Hallo,
hier ist der Log von Malwarebytes (Quick-Scan): Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.24.04
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16660
Lisa :: LISA-PC [Administrator]
24.08.2013 19:57:58
mbam-log-2013-08-24 (19-57-58).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 286526
Laufzeit: 22 Minute(n), 3 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|bProtectorDefaultScope (PUP.BProtector) -> Daten: {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) Hier von AdwCleaner: Code:
# AdwCleaner v3.001 - Report created 24/08/2013 at 20:26:16
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Lisa - LISA-PC
# Running from : C:\Users\Lisa\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : ICQ Service
***** [ Files / Folders ] *****
Folder Deleted : C:\DVDVideoSoft
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\BrowserDefender
Folder Deleted : C:\ProgramData\GamesBar
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\iWin
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\Alawar
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GamesBar
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\delta
Folder Deleted : C:\Program Files\GamesBar
Folder Deleted : C:\Program Files\ICQ\ICQToolbar
Folder Deleted : C:\Program Files\ICQ6Toolbar
Folder Deleted : C:\Program Files\Yontoo
Folder Deleted : C:\Program Files\DVDVideoSoft
Folder Deleted : C:\Program Files\Common Files\DVDVideoSoft\TB
Folder Deleted : C:\Program Files\Common Files\DVDVideoSoft
Folder Deleted : C:\Users\Lisa\AppData\Local\PackageAware
Folder Deleted : C:\Users\Lisa\AppData\Local\Temp\AskSearch
Folder Deleted : C:\Users\Lisa\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Lisa\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Lisa\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Lisa\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Lisa\AppData\LocalLow\DVDVideoSoft
Folder Deleted : C:\Users\Lisa\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\Lisa\AppData\Roaming\iWin
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Alawar
Folder Deleted : C:\Users\Lisa\AppData\Roaming\DVDVideoSoft
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
Folder Deleted : C:\Users\Lisa\Documents\DVDVideoSoft
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Conduit
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\ConduitEngine
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\jetpack
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\CT2438727
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\CT2269050
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\engine@conduit.com
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\ffxtlbr@babylon.com
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\ffxtlbr@delta.com
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\toolbar@ask.com
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
Folder Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\plugin@yontoo.com.xpi
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\11-suche.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-10.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-5.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-6.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-7.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-8.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-9.xml
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\bProtector_extensions.rdf
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\bprotector_extensions.sqlite
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\bprotector_prefs.js
File Deleted : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\user.js
File Deleted : C:\Windows\System32\Tasks\BrowserDefendert
File Deleted : C:\Windows\System32\Tasks\EPUpdater
File Deleted : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17B66022-92A3-4916-9838-F0F3ADC1607F}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17B66022-92A3-4916-9838-F0F3ADC1607F}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F077C86-7C66-4D9F-B871-04EA76B74513}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0F077C86-7C66-4D9F-B871-04EA76B74513}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC7C703B-30A1-477D-86B7-236B65D8B47D}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CC7C703B-30A1-477D-86B7-236B65D8B47D}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ICQ Service.exe
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Deleted : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook
Key Deleted : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Key Deleted : HKCU\Software\855d6d8b03ebd40
Key Deleted : HKLM\SOFTWARE\855d6d8b03ebd40
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hamster-free-video-converter_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hamster-free-video-converter_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\AppID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD5785E1-D769-4F9D-A619-9F7F3F86C9DC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AB51C4FE-F530-4C7E-9F9A-FDE7AEC1598A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\Interface\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{055FD26D-3A88-4E15-963D-DC8493744B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AB51C4FE-F530-4C7E-9F9A-FDE7AEC1598A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks []
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks []
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}]
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\ICQToolbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\DVDVideoSoft
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\lyrixeeker
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\DVDVideoSoft
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\Software\GamesBarSetup
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\DVDVideoSoft
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICQToolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoft Toolbar
Product Deleted : Ask Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v20.0.1 (de)
[ File : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\prefs.js ]
Line Deleted : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2269050.CTID", "CT2269050");
Line Deleted : user_pref("CT2269050.CurrentServerDate", "15-7-2010");
Line Deleted : user_pref("CT2269050.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2269050.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2269050.EMailNotifierPollDate", "Thu Jul 15 2010 19:20:49 GMT+0200");
Line Deleted : user_pref("CT2269050.ExternalComponentPollDate8877840225553681985", "Wed Jul 14 2010 21:45:10 GMT+0200");
Line Deleted : user_pref("CT2269050.FirstServerDate", "4-1-2010");
Line Deleted : user_pref("CT2269050.FirstTime", true);
Line Deleted : user_pref("CT2269050.FirstTimeFF3", true);
Line Deleted : user_pref("CT2269050.FirstTimeSettingsDone", true);
Line Deleted : user_pref("CT2269050.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2269050.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2269050.Initialize", true);
Line Deleted : user_pref("CT2269050.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2269050.InstallationAndCookieDataSentCount", 2);
Line Deleted : user_pref("CT2269050.InstalledDate", "Tue Dec 29 2009 21:25:43 GMT+0100");
Line Deleted : user_pref("CT2269050.InvalidateCache", false);
Line Deleted : user_pref("CT2269050.IsGrouping", false);
Line Deleted : user_pref("CT2269050.IsMulticommunity", false);
Line Deleted : user_pref("CT2269050.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2269050.IsOpenUninstallPage", false);
Line Deleted : user_pref("CT2269050.LanguagePackLastCheckTime", "Wed Jul 14 2010 21:45:10 GMT+0200");
Line Deleted : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2269050.LastLogin_2.4.0.4", "Sun Jan 03 2010 21:49:55 GMT+0100");
Line Deleted : user_pref("CT2269050.LastLogin_2.5.2.14", "Mon Jan 25 2010 16:54:56 GMT+0100");
Line Deleted : user_pref("CT2269050.LastLogin_2.5.6.0", "Fri Feb 12 2010 13:23:49 GMT+0100");
Line Deleted : user_pref("CT2269050.LastLogin_2.7.0.14", "Thu Jul 15 2010 19:15:46 GMT+0200");
Line Deleted : user_pref("CT2269050.LatestVersion", "2.1.0.18");
Line Deleted : user_pref("CT2269050.Locale", "en");
Line Deleted : user_pref("CT2269050.LoginCache", 4);
Line Deleted : user_pref("CT2269050.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2269050.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2269050.RadioIsPodcast", false);
Line Deleted : user_pref("CT2269050.RadioLastCheckTime", "Thu Jul 15 2010 21:45:21 GMT+0200");
Line Deleted : user_pref("CT2269050.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
Line Deleted : user_pref("CT2269050.RadioMediaID", "12473383");
Line Deleted : user_pref("CT2269050.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383");
Line Deleted : user_pref("CT2269050.RadioStationName", "Hotmix%20108");
Line Deleted : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082");
Line Deleted : user_pref("CT2269050.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2269050.SearchBoxWidth", 100);
Line Deleted : user_pref("CT2269050.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2269050&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2269050.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=");
Line Deleted : user_pref("CT2269050.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Thu Jul 15 2010 21:45:11 GMT+0200");
Line Deleted : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2269050.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2269050.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2269050.SettingsLastCheckTime", "Thu Jul 15 2010 19:15:40 GMT+0200");
Line Deleted : user_pref("CT2269050.SettingsLastUpdate", "1277823092");
Line Deleted : user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Wed Jul 14 2010 21:45:03 GMT+0200");
Line Deleted : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1277823092");
Line Deleted : user_pref("CT2269050.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
Line Deleted : user_pref("CT2269050.UserID", "UN18937493875262190");
Line Deleted : user_pref("CT2269050.ValidationData_Toolbar", 2);
Line Deleted : user_pref("CT2269050.WeatherNetwork", "");
Line Deleted : user_pref("CT2269050.WeatherPollDate", "Thu Jul 15 2010 19:15:49 GMT+0200");
Line Deleted : user_pref("CT2269050.WeatherUnit", "C");
Line Deleted : user_pref("CT2269050.alertChannelId", "666138");
Line Deleted : user_pref("CT2269050.clientLogIsEnabled", true);
Line Deleted : user_pref("CT2269050.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2269050.myStuffEnabled", true);
Line Deleted : user_pref("CT2269050.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2269050.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2438727.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2438727.CTID", "CT2438727");
Line Deleted : user_pref("CT2438727.CommunitiesChangesLastCheckTime", "0");
Line Deleted : user_pref("CT2438727.CurrentServerDate", "7-7-2010");
Line Deleted : user_pref("CT2438727.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2438727.FirstServerDate", "12-2-2010");
Line Deleted : user_pref("CT2438727.FirstTime", true);
Line Deleted : user_pref("CT2438727.FirstTimeFF3", true);
Line Deleted : user_pref("CT2438727.GroupingInvalidateCache", false);
Line Deleted : user_pref("CT2438727.GroupingLastCheckTime", "0");
Line Deleted : user_pref("CT2438727.GroupingLastServerUpdateTime", "0");
Line Deleted : user_pref("CT2438727.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2438727.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2438727.Initialize", true);
Line Deleted : user_pref("CT2438727.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2438727.InstalledDate", "Fri Feb 12 2010 13:27:40 GMT+0100");
Line Deleted : user_pref("CT2438727.InvalidateCache", false);
Line Deleted : user_pref("CT2438727.IsGrouping", false);
Line Deleted : user_pref("CT2438727.IsMulticommunity", false);
Line Deleted : user_pref("CT2438727.IsOpenThankYouPage", true);
Line Deleted : user_pref("CT2438727.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2438727.LanguagePackLastCheckTime", "Tue Jul 06 2010 18:28:29 GMT+0200");
Line Deleted : user_pref("CT2438727.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2438727.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2438727.LastLogin_2.5.6.0", "Wed Jul 07 2010 14:11:28 GMT+0200");
Line Deleted : user_pref("CT2438727.LatestVersion", "2.1.0.18");
Line Deleted : user_pref("CT2438727.Locale", "en");
Line Deleted : user_pref("CT2438727.LoginCache", 4);
Line Deleted : user_pref("CT2438727.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2438727.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2438727.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2438727.RadioLastCheckTime", "0");
Line Deleted : user_pref("CT2438727.RadioLastUpdateIPServer", "0");
Line Deleted : user_pref("CT2438727.RadioLastUpdateServer", "0");
Line Deleted : user_pref("CT2438727.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2438727.SearchBoxWidth", 100);
Line Deleted : user_pref("CT2438727.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2438727&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2438727.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2438727.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2438727&q=");
Line Deleted : user_pref("CT2438727.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2438727.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2438727.SearchInNewTabLastCheckTime", "Tue Jul 06 2010 18:28:17 GMT+0200");
Line Deleted : user_pref("CT2438727.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2438727.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2438727.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2438727.SettingsLastCheckTime", "Wed Jul 07 2010 14:11:19 GMT+0200");
Line Deleted : user_pref("CT2438727.SettingsLastUpdate", "1275607866");
Line Deleted : user_pref("CT2438727.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2438727.ThirdPartyComponentsLastCheck", "Tue Jun 29 2010 22:06:08 GMT+0200");
Line Deleted : user_pref("CT2438727.ThirdPartyComponentsLastUpdate", "1275546478");
Line Deleted : user_pref("CT2438727.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
Line Deleted : user_pref("CT2438727.UserID", "UN82334188226881893");
Line Deleted : user_pref("CT2438727.ValidationData_Search", 0);
Line Deleted : user_pref("CT2438727.ValidationData_Toolbar", 2);
Line Deleted : user_pref("CT2438727.alertChannelId", "832836");
Line Deleted : user_pref("CT2438727.clientLogIsEnabled", true);
Line Deleted : user_pref("CT2438727.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2438727.myStuffEnabled", true);
Line Deleted : user_pref("CT2438727.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2438727.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2438727.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2438727.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2438727.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"80927e5f86f7cb1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.2.1", "\"0652eeacc6cb1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");
Line Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Line Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Line Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Line Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Line Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://storage.conduit.com/MarketPlace/3d/f6/3da3ff3d-3fb4-4a03-be93-468e59eee9f6/Gadgets/6f84459b-aa48-4d42-a112-f694a40444c0.html", "47x151");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Line Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2269050,CT2438727,ConduitEngine");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2269050,CT2438727");
Line Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Tue Apr 12 2011 22:04:05 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Line Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed May 18 2011 20:30:05 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Line Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Line Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed May 18 2011 13:53:01 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Line Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Line Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Line Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Line Deleted : user_pref("CommunityToolbar.alert.userId", "b179dae5-9e09-4546-8422-2a5e5b2629a7");
Line Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Jul 15 2010 21:45:12 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sat May 14 2011 20:26:15 GMT+0200");
Line Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Line Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed May 18 2011 13:53:02 GMT+0200");
Line Deleted : user_pref("ConduitEngine.FirstServerDate", "03/21/2011 14");
Line Deleted : user_pref("ConduitEngine.FirstTime", true);
Line Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Line Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Line Deleted : user_pref("ConduitEngine.Initialize", true);
Line Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Line Deleted : user_pref("ConduitEngine.InstalledDate", "Mon Mar 21 2011 13:26:23 GMT+0100");
Line Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Line Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Line Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Line Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed May 18 2011 13:53:02 GMT+0200");
Line Deleted : user_pref("ConduitEngine.LastLogin_3.3.2.1", "Tue Mar 22 2011 22:18:17 GMT+0100");
Line Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed May 18 2011 20:30:04 GMT+0200");
Line Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed May 18 2011 20:30:06 GMT+0200");
Line Deleted : user_pref("ConduitEngine.UserID", "UN64127379424137561");
Line Deleted : user_pref("ConduitEngine.componentAlertEnabled", false);
Line Deleted : user_pref("ConduitEngine.counterAppsAdded", 2);
Line Deleted : user_pref("ConduitEngine.engineLocale", "de");
Line Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed May 18 2011 13:53:02 GMT+0200");
Line Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed May 18 2011 20:30:04 GMT+0200");
Line Deleted : user_pref("ConduitEngine.initDone", true);
Line Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Line Deleted : user_pref("ConduitEngine.usagesFlag", 2);
Line Deleted : user_pref("browser.newtab.url", "hxxp://www1.delta-search.com/?babsrc=NT_ss&mntrId=CC81001E8CC7C0AB&affID=119357&tsp=4983");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=CC81001E8CC7C0AB&affID=119357&tsp=4983");
Line Deleted : user_pref("extensions.aniweather.timeShifted", 1593868);
Line Deleted : user_pref("extensions.enabledAddons", "externalip%40erik.morlin:0.9.9.6,googleimagehelp%40shivam.org:3.1,MouseControl%40neocodex.us:1.5.1,%7B097d3191-e6fa-4728-9826-b533d755359d%7D:0.7.18,%7Bd40f5e7b-[...]
Line Deleted : user_pref("extensions.enabledItems", "{097d3191-e6fa-4728-9826-b533d755359d}:0.7.13,en-GB@dictionaries.addons.mozilla.org:1.19.1,{0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6.5,piclens@cooliris.com:1.12.[...]
Line Deleted : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\M[...]
Line Deleted : user_pref("extensions.startxxl.originalHomepage", "hxxp://de.ask.com/?l=dis&o=1586&gct=hp");
Line Deleted : user_pref("extensions.toolbar@ask.com.install-event-fired", true);
Line Deleted : user_pref("extentions.y2layers.defaultEnableAppsList", "twittube,ezLooker,pagerage,buzzdock,toprelatedtopics");
Line Deleted : user_pref("extentions.y2layers.installId", "32726400-c4f4-438c-9b73-d0758c53f26d");
Line Deleted : user_pref("extentions.y2layers.lastDnsTest", 371874);
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", true);
Line Deleted : user_pref("icqtoolbar.geolastmodified", 1305579617);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "k%C3%BCken||feuer||ph%C3%B6nix||ph%C3%B6nix%20aus%20der%20asche||bewerbungsvorlagen%20praktikum||bewerbungsvorlage%20wirtschaftspr%C3%BCfer%2Fsteuerberater||bewerbung%[...]
Line Deleted : user_pref("icqtoolbar.icqgeo", 49);
Line Deleted : user_pref("icqtoolbar.installTime", "1304971412");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "4.0.1");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "120897317512089731751209052195780");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1305719585);
Line Deleted : user_pref("icqtoolbar.version", "1.1.9");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "de");
Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
-\\ Google Chrome v29.0.1547.57
[ File : C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [44790 octets] - [24/08/2013 20:23:21]
AdwCleaner[S0].txt - [39799 octets] - [24/08/2013 20:26:16]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [39860 octets] ########## Hier von JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.4 (08.22.2013:1)
OS: Windows 7 Home Premium x86
Ran by Lisa on 24.08.2013 at 20:33:47,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2269050
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ConfigTask_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ConfigTask_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ZY-SherlockHolmes_TheHoundofTheBaskervilles_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ZY-SherlockHolmes_TheHoundofTheBaskervilles_RASMANCS
~~~ Files
Successfully deleted: [File] "C:\Windows\system32\turegopt.exe"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Lisa\AppData\Roaming\big fish games"
Successfully deleted: [Folder] "C:\Program Files\icqtoolbar"
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{1665FC9B-8CA8-4C97-B48F-E9F5AA836651}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{1ECDCEB8-E67C-4169-96D3-50F22C3370CE}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{234F7C63-98CC-4DAA-AC92-73ED74E385B4}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{256022BE-FEE6-4782-A408-846D2CBC912D}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{26CA32D1-7484-4B31-9849-694752C92075}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{38486736-2C75-4FF7-8545-3A809F0D47BA}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{4294DEDB-31C9-4B4F-8DCC-DE7446C57B96}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{46CD7A35-5FFD-49D7-A84F-6DD5CE107C6D}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{53E54233-EC2B-4741-80F6-BA964729749E}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{53F524F4-97B3-414B-AF65-8FF9E7AFEBFA}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{55E2B379-F67F-4BE5-BED1-640272430B7B}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{56D9F6CA-04EB-4403-ADAA-D7F2E580FFEE}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{5AD880F2-7D0A-4C23-A1E1-F3FFB978C267}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{7A8B373A-A19E-403E-AB6B-D4D75723DE12}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{801B415C-95FC-42F1-A40B-C68FEEFB5836}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{8776001D-CF02-4264-AED1-0FD4B68823DD}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{8ADE48C9-3B76-423B-BA24-4B3D37418E66}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{9214AC4E-1C39-4041-AAA1-19972622C22F}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{A1C6A4D2-026E-4289-8569-1F8995FD11BA}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{A845FF7F-03AA-4AA3-96CF-C969F4E37913}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{B6BD2D67-C3F1-437A-8B73-F5D36A1FDE34}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{B9864B20-0EBA-4D1E-A6B0-0F79B69EBACA}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{BE5A5094-64CD-453A-8DBE-2C7DCCF5EC3A}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{C4208065-5E32-4BFF-91CE-1AC27753CBA6}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{CC781535-80FB-4073-9186-304B7803F36C}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{DC050C01-D2E3-4E60-A80B-55733F8D9A8E}
Successfully deleted: [Empty Folder] C:\Users\Lisa\appdata\local\{E906CE18-540A-4D8E-B75E-59879B109EC5}
~~~ FireFox
Successfully deleted: [File] C:\Users\Lisa\AppData\Roaming\mozilla\firefox\profiles\6dx3b5so.default\extensions\searchy@searchy.xpi
Successfully deleted: [Folder] C:\Users\Lisa\AppData\Roaming\mozilla\firefox\profiles\6dx3b5so.default\extensions\staged
Successfully deleted the following from C:\Users\Lisa\AppData\Roaming\mozilla\firefox\profiles\6dx3b5so.default\prefs.js
user_pref("google.toolbar.button_option.cached.gtbSearchBlogs", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchBlogs\" t
user_pref("google.toolbar.button_option.cached.gtbSearchPhotos", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchPhotos\"
user_pref("google.toolbar.button_option.cached.gtbSearchScholar", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchScholar
user_pref("google.toolbar.button_option.cached.gtbstoolbar-google-com_CTK0Y7F4MTG6NKYH03WT-xml", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.o
user_pref("google.toolbar.button_option.cached.gtbstoolbar-google-com_J66T77NJDBMW4FEUU7FA-xml", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.o
user_pref("google.toolbar.search-icon", "data:image/x-icon;base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7PT7/3zF6/9Ptu//RbHx/
user_pref("samfind.social.notused", "allvoices,attentionmeter,ballhype,barrapunto,bebo,bitly,bizsugar,blinklist,blogger,blogmemesfr,bookmarksfr,bx,care2,citeulike,cliqset,conn
Emptied folder: C:\Users\Lisa\AppData\Roaming\mozilla\firefox\profiles\6dx3b5so.default\minidumps [112 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24.08.2013 at 20:35:47,07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und hier nochmal das frische FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-08-2013 01
Ran by Lisa (administrator) on 24-08-2013 20:39:15
Running from C:\Users\Lisa\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corp.) C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\system32\PnkBstrA.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(SigmaTel, Inc.) C:\Windows\system32\STacSV.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
(Safer Networking Ltd.) C:\Program Files\sicherheit\Spybot-Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
() C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe
(SigmaTel, Inc.) C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Nokia) C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
(SAMSUNG ELECTRONICS) C:\Program Files\Samsung\EmoDio\SMSTray.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\LBTWiz.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(1und1 Mail und Media GmbH) C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck_Broker.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Akamai Technologies, Inc.) C:\Users\Lisa\AppData\Local\Akamai\netsession_win.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Akamai Technologies, Inc.) C:\Users\Lisa\AppData\Local\Akamai\netsession_win.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(LOL Replay) C:\Program Files\LOLReplay\LOLRecorder.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Dropbox, Inc.) C:\Users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\LogiAppBroker.exe
(Farbar) C:\Users\Lisa\Downloads\FRST (1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SigmatelSysTrayApp] - C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-09-12] (SigmaTel, Inc.)
HKLM\...\Run: [Bluetooth HCI Monitor] - C:\Windows\System32\HCIMNTR.DLL [9728 2006-12-08] (Logitech Inc.)
HKLM\...\Run: [ECenter] - C:\Dell\E-Center\EULALauncher.exe [17920 2008-01-18] ( )
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [NokiaMServer] - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup [x]
HKLM\...\Run: [NokiaMusic FastStart] - C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe [2090272 2009-11-06] (Nokia)
HKLM\...\Run: [Corel File Shell Monitor] - C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16200 2007-10-30] ()
HKLM\...\Run: [SMSTray] - C:\Program Files\Samsung\EmoDio\SMSTray.exe [479232 2009-04-16] (SAMSUNG ELECTRONICS)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [1425208 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [Bluetooth Connection Assistant] - LBTWIZ.EXE -silent [x]
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Nvtmru] - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [BingDesktop] - C:\Program Files\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-20] (Microsoft Corp.)
HKLM\...\Run: [MailCheck IE Broker] - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck_Broker.exe [1519680 2013-07-01] (1und1 Mail und Media GmbH)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [2238704 2013-02-21] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [718688 2009-09-30] (Microsoft Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [X]
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2008-03-31] (Google Inc.)
HKCU\...\Run: [AutoStartNPSAgent] - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [102400 2010-03-28] (Samsung Electronics Co., Ltd.)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Lisa\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [WEB.DE Application {sync-000021}] - C:\Users\Lisa\AppData\Local\WEB.DE Application {sync-000021}\webde_onlinespeicher.exe [943616 2013-05-13] (1&1 Mail & Media GmbH)
HKCU\...\Run: [Xvid] - C:\Program Files\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
HKU\Gast\...\Run: [DellSupportCenter] - "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [x]
HKU\Gast\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [ 2010-11-20] (Microsoft Corporation)
HKU\Gast\...\Run: [SpybotSD TeaTimer] - C:\Program Files\sicherheit\Spybot-Search & Destroy\TeaTimer.exe [ 2008-01-28] (Safer Networking Limited)
HKU\Gast\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2008-03-31] (Google Inc.)
HKU\Gast\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [ 2010-11-20] (Microsoft Corporation)
HKU\Gast\...\RunOnce: [DPAPIKeyMig] - C:\Windows\system32\dpapimig.exe [ 2009-07-14] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk
ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk
ShortcutTarget: LOLRecorder.lnk -> C:\Program Files\LOLReplay\LOLRecorder.exe (LOL Replay)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Nokia Ovi Suite.lnk
ShortcutTarget: Nokia Ovi Suite.lnk -> C:\Program Files\Nokia\Ovi\Suite\RunLauncher.exe (Nokia)
Startup: C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
SearchScopes: HKLM - DefaultScope value is missing.
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - WEB.DE MailCheck - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -WEB.DE MailCheck - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Handler: webde - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE MailCheck\IE\WEB.DE_MailCheck.dll (1und1 Mail und Media GmbH)
Winsock: Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default
FF NetworkProxy: "ftp", "65.126.16.155"
FF NetworkProxy: "ftp_port", 8089
FF NetworkProxy: "http", "65.126.16.155"
FF NetworkProxy: "http_port", 8089
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "65.126.16.155"
FF NetworkProxy: "socks_port", 8089
FF NetworkProxy: "ssl", "65.126.16.155"
FF NetworkProxy: "ssl_port", 8089
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @real.com/nppl3260;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=12.0.1.669 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=12.0.1.669 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\amazonde.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-11.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-12.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-13.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-14.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-15.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-16.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-17.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\icqplugin-18.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\preisvergleich.xml
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\GoogleDesktopMozilla.png
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\GoogleDesktopMozilla.src
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\allglassv2@ambroos.neowin.net
FF Extension: Deutsches Wörterbuch - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: LavaFox V2-Blue - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\djziggy@gmail.com
FF Extension: British English Dictionary - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\en-GB@dictionaries.addons.mozilla.org
FF Extension: United States English Spellchecker - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\en-US@dictionaries.addons.mozilla.org
FF Extension: external IP - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\externalip@erik.morlin
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\FirefoxAddon@similarWeb.com
FF Extension: LavaFox V2 - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\info@djzig.com
FF Extension: Scale tabs - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\jid0-wQgRuE1ziTuF2sAupFeSZa9xUGU@jetpack
FF Extension: MouseControl - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\MouseControl@neocodex.us
FF Extension: Cooliris - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\piclens@cooliris.com
FF Extension: samfind Bookmarks Bar - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\sam@samfind.com
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\swiffout@grownsoftware.com
FF Extension: LavaFox V2-Purple - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\zigboom555@aol.com
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF Extension: Flagfox - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: Google Toolbar for Firefox - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF Extension: FT DeepDark - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
FF Extension: iMacros for Firefox - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
FF Extension: Update Notifier - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{95f24680-9e31-11da-a746-0800200c9a66}
FF Extension: WOT - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF Extension: ReminderFox - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
FF Extension: DownloadHelper - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: adblockpopups - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\adblockpopups@jessehakanen.net.xpi
FF Extension: bizdom - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\bizdom@wizbites.com.xpi
FF Extension: canitbecheaper - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\canitbecheaper@trafficbroker.co.uk.xpi
FF Extension: dendzones - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\dendzones@captaincaveman.nl.xpi
FF Extension: feedly - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\feedly@devhd.xpi
FF Extension: finder - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\finder@meingutscheincode.de.xpi
FF Extension: firebug - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\firebug@software.joehewitt.com.xpi
FF Extension: GodLesZ.XxSoulCatcherxX - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\GodLesZ.XxSoulCatcherxX@ShaiyaChecker.de.xpi
FF Extension: googleimagehelp - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\googleimagehelp@shivam.org.xpi
FF Extension: jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
FF Extension: personas - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\personas@christopher.beard.xpi
FF Extension: plugin - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\plugin@apture.com.xpi
FF Extension: quickdrag - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\quickdrag@mozilla.ktechcomputing.com.xpi
FF Extension: silvermelxt - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\silvermelxt@pardal.de.xpi
FF Extension: stealthyextension - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\stealthyextension@gmail.com.xpi
FF Extension: support - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\support@startxxl.com.xpi
FF Extension: tabscope - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\tabscope@xuldev.org.xpi
FF Extension: toolbar - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\toolbar@web.de.xpi
FF Extension: videosurf_enhanced - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\videosurf_enhanced@videosurf.com.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{75df891f-e299-4725-b14f-7d52f086dea2}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{c7b3cf78-9cbc-47b9-ba47-bb84a56069dd}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{E10A6337-382E-4FE6-96DE-936ADC34DD04}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF Extension: No Name - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\6dx3b5so.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [lyrix@lyrixeeker.co] C:\Program Files\LyriXeeker\128.xpi
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com", "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=CC81001E8CC7C0AB&affID=119357&tsp=4983"
CHR DefaultSearchURL: (Google) - https://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t&q={searchTerms}&ie=utf-8&oe=utf-8&aq=t&channel=fflb&q={searchTerms}&ie=utf-8&oe=utf-8&aq=t&channel=rcs
CHR DefaultSuggestURL: (Google) - https://www.google.com/complete/search?q={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
CHR Plugin: (Skype Toolbars) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll (Skype Technologies S.A.)
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll No File
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Turn Off the Lights) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.2.0.21_0
CHR Extension: (Adblock Plus) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.4_0
CHR Extension: (Warrior Girl) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbngkgeakdhomabndkmfcjijooohmpff\1_0
CHR Extension: (Springpad Clipper) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\eclcnlepmfepnccogfjdafhhlgcfdmnj\1.1212.12.6_0
CHR Extension: (Logitech SetPoint) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd\6.52.74_0
CHR Extension: (Black Menu for Google\u2122) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\eignhdfgaldabilaaegmdfbajngjmoke\4.7.2_0
CHR Extension: (Chrome Toolbox (by Google)) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjccknnhdnkbanjilpjddjhmkghmachn\1.0.32_0
CHR Extension: (Checker Plus for Google Calendar\u2122) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha\13.8.5_0
CHR Extension: (RealDownloader) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.2_0
CHR Extension: (Stealthy) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieaebnkibonmpbhdaanjkmedikadnoje\3.0.1_0
CHR Extension: (WEB.DE MailCheck) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo\1.2_0
CHR Extension: (Panel View for Keep) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jccocffecajimkdjgfpjhlpiimcnadhb\1.8_0
CHR Extension: (Flava Clipper) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnpejdnkidnilbdgonnnnpbahhhlkheo\0.2.3_0
CHR Extension: (Skype Click to Call) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0
CHR Extension: (Ghostery) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.2_0
CHR Extension: (Flava\u2122) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngbgeoblgfklfhenfldifemcjfchgdhj\0.9_0
CHR Extension: (Springpad Extension) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\njhgeimnepehieioinbhmfpphfoocmng\2.5.1109.21_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0
CHR HKLM\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
========================== Services (Whitelisted) =================
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG)
R2 BingDesktopUpdate; C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.)
S3 GoogleDesktopManager-061008-081103; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [29744 2008-12-15] (Google)
S2 gupdate1ca87bbb1afce56; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-12-28] (Google Inc.)
S3 npggsvc; C:\Windows\system32\GameMon.des [4264632 2011-05-15] (INCA Internet Co., Ltd.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14592288 2013-07-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-07-31] ()
S4 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
S4 RoxLiveShare10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [309744 2007-12-14] (Sonic Solutions)
R2 SBSDWSCService; C:\Program Files\sicherheit\Spybot-Search & Destroy\SDWinSec.exe [810320 2008-01-28] (Safer Networking Ltd.)
S3 ServiceLayer; C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [651776 2009-09-17] (Nokia)
R2 STacSV; C:\Windows\system32\STacSV.exe [94208 2007-09-12] (SigmaTel, Inc.)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1723744 2012-11-29] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
R2 ACEDRV07; C:\Windows\system32\drivers\ACEDRV07.sys [101376 2010-06-16] (Protect Software GmbH)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2010-02-28] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-03-30] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-03-30] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-30] (Avira Operations GmbH & Co. KG)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [219352 2009-06-05] (Intel Corporation)
S3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2009-03-31] ()
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [60104 2010-07-12] (FTDI Ltd.)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 LEqdUsb; C:\Windows\System32\Drivers\LEqdUsb.Sys [44296 2013-01-03] (Logitech, Inc.)
R3 LHidEqd; C:\Windows\System32\Drivers\LHidEqd.Sys [12808 2013-01-03] (Logitech, Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2010-02-28] ()
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34592 2013-05-14] (NVIDIA Corporation)
S0 sfsync04; C:\Windows\System32\drivers\sfsync04.sys [50176 2006-03-24] (Protection Technology (StarForce))
S0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [63488 2005-11-03] (Protection Technology)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-10] (Avira GmbH)
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [90112 2009-03-20] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14976 2009-03-20] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [121856 2009-03-20] (MCCI Corporation)
R3 STHDA; C:\Windows\System32\drivers\stwrt.sys [326656 2007-09-12] (SigmaTel, Inc.)
S3 TKFsAc; C:\Windows\system32\TKFsAc2k.sys [127584 2010-06-03] (INCA Internet Co., Ltd.)
S3 TKFsAv; C:\Windows\system32\TKFsAv2k.sys [55776 2010-04-13] (Copyright (C) INCA Internet. 2000-2010)
S3 TKFsFt; C:\Windows\system32\TKFsFt2k.sys [81888 2010-06-03] (INCA Internet Co., Ltd.)
S3 TKRgAc; C:\Windows\system32\TKRgAc2k.sys [68192 2010-06-03] (INCA Internet Co., Ltd.)
S3 TKRgFt; C:\Windows\system32\TKRgFtXp.sys [30432 2010-06-03] (INCA Internet Co., Ltd.)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-08-29] (TuneUp Software)
S3 vsdatant; C:\Windows\system32\vsdatant.sys [394192 2007-03-09] (Zone Labs, LLC)
S3 catchme; \??\C:\Users\Lisa\AppData\Local\Temp\catchme.sys [x]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S3 massfilter; system32\drivers\massfilter.sys [x]
S3 XDva369; \??\C:\Windows\system32\XDva369.sys [x]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-24 20:34 - 2013-08-24 20:36 - 00000000 ____D C:\Users\Lisa\Desktop\Neuer Ordner
2013-08-24 20:33 - 2013-08-24 20:33 - 01021434 _____ (Thisisu) C:\Users\Lisa\Downloads\JRT.exe
2013-08-24 20:33 - 2013-08-24 20:33 - 00000000 ____D C:\Windows\ERUNT
2013-08-24 20:23 - 2013-08-24 20:28 - 00000000 ____D C:\AdwCleaner
2013-08-24 20:21 - 2013-08-24 20:21 - 00994642 _____ C:\Users\Lisa\Downloads\adwcleaner.exe
2013-08-24 19:56 - 2013-08-24 19:56 - 00001069 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-24 19:56 - 2013-08-24 19:56 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-24 19:56 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-24 19:55 - 2013-08-24 19:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-1.75.0.1300 (1).exe
2013-08-24 16:05 - 2013-08-24 16:05 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2013-08-24 16:04 - 2013-08-24 16:04 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories
2013-08-24 16:03 - 2013-08-24 16:03 - 07522680 _____ (Microsoft Corporation) C:\Users\Lisa\Desktop\Xbox360_32Deu.exe
2013-08-24 15:27 - 2013-08-24 15:27 - 00031542 _____ C:\ComboFix.txt
2013-08-24 15:05 - 2013-08-24 15:27 - 00000000 ____D C:\ComboFix
2013-08-24 15:05 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-24 15:02 - 2013-08-24 15:02 - 00001402 _____ C:\Users\Lisa\Desktop\ComboFix.exe - Verknüpfung.lnk
2013-08-24 14:21 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-24 14:21 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-24 14:21 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-24 14:21 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-24 14:21 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-24 14:21 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-24 14:21 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-24 14:20 - 2013-08-24 15:27 - 00000000 ____D C:\Qoobox
2013-08-24 14:20 - 2013-08-24 14:20 - 05111180 ____R (Swearware) C:\Users\Lisa\Downloads\ComboFix (1).exe
2013-08-24 14:19 - 2013-08-24 15:26 - 00000000 ____D C:\Windows\erdnt
2013-08-24 14:10 - 2013-08-24 14:10 - 05111180 ____R (Swearware) C:\Users\Lisa\Downloads\ComboFix.exe
2013-08-24 11:58 - 2013-08-24 11:58 - 00073702 _____ C:\Users\Lisa\Desktop\FRST1.txt
2013-08-24 11:58 - 2013-08-24 11:58 - 00034916 _____ C:\Users\Lisa\Desktop\Addition.txt
2013-08-24 11:57 - 2013-08-24 11:57 - 00034916 _____ C:\Users\Lisa\Downloads\Addition.txt
2013-08-24 11:55 - 2013-08-24 11:55 - 00000000 ____D C:\FRST
2013-08-24 11:54 - 2013-08-24 11:54 - 01070467 _____ (Farbar) C:\Users\Lisa\Downloads\FRST.exe
2013-08-23 21:36 - 2013-08-23 21:36 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Malwarebytes
2013-08-23 21:35 - 2013-08-23 21:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-23 21:34 - 2013-08-23 21:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-23 21:27 - 2013-08-23 21:27 - 02347384 _____ (ESET) C:\Users\Lisa\Downloads\esetsmartinstaller_enu.exe
2013-08-23 20:57 - 2013-08-23 20:57 - 00000000 ____D C:\Users\Lisa\AppData\Local\avgchrome
2013-08-23 19:21 - 2013-08-23 19:21 - 46960392 _____ (Trend Micro ) C:\Users\Lisa\Downloads\tis14de_1479_eval30.exe
2013-08-23 19:07 - 2013-08-23 19:07 - 00143980 _____ C:\Users\Lisa\Downloads\Ausgleich der stornierten Lastschrift Ihrer Bestellung 23.08.2013.zip
2013-08-23 19:07 - 2013-08-23 19:07 - 00143980 _____ C:\Users\Lisa\Downloads\Ausgleich der stornierten Lastschrift Ihrer Bestellung 23.08.2013 (1).zip
2013-08-20 13:21 - 2013-08-20 13:21 - 00092776 _____ (Spotify Ltd) C:\Users\Lisa\Downloads\SpotifySetup.exe
2013-08-16 02:51 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-16 02:51 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-16 02:51 - 2013-07-26 05:13 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-16 02:51 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-16 02:51 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-16 02:51 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-16 02:51 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-16 02:51 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-16 02:51 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-16 02:51 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-16 02:51 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-16 02:51 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-16 02:51 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-16 02:51 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-16 02:51 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-16 02:51 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-15 19:47 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 19:47 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-15 19:47 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-15 19:47 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-15 19:47 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-15 19:47 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 19:47 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 19:47 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 19:47 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 19:47 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 19:47 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 19:47 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-07-31 18:27 - 2013-07-31 18:27 - 00281392 _____ C:\Windows\system32\PnkBstrB.xtr
2013-07-31 18:27 - 2013-07-31 18:27 - 00138736 _____ C:\Windows\system32\Drivers\PnkBstrK.sys
2013-07-31 18:27 - 2013-07-31 18:27 - 00000000 ____D C:\Users\Lisa\AppData\Local\PunkBuster
2013-07-30 23:42 - 2013-07-30 23:42 - 00000000 ____D C:\NvidiaLogging
2013-07-30 23:32 - 2013-05-14 21:28 - 00034592 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2013-07-30 23:32 - 2013-05-14 21:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll
2013-07-30 13:25 - 2013-07-30 13:25 - 00000676 _____ C:\Users\Lisa\Desktop\Assassin's Creed III - Verknüpfung.lnk
2013-07-30 01:30 - 2013-07-31 18:28 - 00000000 ____D C:\Users\Lisa\Documents\Assassin's Creed III
2013-07-30 01:18 - 2013-07-30 02:01 - 00000000 ____D C:\Users\Lisa\AppData\Local\Ubisoft Game Launcher
2013-07-30 00:54 - 2013-07-31 18:27 - 00281392 _____ C:\Windows\system32\PnkBstrB.exe
2013-07-30 00:54 - 2013-07-31 18:27 - 00076888 _____ C:\Windows\system32\PnkBstrA.exe
2013-07-30 00:54 - 2013-07-30 00:54 - 00189248 _____ C:\Windows\system32\PnkBstrB.ex0
2013-07-30 00:54 - 2013-07-30 00:54 - 00001161 _____ C:\Users\Lisa\Desktop\Uplay.lnk
2013-07-30 00:54 - 2013-07-30 00:54 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-07-30 00:54 - 2012-06-19 13:02 - 03123272 _____ C:\Windows\system32\pbsvc.exe
2013-07-29 21:37 - 2013-07-30 00:37 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\GetRightToGo
2013-07-29 21:36 - 2013-07-29 21:36 - 00435172 _____ C:\Users\Lisa\Downloads\Assassins_Creed_III_DownloadManager.zip
==================== One Month Modified Files and Folders =======
2013-08-24 20:40 - 2009-12-28 14:58 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-24 20:39 - 2013-08-24 20:38 - 01070693 _____ (Farbar) C:\Users\Lisa\Downloads\FRST (1).exe
2013-08-24 20:37 - 2009-11-03 21:46 - 00009504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-24 20:37 - 2009-11-03 21:46 - 00009504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-24 20:36 - 2013-08-24 20:34 - 00000000 ____D C:\Users\Lisa\Desktop\Neuer Ordner
2013-08-24 20:33 - 2013-08-24 20:33 - 01021434 _____ (Thisisu) C:\Users\Lisa\Downloads\JRT.exe
2013-08-24 20:33 - 2013-08-24 20:33 - 00000000 ____D C:\Windows\ERUNT
2013-08-24 20:31 - 2012-10-20 23:17 - 00000000 ___RD C:\Users\Lisa\Dropbox
2013-08-24 20:31 - 2012-10-20 23:13 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Dropbox
2013-08-24 20:31 - 2009-02-14 20:55 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Skype
2013-08-24 20:29 - 2010-01-22 15:42 - 00000000 ____D C:\Program Files\Common Files\Akamai
2013-08-24 20:29 - 2009-12-28 14:58 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-24 20:29 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-24 20:29 - 2009-07-14 06:39 - 00475667 _____ C:\Windows\setupact.log
2013-08-24 20:29 - 2008-03-31 22:06 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-24 20:28 - 2013-08-24 20:23 - 00000000 ____D C:\AdwCleaner
2013-08-24 20:28 - 2010-03-05 22:20 - 01276274 _____ C:\Windows\WindowsUpdate.log
2013-08-24 20:21 - 2013-08-24 20:21 - 00994642 _____ C:\Users\Lisa\Downloads\adwcleaner.exe
2013-08-24 19:56 - 2013-08-24 19:56 - 00001069 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-24 19:56 - 2013-08-24 19:56 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-24 19:55 - 2013-08-24 19:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-1.75.0.1300 (1).exe
2013-08-24 16:05 - 2013-08-24 16:05 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2013-08-24 16:04 - 2013-08-24 16:04 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories
2013-08-24 16:04 - 2008-03-31 21:56 - 00351036 _____ C:\Windows\DirectX.log
2013-08-24 16:03 - 2013-08-24 16:03 - 07522680 _____ (Microsoft Corporation) C:\Users\Lisa\Desktop\Xbox360_32Deu.exe
2013-08-24 15:27 - 2013-08-24 15:27 - 00031542 _____ C:\ComboFix.txt
2013-08-24 15:27 - 2013-08-24 15:05 - 00000000 ____D C:\ComboFix
2013-08-24 15:27 - 2013-08-24 14:20 - 00000000 ____D C:\Qoobox
2013-08-24 15:27 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2013-08-24 15:26 - 2013-08-24 14:19 - 00000000 ____D C:\Windows\erdnt
2013-08-24 15:21 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2013-08-24 15:20 - 2009-11-03 22:02 - 02618754 _____ C:\Windows\PFRO.log
2013-08-24 15:20 - 2009-07-14 04:03 - 76808192 _____ C:\Windows\system32\config\SOFTWARE.bak
2013-08-24 15:20 - 2009-07-14 04:03 - 27787264 _____ C:\Windows\system32\config\SYSTEM.bak
2013-08-24 15:20 - 2009-07-14 04:03 - 00524288 _____ C:\Windows\system32\config\DEFAULT.bak
2013-08-24 15:20 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak
2013-08-24 15:20 - 2009-07-14 04:03 - 00262144 _____ C:\Windows\system32\config\SAM.bak
2013-08-24 15:19 - 2010-03-05 21:45 - 00000000 ____D C:\Users\Lisa
2013-08-24 15:19 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-08-24 15:02 - 2013-08-24 15:02 - 00001402 _____ C:\Users\Lisa\Desktop\ComboFix.exe - Verknüpfung.lnk
2013-08-24 14:58 - 2009-07-14 10:56 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-08-24 14:58 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-08-24 14:58 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration
2013-08-24 14:20 - 2013-08-24 14:20 - 05111180 ____R (Swearware) C:\Users\Lisa\Downloads\ComboFix (1).exe
2013-08-24 14:10 - 2013-08-24 14:10 - 05111180 ____R (Swearware) C:\Users\Lisa\Downloads\ComboFix.exe
2013-08-24 11:58 - 2013-08-24 11:58 - 00073702 _____ C:\Users\Lisa\Desktop\FRST1.txt
2013-08-24 11:58 - 2013-08-24 11:58 - 00034916 _____ C:\Users\Lisa\Desktop\Addition.txt
2013-08-24 11:57 - 2013-08-24 11:57 - 00034916 _____ C:\Users\Lisa\Downloads\Addition.txt
2013-08-24 11:55 - 2013-08-24 11:55 - 00000000 ____D C:\FRST
2013-08-24 11:54 - 2013-08-24 11:54 - 01070467 _____ (Farbar) C:\Users\Lisa\Downloads\FRST.exe
2013-08-24 02:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Cursors
2013-08-24 02:14 - 2013-04-14 18:41 - 00000000 ____D C:\Program Files\Jungle Timer
2013-08-24 00:11 - 2011-12-13 17:07 - 00000000 ____D C:\Users\Lisa\AppData\Local\PMB Files
2013-08-24 00:11 - 2011-12-13 17:07 - 00000000 ____D C:\ProgramData\PMB Files
2013-08-23 21:36 - 2013-08-23 21:36 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Malwarebytes
2013-08-23 21:35 - 2013-08-23 21:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-23 21:35 - 2013-08-23 21:34 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-23 21:27 - 2013-08-23 21:27 - 02347384 _____ (ESET) C:\Users\Lisa\Downloads\esetsmartinstaller_enu.exe
2013-08-23 20:57 - 2013-08-23 20:57 - 00000000 ____D C:\Users\Lisa\AppData\Local\avgchrome
2013-08-23 19:21 - 2013-08-23 19:21 - 46960392 _____ (Trend Micro ) C:\Users\Lisa\Downloads\tis14de_1479_eval30.exe
2013-08-23 19:07 - 2013-08-23 19:07 - 00143980 _____ C:\Users\Lisa\Downloads\Ausgleich der stornierten Lastschrift Ihrer Bestellung 23.08.2013.zip
2013-08-23 19:07 - 2013-08-23 19:07 - 00143980 _____ C:\Users\Lisa\Downloads\Ausgleich der stornierten Lastschrift Ihrer Bestellung 23.08.2013 (1).zip
2013-08-22 21:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2013-08-22 01:52 - 2010-06-28 15:44 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\HpUpdate
2013-08-21 15:40 - 2012-04-11 12:00 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-08-21 15:40 - 2011-05-26 15:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-08-21 14:22 - 2012-05-20 21:13 - 00000000 ____D C:\Users\Lisa\AppData\Local\Origin
2013-08-21 14:22 - 2012-05-20 21:07 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Origin
2013-08-21 14:21 - 2012-05-20 21:07 - 00000000 ____D C:\Program Files\Origin
2013-08-21 13:46 - 2010-09-12 18:48 - 00000000 ____D C:\Users\Lisa\Desktop\Sonstiges
2013-08-20 13:21 - 2013-08-20 13:21 - 00092776 _____ (Spotify Ltd) C:\Users\Lisa\Downloads\SpotifySetup.exe
2013-08-16 16:53 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-08-16 15:06 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-16 12:20 - 2010-12-13 21:46 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\TS3Client
2013-08-16 02:59 - 2013-07-15 09:43 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 02:55 - 2010-03-13 21:00 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-16 02:53 - 2010-03-05 22:30 - 01657590 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-31 18:28 - 2013-07-30 01:30 - 00000000 ____D C:\Users\Lisa\Documents\Assassin's Creed III
2013-07-31 18:27 - 2013-07-31 18:27 - 00281392 _____ C:\Windows\system32\PnkBstrB.xtr
2013-07-31 18:27 - 2013-07-31 18:27 - 00138736 _____ C:\Windows\system32\Drivers\PnkBstrK.sys
2013-07-31 18:27 - 2013-07-31 18:27 - 00000000 ____D C:\Users\Lisa\AppData\Local\PunkBuster
2013-07-31 18:27 - 2013-07-30 00:54 - 00281392 _____ C:\Windows\system32\PnkBstrB.exe
2013-07-31 18:27 - 2013-07-30 00:54 - 00076888 _____ C:\Windows\system32\PnkBstrA.exe
2013-07-30 23:42 - 2013-07-30 23:42 - 00000000 ____D C:\NvidiaLogging
2013-07-30 23:38 - 2010-05-09 20:30 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-07-30 13:25 - 2013-07-30 13:25 - 00000676 _____ C:\Users\Lisa\Desktop\Assassin's Creed III - Verknüpfung.lnk
2013-07-30 02:01 - 2013-07-30 01:18 - 00000000 ____D C:\Users\Lisa\AppData\Local\Ubisoft Game Launcher
2013-07-30 00:54 - 2013-07-30 00:54 - 00189248 _____ C:\Windows\system32\PnkBstrB.ex0
2013-07-30 00:54 - 2013-07-30 00:54 - 00001161 _____ C:\Users\Lisa\Desktop\Uplay.lnk
2013-07-30 00:54 - 2013-07-30 00:54 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-07-30 00:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles
2013-07-30 00:54 - 2008-04-04 21:55 - 00000000 ____D C:\Program Files\Ubisoft
2013-07-30 00:54 - 2008-03-31 21:47 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-07-30 00:37 - 2013-07-29 21:37 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\GetRightToGo
2013-07-29 21:36 - 2013-07-29 21:36 - 00435172 _____ C:\Users\Lisa\Downloads\Assassins_Creed_III_DownloadManager.zip
2013-07-27 16:44 - 2008-03-31 21:53 - 00000000 ____D C:\Program Files\Google
2013-07-26 05:13 - 2013-08-16 02:51 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-26 05:13 - 2013-08-16 02:51 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 05:13 - 2013-08-16 02:51 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 05:12 - 2013-08-16 02:51 - 14329344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 05:12 - 2013-08-16 02:51 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 05:12 - 2013-08-16 02:51 - 02048512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 05:12 - 2013-08-16 02:51 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-26 05:12 - 2013-08-16 02:51 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 05:12 - 2013-08-16 02:51 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-26 05:12 - 2013-08-16 02:51 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 05:12 - 2013-08-16 02:51 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 05:12 - 2013-08-16 02:51 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 05:11 - 2013-08-16 02:51 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 05:11 - 2013-08-16 02:51 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-26 04:49 - 2013-08-16 02:51 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-26 03:59 - 2013-08-16 02:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-25 10:57 - 2013-08-15 19:47 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
Files to move or delete:
====================
C:\Users\Lisa\AppData\Local\Temp\catchme.dll
C:\Users\Lisa\AppData\Local\Temp\Quarantine.exe
C:\Users\Lisa\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\Lisa\AppData\Local\Temp\jrt\erunt\ERUNT.EXE.manifest
C:\Users\Lisa\AppData\Local\Temp\be29e7f1-71ae-4703-50cb-1d52be512f51\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-22 19:21
==================== End Of Log ============================ --- --- --- |