19:05 - 2013-09-08 22:41 - 00000000 ____D C:\Windows\ERUNT
2013-09-11 19:04 - 2013-09-11 19:04 - 01029490 _____ (Thisisu) C:\Users\SchokoMilch\Desktop\JRT.exe
2013-09-11 18:55 - 2009-07-14 06:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-11 18:55 - 2009-07-14 06:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-11 18:50 - 2012-04-02 19:15 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-09-11 18:50 - 2012-03-19 18:06 - 00000000 ____D C:\Users\SchokoMilch\Documents\Youcam
2013-09-11 18:48 - 2012-07-19 21:31 - 00000000 ____D C:\Users\SCHOKO~1\AppData\Local\Htc
2013-09-11 18:48 - 2012-07-06 22:36 - 00000000 ____D C:\Users\SchokoMilch\Tracing
2013-09-11 18:47 - 2012-03-19 18:58 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-11 18:46 - 2013-09-07 19:40 - 00000560 _____ C:\Windows\setupact.log
2013-09-11 18:46 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-11 18:45 - 2012-03-19 18:56 - 01642895 _____ C:\Windows\WindowsUpdate.log
2013-09-11 18:44 - 2013-09-11 18:42 - 00000000 ____D C:\AdwCleaner
2013-09-11 18:44 - 2012-03-19 18:03 - 00000000 ____D C:\Users\SchokoMilch
2013-09-11 18:43 - 2012-11-21 22:38 - 00000952 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2896008240-3652194997-1925210094-1002UA.job
2013-09-11 18:42 - 2013-09-11 18:42 - 01037278 _____ C:\Users\SchokoMilch\Downloads\adwcleaner.exe
2013-09-11 17:46 - 2013-06-29 21:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-11 13:46 - 2013-09-11 13:08 - 09430408 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-09-11 13:46 - 2013-06-29 21:29 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-11 13:46 - 2013-03-22 00:34 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-11 13:46 - 2011-11-07 18:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-11 13:44 - 2013-09-11 01:15 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-09-11 13:35 - 2013-07-06 20:41 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Masken
2013-09-11 01:51 - 2013-09-11 01:51 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Neuer Ordner
2013-09-11 01:50 - 2013-09-11 01:12 - 00000000 ____D C:\Users\SchokoMilch\Desktop\mbar
2013-09-11 01:12 - 2013-09-11 01:11 - 12907592 _____ (Malwarebytes Corp.) C:\Users\SchokoMilch\Downloads\mbar-1.07.0.1005.exe
2013-09-11 00:09 - 2013-09-10 23:35 - 00038508 _____ C:\Users\SchokoMilch\Downloads\Addition.txt
2013-09-10 23:33 - 2013-09-10 23:33 - 00000000 ____D C:\FRST
2013-09-10 23:33 - 2013-09-10 23:32 - 01949196 _____ (Farbar) C:\Users\SchokoMilch\Downloads\FRST64(1).exe
2013-09-10 23:32 - 2013-09-10 23:32 - 01949196 _____ (Farbar) C:\Users\SchokoMilch\Downloads\FRST64.exe
2013-09-10 23:31 - 2013-09-10 23:31 - 01082349 _____ (Farbar) C:\Users\SchokoMilch\Downloads\FRST.exe
2013-09-10 23:18 - 2013-09-10 23:18 - 00000000 ____D C:\Users\SchokoMilch\AppData\Roaming\Malwarebytes
2013-09-10 23:17 - 2013-09-10 23:17 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-10 23:15 - 2013-09-10 23:15 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\SchokoMilch\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-09-10 23:14 - 2013-09-10 23:14 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\SchokoMilch\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-10 22:47 - 2013-07-28 00:49 - 00000114 _____ C:\Users\SchokoMilch\AppData\Roaming\WB.CFG
2013-09-10 22:47 - 2013-07-18 20:44 - 00000005 _____ C:\Users\SchokoMilch\AppData\Roaming\WBPU-TTL.DAT
2013-09-10 22:33 - 2013-09-10 22:33 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk
2013-09-10 22:33 - 2013-09-10 22:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-09-10 22:33 - 2013-09-10 22:31 - 32782192 _____ (Skype Technologies S.A.) C:\Users\SchokoMilch\Downloads\SkypeSetupFull(1).exe
2013-09-10 22:33 - 2012-04-12 23:19 - 00000000 ____D C:\ProgramData\Skype
2013-09-10 22:31 - 2013-09-10 22:31 - 00003148 _____ C:\Windows\System32\Tasks\{922C973C-31F1-410D-B136-2588979BA248}
2013-09-10 22:29 - 2013-09-10 22:28 - 32776560 _____ (Skype Technologies S.A.) C:\Users\SchokoMilch\Downloads\SkypeSetupFull.exe
2013-09-10 21:59 - 2012-11-21 22:38 - 00000930 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2896008240-3652194997-1925210094-1002Core.job
2013-09-09 11:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-08 22:52 - 2011-11-04 03:51 - 03566406 _____ C:\Windows\system32\perfh007.dat
2013-09-08 22:52 - 2011-11-04 03:51 - 01061214 _____ C:\Windows\system32\perfc007.dat
2013-09-08 22:52 - 2009-07-14 07:13 - 00005194 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-08 22:46 - 2013-04-27 00:43 - 00000000 ____D C:\Users\SchokoMilch\AppData\Roaming\Mikogo 4
2013-09-08 22:20 - 2012-03-19 18:06 - 00000000 ____D C:\Users\SCHOKO~1\AppData\Local\Google
2013-09-08 01:19 - 2012-07-21 07:56 - 00000000 ____D C:\Users\Hubi\AppData\Local\Htc
2013-09-07 23:39 - 2013-06-30 20:10 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Urlaub Spanien 2013
2013-09-07 20:44 - 2013-09-07 20:27 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Rüdesheim
2013-09-07 19:41 - 2009-07-14 06:45 - 00545760 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-07 19:40 - 2013-09-07 19:40 - 00001500 _____ C:\Windows\PFRO.log
2013-09-07 19:40 - 2013-09-07 19:40 - 00000000 _____ C:\Windows\setuperr.log
2013-09-07 19:40 - 2012-05-24 16:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-03 21:42 - 2013-08-25 22:00 - 00000000 ____D C:\Users\Hubi\Desktop\bewerbung-ciba-vision
2013-09-02 19:54 - 2012-03-22 23:27 - 00000000 ____D C:\Windows\Minidump
2013-09-02 19:46 - 2013-09-02 19:46 - 00000000 ____D C:\Users\SchokoMilch\AppData\Roaming\eCyber
2013-09-02 19:46 - 2012-03-21 11:47 - 00150512 _____ C:\Users\Hubi\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-02 19:45 - 2013-09-02 19:45 - 00000000 ____D C:\Users\Hubi\AppData\Roaming\iSafe
2013-09-02 19:44 - 2013-09-02 19:44 - 00633672 _____ (Woodtale Technology Inc) C:\Users\SchokoMilch\Downloads\iSafedl.exe
2013-09-01 21:33 - 2013-09-01 21:12 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Mit Papa und Iva
2013-08-30 14:49 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-26 16:29 - 2013-08-26 16:29 - 00000000 ____D C:\Users\SchokoMilch\AppData\Roaming\OpenOffice
2013-08-25 23:41 - 2012-03-19 18:04 - 00150512 _____ C:\Users\SCHOKO~1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-25 21:49 - 2013-08-25 21:49 - 00000000 ____D C:\Users\Hubi\AppData\Roaming\OpenOffice
2013-08-25 21:49 - 2013-08-25 21:10 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-08-25 21:07 - 2013-08-25 21:07 - 00000000 ____D C:\Users\Hubi\Desktop\OpenOffice 4.0.0 (de) Installation Files
2013-08-25 21:07 - 2013-08-25 20:02 - 162401424 _____ C:\Users\Hubi\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de (1).exe
2013-08-25 19:58 - 2013-08-25 19:57 - 05239951 _____ C:\Users\Hubi\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de.exe.part
2013-08-25 19:57 - 2013-08-25 19:57 - 03289915 _____ C:\Users\Hubi\Downloads\Apache_OpenOffice_4.0.0_Win_x86_install_de(1).exe.part
2013-08-25 19:53 - 2013-08-25 19:53 - 00000000 ____D C:\Users\Hubi\AppData\Local\Microsoft Help
2013-08-25 19:53 - 2012-10-03 18:44 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-18 20:55 - 2013-07-24 21:03 - 00000005 _____ C:\Users\SchokoMilch\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-08-18 15:52 - 2013-07-06 21:38 - 00070656 ____H C:\Users\SchokoMilch\Desktop\photothumb.db
2013-08-18 00:43 - 2013-08-18 00:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 15:48 - 2013-08-08 15:06 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 15:23 - 2011-11-03 22:34 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-15 13:54 - 2013-06-26 00:23 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Originals
2013-08-15 13:51 - 2012-10-05 23:14 - 00000000 ____D C:\Users\SchokoMilch\.gimp-2.8
2013-08-15 13:45 - 2013-08-15 13:45 - 00003365 _____ C:\Users\SCHOKO~1\AppData\Local\recently-used.xbel
2013-08-15 00:10 - 2013-04-18 21:49 - 00000000 ____D C:\Users\SchokoMilch\Desktop\Anhänge_2013418
Files to move or delete:
====================
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLeu.DAT
C:\ProgramData\PKP_DLev.DAT
C:\Users\SCHOKO~1\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\SCHOKO~1\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-02 15:06
==================== End Of Log ============================ --- --- --- |