baumdeva | 26.10.2013 21:51 | Da war ich wohl schon wieder zu voreilig. Mittendrin kam die Meldung, dass Delta toolbar jetzt gelöscht ist, und aus der Liste der Programme ist es auch verschwunden.
Die Logs: Code:
# AdwCleaner v3.010 - Bericht erstellt am 26/10/2013 um 22:30:23
# Updated 20/10/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Sarina - VICTORIA
# Gestartet von : C:\Users\sarinchen\Desktop\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : \END
Datei Gefunden : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\bprotector_extensions.sqlite
Datei Gefunden : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\bprotector_prefs.js
Datei Gefunden : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\searchplugins\Babylon.xml
Datei Gefunden : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\searchplugins\BrowserDefender.xml
Datei Gefunden : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\searchplugins\Conduit.xml
Datei Gefunden : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\user.js
Datei Gefunden : C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\bprotector_extensions.sqlite
Datei Gefunden : C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\bprotector_prefs.js
Datei Gefunden : C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\foxydeal.sqlite
Datei Gefunden : C:\windows\System32\Tasks\AmiUpdXp
Datei Gefunden : C:\windows\System32\Tasks\BrowserDefendert
Datei Gefunden : C:\windows\Tasks\AmiUpdXp.job
Ordner Gefunden : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\Extensions\{462be121-2b54-4218-bf00-b9bf8135b23f}
Ordner Gefunden : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\Extensions\50cd0a86c12ae@50cd0a86c12e8.com
Ordner Gefunden C:\Program Files (x86)\BrowseToSave
Ordner Gefunden C:\ProgramData\Babylon
Ordner Gefunden C:\ProgramData\Browse2Save
Ordner Gefunden C:\ProgramData\Browse2save
Ordner Gefunden C:\Users\Sarina\AppData\Local\SwvUpdater
Ordner Gefunden C:\Users\Sarina\AppData\Roaming\Babylon
Ordner Gefunden C:\Users\Sarina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
Ordner Gefunden C:\Users\Sarina\AppData\Roaming\OpenCandy
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\5a53d7dfb33cba15
Schlüssel Gefunden : HKCU\Software\AppDataLow\SProtector
Schlüssel Gefunden : HKCU\Software\BabSolution
Schlüssel Gefunden : HKCU\Software\DataMngr
Schlüssel Gefunden : HKCU\Software\DataMngr_Toolbar
Schlüssel Gefunden : HKCU\Software\Delta
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Schlüssel Gefunden : [x64] HKCU\Software\BabSolution
Schlüssel Gefunden : [x64] HKCU\Software\DataMngr
Schlüssel Gefunden : [x64] HKCU\Software\DataMngr_Toolbar
Schlüssel Gefunden : [x64] HKCU\Software\Delta
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKLM\SOFTWARE\5a53d7dfb33cba15
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Schlüssel Gefunden : HKLM\Software\DataMngr
Schlüssel Gefunden : HKLM\Software\Delta
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\jgnddndhkgojgeoeapjgicdgflhdldja
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\wsconduit__166_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\wsconduit__166_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Schlüssel Gefunden : HKLM\Software\SP Global
Schlüssel Gefunden : HKLM\Software\SProtector
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
***** [ Browser ] *****
-\\ Internet Explorer v0.0.0.0
Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=1E96E8039A88DAF9&affID=121564&tsp=4974
-\\ Mozilla Firefox v24.0 (de)
[ Datei : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\prefs.js ]
Zeile gefunden : user_pref("browser.search.defaultthis.engineName", "WhiteSmoke US New Customized Web Search");
Zeile gefunden : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3244149&SearchSource=3&q={searchTerms}");
Zeile gefunden : user_pref("CT3244149.browser.search.defaultthis.engineName", "true");
Zeile gefunden : user_pref("CT3244149.keyword", "true");
Zeile gefunden : user_pref("CT3244149.smartbar.homepage", "true");
Zeile gefunden : user_pref("extensions.50cd0a86c135b.scode", "if(window.self.location.protocol.indexOf('hxxp')>-1 && window.self==window.top && !document.getElementById('sjsjszmzmaw28aj6')){var script=document.createE[...]
Zeile gefunden : user_pref("extensions.delta.admin", false);
Zeile gefunden : user_pref("extensions.delta.aflt", "babsst");
Zeile gefunden : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gefunden : user_pref("extensions.delta.autoRvrt", "false");
Zeile gefunden : user_pref("extensions.delta.dfltLng", "de");
Zeile gefunden : user_pref("extensions.delta.excTlbr", false);
Zeile gefunden : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gefunden : user_pref("extensions.delta.id", "1e9670fd000000000000e8039a88daf9");
Zeile gefunden : user_pref("extensions.delta.instlDay", "15931");
Zeile gefunden : user_pref("extensions.delta.instlRef", "sst");
Zeile gefunden : user_pref("extensions.delta.newTab", false);
Zeile gefunden : user_pref("extensions.delta.prdct", "delta");
Zeile gefunden : user_pref("extensions.delta.prtnrId", "delta");
Zeile gefunden : user_pref("extensions.delta.rvrt", "false");
Zeile gefunden : user_pref("extensions.delta.smplGrp", "none");
Zeile gefunden : user_pref("extensions.delta.tlbrId", "base");
Zeile gefunden : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gefunden : user_pref("extensions.delta.vrsn", "1.8.22.0");
Zeile gefunden : user_pref("extensions.delta.vrsni", "1.8.22.0");
Zeile gefunden : user_pref("extensions.delta.vrsnTs", "1.8.22.014:05:10");
Zeile gefunden : user_pref("extensions.delta_i.babExt", "");
Zeile gefunden : user_pref("extensions.delta_i.babTrack", "affID=121564&tsp=4974");
Zeile gefunden : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gefunden : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3244149&SearchSource=13");
Zeile gefunden : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3244149&SearchSource=2&q=");
Zeile gefunden : user_pref("smartbar.originalHomepage", "about:blank");
Zeile gefunden : user_pref("smartbar.originalSearchAddressUrl", "");
Zeile gefunden : user_pref("smartbar.originalSearchEngine", "");
Zeile gefunden : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
[ Datei : C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\prefs.js ]
Zeile gefunden : user_pref("aol_toolbar.default.homepage.check", false);
Zeile gefunden : user_pref("aol_toolbar.default.search.check", false);
Zeile gefunden : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Zeile gefunden : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Zeile gefunden : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Zeile gefunden : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Zeile gefunden : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Zeile gefunden : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Zeile gefunden : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ".*");
Zeile gefunden : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "1");
Zeile gefunden : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "1");
Zeile gefunden : user_pref("sweetim.toolbar.searchguard.enable", "false");
*************************
AdwCleaner[R0].txt - [9430 octets] - [26/10/2013 22:30:23]
########## EOF - \AdwCleaner\AdwCleaner[R0].txt - [9490 octets] ##########
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2013 01
Ran by sarinchen (ATTENTION: The logged in user is not administrator) on VICTORIA on 26-10-2013 22:45:01
Running from D:\_Sarina\Trojanerkampf
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2149160 2010-05-21] (Synaptics Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-08-12] (Microsoft Corporation)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [140568 2008-02-27] (Acronis)
HKLM\...\Runonce: [MSPCLOCK] - rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
HKLM\...\Runonce: [MSPQM] - rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
HKLM\...\Runonce: [MSKSSRV] - rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
HKLM\...\Runonce: [MSTEE.CxTransform] - rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\windows\inf\ksfilter.inf,MSTEE.Interface.Install
HKLM\...\Runonce: [MSTEE.Splitter] - rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\windows\inf\ksfilter.inf,MSTEE.Interface.Install
HKLM\...\Runonce: [WDM_DRMKAUD] - rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\windows\inf\WDMAUDIO.inf,WDM_DRMKAUD.Interface.Install
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-02-26] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe [87336 2010-09-20] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-02] (CyberLink)
HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2622112 2008-02-27] (Acronis)
HKLM-x32\...\Run: [AcronisTimounterMonitor] - C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [911184 2008-02-27] (Acronis)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
AppInit_DLLs-x32: [ ] ()
Lsa: [Authentication Packages] msv1_0 relog_ap
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu
FF NewTab: user_pref("browser.newtab.url", "");
FF DefaultSearchEngine: LEO Eng-Deu
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", "");
FF SelectedSearchEngine: LEO Eng-Deu
FF Homepage: user_pref("browser.startup.homepage", "");
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\PDFViewer\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\PDFViewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\sarinchen\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{de54d057-a919-42bd-bd12-402c0de91fc9}.xpi
FF Extension: HTTPS-Everywhere - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\https-everywhere@eff.org
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\ich@maltegoetz.de
FF Extension: Pocket - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\isreaditlater@ideashower.com
FF Extension: Forecastfox - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF Extension: sharemenot - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\sharemenot@franziroesner.com.xpi
FF Extension: tinyurl.addon - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\tinyurl.addon@fast-chat.co.uk.xpi
FF Extension: prefs - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi
FF Extension: noscript - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: Adblock Plus - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: bprivacyprefs - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
FF Extension: greasemonkey - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF Extension: No Name - C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
==================== Services (Whitelisted) =================
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-09-02] (Nero AG)
R2 lmhosts; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-08-12] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-08-12] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] ()
R2 TryAndDecideService; C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [498792 2008-02-27] ()
==================== Drivers (Whitelisted) ====================
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-05-11] (Windows (R) 2003 DDK 3790 provider)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-26 22:30 - 2013-10-26 22:42 - 00000000 ____D C:\AdwCleaner
2013-10-26 22:29 - 2013-10-26 22:29 - 01060070 _____ C:\Users\sarinchen\Desktop\adwcleaner.exe
2013-10-26 21:31 - 2013-10-26 21:31 - 00000000 ____D C:\FRST
2013-10-22 19:54 - 2013-10-22 19:54 - 00010213 _____ C:\Users\sarinchen\Documents\HK1213 Teufel Theater 6_korr.rb1
2013-10-22 19:54 - 2013-10-22 19:25 - 00010183 _____ C:\Users\sarinchen\Documents\HK1213 Teufel Theater 6_korr.rb2
2013-10-22 13:30 - 2013-10-22 13:30 - 00006953 _____ C:\Users\sarinchen\Documents\Sony KD-55X9005-neu_korr.rb1
2013-10-22 13:30 - 2013-10-22 13:24 - 00006838 _____ C:\Users\sarinchen\Documents\Sony KD-55X9005-neu_korr.rb2
2013-10-22 13:23 - 2013-10-22 13:23 - 00003304 _____ C:\Users\sarinchen\Documents\Inakustik Bluetooth-Receiver_korr.rb1
2013-10-22 13:23 - 2013-10-22 13:20 - 00003312 _____ C:\Users\sarinchen\Documents\Inakustik Bluetooth-Receiver_korr.rb2
2013-10-22 13:08 - 2013-10-22 13:16 - 00006768 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb1
2013-10-22 13:08 - 2013-10-22 13:15 - 00006768 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb2
2013-10-22 13:08 - 2013-10-22 13:11 - 00006027 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb3
2013-10-22 13:08 - 2013-10-22 13:08 - 00006045 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb4
2013-10-22 13:08 - 2013-10-22 13:05 - 00006048 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb5
2013-10-22 12:50 - 2013-10-22 12:53 - 00007952 _____ C:\Users\sarinchen\Documents\HK1213_Quadral_Set_korr.rb1
2013-10-22 12:50 - 2013-10-22 12:50 - 00007959 _____ C:\Users\sarinchen\Documents\HK1213_Quadral_Set_korr.rb2
2013-10-22 12:50 - 2013-10-22 12:45 - 00007918 _____ C:\Users\sarinchen\Documents\HK1213_Quadral_Set_korr.rb3
2013-10-22 12:34 - 2013-10-22 12:39 - 00007391 _____ C:\Users\sarinchen\Documents\Denon_HK1213_korr.rb1
2013-10-22 12:34 - 2013-10-22 12:36 - 00007423 _____ C:\Users\sarinchen\Documents\Denon_HK1213_korr.rb2
2013-10-22 12:34 - 2013-10-22 12:34 - 00007418 _____ C:\Users\sarinchen\Documents\Denon_HK1213_korr.rb3
2013-10-22 12:34 - 2013-10-22 12:33 - 00007441 _____ C:\Users\sarinchen\Documents\Denon_HK1213_korr.rb4
2013-10-21 20:56 - 2013-10-21 21:03 - 00007131 _____ C:\Users\sarinchen\Documents\Heimkino_Musik_HK1213_korr.rb1
2013-10-21 20:56 - 2013-10-21 20:57 - 00007153 _____ C:\Users\sarinchen\Documents\Heimkino_Musik_HK1213_korr.rb2
2013-10-21 20:56 - 2013-10-21 20:56 - 00007166 _____ C:\Users\sarinchen\Documents\Heimkino_Musik_HK1213_korr.rb3
2013-10-21 20:56 - 2013-10-21 20:51 - 00007164 _____ C:\Users\sarinchen\Documents\Heimkino_Musik_HK1213_korr.rb4
2013-10-19 11:37 - 2013-10-19 11:37 - 00001991 _____ C:\Users\Public\Desktop\HTC Sync Manager.lnk
2013-10-19 11:31 - 2013-10-19 11:31 - 00000000 ____D C:\Users\Sarina\AppData\Roaming\HTC
2013-10-19 11:31 - 2013-10-19 11:31 - 00000000 ____D C:\Users\Sarina\AppData\Roaming\Apple Computer
2013-10-19 11:31 - 2013-10-19 11:31 - 00000000 ____D C:\Users\Sarina\AppData\Local\HTC MediaHub
2013-10-19 11:31 - 2013-10-19 11:31 - 00000000 ____D C:\Users\Sarina\AppData\Local\Apple Computer
2013-10-18 13:43 - 2013-10-18 13:49 - 00005753 _____ C:\Users\sarinchen\Documents\HK1213-TV-Test_Metz Axio_korr.rb1
2013-10-18 13:43 - 2013-10-18 13:43 - 00005753 _____ C:\Users\sarinchen\Documents\HK1213-TV-Test_Metz Axio_korr.rb2
2013-10-18 13:43 - 2013-10-18 13:42 - 00005751 _____ C:\Users\sarinchen\Documents\HK1213-TV-Test_Metz Axio_korr.rb3
2013-10-18 13:12 - 2013-10-18 13:59 - 00020594 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb1
2013-10-18 13:12 - 2013-10-18 13:42 - 00017589 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb2
2013-10-18 13:12 - 2013-10-18 13:38 - 00017486 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb3
2013-10-18 13:12 - 2013-10-18 13:30 - 00017490 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb4
2013-10-18 13:12 - 2013-10-18 13:22 - 00017511 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb5
2013-10-18 13:12 - 2013-10-18 13:21 - 00017514 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb7
2013-10-18 13:12 - 2013-10-18 13:21 - 00017512 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb6
2013-10-18 13:12 - 2013-10-18 13:12 - 00017517 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb8
2013-10-17 14:37 - 2013-10-17 14:46 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\Audacity
2013-10-17 14:35 - 2013-10-17 14:36 - 00000000 ____D C:\Program Files (x86)\Audacity
2013-10-17 13:35 - 2013-10-17 15:03 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\foobar2000
2013-10-17 13:35 - 2013-10-17 13:35 - 00000995 _____ C:\Users\Public\Desktop\foobar2000.lnk
2013-10-17 13:34 - 2013-10-17 13:45 - 00000000 ____D C:\Program Files (x86)\foobar2000
2013-10-17 13:10 - 2013-10-17 13:10 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\HTC Sync
2013-10-17 13:10 - 2013-10-17 13:10 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\HTC
2013-10-17 13:09 - 2013-10-17 13:09 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\Apple Computer
2013-10-17 13:09 - 2013-10-17 13:09 - 00000000 ____D C:\Users\sarinchen\AppData\Local\Apple Computer
2013-10-17 13:08 - 2013-10-26 22:34 - 00000000 ____D C:\Users\sarinchen\AppData\Local\HTC MediaHub
2013-10-17 13:08 - 2013-10-17 13:10 - 00000000 ____D C:\Users\sarinchen\Documents\HTC
2013-10-17 13:08 - 2013-10-17 13:08 - 00000000 ____D C:\Users\sarinchen\.android
2013-10-17 13:08 - 2013-10-17 13:08 - 00000000 ____D C:\ProgramData\Motorola
2013-10-17 13:06 - 2013-10-17 13:06 - 00000000 ____D C:\Program Files (x86)\Spirent Communications
2013-10-17 13:03 - 2013-10-19 11:33 - 00000000 ____D C:\Users\Sarina\AppData\Local\Downloaded Installations
2013-10-17 13:02 - 2013-10-17 13:07 - 00000000 ____D C:\Program Files (x86)\HTC
2013-10-17 13:01 - 2013-10-17 13:01 - 00000000 ____D C:\ProgramData\HTC
2013-10-16 00:48 - 2013-10-16 00:48 - 00137735 _____ C:\Users\sarinchen\Documents\070131015.pb1
2013-10-16 00:10 - 2013-10-16 00:10 - 00140691 _____ C:\Users\sarinchen\Documents\066131015.pb2
2013-10-16 00:10 - 2013-10-16 00:10 - 00140691 _____ C:\Users\sarinchen\Documents\066131015.pb1
2013-10-09 19:59 - 2013-09-22 17:43 - 17833984 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-10-09 19:59 - 2013-09-22 17:01 - 10926080 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-10-09 19:59 - 2013-09-22 16:42 - 02312704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-10-09 19:59 - 2013-09-22 16:36 - 01346560 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-10-09 19:59 - 2013-09-22 16:33 - 01494528 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-10-09 19:59 - 2013-09-22 16:33 - 01392128 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-10-09 19:59 - 2013-09-22 16:30 - 00237056 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2013-10-09 19:59 - 2013-09-22 16:27 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-10-09 19:59 - 2013-09-22 16:23 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-10-09 19:59 - 2013-09-22 16:22 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-10-09 19:59 - 2013-09-22 16:21 - 00599040 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2013-10-09 19:59 - 2013-09-22 16:19 - 02147840 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-10-09 19:59 - 2013-09-22 16:19 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-10-09 19:59 - 2013-09-22 16:16 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2013-10-09 19:59 - 2013-09-22 16:15 - 02382848 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-10-09 19:59 - 2013-09-22 16:07 - 00248320 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-10-09 19:59 - 2013-09-22 12:29 - 12336128 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-10-09 19:59 - 2013-09-22 12:22 - 09739264 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-10-09 19:59 - 2013-09-22 12:22 - 01800704 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-10-09 19:59 - 2013-09-22 12:14 - 01427968 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-10-09 19:59 - 2013-09-22 12:13 - 01129472 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-10-09 19:59 - 2013-09-22 12:13 - 01104896 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-10-09 19:59 - 2013-09-22 12:12 - 00231936 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2013-10-09 19:59 - 2013-09-22 12:09 - 00065024 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-10-09 19:59 - 2013-09-22 12:08 - 00142848 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2013-10-09 19:59 - 2013-09-22 12:07 - 00717824 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-10-09 19:59 - 2013-09-22 12:06 - 00420864 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2013-10-09 19:59 - 2013-09-22 12:05 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-10-09 19:59 - 2013-09-22 12:03 - 02382848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-10-09 19:59 - 2013-09-22 12:03 - 01796096 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-10-09 19:59 - 2013-09-22 12:03 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2013-10-09 19:59 - 2013-09-22 11:59 - 00176640 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-10-09 19:06 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2013-10-09 19:06 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-10-09 19:06 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2013-10-09 19:06 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2013-10-09 19:06 - 2013-08-29 03:29 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbser.sys
2013-10-09 19:06 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2013-10-09 19:06 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2013-10-09 19:06 - 2013-07-12 12:40 - 00109824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBAUDIO.sys
2013-10-09 19:06 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2013-10-09 19:06 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2013-10-09 19:06 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2013-10-09 19:06 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2013-10-09 19:06 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2013-10-09 19:06 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2013-10-09 19:06 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2013-10-09 19:06 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbscan.sys
2013-10-09 19:06 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2013-10-09 19:06 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2013-10-09 19:06 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2013-10-09 19:06 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2013-10-09 19:06 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2013-10-09 19:06 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2013-10-09 19:06 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2013-10-09 19:06 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2013-10-09 19:06 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2013-10-09 19:06 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2013-10-09 19:06 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2013-10-09 19:06 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2013-10-09 19:06 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2013-10-09 19:05 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2013-10-09 19:05 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2013-10-09 19:05 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2013-10-09 19:05 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2013-10-09 19:05 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2013-10-09 19:05 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2013-10-09 19:05 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2013-10-09 19:05 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-10-09 19:05 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-10-09 19:05 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2013-10-09 19:05 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2013-10-09 19:05 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2013-10-09 19:05 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2013-10-09 19:05 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2013-10-09 19:05 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2013-10-09 19:05 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2013-10-09 19:05 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2013-10-09 19:05 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2013-10-09 19:05 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2013-10-09 19:05 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2013-10-09 19:05 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2013-10-09 19:05 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2013-10-09 19:05 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-10-09 19:05 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2013-10-09 19:05 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2013-10-09 19:05 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 19:05 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-01 16:09 - 2013-10-01 16:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-27 00:07 - 2013-09-27 00:08 - 00000000 ____D C:\Users\sarinchen\Desktop\RIL_pages-alt
2013-09-26 15:08 - 2013-09-26 15:08 - 00006954 _____ C:\Users\sarinchen\Documents\HK1113-Philips- einzeltest_korr.rb1
2013-09-26 15:08 - 2013-09-26 15:03 - 00006922 _____ C:\Users\sarinchen\Documents\HK1113-Philips- einzeltest_korr.rb2
==================== One Month Modified Files and Folders =======
2013-10-26 22:42 - 2013-10-26 22:30 - 00000000 ____D C:\AdwCleaner
2013-10-26 22:40 - 2009-07-14 06:45 - 00020992 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-26 22:40 - 2009-07-14 06:45 - 00020992 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-26 22:36 - 2012-01-05 23:41 - 01728638 _____ C:\windows\WindowsUpdate.log
2013-10-26 22:34 - 2013-10-17 13:08 - 00000000 ____D C:\Users\sarinchen\AppData\Local\HTC MediaHub
2013-10-26 22:33 - 2012-12-19 16:11 - 00039248 _____ C:\windows\setupact.log
2013-10-26 22:33 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-10-26 22:32 - 2012-12-19 16:10 - 00010294 _____ C:\windows\PFRO.log
2013-10-26 22:29 - 2013-10-26 22:29 - 01060070 _____ C:\Users\sarinchen\Desktop\adwcleaner.exe
2013-10-26 22:08 - 2012-12-16 01:22 - 00000000 ____D C:\ProgramData\InstallMate
2013-10-26 21:51 - 2012-06-28 15:04 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-10-26 21:51 - 2012-06-24 22:01 - 00000000 ____D C:\Installdateien
2013-10-26 21:31 - 2013-10-26 21:31 - 00000000 ____D C:\FRST
2013-10-26 19:17 - 2012-12-10 21:39 - 00003946 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{9BCF4A4F-AD42-4576-991A-C7CC203F8FFE}
2013-10-24 21:56 - 2012-06-24 20:52 - 00000000 ____D C:\Users\Sarina
2013-10-22 21:35 - 2012-01-05 22:57 - 00654400 _____ C:\windows\system32\perfh007.dat
2013-10-22 21:35 - 2012-01-05 22:57 - 00130240 _____ C:\windows\system32\perfc007.dat
2013-10-22 21:35 - 2009-07-14 07:13 - 01498742 _____ C:\windows\system32\PerfStringBackup.INI
2013-10-22 19:54 - 2013-10-22 19:54 - 00010213 _____ C:\Users\sarinchen\Documents\HK1213 Teufel Theater 6_korr.rb1
2013-10-22 19:25 - 2013-10-22 19:54 - 00010183 _____ C:\Users\sarinchen\Documents\HK1213 Teufel Theater 6_korr.rb2
2013-10-22 13:30 - 2013-10-22 13:30 - 00006953 _____ C:\Users\sarinchen\Documents\Sony KD-55X9005-neu_korr.rb1
2013-10-22 13:24 - 2013-10-22 13:30 - 00006838 _____ C:\Users\sarinchen\Documents\Sony KD-55X9005-neu_korr.rb2
2013-10-22 13:23 - 2013-10-22 13:23 - 00003304 _____ C:\Users\sarinchen\Documents\Inakustik Bluetooth-Receiver_korr.rb1
2013-10-22 13:20 - 2013-10-22 13:23 - 00003312 _____ C:\Users\sarinchen\Documents\Inakustik Bluetooth-Receiver_korr.rb2
2013-10-22 13:16 - 2013-10-22 13:08 - 00006768 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb1
2013-10-22 13:15 - 2013-10-22 13:08 - 00006768 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb2
2013-10-22 13:11 - 2013-10-22 13:08 - 00006027 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb3
2013-10-22 13:08 - 2013-10-22 13:08 - 00006045 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb4
2013-10-22 13:05 - 2013-10-22 13:08 - 00006048 _____ C:\Users\sarinchen\Documents\Yamaha_HK1213_korr.rb5
2013-10-22 12:53 - 2013-10-22 12:50 - 00007952 _____ C:\Users\sarinchen\Documents\HK1213_Quadral_Set_korr.rb1
2013-10-22 12:50 - 2013-10-22 12:50 - 00007959 _____ C:\Users\sarinchen\Documents\HK1213_Quadral_Set_korr.rb2
2013-10-22 12:45 - 2013-10-22 12:50 - 00007918 _____ C:\Users\sarinchen\Documents\HK1213_Quadral_Set_korr.rb3
2013-10-22 12:39 - 2013-10-22 12:34 - 00007391 _____ C:\Users\sarinchen\Documents\Denon_HK1213_korr.rb1
2013-10-22 12:36 - 2013-10-22 12:34 - 00007423 _____ C:\Users\sarinchen\Documents\Denon_HK1213_korr.rb2
2013-10-22 12:34 - 2013-10-22 12:34 - 00007418 _____ C:\Users\sarinchen\Documents\Denon_HK1213_korr.rb3
2013-10-22 12:33 - 2013-10-22 12:34 - 00007441 _____ C:\Users\sarinchen\Documents\Denon_HK1213_korr.rb4
2013-10-22 12:21 - 2012-06-24 21:10 - 00093728 _____ C:\Users\Sarina\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-21 21:03 - 2013-10-21 20:56 - 00007131 _____ C:\Users\sarinchen\Documents\Heimkino_Musik_HK1213_korr.rb1
2013-10-21 20:57 - 2013-10-21 20:56 - 00007153 _____ C:\Users\sarinchen\Documents\Heimkino_Musik_HK1213_korr.rb2
2013-10-21 20:56 - 2013-10-21 20:56 - 00007166 _____ C:\Users\sarinchen\Documents\Heimkino_Musik_HK1213_korr.rb3
2013-10-21 20:51 - 2013-10-21 20:56 - 00007164 _____ C:\Users\sarinchen\Documents\Heimkino_Musik_HK1213_korr.rb4
2013-10-21 20:07 - 2012-12-09 15:57 - 00000000 ____D C:\Program Files\Calibre2
2013-10-21 19:35 - 2012-07-23 11:21 - 00000000 ____D C:\Users\sarinchen\Documents\My Digital Editions
2013-10-20 18:10 - 2012-06-29 18:01 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\vlc
2013-10-20 12:04 - 2009-07-14 06:45 - 00390656 _____ C:\windows\system32\FNTCACHE.DAT
2013-10-19 11:37 - 2013-10-19 11:37 - 00001991 _____ C:\Users\Public\Desktop\HTC Sync Manager.lnk
2013-10-19 11:37 - 2012-06-28 00:07 - 00093728 _____ C:\Users\sarinchen\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-19 11:35 - 2013-09-09 15:22 - 00083070 _____ C:\windows\DPINST.LOG
2013-10-19 11:33 - 2013-10-17 13:03 - 00000000 ____D C:\Users\Sarina\AppData\Local\Downloaded Installations
2013-10-19 11:31 - 2013-10-19 11:31 - 00000000 ____D C:\Users\Sarina\AppData\Roaming\HTC
2013-10-19 11:31 - 2013-10-19 11:31 - 00000000 ____D C:\Users\Sarina\AppData\Roaming\Apple Computer
2013-10-19 11:31 - 2013-10-19 11:31 - 00000000 ____D C:\Users\Sarina\AppData\Local\HTC MediaHub
2013-10-19 11:31 - 2013-10-19 11:31 - 00000000 ____D C:\Users\Sarina\AppData\Local\Apple Computer
2013-10-18 13:59 - 2013-10-18 13:12 - 00020594 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb1
2013-10-18 13:49 - 2013-10-18 13:43 - 00005753 _____ C:\Users\sarinchen\Documents\HK1213-TV-Test_Metz Axio_korr.rb1
2013-10-18 13:43 - 2013-10-18 13:43 - 00005753 _____ C:\Users\sarinchen\Documents\HK1213-TV-Test_Metz Axio_korr.rb2
2013-10-18 13:42 - 2013-10-18 13:43 - 00005751 _____ C:\Users\sarinchen\Documents\HK1213-TV-Test_Metz Axio_korr.rb3
2013-10-18 13:42 - 2013-10-18 13:12 - 00017589 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb2
2013-10-18 13:38 - 2013-10-18 13:12 - 00017486 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb3
2013-10-18 13:30 - 2013-10-18 13:12 - 00017490 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb4
2013-10-18 13:22 - 2013-10-18 13:12 - 00017511 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb5
2013-10-18 13:21 - 2013-10-18 13:12 - 00017514 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb7
2013-10-18 13:21 - 2013-10-18 13:12 - 00017512 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb6
2013-10-18 13:12 - 2013-10-18 13:12 - 00017517 _____ C:\Users\sarinchen\Documents\Strecke_Leserkino Cinelounge_korr.rb8
2013-10-17 16:03 - 2013-09-09 20:50 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\Nokia
2013-10-17 16:01 - 2013-09-09 15:23 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\PC Suite
2013-10-17 15:48 - 2013-09-09 15:28 - 00000000 __SHD C:\Users\sarinchen\Phone Browser
2013-10-17 15:03 - 2013-10-17 13:35 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\foobar2000
2013-10-17 14:46 - 2013-10-17 14:37 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\Audacity
2013-10-17 14:36 - 2013-10-17 14:35 - 00000000 ____D C:\Program Files (x86)\Audacity
2013-10-17 13:45 - 2013-10-17 13:34 - 00000000 ____D C:\Program Files (x86)\foobar2000
2013-10-17 13:35 - 2013-10-17 13:35 - 00000995 _____ C:\Users\Public\Desktop\foobar2000.lnk
2013-10-17 13:10 - 2013-10-17 13:10 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\HTC Sync
2013-10-17 13:10 - 2013-10-17 13:10 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\HTC
2013-10-17 13:10 - 2013-10-17 13:08 - 00000000 ____D C:\Users\sarinchen\Documents\HTC
2013-10-17 13:09 - 2013-10-17 13:09 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\Apple Computer
2013-10-17 13:09 - 2013-10-17 13:09 - 00000000 ____D C:\Users\sarinchen\AppData\Local\Apple Computer
2013-10-17 13:08 - 2013-10-17 13:08 - 00000000 ____D C:\Users\sarinchen\.android
2013-10-17 13:08 - 2013-10-17 13:08 - 00000000 ____D C:\ProgramData\Motorola
2013-10-17 13:08 - 2012-06-28 00:06 - 00000000 ____D C:\Users\sarinchen
2013-10-17 13:07 - 2013-10-17 13:02 - 00000000 ____D C:\Program Files (x86)\HTC
2013-10-17 13:06 - 2013-10-17 13:06 - 00000000 ____D C:\Program Files (x86)\Spirent Communications
2013-10-17 13:01 - 2013-10-17 13:01 - 00000000 ____D C:\ProgramData\HTC
2013-10-16 00:48 - 2013-10-16 00:48 - 00137735 _____ C:\Users\sarinchen\Documents\070131015.pb1
2013-10-16 00:10 - 2013-10-16 00:10 - 00140691 _____ C:\Users\sarinchen\Documents\066131015.pb2
2013-10-16 00:10 - 2013-10-16 00:10 - 00140691 _____ C:\Users\sarinchen\Documents\066131015.pb1
2013-10-15 16:06 - 2009-07-14 05:20 - 00000000 ____D C:\windows\rescache
2013-10-13 13:34 - 2009-07-14 07:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-10-11 20:22 - 2013-03-14 01:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-11 20:22 - 2013-03-14 01:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-09 22:57 - 2013-09-06 15:30 - 00000000 ____D C:\Users\sarinchen\AppData\Local\calibre-cache
2013-10-09 22:46 - 2012-06-28 20:42 - 00000000 ____D C:\Users\sarinchen\AppData\Roaming\calibre
2013-10-09 20:03 - 2012-08-13 18:28 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-09 19:51 - 2013-08-15 22:40 - 00000000 ____D C:\windows\system32\MRT
2013-10-09 19:45 - 2012-06-25 23:43 - 80541720 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-10-09 19:40 - 2012-06-28 17:00 - 00001912 _____ C:\windows\epplauncher.mif
2013-10-09 19:40 - 2012-06-28 16:59 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-10-09 19:40 - 2012-06-28 16:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2013-10-09 14:52 - 2012-06-28 15:04 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 14:52 - 2012-06-28 15:04 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 14:52 - 2012-06-28 15:04 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-10-08 19:44 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\NDF
2013-10-02 11:56 - 2012-12-17 12:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-01 21:48 - 2012-06-28 00:09 - 00000000 ____D C:\Users\sarinchen\AppData\Local\Mozilla
2013-10-01 21:47 - 2013-08-22 23:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox.bak
2013-10-01 16:11 - 2013-10-01 16:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-27 00:08 - 2013-09-27 00:07 - 00000000 ____D C:\Users\sarinchen\Desktop\RIL_pages-alt
2013-09-26 15:08 - 2013-09-26 15:08 - 00006954 _____ C:\Users\sarinchen\Documents\HK1113-Philips- einzeltest_korr.rb1
2013-09-26 15:03 - 2013-09-26 15:08 - 00006922 _____ C:\Users\sarinchen\Documents\HK1113-Philips- einzeltest_korr.rb2
Some content of TEMP:
====================
C:\Users\Sarina\AppData\Local\Temp\MouseKeyboardCenterx64_1031.exe
C:\Users\Sarina\AppData\Local\Temp\uninst1.exe
C:\Users\Sarina\AppData\Local\Temp\Updater.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
# AdwCleaner v3.010 - Bericht erstellt am 26/10/2013 um 22:31:39
# Updated 20/10/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Sarina - VICTORIA
# Gestartet von : C:\Users\sarinchen\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Browse2Save
Ordner Gelöscht : C:\Program Files (x86)\BrowseToSave
Ordner Gelöscht : C:\Users\Sarina\AppData\Local\SwvUpdater
Ordner Gelöscht : C:\Users\Sarina\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Sarina\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Sarina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
Ordner Gelöscht : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\Extensions\50cd0a86c12ae@50cd0a86c12e8.com
Ordner Gelöscht : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\Extensions\{462be121-2b54-4218-bf00-b9bf8135b23f}
Datei Gelöscht : \END
Datei Gelöscht : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\bprotector_prefs.js
Datei Gelöscht : C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\bprotector_prefs.js
Datei Gelöscht : C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\foxydeal.sqlite
Datei Gelöscht : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\searchplugins\Babylon.xml
Datei Gelöscht : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\searchplugins\BrowserDefender.xml
Datei Gelöscht : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\searchplugins\Conduit.xml
Datei Gelöscht : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\user.js
Datei Gelöscht : C:\windows\Tasks\AmiUpdXp.job
Datei Gelöscht : C:\windows\System32\Tasks\AmiUpdXp
Datei Gelöscht : C:\windows\System32\Tasks\BrowserDefendert
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jgnddndhkgojgeoeapjgicdgflhdldja
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wsconduit__166_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wsconduit__166_RASMANCS
Schlüssel Gelöscht : HKCU\Software\5a53d7dfb33cba15
Schlüssel Gelöscht : HKLM\SOFTWARE\5a53d7dfb33cba15
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\DataMngr
[#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\AppDataLow\SProtector
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\SP Global
Schlüssel Gelöscht : HKLM\Software\SProtector
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
***** [ Browser ] *****
-\\ Internet Explorer v0.0.0.0
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v24.0 (de)
[ Datei : C:\Users\Sarina\AppData\Roaming\Mozilla\Firefox\Profiles\3rpb4gi9.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultthis.engineName", "WhiteSmoke US New Customized Web Search");
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3244149&SearchSource=3&q={searchTerms}");
Zeile gelöscht : user_pref("CT3244149.browser.search.defaultthis.engineName", "true");
Zeile gelöscht : user_pref("CT3244149.keyword", "true");
Zeile gelöscht : user_pref("CT3244149.smartbar.homepage", "true");
Zeile gelöscht : user_pref("extensions.50cd0a86c135b.scode", "if(window.self.location.protocol.indexOf('hxxp')>-1 && window.self==window.top && !document.getElementById('sjsjszmzmaw28aj6')){var script=document.createE[...]
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.id", "1e9670fd000000000000e8039a88daf9");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15931");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.22.0");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.22.0");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.22.014:05:10");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=121564&tsp=4974");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gelöscht : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3244149&SearchSource=13");
Zeile gelöscht : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3244149&SearchSource=2&q=");
Zeile gelöscht : user_pref("smartbar.originalHomepage", "about:blank");
Zeile gelöscht : user_pref("smartbar.originalSearchAddressUrl", "");
Zeile gelöscht : user_pref("smartbar.originalSearchEngine", "");
Zeile gelöscht : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
[ Datei : C:\Users\sarinchen\AppData\Roaming\Mozilla\Firefox\Profiles\mq3q3tcp.Neu\prefs.js ]
Zeile gelöscht : user_pref("aol_toolbar.default.homepage.check", false);
Zeile gelöscht : user_pref("aol_toolbar.default.search.check", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ".*");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "1");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "1");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.enable", "false");
*************************
AdwCleaner[R0].txt - [9592 octets] - [26/10/2013 22:30:23]
AdwCleaner[S0].txt - [8980 octets] - [26/10/2013 22:31:39]
########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [9040 octets] ########## |