Code:
# AdwCleaner v3.308 - Report created 26/08/2014 at 09:09:23
# Updated 20/08/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : rbratz - PAS-E6420-D
# Running from : C:\Users\rbratz\Desktop\adwcleaner_3.308.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : netfilter64
[#] Service Deleted : pricemeterliveUpdate
[#] Service Deleted : pricemeterliveUpdatem
Service Deleted : SupraSavingsService64
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\IePluginService
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\ProgramData\PriceMeterLiveUpdate
Folder Deleted : C:\ProgramData\WPM
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\ConduitEngine
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Mobogenie
Folder Deleted : C:\Program Files (x86)\PriceMeterLiveUpdate
Folder Deleted : C:\Program Files (x86)\SimilarSites
Folder Deleted : C:\Program Files (x86)\smart pc cleaner
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\Uniblue
Folder Deleted : C:\Program Files\003
Folder Deleted : C:\Program Files\SupraSavings
Folder Deleted : C:\Users\rbratz\AppData\Local\Conduit
Folder Deleted : C:\Users\rbratz\AppData\Local\globalUpdate
Folder Deleted : C:\Users\rbratz\AppData\Local\Mobogenie
Folder Deleted : C:\Users\rbratz\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\rbratz\AppData\Local\PriceMeterLiveUpdate
Folder Deleted : C:\Users\rbratz\AppData\Local\TBHostSupport
Folder Deleted : C:\Users\rbratz\AppData\Local\Temp\NativeMessaging
Folder Deleted : C:\Users\rbratz\AppData\Local\Temp\Spigot
Folder Deleted : C:\Users\rbratz\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\rbratz\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\rbratz\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\rbratz\AppData\LocalLow\Delta
Folder Deleted : C:\Users\rbratz\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\rbratz\AppData\Roaming\Babylon
Folder Deleted : C:\Users\rbratz\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\rbratz\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\rbratz\AppData\Roaming\ParetoLogic
Folder Deleted : C:\Users\rbratz\AppData\Roaming\PriceMeterUpdater
Folder Deleted : C:\Users\rbratz\AppData\Roaming\SearchProtect
Folder Deleted : C:\Users\rbratz\AppData\Roaming\SimilarSites
Folder Deleted : C:\Users\rbratz\AppData\Roaming\SupTab
Folder Deleted : C:\Users\rbratz\Documents\Mobogenie
Folder Deleted : C:\Users\rbratz\Documents\Optimizer Pro
Folder Deleted : C:\Users\rbratz\Documents\smart pc cleaner
Folder Deleted : C:\Users\Robert_privat\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Robert_privat\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\Robert_privat\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Robert_privat\AppData\LocalLow\Vuze_Remote
Folder Deleted : C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
File Deleted : C:\END
File Deleted : C:\Windows\System32\drivers\netfilter64.sys
File Deleted : C:\Windows\System32\SecureAssist64.dll
File Deleted : C:\Users\rbratz\daemonprocess.txt
File Deleted : C:\Users\rbratz\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\crpeqp8w.default\bprotector_extensions.sqlite
File Deleted : C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\crpeqp8w.default\searchplugins\Babylon.xml
File Deleted : C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\778oqeqv.default-1376129905533\searchplugins\Conduit.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\qone8.xml
File Deleted : C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\778oqeqv.default-1376129905533\searchplugins\safeguard-secure-search.xml
File Deleted : C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\crpeqp8w.default\searchplugins\safeguard-secure-search.xml
File Deleted : C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\crpeqp8w.default\user.js
File Deleted : C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.betterdeals00.betterdeals.co_0.localstorage
File Deleted : C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.betterdeals00.betterdeals.co_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : BackgroundContainer Startup Task
Task Deleted : pricemeterdownloader
Task Deleted : PriceMeterLiveUpdateUpdateTaskMachineCore
Task Deleted : PriceMeterLiveUpdateUpdateTaskMachineUA
Task Deleted : PriceMeterUpdater
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\rbratz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\rbratz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\rbratz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [quick_start@gmail.com]
Key Deleted : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BackgroundContainer]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\PriceMeterLiveUpdate.exe
Key Deleted : HKLM\SOFTWARE\Classes\AppID\PropertySync.EXE
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdate.OneClickCtrl.9
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdate.Update3WebControl.3
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BabMaint_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BabMaint_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9
Key Deleted : HKCU\Software\9578888b53dbd14
Key Deleted : HKLM\SOFTWARE\9578888b53dbd14
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3106777
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3306926
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{126C78A0-36E7-4697-A3AB-32706144398B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{8D73A258-9787-4AE7-9232-41036673FD0E}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00A154AE-6C33-4F1E-9057-242350540936}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{126C78A0-36E7-4697-A3AB-32706144398B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{30D1E30D-B7F5-4C7A-8EDA-9F02966538A8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{41C35ADE-DEDA-439F-8140-D53F2C76C963}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4211E851-747F-4470-923D-6EF683EE79CA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{45F8961E-1314-421E-9F00-BDDE18CF8EA0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4825ACAD-F495-4CDD-9603-9C91BABB2B88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5B60D1C0-453A-485D-AE91-61FAC9203719}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{74930D00-2198-46FE-B6BC-FEEC60C666C9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{89449F37-4AB2-46ED-A566-BB3A7797701B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8D73A258-9787-4AE7-9232-41036673FD0E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9D24562E-40EC-4E46-B57C-700352059B55}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B1F29F0C-2EC8-487B-97C2-8B8FEA6CEF14}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C0756D99-64A1-4332-B783-A5A1B571D431}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CF0A778A-DDA0-4492-9804-EF38C9A9F1A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D1C6444C-CC06-4060-A486-736DEAFD9C16}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D8746A3A-A372-4C8B-96E5-B58F6474EB19}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{93CF54F5-CFAA-4440-B588-8ED0DFAD5C21}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D3BC53E7-0437-4C97-90EE-2CD6FF47FB14}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9863E762-BACC-46E4-8CAA-2A6ADA06B65B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{597A9974-8CB0-4F41-B61F-ED065738A397}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA14329E-9550-4989-B3F2-9732E92D17CC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89449F37-4AB2-46ED-A566-BB3A7797701B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{30D1E30D-B7F5-4C7A-8EDA-9F02966538A8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{89449F37-4AB2-46ED-A566-BB3A7797701B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D3AC848A-5294-4E1C-BDCF-03BD4C9F79CF}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{93CF54F5-CFAA-4440-B588-8ED0DFAD5C21}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D3BC53E7-0437-4C97-90EE-2CD6FF47FB14}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\BABSOLUTION
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\delta LTD
Key Deleted : HKCU\Software\filescout
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\powerpack
Key Deleted : HKCU\Software\PriceMeterLiveUpdate
Key Deleted : HKCU\Software\PriceMeterUpdater
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\Rr Savings
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Supra Savings
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\BabylonToolbar
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\conduitEngine
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\DealPlyLive
Key Deleted : HKLM\SOFTWARE\Driver-Soft
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstallIQ
Key Deleted : HKLM\SOFTWARE\ParetoLogic
Key Deleted : HKLM\SOFTWARE\PriceMeterLiveUpdate
Key Deleted : HKLM\SOFTWARE\qone8Software
Key Deleted : HKLM\SOFTWARE\suprasavings
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\Wpm
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wpm
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conduit Engine
Key Deleted : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Key Deleted : [x64] HKLM\SOFTWARE\Supra Savings
Key Deleted : [x64] HKLM\SOFTWARE\suprasavings
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PriceMeterLiveUpdate.exe
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v31.0 (x86 en-US)
[ File : C:\Users\pureadmin\AppData\Roaming\Mozilla\Firefox\Profiles\yut01lse.default\prefs.js ]
[ File : C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\778oqeqv.default-1376129905533\prefs.js ]
Line Deleted : user_pref("CT3306926_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1386493164561,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "");
Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", "");
Line Deleted : user_pref("Smartbar.ConduitSearchUrlList", "");
Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3306926");
Line Deleted : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "Gameoff-games Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3306926&CUI=UN29000216426165631&UM=2&SearchSource=3&q={searchTerms}&sspv=TB_CNI");
Line Deleted : user_pref("browser.search.order.1", "Delta Search");
Line Deleted : user_pref("extensions.crossrider.bic", "145fbd62b24b0d569ca327bee5eff1a7");
Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
Line Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 2);
Line Deleted : user_pref("smartbar.machineId", "K7O8IV/O8OWHWIJJ6K8KMWPMEPQ9LHEUUKMHUINV4CUSNETGMM+G5AVZDQDZBT4NLLS6DTKYGKCNINEVA/JWPA");
[ File : C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\crpeqp8w.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultthis.engineName", "Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("browser.search.order.1", "Delta Search");
Line Deleted : user_pref("extensions.507dae0fa4ce5.scode", "if(window.self.location.protocol=='hxxp:' && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src=[...]
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.bbDpng", "12");
Line Deleted : user_pref("extensions.delta.cntry", "DE");
Line Deleted : user_pref("extensions.delta.dfltLng", "en");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.hdrMd5", "3C70EFA624E90AA0C29D21CC9135B43E");
Line Deleted : user_pref("extensions.delta.id", "bafa11ae00000000000068a3c4c9506d");
Line Deleted : user_pref("extensions.delta.instlDay", "15810");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.16.1611:53:57");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.sg", "azb");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.16.16");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.16.16");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.16.1611:53:57");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://de.search.yahoo.com/?type=994519&fr=spigot-yhp-ff");
-\\ Google Chrome v
[ File : C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN16035642584541656&ctid=CT3306926&UM=2&sspv=TB_CNI3
Deleted [Search Provider] : hxxp://www.qone8.com/web/?type=ds&ts=1400089458&from=ild&uid=HitachiXHTS723225A7A364_E3824562GB952NGB952NX&q={searchTerms}
Deleted [Extension] : olakgnkoldmagdblaalodobkmeokmgjj
Deleted [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma
*************************
AdwCleaner[R0].txt - [28036 octets] - [26/08/2014 08:49:53]
AdwCleaner[S0].txt - [26227 octets] - [26/08/2014 09:09:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [26288 octets] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 8/26/2014
Scan Time: 9:25:48 AM
Logfile: anti_malware.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.25.05
Rootkit Database: v2014.08.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: rbratz
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 434028
Time Elapsed: 53 min, 32 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by rbratz on Tue 08/26/2014 at 10:37:47.71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2186728067-1712137595-3068445564-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{50F78362-6D36-40E1-969A-3B7AC87FB5CB}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{04A6E20F-572C-4B2A-BCEF-53D0DCE2331F}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{1A429FDD-6B2F-48E7-B58D-DA8C9A1D9D28}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{23B167E8-2ABB-4670-A316-0FC793E8DEE2}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{2D5F2645-1C8F-4E56-85BE-87B9FF352E6B}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{374F2E09-53D3-43D1-A7C2-346E890BCCC8}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{3C38E632-DD94-4CBA-A13D-6948EF8FF493}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{4B8BB256-011E-4DB0-B8AD-AC299B547267}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{76EE336A-B825-47B9-A1B4-4F8DF0AF9617}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{841699B0-8E1C-45E2-8DD6-B645FBE7358A}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{89CC73D2-44FC-4B9E-9062-CCEA6B9EF971}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{8BC75410-C1DC-4B28-B24E-E040356AA187}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{96539E91-EB58-4AD3-875C-2D739B3A8DB0}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{9A12AF61-95AE-4A29-AC74-1AC9B55D3AA9}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{9C1FC5CF-14C0-4759-8F1D-833C78932067}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{9F124AE7-EA9E-4281-B730-E067A75898BE}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{9F5A4616-9D3F-4DBA-A6B6-ABAA2466250E}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{A57D31EE-18D5-44E1-A9C8-2CFA0D31A0FB}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{A6E0809E-0C0E-467B-BDEC-ACD3456DCE56}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{B5A494FF-595E-46F8-A743-3808A4C15137}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{CBE89DE9-C2E4-4088-8C96-A76F1E7E50F0}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{DAA2D195-F22D-4397-94CC-706BD3151A68}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{E983E57C-027B-4BC7-B19F-130D417548E1}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{EFA685E2-FF10-4C71-BF60-31D9E0262AE7}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{F24A7E49-1E91-4FE1-903D-BF7D0869C160}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{FE2B377D-FA02-424E-B4F3-C87130007F05}
Successfully deleted: [Empty Folder] C:\Users\rbratz\appdata\local\{FF9175BD-CA5A-40AD-99D7-85788AFF3D3A}
~~~ FireFox
Emptied folder: C:\Users\rbratz\AppData\Roaming\mozilla\firefox\profiles\778oqeqv.default-1376129905533\minidumps [279 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 08/26/2014 at 10:45:47.34
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-08-2014 03
Ran by rbratz (administrator) on PAS-E6420-D on 26-08-2014 10:50:05
Running from C:\Users\rbratz\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE
(UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\scheduler.exe
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FCDBLog.exe
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\fcappdb.exe
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FortiESNAC.exe
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FortiSSLVPNdaemon.exe
(Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
(Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\ssonsvr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(O2Micro International) C:\Windows\System32\drivers\o2flash.exe
() C:\Windows\SysWOW64\srvany.exe
(O2Micro.) C:\Windows\SysWOW64\SDIOAssist.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FCHelper64.exe
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FortiTray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Dell Inc.) C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FortiProxy.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
(NewSoft Technology Corporation) C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
(NewSoft Technology Corporation) C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_FATIBVA.EXE
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(NewSoft Technology Corporation) C:\Program Files (x86)\NewSoft\Presto! PageManager 9 for EP\PMSpeed.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Dell Inc.) C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\pnamain.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\fmon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [592240 2011-01-05] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [6492672 2011-01-16] (Dell Inc.)
HKLM\...\Run: [WrtMon.exe] => C:\Windows\system32\spool\drivers\x64\3\WrtMon.exe [26448 2008-05-24] (NewSoft Technology Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2010-12-04] (Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [462993 2010-03-13] (Creative Technology Ltd)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-04-30] (CyberLink Corp.)
HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-12] (Adobe Systems Inc.)
HKLM-x32\...\Run: [PMSpeed] => C:\Program Files (x86)\NewSoft\Presto! PageManager 9 for EP\PMSpeed.EXE [112464 2009-12-05] (NewSoft Technology Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [309184 2012-03-28] (Citrix Systems, Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-05-12] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\Run: [Google Update] => C:\Users\rbratz\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-12-21] (Google Inc.)
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22734160 2014-08-08] (Google)
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20917408 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\Run: [EPSON Stylus CX5000 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBVA.EXE [143360 2006-10-18] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {0045224c-969d-11e1-aa7c-90004ef0d0af} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {00e09687-e7cd-11e1-b13b-90004ef0d0af} - E:\Setup.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {5b6da3cd-736f-11e2-8279-90004ef0d0af} - E:\LaunchU3.exe -a
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {6f9a5156-2cb0-11e1-b336-90004ef0d0af} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {7862c154-7693-11e2-a2ad-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {7862c163-7693-11e2-a2ad-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {7862c1a9-7693-11e2-a2ad-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {7862c1c3-7693-11e2-a2ad-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {7862c1fc-7693-11e2-a2ad-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {7862c359-7693-11e2-a2ad-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {9015b3ad-86f9-11e2-a003-001e101f2500} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {9753809b-5468-11e2-ba54-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {a6c3345a-51ea-11e2-9b57-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {b561dea8-51e9-11e2-9bbf-90004ef0d0af} - E:\AutoRun.exe
HKU\S-1-5-21-2186728067-1712137595-3068445564-1001\...\MountPoints2: {f8e3eac1-9c12-11e1-84b3-5c260a5996ba} - "E:\WD SmartWare.exe" autoplay=true
Lsa: [Authentication Packages] msv1_0 wvauth
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell System Manager.lnk
ShortcutTarget: Dell System Manager.lnk -> C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Online plug-in.lnk
ShortcutTarget: Online plug-in.lnk -> C:\Windows\Installer\{913778D3-E1D8-4B55-9246-3308C54D3162}\pnaico.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe ()
Startup: C:\Users\rbratz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk
ShortcutTarget: MultiSkypeLauncher.lnk -> C:\Program Files (x86)\MultiSkypeLauncher\MultiSkypeLauncher.exe (IM-history)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\rbratz\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\rbratz\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\rbratz\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\rbratz\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: EnabledUnlockedFDEIconOverlay -> {30D3C2AF-9709-4D05-9CF4-13335F3C1E4A} => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll (Wave Systems Corp.)
ShellIconOverlayIdentifiers: UninitializedFdeIconOverlay -> {CF08DA3E-C97D-4891-A66B-E39B28DD270F} => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll (Wave Systems Corp.)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\rbratz\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\rbratz\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\rbratz\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.com/
SearchScopes: HKCU - {92892FC0-CAE5-455C-96D7-5D805F4DA9C0} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=994519&p={searchTerms}
BHO: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll No File
BHO: avast! Online Security -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: WinZip Courier BHO -> {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} -> C:\PROGRA~2\WINZIP~2\wzwmcie.dll No File
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll No File
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll No File
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\778oqeqv.default-1376129905533
FF Homepage: https://mail.google.com/mail/u/0/#inbox
FF Keyword.URL: hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=994519&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @ei.CieoNetUtilities_0e.com/Plugin -> C:\Program Files (x86)\CieoNetUtilities_0eEI\Installr\2.bin\NP0eEISB.dll No File
FF Plugin-x32: @FortinetCacheClean -> C:\Program Files (x86)\Fortinet\FortiClient\npccplugin.dll (Fortinet Inc.)
FF Plugin-x32: @FortinetCacheCleanEx -> C:\Program Files (x86)\Fortinet\FortiClient\npccpluginex.dll (Fortinet Inc.)
FF Plugin-x32: @FortinetTunnelControl -> C:\Program Files (x86)\Fortinet\FortiClient\nptcplugin.dll (Fortinet Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @winzip.com/Winzip Courier -> C:\Program Files (x86)\WinZip Courier\npwzwmc.dll (WinZip Computing, S.L.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\rbratz\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\rbratz\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll (Citrix Systems, Inc.)
FF SearchPlugin: C:\Users\rbratz\AppData\Roaming\Mozilla\Firefox\Profiles\778oqeqv.default-1376129905533\searchplugins\yahoo_ff.xml
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\FirefoxExtension
FF HKLM-x32\...\Firefox\Extensions: [{74c841e3-b59f-479e-8d7a-e26a942a87c8}] - C:\Program Files (x86)\WinZip Courier\FFExt
FF Extension: No Name - C:\Program Files (x86)\WinZip Courier\FFExt [2011-11-24]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR HomePage: hxxp://google.com/
CHR StartupUrls: "hxxp://google.com/"
CHR NewTab: "chrome-extension://pelmeidfhdlhlbjimpabfcbnnojbboma/index.html"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\rbratz\AppData\Local\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\rbratz\AppData\Local\Google\Chrome\Application\36.0.1985.143\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\rbratz\AppData\Local\Google\Chrome\Application\36.0.1985.143\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (CieoNet Utilities Installer Plugin Stub) - C:\Program Files (x86)\CieoNetUtilities_0eEI\Installr\2.bin\NP0eEISB.dll No File
CHR Plugin: (WinZip Courier) - C:\Program Files (x86)\WinZip Courier\npwzwmc.dll (WinZip Computing, S.L.)
CHR Plugin: (Windows Live? Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\rbratz\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (Google Drive) - C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-24]
CHR Extension: (YouTube) - C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-21]
CHR Extension: (Google Search) - C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-21]
CHR Extension: (Google Wallet) - C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Gmail) - C:\Users\rbratz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-21]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\rbratz\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-03-29]
CHR HKCU\...\Chrome\Extension: [pckaochijkjekcndgjamcfccjimechdg] - C:\Users\rbratz\AppData\Local\CRE\pckaochijkjekcndgjamcfccjimechdg.crx [2013-12-05]
CHR HKLM-x32\...\Chrome\Extension: [pckaochijkjekcndgjamcfccjimechdg] - C:\Users\rbratz\AppData\Local\CRE\pckaochijkjekcndgjamcfccjimechdg.crx [2013-12-05]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE [102400 2006-04-18] (SEIKO EPSON CORPORATION)
R2 FA_Scheduler; C:\Program Files (x86)\Fortinet\FortiClient\scheduler.exe [98322 2014-04-16] (Fortinet Inc.) [File not signed]
R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] () [File not signed]
S3 SecureStorageService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe [2117120 2010-11-04] (Wave Systems Corp.) [File not signed]
S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-14] () [File not signed]
R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [5839872 2011-01-16] (Dell Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U0 bgxoja; C:\Windows\System32\drivers\gdpnleb.sys [79064 2014-08-26] (Malwarebytes Corporation)
R1 FAFileMon; C:\Windows\System32\drivers\fortimon2.sys [56032 2014-04-16] (Fortinet Inc)
S3 FARegMon; C:\Windows\System32\drivers\FortiRmon.sys [50912 2014-04-16] (Fortinet Inc)
R3 fortiapd; C:\Windows\System32\drivers\fortiapd.sys [16096 2014-04-16] (Fortinet Inc)
R1 FortiFilter; C:\Windows\System32\DRIVERS\FortiFilter.sys [25312 2013-09-18] (Fortinet Inc)
S1 FortiFW; C:\Windows\System32\drivers\FortiFW2.sys [37600 2014-04-16] (Fortinet Inc)
R0 fortiloader; C:\Windows\System32\drivers\fortiloader.sys [12512 2014-04-16] (Fortinet Inc)
S3 Fortips; C:\Windows\System32\drivers\fortips.sys [133856 2014-04-16] (Fortinet Inc)
S3 FortiRdr; C:\Windows\System32\drivers\FortiRdr2.sys [47328 2014-04-16] (Fortinet Inc)
R1 FortiShield; C:\Windows\System32\drivers\FortiShield.sys [56544 2014-04-16] (Fortinet Inc)
R3 FortiWF; C:\Windows\System32\drivers\FortiWF2.sys [28384 2014-04-16] (Fortinet Inc)
R3 ft_vnic; C:\Windows\System32\DRIVERS\ftvnic.sys [16928 2011-03-21] (Fortinet Inc.)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-26] (Malwarebytes Corporation)
S3 mdareDriver_43; C:\Users\rbratz\AppData\Local\Temp\FCPreScan\mdare64_43.sys [90848 2014-01-30] (Fortinet Inc.)
S3 mdareDriver_47; C:\Program Files (x86)\Fortinet\FortiClient\mdare64_47.sys [91872 2014-05-22] (Fortinet Inc.)
R3 mdareDriver_48; C:\Program Files (x86)\Fortinet\FortiClient\mdare64_48.sys [91872 2014-07-04] (Fortinet Inc.)
R3 pppop; C:\Windows\System32\DRIVERS\pppop64.sys [42528 2011-03-21] (Fortinet Inc.)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-26 10:45 - 2014-08-26 10:45 - 00004217 _____ () C:\Users\rbratz\Desktop\JRT.txt
2014-08-26 10:37 - 2014-08-26 10:37 - 00000000 ____D () C:\Windows\ERUNT
2014-08-26 10:36 - 2014-08-26 10:36 - 01016261 _____ (Thisisu) C:\Users\rbratz\Desktop\JRT.exe
2014-08-26 10:30 - 2014-08-26 10:30 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\gdpnleb.sys
2014-08-26 10:30 - 2014-08-26 10:30 - 00001066 _____ () C:\Users\rbratz\Desktop\anti_malware.txt
2014-08-26 09:28 - 2014-08-26 09:28 - 00000165 ____H () C:\Users\rbratz\Desktop\~$pre order overview.xlsx
2014-08-26 09:23 - 2014-08-26 09:25 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-26 09:22 - 2014-08-26 09:22 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-26 09:22 - 2014-08-26 09:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-26 09:22 - 2014-08-26 09:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-26 09:22 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-26 09:22 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-26 09:22 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-26 09:20 - 2014-08-26 09:21 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\rbratz\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-08-26 08:51 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-26 08:49 - 2014-08-26 09:10 - 00000000 ____D () C:\AdwCleaner
2014-08-26 08:28 - 2014-08-26 08:29 - 01364531 _____ () C:\Users\rbratz\Desktop\adwcleaner_3.308.exe
2014-08-25 09:01 - 2014-08-25 09:02 - 00056829 _____ () C:\Users\rbratz\Desktop\Addition.txt
2014-08-25 08:59 - 2014-08-26 10:51 - 00034357 _____ () C:\Users\rbratz\Desktop\FRST.txt
2014-08-25 08:57 - 2014-08-26 10:50 - 00000000 ____D () C:\FRST
2014-08-25 08:56 - 2014-08-25 08:56 - 02103296 _____ (Farbar) C:\Users\rbratz\Desktop\FRST64.exe
2014-08-25 08:55 - 2014-08-25 08:55 - 01095168 _____ (Farbar) C:\Users\rbratz\Desktop\FRST.exe
2014-08-22 11:58 - 2014-08-22 11:58 - 00052224 _____ () C:\Users\rbratz\Downloads\SearchResults(2).xls
2014-08-21 21:32 - 2014-08-21 21:48 - 00012504 _____ () C:\Users\rbratz\Desktop\turnover.xlsx
2014-08-21 08:31 - 2014-05-15 02:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-21 08:31 - 2014-05-15 02:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-21 08:31 - 2014-05-15 02:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-21 08:31 - 2014-05-15 02:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-21 08:31 - 2014-05-15 02:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-21 08:31 - 2014-05-15 02:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-21 08:31 - 2014-05-15 02:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-21 08:30 - 2014-05-15 02:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-21 08:30 - 2014-05-15 02:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-21 08:30 - 2014-05-15 02:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-21 08:30 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-21 08:30 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-21 08:30 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-21 08:30 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-19 16:08 - 2014-08-19 17:07 - 00048195 _____ () C:\Users\rbratz\Desktop\zahlen.xlsx
2014-08-19 10:15 - 2014-08-26 09:32 - 00123951 _____ () C:\Users\rbratz\Desktop\pre order overview.xlsx
2014-08-18 15:31 - 2014-08-18 15:31 - 00009599 _____ () C:\Users\rbratz\Desktop\POP EU.xlsx
2014-08-15 11:56 - 2014-08-15 11:56 - 00165376 _____ () C:\Users\rbratz\Desktop\Copy of SYD Stock On Hand Thursday 14 August 2014 20_00_44_RB.xls
2014-08-14 10:00 - 2014-08-14 10:07 - 00000000 ____D () C:\def8b9787b111ada1366d9301a4c82
2014-08-14 09:54 - 2014-07-01 08:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-14 09:54 - 2014-07-01 08:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 09:54 - 2014-06-06 16:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 09:54 - 2014-06-06 16:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-14 09:54 - 2014-03-10 07:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-14 09:54 - 2014-03-10 07:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-14 09:54 - 2014-03-10 07:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 09:54 - 2014-03-10 07:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 09:37 - 2014-08-14 09:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-14 09:00 - 2014-07-09 12:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-14 09:00 - 2014-07-09 12:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-14 09:00 - 2014-07-09 12:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-14 09:00 - 2014-07-09 12:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-14 09:00 - 2014-07-09 12:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-14 09:00 - 2014-07-09 11:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-14 09:00 - 2014-07-09 11:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-14 09:00 - 2014-07-09 11:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-14 09:00 - 2014-07-09 11:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-14 09:00 - 2014-07-09 11:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-14 09:00 - 2014-07-09 08:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-14 09:00 - 2014-07-09 08:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-14 08:56 - 2014-07-16 13:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-14 08:56 - 2014-07-16 12:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-14 08:56 - 2014-06-03 20:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-14 08:56 - 2014-06-03 20:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-14 08:56 - 2014-06-03 20:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-14 08:56 - 2014-06-03 20:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-14 08:56 - 2014-06-03 19:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-14 08:56 - 2014-06-03 19:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-14 08:56 - 2014-06-03 19:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-14 08:55 - 2014-07-16 13:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-14 08:55 - 2014-07-16 12:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-14 08:55 - 2014-07-16 12:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-14 08:55 - 2014-07-14 12:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-14 08:55 - 2014-07-14 11:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-14 08:55 - 2014-06-25 12:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-14 08:55 - 2014-06-25 11:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-14 08:55 - 2014-06-16 12:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-14 08:52 - 2014-08-07 12:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-14 08:52 - 2014-08-07 12:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-12 15:26 - 2014-08-12 15:29 - 90288664 _____ () C:\Users\rbratz\Downloads\gimp-2.8.10-setup.exe
2014-08-12 12:12 - 2014-08-12 12:12 - 02948254 _____ () C:\Users\rbratz\Downloads\wetransfer-64cfcc.zip.part
2014-08-12 10:16 - 2014-08-12 10:16 - 00004822 _____ () C:\Users\rbratz\Downloads\Mapped Dealers List.xlsx
2014-08-11 17:16 - 2014-08-18 09:44 - 00082064 _____ () C:\Users\rbratz\Desktop\ROBERT2014.TAX
2014-08-11 17:16 - 2014-08-18 09:42 - 00082048 _____ () C:\Users\rbratz\Desktop\ROBERT2014.BAK
2014-08-11 16:27 - 2014-08-11 16:35 - 00000416 _____ () C:\Users\rbratz\Documents\ROBERT2014.TAX
2014-08-11 16:27 - 2014-08-11 16:27 - 00000256 _____ () C:\Users\rbratz\Documents\ROBERT2014.BAK
2014-08-11 15:52 - 2014-08-11 15:52 - 00000000 ____D () C:\Users\rbratz\AppData\Local\etax2014
2014-08-11 15:51 - 2014-08-11 15:51 - 00001887 _____ () C:\Users\rbratz\Desktop\e-tax 2014.lnk
2014-08-11 15:51 - 2014-08-11 15:51 - 00000000 ____D () C:\Users\rbratz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\e-tax 2014
2014-08-11 15:50 - 2014-08-11 15:51 - 00000000 ____D () C:\Program Files (x86)\etax2014
2014-08-11 15:45 - 2014-08-11 15:48 - 30756864 _____ () C:\Users\rbratz\Downloads\etax2014_1.msi
2014-08-06 11:09 - 2014-08-06 11:10 - 00013045 _____ () C:\Users\rbratz\Downloads\_DetailTranSummary (Bratz,Robert)(2).html
2014-08-04 09:31 - 2014-08-04 09:34 - 02462356 _____ () C:\Users\rbratz\Downloads\2015_launch_banners.zip
2014-07-30 14:25 - 2014-07-30 14:25 - 00064464 _____ () C:\Users\rbratz\Downloads\Item list_RB.xlsx
2014-07-30 14:03 - 2014-07-30 14:03 - 00047368 _____ () C:\Users\rbratz\Downloads\Item list.xlsx
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-26 10:51 - 2014-08-25 08:59 - 00034357 _____ () C:\Users\rbratz\Desktop\FRST.txt
2014-08-26 10:51 - 2012-11-21 20:30 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-26 10:50 - 2014-08-25 08:57 - 00000000 ____D () C:\FRST
2014-08-26 10:45 - 2014-08-26 10:45 - 00004217 _____ () C:\Users\rbratz\Desktop\JRT.txt
2014-08-26 10:37 - 2014-08-26 10:37 - 00000000 ____D () C:\Windows\ERUNT
2014-08-26 10:36 - 2014-08-26 10:36 - 01016261 _____ (Thisisu) C:\Users\rbratz\Desktop\JRT.exe
2014-08-26 10:30 - 2014-08-26 10:30 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\gdpnleb.sys
2014-08-26 10:30 - 2014-08-26 10:30 - 00001066 _____ () C:\Users\rbratz\Desktop\anti_malware.txt
2014-08-26 10:30 - 2009-07-14 13:20 - 00000000 ____D () C:\Windows\tracing
2014-08-26 10:29 - 2014-05-15 03:44 - 00000000 ____D () C:\temp
2014-08-26 10:26 - 2011-07-16 03:39 - 00000000 ____D () C:\Users\rbratz\AppData\Roaming\Skype
2014-08-26 10:15 - 2011-12-21 20:43 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2186728067-1712137595-3068445564-1001UA.job
2014-08-26 09:32 - 2014-08-19 10:15 - 00123951 _____ () C:\Users\rbratz\Desktop\pre order overview.xlsx
2014-08-26 09:28 - 2014-08-26 09:28 - 00000165 ____H () C:\Users\rbratz\Desktop\~$pre order overview.xlsx
2014-08-26 09:25 - 2014-08-26 09:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-26 09:22 - 2014-08-26 09:22 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-26 09:22 - 2014-08-26 09:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-26 09:22 - 2014-08-26 09:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-26 09:21 - 2014-08-26 09:20 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\rbratz\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-08-26 09:20 - 2011-07-16 03:41 - 00000000 ____D () C:\Users\rbratz\Documents\Outlook Files
2014-08-26 09:20 - 2009-07-14 14:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-26 09:20 - 2009-07-14 14:45 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-26 09:16 - 2011-05-24 23:22 - 01598961 _____ () C:\Windows\WindowsUpdate.log
2014-08-26 09:13 - 2011-07-27 21:52 - 00000000 ____D () C:\Users\rbratz\AppData\Roaming\.oit
2014-08-26 09:12 - 2013-10-20 18:18 - 03075144 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-26 09:12 - 2012-11-21 20:30 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-26 09:12 - 2009-07-14 15:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-26 09:11 - 2013-10-20 18:18 - 00630346 _____ () C:\Windows\PFRO.log
2014-08-26 09:11 - 2013-10-20 18:18 - 00050580 _____ () C:\Windows\setupact.log
2014-08-26 09:10 - 2014-08-26 08:49 - 00000000 ____D () C:\AdwCleaner
2014-08-26 09:10 - 2011-07-14 06:52 - 00000000 ____D () C:\Users\rbratz
2014-08-26 08:29 - 2014-08-26 08:28 - 01364531 _____ () C:\Users\rbratz\Desktop\adwcleaner_3.308.exe
2014-08-25 14:03 - 2013-05-17 01:55 - 00000000 ____D () C:\Users\rbratz\Desktop\Auatralia
2014-08-25 12:15 - 2011-12-21 20:43 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2186728067-1712137595-3068445564-1001Core.job
2014-08-25 09:02 - 2014-08-25 09:01 - 00056829 _____ () C:\Users\rbratz\Desktop\Addition.txt
2014-08-25 08:56 - 2014-08-25 08:56 - 02103296 _____ (Farbar) C:\Users\rbratz\Desktop\FRST64.exe
2014-08-25 08:55 - 2014-08-25 08:55 - 01095168 _____ (Farbar) C:\Users\rbratz\Desktop\FRST.exe
2014-08-23 21:59 - 2014-04-11 13:44 - 00000000 ____D () C:\Windows\rescache
2014-08-23 20:33 - 2011-07-26 21:26 - 00000000 ____D () C:\Users\rbratz\Desktop\BEST
2014-08-22 11:58 - 2014-08-22 11:58 - 00052224 _____ () C:\Users\rbratz\Downloads\SearchResults(2).xls
2014-08-21 21:48 - 2014-08-21 21:32 - 00012504 _____ () C:\Users\rbratz\Desktop\turnover.xlsx
2014-08-20 20:55 - 2014-04-03 14:22 - 00000000 ____D () C:\Users\rbratz\Desktop\Transition period Navi
2014-08-20 13:06 - 2013-03-29 04:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-08-19 17:07 - 2014-08-19 16:08 - 00048195 _____ () C:\Users\rbratz\Desktop\zahlen.xlsx
2014-08-18 15:31 - 2014-08-18 15:31 - 00009599 _____ () C:\Users\rbratz\Desktop\POP EU.xlsx
2014-08-18 09:44 - 2014-08-11 17:16 - 00082064 _____ () C:\Users\rbratz\Desktop\ROBERT2014.TAX
2014-08-18 09:42 - 2014-08-11 17:16 - 00082048 _____ () C:\Users\rbratz\Desktop\ROBERT2014.BAK
2014-08-15 11:56 - 2014-08-15 11:56 - 00165376 _____ () C:\Users\rbratz\Desktop\Copy of SYD Stock On Hand Thursday 14 August 2014 20_00_44_RB.xls
2014-08-14 22:58 - 2012-06-13 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-14 10:07 - 2014-08-14 10:00 - 00000000 ____D () C:\def8b9787b111ada1366d9301a4c82
2014-08-14 10:07 - 2013-09-19 08:49 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 10:07 - 2011-07-09 04:53 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-14 10:00 - 2011-07-09 04:59 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 09:53 - 2014-05-06 12:41 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-14 09:37 - 2014-08-14 09:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-12 15:29 - 2014-08-12 15:26 - 90288664 _____ () C:\Users\rbratz\Downloads\gimp-2.8.10-setup.exe
2014-08-12 13:56 - 2011-09-30 22:24 - 00000000 ____D () C:\Users\rbratz\Desktop\privat
2014-08-12 12:12 - 2014-08-12 12:12 - 02948254 _____ () C:\Users\rbratz\Downloads\wetransfer-64cfcc.zip.part
2014-08-12 10:16 - 2014-08-12 10:16 - 00004822 _____ () C:\Users\rbratz\Downloads\Mapped Dealers List.xlsx
2014-08-11 16:35 - 2014-08-11 16:27 - 00000416 _____ () C:\Users\rbratz\Documents\ROBERT2014.TAX
2014-08-11 16:27 - 2014-08-11 16:27 - 00000256 _____ () C:\Users\rbratz\Documents\ROBERT2014.BAK
2014-08-11 15:52 - 2014-08-11 15:52 - 00000000 ____D () C:\Users\rbratz\AppData\Local\etax2014
2014-08-11 15:51 - 2014-08-11 15:51 - 00001887 _____ () C:\Users\rbratz\Desktop\e-tax 2014.lnk
2014-08-11 15:51 - 2014-08-11 15:51 - 00000000 ____D () C:\Users\rbratz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\e-tax 2014
2014-08-11 15:51 - 2014-08-11 15:50 - 00000000 ____D () C:\Program Files (x86)\etax2014
2014-08-11 15:48 - 2014-08-11 15:45 - 30756864 _____ () C:\Users\rbratz\Downloads\etax2014_1.msi
2014-08-07 12:06 - 2014-08-14 08:52 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 12:01 - 2014-08-14 08:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-06 11:10 - 2014-08-06 11:09 - 00013045 _____ () C:\Users\rbratz\Downloads\_DetailTranSummary (Bratz,Robert)(2).html
2014-08-05 09:20 - 2010-11-21 13:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-04 09:34 - 2014-08-04 09:31 - 02462356 _____ () C:\Users\rbratz\Downloads\2015_launch_banners.zip
2014-07-30 15:36 - 2009-07-14 15:13 - 00816122 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-30 14:25 - 2014-07-30 14:25 - 00064464 _____ () C:\Users\rbratz\Downloads\Item list_RB.xlsx
2014-07-30 14:03 - 2014-07-30 14:03 - 00047368 _____ () C:\Users\rbratz\Downloads\Item list.xlsx
2014-07-27 16:51 - 2009-07-14 15:08 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
Some content of TEMP:
====================
C:\Users\pureadmin\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\pureadmin\AppData\Local\Temp\FP_PL_MSI_INSTALLER.exe
C:\Users\pureadmin\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\pureadmin\AppData\Local\Temp\MSNDE55.exe
C:\Users\rbratz\AppData\Local\Temp\-vauecmt.dll
C:\Users\rbratz\AppData\Local\Temp\1nfbw9um.dll
C:\Users\rbratz\AppData\Local\Temp\1_Offer_6.exe
C:\Users\rbratz\AppData\Local\Temp\1_Offer_8.exe
C:\Users\rbratz\AppData\Local\Temp\3dynbvvj.dll
C:\Users\rbratz\AppData\Local\Temp\3q7t2sut.dll
C:\Users\rbratz\AppData\Local\Temp\arcparlupd.exe
C:\Users\rbratz\AppData\Local\Temp\BackupSetup.exe
C:\Users\rbratz\AppData\Local\Temp\dchlwbuq.dll
C:\Users\rbratz\AppData\Local\Temp\EpsonInkjetDriverDownloader.EXE
C:\Users\rbratz\AppData\Local\Temp\fasle.dll
C:\Users\rbratz\AppData\Local\Temp\FortiClientVirusCleaner.exe
C:\Users\rbratz\AppData\Local\Temp\gh3bg-lo.dll
C:\Users\rbratz\AppData\Local\Temp\gu2cbl5z.dll
C:\Users\rbratz\AppData\Local\Temp\GUR1CD2.exe
C:\Users\rbratz\AppData\Local\Temp\i4jdel0.exe
C:\Users\rbratz\AppData\Local\Temp\jkr7zrhe.dll
C:\Users\rbratz\AppData\Local\Temp\jnecc7tk.dll
C:\Users\rbratz\AppData\Local\Temp\libav.dll
C:\Users\rbratz\AppData\Local\Temp\mdare.dll
C:\Users\rbratz\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\rbratz\AppData\Local\Temp\oi_{05CEF480-B928-4558-8BAF-FF18A9224D67}.exe
C:\Users\rbratz\AppData\Local\Temp\oxhiy6fr.dll
C:\Users\rbratz\AppData\Local\Temp\Quarantine.exe
C:\Users\rbratz\AppData\Local\Temp\rev6mp49.dll
C:\Users\rbratz\AppData\Local\Temp\SimilarBundleGenericDl.exe
C:\Users\rbratz\AppData\Local\Temp\SpOrder.dll
C:\Users\rbratz\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\rbratz\AppData\Local\Temp\tbo9u6eu.dll
C:\Users\rbratz\AppData\Local\Temp\vyora7kx.dll
C:\Users\rbratz\AppData\Local\Temp\webxvid-setup-on.exe
C:\Users\rbratz\AppData\Local\Temp\xvidupdate.exe
C:\Users\rbratz\AppData\Local\Temp\z89fnrwh.dll
C:\Users\rbratz\AppData\Local\Temp\_pzwjlq9.dll
C:\Users\Robert_privat\AppData\Local\Temp\AskSLib.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-17 20:23
==================== End Of Log ============================ --- --- ---
--- --- --- |