Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 06.04.2015, 14:27   #1
TreeFriends
 
Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt - Standard

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt



Guten Tag liebes trojaner-board.

Der pC an dem ich Sitze hat das Problem, dass wenn ich den Browser aufrufe automatisch die Internetseite "hxxp://gotut.ru/" geöffnet wird. Ich habe bereits in den Einstellungen geguckt, bei den Plugins, vermutliche installierte Toolbarsoftware und die Cookies gelöscht.
Leider alles vergebens.
Einen Scan mit Spybot S&D sowie mit AdwCleaner habe ich bereits ausgeführt.
Beide Programme haben Fehler gefunden und behoben allerdings zu keiner Lösung des Problems mit dem Internetbrowser geführt.

Leider habe ich nur ein Log vom Spybot und den anderen nicht, weil ich das erste mal hier bin und nicht wusste wie der Spaß läuft....

Momentan bemüht sich ESET Onlinescanner und meldet 14 Infizierte Datein bis jetzt.
Win32/Toobar.Widgi
Win32/Conditut.SearchProtectY
win32/clientconnect.A

Ich hoffe ich kann etwas mehr mit eurer Unterstützung erreichen und das Problem besser für euch Analysieren.

Viele Grüße und danke im vorraus

Zitat:
Search results from Spybot - Search & Destroy

06.04.2015 14:22:44
Scan took 00:22:29.
280 items found.

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\2970143.pix-cdn.org\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1402176434
Properties.filedatetext=2014-06-07 23:27:14

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\2970143.pix-cdn.org\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4420
Properties.md5=4DC52D74FF8F5F2FABEBE49283878510
Properties.filedate=1402176376
Properties.filedatetext=2014-06-07 23:26:15

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\2970143.pix-cdn.org\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1402176434
Properties.filedatetext=2014-06-07 23:27:14

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\2986158.pix-cdn.org\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1402524688
Properties.filedatetext=2014-06-12 00:11:27

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\2986158.pix-cdn.org\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4404
Properties.md5=084B896D39273BF3A6F66360CEAA97D6
Properties.filedate=1402732188
Properties.filedatetext=2014-06-14 09:49:48

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\2986158.pix-cdn.org\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1402524688
Properties.filedatetext=2014-06-12 00:11:27

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\37.220.36.28\smpAxiomatic.sol
Properties.size=51
Properties.md5=362CDE1727D2166876F2D6D6715D4B3A
Properties.filedate=1428236088
Properties.filedatetext=2015-04-05 14:14:47

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\account.goodgamestudios.com\GGSAccount.sol
Properties.size=64
Properties.md5=FCE1B0FDB5474C95DBBF4C88DE3220E3
Properties.filedate=1389975052
Properties.filedatetext=2014-01-17 18:10:52

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\acool.com\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1402921604
Properties.filedatetext=2014-06-16 14:26:43

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\acool.com\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=3916
Properties.md5=114DB4AAE75025FC6CBE8D04A5AF7853
Properties.filedate=1402913477
Properties.filedatetext=2014-06-16 12:11:17

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\acool.com\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1402921604
Properties.filedatetext=2014-06-16 14:26:43

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\ad.admixer.net\cookies.sol
Properties.size=67
Properties.md5=703F196989C8E131AFDD521B6A377C71
Properties.filedate=1380821437
Properties.filedatetext=2013-10-03 19:30:37

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\arcadeplay.com\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1401831744
Properties.filedatetext=2014-06-03 23:42:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\arcadeplay.com\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4380
Properties.md5=AC39FCC17DF2DA7FFB6C3071131F1754
Properties.filedate=1402062808
Properties.filedatetext=2014-06-06 15:53:28

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\arcadeplay.com\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1401831744
Properties.filedatetext=2014-06-03 23:42:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\casino.skillonnet.com\Data.sol
Properties.size=227
Properties.md5=02199B4BE5BAE9C571A71F2A55E01FCE
Properties.filedate=1404293709
Properties.filedatetext=2014-07-02 11:35:09

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\cdn-assets0.kroogi.com\analytics.sol
Properties.size=460
Properties.md5=0F2AABF9A0AC9492332DEDD978832B51
Properties.filedate=1392838568
Properties.filedatetext=2014-02-19 21:36:08

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\cdn.flashtalking.com\ftLocalComms.sol
Properties.size=62
Properties.md5=603C2B45A256810B3DBF343FABFF51AA
Properties.filedate=1394125412
Properties.filedatetext=2014-03-06 19:03:32

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\cdn.ghstatic.com\com.longtailvideo.jwplayer.sol
Properties.size=58
Properties.md5=7B75DC307A208645752DA5C329CDE753
Properties.filedate=1394743378
Properties.filedatetext=2014-03-13 22:42:57

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\cdn.movad.net\movad.sol
Properties.size=67
Properties.md5=8DAE8ADD1F04DD13EBFF290957E4D32C
Properties.filedate=1392162454
Properties.filedatetext=2014-02-12 01:47:33

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\clixsense.com\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1405520172
Properties.filedatetext=2014-07-16 16:16:11

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\clixsense.com\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=3926
Properties.md5=527FBDBD6523DB2C84DD339C610F695C
Properties.filedate=1405518289
Properties.filedatetext=2014-07-16 15:44:48

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\clixsense.com\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1405520172
Properties.filedatetext=2014-07-16 16:16:11

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\content.adriver.ru\storage.sol
Properties.size=72
Properties.md5=8B0AC6A3A6E0946300DDC8AEFDF55C88
Properties.filedate=1379186047
Properties.filedatetext=2013-09-14 21:14:07

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\core.mochibot.com\com.mochibot.sol
Properties.size=105
Properties.md5=C4288807973D11F7DA48CADB4770E425
Properties.filedate=1383128293
Properties.filedatetext=2013-10-30 12:18:12

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\counter.rambler.ru\iruid.sol
Properties.size=62
Properties.md5=6B027CEB0D75CE3ACA41D845EEB70478
Properties.filedate=1378838133
Properties.filedatetext=2013-09-10 20:35:33

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\divaag.vo.llnwd.net\hiro_companion_cookie.sol
Properties.size=106
Properties.md5=DC226D18B76E5FFAF964B06AC53D5C33
Properties.filedate=1389113100
Properties.filedatetext=2014-01-07 18:44:59

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\divaag.vo.llnwd.net\HIRO_NETWORK_CAPPING_COOKIE.sol
Properties.size=542
Properties.md5=CDB23D18BD3EAFA58B8F7C5B3AB7BA21
Properties.filedate=1389113100
Properties.filedatetext=2014-01-07 18:45:00

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\divaag.vo.llnwd.net\US_FARM__STREMING_CLIENT_ID_COOKIE.sol
Properties.size=109
Properties.md5=7B5CAB530AAE2A8AEDD9D74A5719B975
Properties.filedate=1389113100
Properties.filedatetext=2014-01-07 18:45:00

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\doodoo.ru\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1402216458
Properties.filedatetext=2014-06-08 10:34:18

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\doodoo.ru\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4052
Properties.md5=19E244FE7BD157696FBFAD658DAA1731
Properties.filedate=1426718581
Properties.filedatetext=2015-03-19 00:43:00

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\doodoo.ru\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1426684503
Properties.filedatetext=2015-03-18 15:15:02

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\files.cdn.spilcloud.com\analytics.sol
Properties.size=451
Properties.md5=D9419393D22978F5E0AEF5D60027B6B2
Properties.filedate=1426601874
Properties.filedatetext=2015-03-17 16:17:54

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\files.cdn.spilcloud.com\com.spilgames.settings.1.sol
Properties.size=67
Properties.md5=97B72085FC59E91DCA69268C3B4617B6
Properties.filedate=1421339809
Properties.filedatetext=2015-01-15 18:36:49

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\flashgamestv.ru\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1417447057
Properties.filedatetext=2014-12-01 17:17:37

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\flashgamestv.ru\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4356
Properties.md5=3C1D1990870E58D29451F16DEEC3EDD9
Properties.filedate=1427907222
Properties.filedatetext=2015-04-01 18:53:42

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\flashgamestv.ru\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1423324197
Properties.filedatetext=2015-02-07 17:49:57

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\freeonlinegames.com.free-game.us\analytics.sol
Properties.size=419
Properties.md5=E98CBF6EEF43C9FE77F47323E6F67399
Properties.filedate=1408392985
Properties.filedatetext=2014-08-18 22:16:25

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\freeonlinegames.com.free-game.us\SpilGames_1001_arabian_nights_UserData.sol
Properties.size=695
Properties.md5=C43A3E4243CF7A985093F6256095616D
Properties.filedate=1408392260
Properties.filedatetext=2014-08-18 22:04:20

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\analytics.sol
Properties.size=419
Properties.md5=4CE9B944215E4404A7064B6AAEA6A9ED
Properties.filedate=1421339816
Properties.filedatetext=2015-01-15 18:36:55

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\bubbles_fantasy.sol
Properties.size=64
Properties.md5=B323217DDAFD7013E82C71E05FF9A26D
Properties.filedate=1390925163
Properties.filedatetext=2014-01-28 18:06:03

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\Bubble_Hit_halloween.sol
Properties.size=68
Properties.md5=E6CC2579EF21491AD70FBC3C3FBEF9DC
Properties.filedate=1390254392
Properties.filedatetext=2014-01-20 23:46:32

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\com.eweb.shared.gus.ad.time.sol
Properties.size=72
Properties.md5=1EABB035B7315C19F66B8050F9C791BD
Properties.filedate=1390248623
Properties.filedatetext=2014-01-20 22:10:23

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\com.spilgames.settings.1.sol
Properties.size=67
Properties.md5=6C3C3522F148A5B28C521755DA7AC64E
Properties.filedate=1389974164
Properties.filedatetext=2014-01-17 17:56:04

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\SpilGames_1001_arabian_nights_UserData.sol
Properties.size=551
Properties.md5=EDA8CEED5313AB254350F8A3242C9FEB
Properties.filedate=1417118057
Properties.filedatetext=2014-11-27 21:54:17

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\SpilGames_bubble_mover_UserData.sol
Properties.size=257
Properties.md5=ED38937514D63EA519D99D93FF689DC5
Properties.filedate=1384199139
Properties.filedatetext=2013-11-11 21:45:39

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegirl.su\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1402606990
Properties.filedatetext=2014-06-12 23:03:10

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegirl.su\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4388
Properties.md5=8437877D23E28AD4D14B1ABC535B6D6C
Properties.filedate=1416857027
Properties.filedatetext=2014-11-24 21:23:46

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegirl.su\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1416779732
Properties.filedatetext=2014-11-23 23:55:32

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\games.cdn.spilcloud.com\7Wondersoftheworld.sol
Properties.size=65
Properties.md5=143D34AA54466F2FA31583ED730060D2
Properties.filedate=1406720947
Properties.filedatetext=2014-07-30 13:49:07

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\games.cdn.spilcloud.com\CoffeeMahjong.sol
Properties.size=62
Properties.md5=EE2AD0AAAAB0E19C7AD9FF92F2175C8E
Properties.filedate=1395508698
Properties.filedatetext=2014-03-22 19:18:18

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\games.cdn.spilcloud.com\com.eweb.shared.gus.ad.time.sol
Properties.size=72
Properties.md5=DC6EA04C67CC05D34C57DC15B868AEB0
Properties.filedate=1406721248
Properties.filedatetext=2014-07-30 13:54:07

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\games.cdn.spilcloud.com\jarofedOneMoreChance.sol
Properties.size=68
Properties.md5=435689BA167EF87E93B20C214805E994
Properties.filedate=1398176719
Properties.filedatetext=2014-04-22 16:25:19

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\games.cdn.spilcloud.com\OrientExpress.sol
Properties.size=59
Properties.md5=C1380B2CAA93436341618C32F83B5080
Properties.filedate=1400507078
Properties.filedatetext=2014-05-19 15:44:37

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\girsa.ru\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1403560509
Properties.filedatetext=2014-06-23 23:55:09

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\girsa.ru\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4082
Properties.md5=E3B08F69006E0BA0429755458D7F1155
Properties.filedate=1403560499
Properties.filedatetext=2014-06-23 23:54:59

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\girsa.ru\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1403560509
Properties.filedatetext=2014-06-23 23:55:09

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\igra-flash.ru\analytics.sol
Properties.size=415
Properties.md5=B97B2462B974B6BDD6D33F549D2825D8
Properties.filedate=1428082864
Properties.filedatetext=2015-04-03 19:41:03

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\igra-flash.ru\com.spilgames.settings.1.sol
Properties.size=67
Properties.md5=6C3C3522F148A5B28C521755DA7AC64E
Properties.filedate=1428082842
Properties.filedatetext=2015-04-03 19:40:41

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\igralkin.net\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1403623285
Properties.filedatetext=2014-06-24 17:21:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\igralkin.net\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4362
Properties.md5=585D63A0A5F50DEAFE777FD126FBD654
Properties.filedate=1425383606
Properties.filedatetext=2015-03-03 13:53:25

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\igralkin.net\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1425331990
Properties.filedatetext=2015-03-02 23:33:09

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\igryflash.net\analytics.sol
Properties.size=351
Properties.md5=BEB9727F6CA5EADF31AF171AE2F1CDF3
Properties.filedate=1407173923
Properties.filedatetext=2014-08-04 19:38:42

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\igryflash.net\SpilGames_1001_arabian_nights_UserData.sol
Properties.size=695
Properties.md5=4547AF294FE79268AFC2A0E8C3961FC4
Properties.filedate=1407179772
Properties.filedatetext=2014-08-04 21:16:11

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\images-na.ssl-images-amazon.com\mercury.sol
Properties.size=69
Properties.md5=A08B35A8761656704001BB06ADA942D1
Properties.filedate=1379187404
Properties.filedatetext=2013-09-14 21:36:43

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\kaisergames.de\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1402344825
Properties.filedatetext=2014-06-09 22:13:44

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\kaisergames.de\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=3640
Properties.md5=4C162F95A5E86AFBA4C0A59B861FBD14
Properties.filedate=1419347937
Properties.filedatetext=2014-12-23 17:18:57

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\kaisergames.de\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=E25854D66A1FAA4D11F1FE8A00F47816
Properties.filedate=1419347951
Properties.filedatetext=2014-12-23 17:19:11

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\kiks.yandex.ru\fuid01.sol
Properties.size=188
Properties.md5=8FE1CA42E8FE1D97762F4B54774DC244
Properties.filedate=1378816821
Properties.filedatetext=2013-09-10 14:40:21

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\login.yahoo.com\loginCache.sol
Properties.size=79
Properties.md5=33F3DD906BD3CE5E825C965FCCF82579
Properties.filedate=1380308598
Properties.filedatetext=2013-09-27 21:03:17

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\match3.com\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1404933315
Properties.filedatetext=2014-07-09 21:15:15

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\match3.com\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4174
Properties.md5=D1FF4664067E579F94ACD97A19BF5A82
Properties.filedate=1418076468
Properties.filedatetext=2014-12-09 00:07:47

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\match3.com\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1418076531
Properties.filedatetext=2014-12-09 00:08:50

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\megatorrents.kg\uppodData.sol
Properties.size=88
Properties.md5=6FE71680307E12FD7F5863E890F18B28
Properties.filedate=1389113273
Properties.filedatetext=2014-01-07 18:47:52

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mochiads.com\com.mochiads.lock.sol
Properties.size=97
Properties.md5=F1255C67D6C031DD3141948DC76F8F44
Properties.filedate=1395986900
Properties.filedatetext=2014-03-28 08:08:19

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mochiads.com\com.mochiads.sol
Properties.size=2073
Properties.md5=290FA219C123B8FA99B6191DB484B94B
Properties.filedate=1395986901
Properties.filedatetext=2014-03-28 08:08:20

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mochiads.com\mochiLCStatus.sol
Properties.size=152
Properties.md5=441A3B9F25E5BC2A518E76824F373B0D
Properties.filedate=1396468824
Properties.filedatetext=2014-04-02 22:00:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mochiads.com\services.mochiads.com.sol
Properties.size=836
Properties.md5=EE77DB060951D723EF4764DEDDEA66FF
Properties.filedate=1396468814
Properties.filedatetext=2014-04-02 22:00:14

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mochiads.com\__coinsEventLC__.sol
Properties.size=148
Properties.md5=06D330E4D7460B5D30471448E30EA278
Properties.filedate=1396468824
Properties.filedatetext=2014-04-02 22:00:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mochiads.com\__ms_1396468811830_2169.sol
Properties.size=1208
Properties.md5=A11EDA074A032D88481290F72DD62295
Properties.filedate=1396468824
Properties.filedatetext=2014-04-02 22:00:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mochiads.com\__ms_1396468811830_2169_fromgame.sol
Properties.size=69
Properties.md5=DC654CAEFACDBA053CB113F489D94F08
Properties.filedate=1396468815
Properties.filedatetext=2014-04-02 22:00:14

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mochibot.com\com.mochibot.sol
Properties.size=105
Properties.md5=B1609A1BAA8EA76BA59C6DBC88C65FB4
Properties.filedate=1382300355
Properties.filedatetext=2013-10-20 22:19:14

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mpsnare.iesnare.com\stm.sol
Properties.size=79
Properties.md5=F23A0B77DAA75DEDB0D0BD11F26B03C2
Properties.filedate=1391965634
Properties.filedatetext=2014-02-09 19:07:14

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\onlinegames.alawar.ru\The_Treasures_of_Montezuma_2.sol
Properties.size=1068
Properties.md5=624031DACC5D7768A01C5327952E1D22
Properties.filedate=1414184880
Properties.filedatetext=2014-10-24 23:08:00

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\p.jwpcdn.com\com.longtailvideo.jwplayer.sol
Properties.size=58
Properties.md5=38111220EDB5114733E8665129E519DA
Properties.filedate=1428234631
Properties.filedatetext=2015-04-05 13:50:31

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\pifp.ru\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1404314363
Properties.filedatetext=2014-07-02 17:19:23

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\pifp.ru\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4402
Properties.md5=1B8A770F0CCDC0110AC353516035AD40
Properties.filedate=1420314668
Properties.filedatetext=2015-01-03 21:51:07

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\pifp.ru\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1420236417
Properties.filedatetext=2015-01-03 00:06:56

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\playit-online.de\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1406410573
Properties.filedatetext=2014-07-26 23:36:13

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\playit-online.de\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=3230
Properties.md5=894BB39FD3EDC2093B3806F8FF5BE9F5
Properties.filedate=1406409842
Properties.filedatetext=2014-07-26 23:24:01

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\playit-online.de\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=102FDA836B742F8A86F8B44AF20AFD28
Properties.filedate=1406410573
Properties.filedatetext=2014-07-26 23:36:13

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\rs.mail.ru\admanData.sol
Properties.size=55
Properties.md5=F891D6D7C2BABA4F3D47A0613053EABD
Properties.filedate=1388576953
Properties.filedatetext=2014-01-01 13:49:13

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\ru.igames9.com\analytics.sol
Properties.size=419
Properties.md5=D65E38F006EB8EBC9E41A01D27657B53
Properties.filedate=1417691484
Properties.filedatetext=2014-12-04 13:11:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\ru.igames9.com\SpilGames_1001_arabian_nights_UserData.sol
Properties.size=551
Properties.md5=4325FC6555CE3DFC557DC4F858F9DE39
Properties.filedate=1417691474
Properties.filedatetext=2014-12-04 13:11:14

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\s.ytimg.com\restore.sol
Properties.size=62
Properties.md5=8C43FE5AF19D73546FD973420F4E8157
Properties.filedate=1405537169
Properties.filedatetext=2014-07-16 20:59:28

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\s.ytimg.com\soundData.sol
Properties.size=49
Properties.md5=F2945B8419B125F71FC8FD7CDDB59948
Properties.filedate=1399755965
Properties.filedatetext=2014-05-10 23:06:05

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\s3.amazonaws.com\com.quantserve.sol
Properties.size=51
Properties.md5=EA0C356EC701634230DA994C39773A98
Properties.filedate=1394140074
Properties.filedatetext=2014-03-06 23:07:53

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\secureinclude.ebaystatic.com\ebayLSO.sol
Properties.size=131
Properties.md5=E7032EB5B104808FA0B0D0FAC83223BD
Properties.filedate=1407096655
Properties.filedatetext=2014-08-03 22:10:55

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\secureinclude.ebaystatic.com\ebayT.sol
Properties.size=39
Properties.md5=B43F43445AA3414DDC22EC80FBB22871
Properties.filedate=1407096656
Properties.filedatetext=2014-08-03 22:10:55

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\software.hiro.tv\HIRO_REPO.sol
Properties.size=108
Properties.md5=12BCA3B53127DE6FFD731C6226F547CA
Properties.filedate=1389113100
Properties.filedatetext=2014-01-07 18:44:59

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\source.mmi.bemobile.ua\mmi.sol
Properties.size=64
Properties.md5=37757AF34954B94488DA37D9498EC027
Properties.filedate=1390140866
Properties.filedatetext=2014-01-19 16:14:25

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\ssl.hurra.com\restore.hurra.com.sol
Properties.size=178
Properties.md5=170CDF9D890F0E3B9F76DD4880A6BE7D
Properties.filedate=1393162730
Properties.filedatetext=2014-02-23 15:38:50

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\static1.spilcdn.com\analytics.sol
Properties.size=257
Properties.md5=CB7EBE2E3254EA68A6CF9CE8EC289928
Properties.filedate=1387222963
Properties.filedatetext=2013-12-16 21:42:43

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\static2.spilcdn.com\analytics.sol
Properties.size=459
Properties.md5=7418FEB2CC135420A60935B2D4641A4E
Properties.filedate=1407065952
Properties.filedatetext=2014-08-03 13:39:12

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\townden.com\analytics.sol
Properties.size=415
Properties.md5=71B4B6F2AA3B9EFBE9E6193722E832BC
Properties.filedate=1402734901
Properties.filedatetext=2014-06-14 10:35:00

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\townden.com\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1402734786
Properties.filedatetext=2014-06-14 10:33:05

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\townden.com\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4290
Properties.md5=A9EFBEC174F9B212953F4C70AAE1C312
Properties.filedate=1415187071
Properties.filedatetext=2014-11-05 13:31:10

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\townden.com\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=FB9F4CFC6FCA5ED8F281F47A0CB0F975
Properties.filedate=1402869668
Properties.filedatetext=2014-06-16 00:01:08

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\tubegame.com\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1417117936
Properties.filedatetext=2014-11-27 21:52:15

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\tubegame.com\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4402
Properties.md5=80EA3229704D123D5638FCB09B251529
Properties.filedate=1417117959
Properties.filedatetext=2014-11-27 21:52:39

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\tubegame.com\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1417117936
Properties.filedatetext=2014-11-27 21:52:15

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\ungrounded.net\GameTelegraph-wrong-block-basicData-release-2.sol
Properties.size=106
Properties.md5=70A7B67E8322315AF268AE20E41B729F
Properties.filedate=1419438916
Properties.filedatetext=2014-12-24 18:35:16

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\ungrounded.net\GameTelegraph-wrong-block-extraData_release-2_slot-1.sol
Properties.size=4402
Properties.md5=0D9AD3818DF9F87D388A7F5908A43F94
Properties.filedate=1419434795
Properties.filedatetext=2014-12-24 17:26:35

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\ungrounded.net\GameTelegraph-wrong-block-options.sol
Properties.size=204
Properties.md5=27AB4C9557E343512AD651A98061E002
Properties.filedate=1419438916
Properties.filedatetext=2014-12-24 18:35:16

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\up.scene7.com\s7_storage_tracker.sol
Properties.size=65
Properties.md5=FA46DC3DD7E738C110C71F120F4E34B0
Properties.filedate=1394571724
Properties.filedatetext=2014-03-11 23:02:03

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\vk.com\VkontaktePlayer.sol
Properties.size=54
Properties.md5=4C931C53AF72AD9275309F55428BF298
Properties.filedate=1392122139
Properties.filedatetext=2014-02-11 14:35:39

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.arcadeplay.com\localGemsGalacticaData.sol
Properties.size=170
Properties.md5=F6579BC0250353D700453CC21A6DA63A
Properties.filedate=1401987950
Properties.filedatetext=2014-06-05 19:05:50

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.arcadeplay.com\RockGardenPrefs.sol
Properties.size=201
Properties.md5=DBE3C033AB3D1D92995927F30E85ACD3
Properties.filedate=1423165354
Properties.filedatetext=2015-02-05 21:42:33

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.arcadeplay.com\RockGardenUser1.sol
Properties.size=4232
Properties.md5=2BDCC4F94C95E697294494EDAB07F1AD
Properties.filedate=1423425869
Properties.filedatetext=2015-02-08 22:04:29

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.baur.de\REGISTRY.sol
Properties.size=42
Properties.md5=F10611AA2C3676CBFB75469623E46626
Properties.filedate=1382285808
Properties.filedatetext=2013-10-20 18:16:47

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.baur.de\sol.sol
Properties.size=342
Properties.md5=4F73309795F1A65597231B17B210BFD5
Properties.filedate=1386240400
Properties.filedatetext=2013-12-05 12:46:39

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.bestfunportal.ru\analytics.sol
Properties.size=419
Properties.md5=148B3D0C83F88D4847906EE9E53D6968
Properties.filedate=1419168094
Properties.filedatetext=2014-12-21 15:21:33

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.bestfunportal.ru\SpilGames_1001_arabian_nights_UserData.sol
Properties.size=551
Properties.md5=E1880B46717090BCF89FAF8A27A5A4AB
Properties.filedate=1419168046
Properties.filedatetext=2014-12-21 15:20:45

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.doodoo.ru\analytics.sol
Properties.size=419
Properties.md5=3DFA73017EFFFE73F36F79D8141654A9
Properties.filedate=1402254249
Properties.filedatetext=2014-06-08 21:04:09

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.doodoo.ru\ebk.sol
Properties.size=112
Properties.md5=555E535594EC3F50ABFF8A67652206FE
Properties.filedate=1402254204
Properties.filedatetext=2014-06-08 21:03:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.doodoo.ru\wasabi_blockpuzzle_081ea6bf-9096-4b78-943e-da915a6c8659.sol
Properties.size=93
Properties.md5=C78A5F6047206A25F465581AE0B11E5F
Properties.filedate=1402254249
Properties.filedatetext=2014-06-08 21:04:09

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.heine.de\CancelledBasketHeine.sol
Properties.size=190
Properties.md5=1E0030C8A1828FF57D5256BD0E93D639
Properties.filedate=1396522724
Properties.filedatetext=2014-04-03 12:58:43

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.heine.de\REGISTRY.sol
Properties.size=42
Properties.md5=F10611AA2C3676CBFB75469623E46626
Properties.filedate=1382283911
Properties.filedatetext=2013-10-20 17:45:10

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.heine.de\sol.sol
Properties.size=3869
Properties.md5=0002BDEB54526C913251DBFCED1CE434
Properties.filedate=1396522713
Properties.filedatetext=2014-04-03 12:58:32

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.ourgames.ru\analytics.sol
Properties.size=419
Properties.md5=7BCE06A4CD296D8C9C2E355D2F80E53F
Properties.filedate=1386001512
Properties.filedatetext=2013-12-02 18:25:12

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.ourgames.ru\com.spilgames.settings.1.sol
Properties.size=67
Properties.md5=68046847549DF9631D5EA33DB75A3C3C
Properties.filedate=1385996749
Properties.filedatetext=2013-12-02 17:05:49

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.paypalobjects.com\PayPalLSO.sol
Properties.size=173
Properties.md5=C25E18FB32E17DBF69C41B3449EFD660
Properties.filedate=1423860625
Properties.filedatetext=2015-02-13 22:50:24

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.paypalobjects.com\ppLsoTest.sol
Properties.size=48
Properties.md5=74EE4375686A2069414EEF13E7B62789
Properties.filedate=1383745935
Properties.filedatetext=2013-11-06 15:52:15

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\analytics.sol
Properties.size=433
Properties.md5=230DA0EF4A39EB411E926769EC5B11E9
Properties.filedate=1423759409
Properties.filedatetext=2015-02-12 18:43:28

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\Bubble_Hit_halloween.sol
Properties.size=68
Properties.md5=C2CA0969778B1BAFA7AC1C20FC774506
Properties.filedate=1387456055
Properties.filedatetext=2013-12-19 14:27:34

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\ChineseDragonMahjongg.sol
Properties.size=68
Properties.md5=5EE74E6577B07D72ED811F99E46D7B60
Properties.filedate=1392125269
Properties.filedatetext=2014-02-11 15:27:48

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\com.spilgames.settings.1.sol
Properties.size=67
Properties.md5=68046847549DF9631D5EA33DB75A3C3C
Properties.filedate=1399972965
Properties.filedatetext=2014-05-13 11:22:44

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\gamesonly_.sol
Properties.size=50
Properties.md5=12CDE9AE0536F26827A3A066B49979C6
Properties.filedate=1391164546
Properties.filedatetext=2014-01-31 12:35:45

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\MahjongCubes.sol
Properties.size=59
Properties.md5=61541E719EDCA38F860E801C085D6140
Properties.filedate=1394660579
Properties.filedatetext=2014-03-12 23:42:58

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\SpilGames_1001_arabian_nights_UserData.sol
Properties.size=551
Properties.md5=A478E4FC02A43D5365DDE0E635F78BB2
Properties.filedate=1406748216
Properties.filedatetext=2014-07-30 21:23:35

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\SpilGames_gem_invasion_UserData.sol
Properties.size=215
Properties.md5=69454F5BA4CBC397D30002378483E5EB
Properties.filedate=1400506110
Properties.filedatetext=2014-05-19 15:28:29

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\spilgames_language_v100.sol
Properties.size=60
Properties.md5=8E415D0072938E51F3AA7D8269E75BA7
Properties.filedate=1397668519
Properties.filedatetext=2014-04-16 19:15:18

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\SpilGames_mahjong_link_UserData.sol
Properties.size=188
Properties.md5=2BFBCD96BAFF9AC81E92EA628697567F
Properties.filedate=1383572583
Properties.filedatetext=2013-11-04 15:43:03

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\SpilGames_patterns_link_UserData.sol
Properties.size=189
Properties.md5=23D7678B6B3C27D66C22C15E0D15EE98
Properties.filedate=1382975544
Properties.filedatetext=2013-10-28 17:52:23

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\Wellgames.sol
Properties.size=59
Properties.md5=249939D0FA80A0FF583F1AD233F45E83
Properties.filedate=1395508930
Properties.filedatetext=2014-03-22 19:22:09

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www8.agame.com\WellGames_BubbleShooter.sol
Properties.size=882
Properties.md5=075BA4AF9521F145210AA6D4A2B9AA64
Properties.filedate=1395515801
Properties.filedatetext=2014-03-22 21:16:41

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\aa.online-metrix.net\fpc.swf\session.sol
Properties.size=76
Properties.md5=35E1CA5E879F740F623AAA4A62D2115E
Properties.filedate=1407096639
Properties.filedatetext=2014-08-03 22:10:39

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\am15.net\fc.swf\8ab4f53c556260cbceb817da87ccee66n.sol
Properties.size=113
Properties.md5=D7EE736E6FE453D10954F576C062240B
Properties.filedate=1386413801
Properties.filedatetext=2013-12-07 12:56:40

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\b.myspongebob.ru\Vudu21547.swf\VoodooChronicles_FirstSign1.sol
Properties.size=603
Properties.md5=E2C57CC14B990C0B2BB377AD06E90952
Properties.filedate=1427726043
Properties.filedatetext=2015-03-30 16:34:02

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\cdn.arcadeplay.com\ArcadePlayAPI.swf\arcadePlay.sol
Properties.size=61
Properties.md5=E6BB51A9A6763C0685696946E4731AD9
Properties.filedate=1401821748
Properties.filedatetext=2014-06-03 20:55:48

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\igame.2986158.pix-cdn.org\##7B1FA1FA3F9EC2FA\00000001.sol
Properties.size=415
Properties.md5=E77B795780A31BE575596D540A6C9344
Properties.filedate=1390928375
Properties.filedatetext=2014-01-28 18:59:34

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\jsctool.com\d.swf\d.sol
Properties.size=72
Properties.md5=788338DC62B7D99A774C463D1D7C1FBF
Properties.filedate=1403805112
Properties.filedatetext=2014-06-26 19:51:52

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\ndirect.ppro.de\vft\clickIDs.sol
Properties.size=66
Properties.md5=DFCB336F099EC35E45148922E3DADD6B
Properties.filedate=1428258214
Properties.filedatetext=2015-04-05 20:23:34

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\server08.de\woobies.swf\steganos2.sol
Properties.size=54
Properties.md5=80F56DCE8CCE2A81D46F388B3707A2CA
Properties.filedate=1385758617
Properties.filedatetext=2013-11-29 22:56:56

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\skype.com\#ui\preferences.sol
Properties.size=233
Properties.md5=556F01C7A35118B046F278258029BC45
Properties.filedate=1428321440
Properties.filedatetext=2015-04-06 13:57:19

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.audiopoisk.com\banner468x60.swf\superfoo.sol
Properties.size=104
Properties.md5=069ACB323ECD549CE833B6F28917B940
Properties.filedate=1402690180
Properties.filedatetext=2014-06-13 22:09:40

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.clixsense.com\uid.swf\uid.sol
Properties.size=82
Properties.md5=36FC2D442F1F8EEE65F5E5051125C5CA
Properties.filedate=1405517374
Properties.filedatetext=2014-07-16 15:29:33

Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.jsctool.com\d.swf\d.sol
Properties.size=72
Properties.md5=5A7372BED222AF241A5FC9EF90FB9BD6
Properties.filedate=1393162731
Properties.filedatetext=2014-02-23 15:38:51

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\2970143.pix-cdn.org\games\124487.swf\FlashGamesStudio.sol
Properties.size=69
Properties.md5=CC9822938764D6054AE5260B6AFFCEC5
Properties.filedate=1406142181
Properties.filedatetext=2014-07-23 21:03:00

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\2970143.pix-cdn.org\games\50734.swf\FlashGamesStudio.sol
Properties.size=69
Properties.md5=CC9822938764D6054AE5260B6AFFCEC5
Properties.filedate=1409047011
Properties.filedatetext=2014-08-26 11:56:50

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\a.affil.io\s\af.swf\afstorage.sol
Properties.size=53
Properties.md5=FA2133FE1A3AD1B671D3D79AA8F8FB4B
Properties.filedate=1408101205
Properties.filedatetext=2014-08-15 13:13:24

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\bbcdn-bbnaut.ibillboard.com\server-static-files\bbnaut-b.swf\bbcookie.sol
Properties.size=73
Properties.md5=727D537B20D992EBA98929938C9F6E96
Properties.filedate=1393147485
Properties.filedatetext=2014-02-23 11:24:44

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\c.imrk.net\cs\memo2.swf\memo.sol
Properties.size=274
Properties.md5=0BAEAE302C8274484AB1B121832F5BBA
Properties.filedate=1393147480
Properties.filedatetext=2014-02-23 11:24:39

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\counter.botscanner.com\Content\netcustos.swf\netcustos.sol
Properties.size=90
Properties.md5=B292347E09C697974DF2C911838D7765
Properties.filedate=1393147472
Properties.filedatetext=2014-02-23 11:24:32

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\files.cdn.spilcloud.com\flashapi_1_3_1_100\ServicesConnection.swf\locobj.sol
Properties.size=42
Properties.md5=7C5EAB361FD00380B0954A1C55B37B04
Properties.filedate=1426601830
Properties.filedatetext=2015-03-17 16:17:10

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\flash.gamerguru.ru\flash\sokrovishcha-tainstvennogo-moria-0702.swf\8240dfcc-7796bdb7-4da2d8b1f60e.sol
Properties.size=745
Properties.md5=45256CC4876572574BCD3E11B73CCB35
Properties.filedate=1420560663
Properties.filedatetext=2015-01-06 18:11:03

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\flashgamestv.ru\files5\file_13483.swf\Hiden_oject_dsfdsfdsfds11dfff.sol
Properties.size=83
Properties.md5=0F90E68470580EB72016086A0218F9FF
Properties.filedate=1420838923
Properties.filedatetext=2015-01-09 23:28:42

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\freeonlinemahjonggames.net\games\mahjong-connect.swf\FlashGamesStudio.sol
Properties.size=72
Properties.md5=939B3E62B61FA5F5F374CD867392C547
Properties.filedate=1414409844
Properties.filedatetext=2014-10-27 13:37:23

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\100434.swf\BBLdSTR_JABSBAdRdXY.sol
Properties.size=163
Properties.md5=CBC35309C7B8B857367315716FF8557D
Properties.filedate=1396468837
Properties.filedatetext=2014-04-02 22:00:37

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\10576.swf\jewels2.sol
Properties.size=444
Properties.md5=62036394BBC48BF997BDBEF00F91C57A
Properties.filedate=1396468537
Properties.filedatetext=2014-04-02 21:55:36

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\111214.swf\sssg20.sol
Properties.size=278
Properties.md5=C32495A596F420F6015B028DA0516B52
Properties.filedate=1421317095
Properties.filedatetext=2015-01-15 12:18:14

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\11628.swf\kubesGames3ORG.sol
Properties.size=51
Properties.md5=E15B8CDEEE40B6E6B79060537DC38AE8
Properties.filedate=1391276611
Properties.filedatetext=2014-02-01 19:43:30

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\34630.swf\blocks100tut.sol
Properties.size=579
Properties.md5=09CB544B730F499FA6BBD0CC4E0DF9AA
Properties.filedate=1404918837
Properties.filedatetext=2014-07-09 17:13:56

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\3661.swf\sessionId.sol
Properties.size=60
Properties.md5=4D5BB3561914C1EA01ECCB26C6C12FEA
Properties.filedate=1409045698
Properties.filedatetext=2014-08-26 11:34:57

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\6186.swf\TheRiseOfAtlantis.sol
Properties.size=427
Properties.md5=4FE8B73EBD04384B0008094DF84D0B0F
Properties.filedate=1417805889
Properties.filedatetext=2014-12-05 20:58:09

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\64166.swf\gameSave.sol
Properties.size=303
Properties.md5=40663FE1A6A5E735392EE47DA1221934
Properties.filedate=1385757849
Properties.filedatetext=2013-11-29 22:44:09

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\78536.swf\progress.sol
Properties.size=132
Properties.md5=F63B2E8621CC2CFB4F3C8913165AE538
Properties.filedate=1389981229
Properties.filedatetext=2014-01-17 19:53:48

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\91065.swf\TheRiseOfAtlantis.sol
Properties.size=427
Properties.md5=58A18B38B05CE1DC5DFE8EA1A0733EA8
Properties.filedate=1413835185
Properties.filedatetext=2014-10-20 21:59:44

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\9591.swf\xsmashProfile.sol
Properties.size=78
Properties.md5=40B35E1F141FF14EF405B2073007442B
Properties.filedate=1383749388
Properties.filedatetext=2013-11-06 16:49:47

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\gamegame.2970143.pix-cdn.org\games\99325.swf\SphereScoresDrop.sol
Properties.size=52
Properties.md5=F3330745301528EA03C9AC94BA694C4D
Properties.filedate=1396447268
Properties.filedatetext=2014-04-02 16:01:08

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\kinozal.tv\pic\rssa.swf\kinozaltv.sol
Properties.size=74
Properties.md5=E5D7FDE37A35F1E3B685F6A573104B40
Properties.filedate=1379240604
Properties.filedatetext=2013-09-15 12:23:23

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mahjong-online.mini-igra2.ru\media\mahjong-svjaz-connect.swf\FlashGamesStudio.sol
Properties.size=72
Properties.md5=939B3E62B61FA5F5F374CD867392C547
Properties.filedate=1405885399
Properties.filedatetext=2014-07-20 21:43:18

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mahjongall.com\games\mahjong-slide.swf\mydata.sol
Properties.size=60
Properties.md5=083DB17B3DFE54179F0C0A9D1EA0126C
Properties.filedate=1414422587
Properties.filedatetext=2014-10-27 17:09:46

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mahjongonline.ru\games\mahjongcon2.swf\FlashGamesStudio.sol
Properties.size=72
Properties.md5=939B3E62B61FA5F5F374CD867392C547
Properties.filedate=1392548028
Properties.filedatetext=2014-02-16 12:53:48

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\matrix-ua.org\games\mahjongkon.swf\FlashGamesStudio.sol
Properties.size=72
Properties.md5=939B3E62B61FA5F5F374CD867392C547
Properties.filedate=1413924913
Properties.filedatetext=2014-10-21 22:55:12

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\mini-igra2.ru\media\beskonechnyj-madzhong.swf\elite_mahjong_settings_v0.92.sol
Properties.size=2076
Properties.md5=E1A7BC8A798FC8BCE3AAF708C4766CC8
Properties.filedate=1385056251
Properties.filedatetext=2013-11-21 19:50:51

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\onlinemahjong.ru\online\mahjong-connect.swf\FlashGamesStudio.sol
Properties.size=72
Properties.md5=939B3E62B61FA5F5F374CD867392C547
Properties.filedate=1414744436
Properties.filedatetext=2014-10-31 10:33:55

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\roundcdn.com\flash\2053.swf\FlashGamesStudio.sol
Properties.size=69
Properties.md5=CC9822938764D6054AE5260B6AFFCEC5
Properties.filedate=1414325294
Properties.filedatetext=2014-10-26 14:08:13

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\roundcdn.com\flash\2333.swf\elite_mahjong_settings_v0.93onl.sol
Properties.size=1437
Properties.md5=9B552906AF3A4BB403FBB5527DD3D320
Properties.filedate=1414615054
Properties.filedatetext=2014-10-29 22:37:33

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\scachei.gamedesire.com\livefeed\liveclient_019.swf\config.sol
Properties.size=54
Properties.md5=2B6151B2902CD9B03DC0D55CE58CB861
Properties.filedate=1414665858
Properties.filedatetext=2014-10-30 12:44:18

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.free-game-spot.com\online\ancientjewels3_online.swf\gamesettings.xml.sol
Properties.size=288
Properties.md5=FEC507A6D563C87E76272697536CA458
Properties.filedate=1420839119
Properties.filedatetext=2015-01-09 23:31:58

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.free-game-spot.com\online\ancientjewels3_online.swf\saves.sol
Properties.size=600
Properties.md5=65CD8D120940D3E64BBD47619FA858AC
Properties.filedate=1420839126
Properties.filedatetext=2015-01-09 23:32:05

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.liveinternet.ru\flash\mjupl4li.swf\mju_player.sol
Properties.size=351
Properties.md5=846C827EC9668108820B14531EFAF37B
Properties.filedate=1421030621
Properties.filedatetext=2015-01-12 04:43:41

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.ndr.de\flash\OSMFPlayer.swf\HDCore.sol
Properties.size=42
Properties.md5=50978B973ABE8AADC49702CFD4B9D2F4
Properties.filedate=1399836316
Properties.filedatetext=2014-05-11 21:25:15

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.po-igraem.ru\jeu\treasures-of-the-mystic-sea.swf\8240dfcc-7796bdb7-4da2d8b1f60e.sol
Properties.size=1864
Properties.md5=0BFD16B41124C6CFB62110F75503195A
Properties.filedate=1423234602
Properties.filedatetext=2015-02-06 16:56:42

Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done)
C:\Users\dom\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\HN4BZTV6\www.snacktv.de\vpaidplayer\vpaid.swf\SnackTV.sol
Properties.size=79
Properties.md5=1FE57C403C9FA340D403576895983379
Properties.filedate=1387210844
Properties.filedatetext=2013-12-16 18:20:43

DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


Right Media: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


BurstMedia: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


FastClick: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


CasaleMedia: [SBI $4E2AF2AC] Tracking cookie (Internet Explorer (Benutzer): dom) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Zedo: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Zedo: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Zedo: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


BurstMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


FastClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


BurstMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


CoreMetrics: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


BurstMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


FastClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


BurstMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


MediaPlex: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


BurstMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


WebTrends live: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


BurstMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


CasaleMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


CasaleMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


CasaleMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


CasaleMedia: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Firefox: dom (default-1428137666770)) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)


DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)


Tradedoubler: [SBI $4E2AF2AC] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)


Internet Explorer: [SBI $1E8157BE] Typed URL list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Internet Explorer\TypedURLs

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

MS Management Console: [SBI $ECD50EAD] Recent command list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Microsoft Management Console\Recent File List

MS Media Player: [SBI $5C51E349] Client ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\MediaPlayer\Player\Settings\Client ID

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name

MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\DirectInput\MostRecentApplication\Name

MS DirectInput: [SBI $7B184199] Most recent application ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\DirectInput\MostRecentApplication\Id

MS Regedit: [SBI $C3B62FC1] Recent open key (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\LastKey

Windows.OpenWith: [SBI $F7204896] Open with list - .AVI extension (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList

Windows.OpenWith: [SBI $B6B2B96E] Open with list - .CHM extension (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CHM\OpenWithList

Windows Explorer: [SBI $A2C7B3CD] Recent wallpaper list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU

Windows Explorer: [SBI $7308A845] Run history (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU

Windows Explorer: [SBI $AA0766B5] Stream history (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU

Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done)
HKEY_USERS\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

Cookie: [SBI $49804B54] Browser: Cookie (208) (Browser: Cookie, nothing done)


Cache: [SBI $49804B54] Browser: Cache (9377) (Browser: Cache, nothing done)


Verlauf: [SBI $49804B54] Browser: History (309) (Browser: History, nothing done)


Cookie: [SBI $49804B54] Browser: Cookie (3048) (Browser: Cookie, nothing done)


Cookie: [SBI $49804B54] Browser: Cookie (134) (Browser: Cookie, nothing done)



--- Spybot - Search & Destroy version: 2.4.40.131 DLL (build: 20140425) ---

2014-06-24 blindman.exe (2.4.40.151)
2014-06-24 explorer.exe (2.4.40.181)
2014-06-24 SDBootCD.exe (2.4.40.109)
2014-06-24 SDCleaner.exe (2.4.40.110)
2014-06-24 SDDelFile.exe (2.4.40.94)
2013-06-18 SDDisableProxy.exe
2014-06-24 SDFiles.exe (2.4.40.135)
2014-06-24 SDFileScanHelper.exe (2.4.40.1)
2014-06-24 SDFSSvc.exe (2.4.40.217)
2014-06-24 SDHelp.exe (2.4.40.1)
2014-04-25 SDHookHelper.exe (2.3.39.2)
2014-04-25 SDHookInst32.exe (2.3.39.2)
2014-06-24 SDImmunize.exe (2.4.40.130)
2014-06-24 SDLogReport.exe (2.4.40.107)
2014-06-24 SDOnAccess.exe (2.4.40.11)
2014-06-24 SDPESetup.exe (2.4.40.3)
2014-06-24 SDPEStart.exe (2.4.40.86)
2014-06-24 SDPhoneScan.exe (2.4.40.28)
2014-06-24 SDPRE.exe (2.4.40.22)
2014-06-24 SDPrepPos.exe (2.4.40.15)
2014-06-24 SDQuarantine.exe (2.4.40.103)
2014-06-24 SDRootAlyzer.exe (2.4.40.116)
2014-06-24 SDSBIEdit.exe (2.4.40.39)
2014-06-24 SDScan.exe (2.4.40.181)
2014-06-24 SDScript.exe (2.4.40.54)
2014-06-24 SDSettings.exe (2.4.40.139)
2014-06-24 SDShell.exe (2.4.40.2)
2014-06-24 SDShred.exe (2.4.40.108)
2014-06-24 SDSysRepair.exe (2.4.40.102)
2014-06-24 SDTools.exe (2.4.40.157)
2014-06-24 SDTray.exe (2.4.40.129)
2014-06-27 SDUpdate.exe (2.4.40.94)
2014-06-27 SDUpdSvc.exe (2.4.40.77)
2014-06-24 SDWelcome.exe (2.4.40.130)
2014-04-25 SDWSCSvc.exe (2.3.39.2)
2014-05-20 spybotsd2-install-bdcore-update.exe (2.3.39.0)
2014-07-31 spybotsd2-translation-esx.exe
2013-06-19 spybotsd2-translation-frx.exe
2014-08-25 spybotsd2-translation-hux2.exe
2014-10-01 spybotsd2-translation-nlx2.exe
2014-11-05 spybotsd2-translation-ukx.exe
2015-04-06 unins000.exe (51.1052.0.0)
1999-12-02 xcacls.exe
2012-08-23 borlndmm.dll (10.0.2288.42451)
2012-09-05 DelZip190.dll (1.9.0.107)
2012-09-10 libeay32.dll (1.0.0.4)
2012-09-10 libssl32.dll (1.0.0.4)
2014-04-25 NotificationSpreader.dll
2014-06-24 SDAdvancedCheckLibrary.dll (2.4.40.98)
2014-04-25 SDAV.dll
2014-06-24 SDECon32.dll (2.4.40.114)
2014-06-24 SDEvents.dll (2.4.40.2)
2014-06-24 SDFileScanLibrary.dll (2.4.40.14)
2014-04-25 SDHook32.dll (2.3.39.2)
2014-06-24 SDImmunizeLibrary.dll (2.4.40.2)
2014-06-24 SDLicense.dll (2.4.40.0)
2014-06-24 SDLists.dll (2.4.40.4)
2014-06-24 SDResources.dll (2.4.40.7)
2014-06-24 SDScanLibrary.dll (2.4.40.131)
2014-06-24 SDTasks.dll (2.4.40.15)
2014-06-24 SDWinLogon.dll (2.4.40.0)
2012-08-23 sqlite3.dll
2012-09-10 ssleay32.dll (1.0.0.4)
2014-06-24 Tools.dll (2.4.40.36)
2014-03-05 Includes\Adware-000.sbi (*)
2015-02-27 Includes\Adware-001.sbi (*)
2015-03-31 Includes\Adware-C.sbi (*)
2014-01-13 Includes\Adware.sbi (*)
2014-01-13 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2014-11-14 Includes\Dialer-000.sbi (*)
2014-11-14 Includes\Dialer-001.sbi (*)
2014-01-08 Includes\Dialer-C.sbi (*)
2014-01-13 Includes\Dialer.sbi (*)
2014-01-13 Includes\DialerC.sbi (*)
2014-01-09 Includes\Fraud-000.sbi (*)
2014-01-09 Includes\Fraud-001.sbi (*)
2014-03-31 Includes\Fraud-002.sbi (*)
2014-01-09 Includes\Fraud-003.sbi (*)
2012-11-14 Includes\HeavyDuty.sbi (*)
2014-11-14 Includes\Hijackers-000.sbi (*)
2014-11-14 Includes\Hijackers-001.sbi (*)
2014-01-08 Includes\Hijackers-C.sbi (*)
2014-01-13 Includes\Hijackers.sbi (*)
2014-01-13 Includes\HijackersC.sbi (*)
2014-01-08 Includes\iPhone-000.sbi (*)
2014-01-08 Includes\iPhone.sbi (*)
2014-11-14 Includes\Keyloggers-000.sbi (*)
2014-09-24 Includes\Keyloggers-C.sbi (*)
2014-01-13 Includes\Keyloggers.sbi (*)
2014-01-13 Includes\KeyloggersC.sbi (*)
2014-11-14 Includes\Malware-000.sbi (*)
2014-11-14 Includes\Malware-001.sbi (*)
2014-11-14 Includes\Malware-002.sbi (*)
2014-11-14 Includes\Malware-003.sbi (*)
2014-11-14 Includes\Malware-004.sbi (*)
2014-11-14 Includes\Malware-005.sbi (*)
2014-02-26 Includes\Malware-006.sbi (*)
2014-01-09 Includes\Malware-007.sbi (*)
2015-03-31 Includes\Malware-C.sbi (*)
2014-01-13 Includes\Malware.sbi (*)
2013-12-23 Includes\MalwareC.sbi (*)
2014-11-14 Includes\PUPS-000.sbi (*)
2014-01-15 Includes\PUPS-001.sbi (*)
2014-01-15 Includes\PUPS-002.sbi (*)
2015-03-31 Includes\PUPS-C.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2014-01-07 Includes\PUPSC.sbi (*)
2014-01-08 Includes\Security-000.sbi (*)
2014-01-08 Includes\Security-C.sbi (*)
2014-01-21 Includes\Security.sbi (*)
2014-01-21 Includes\SecurityC.sbi (*)
2014-11-14 Includes\Spyware-000.sbi (*)
2014-12-10 Includes\Spyware-001.sbi (*)
2015-01-14 Includes\Spyware-C.sbi (*)
2014-01-21 Includes\Spyware.sbi (*)
2014-01-21 Includes\SpywareC.sbi (*)
2011-06-07 Includes\Tracks.sbi (*)
2012-11-19 Includes\Tracks.uti (*)
2014-01-15 Includes\Trojans-000.sbi (*)
2014-01-15 Includes\Trojans-001.sbi (*)
2014-11-14 Includes\Trojans-002.sbi (*)
2014-01-15 Includes\Trojans-003.sbi (*)
2014-01-15 Includes\Trojans-004.sbi (*)
2014-03-19 Includes\Trojans-005.sbi (*)
2015-03-31 Includes\Trojans-006.sbi (*)
2014-01-15 Includes\Trojans-007.sbi (*)
2014-07-09 Includes\Trojans-008.sbi (*)
2014-07-09 Includes\Trojans-009.sbi (*)
2015-03-31 Includes\Trojans-C.sbi (*)
2014-01-15 Includes\Trojans-OG-000.sbi (*)
2014-01-15 Includes\Trojans-TD-000.sbi (*)
2014-01-15 Includes\Trojans-VM-000.sbi (*)
2014-01-15 Includes\Trojans-VM-001.sbi (*)
2014-01-15 Includes\Trojans-VM-002.sbi (*)
2014-01-15 Includes\Trojans-VM-003.sbi (*)
2014-01-15 Includes\Trojans-VM-004.sbi (*)
2014-01-15 Includes\Trojans-VM-005.sbi (*)
2014-01-15 Includes\Trojans-VM-006.sbi (*)
2014-01-15 Includes\Trojans-VM-007.sbi (*)
2014-01-15 Includes\Trojans-VM-008.sbi (*)
2014-01-15 Includes\Trojans-VM-009.sbi (*)
2014-01-15 Includes\Trojans-VM-010.sbi (*)
2014-01-15 Includes\Trojans-VM-011.sbi (*)
2014-01-15 Includes\Trojans-VM-012.sbi (*)
2014-01-15 Includes\Trojans-VM-013.sbi (*)
2014-01-15 Includes\Trojans-VM-014.sbi (*)
2014-01-15 Includes\Trojans-VM-015.sbi (*)
2014-01-15 Includes\Trojans-VM-016.sbi (*)
2014-01-15 Includes\Trojans-VM-017.sbi (*)
2014-01-15 Includes\Trojans-VM-018.sbi (*)
2014-01-15 Includes\Trojans-VM-019.sbi (*)
2014-01-15 Includes\Trojans-VM-020.sbi (*)
2014-01-15 Includes\Trojans-VM-021.sbi (*)
2014-01-15 Includes\Trojans-VM-022.sbi (*)
2014-01-15 Includes\Trojans-VM-023.sbi (*)
2014-01-15 Includes\Trojans-VM-024.sbi (*)
2014-01-15 Includes\Trojans-ZB-000.sbi (*)
2014-01-15 Includes\Trojans-ZL-000.sbi (*)
2014-01-09 Includes\Trojans.sbi (*)
2014-01-16 Includes\TrojansC-01.sbi (*)
2014-01-16 Includes\TrojansC-02.sbi (*)
2014-01-16 Includes\TrojansC-03.sbi (*)
2014-01-16 Includes\TrojansC-04.sbi (*)
2014-01-16 Includes\TrojansC-05.sbi (*)
2014-01-09 Includes\TrojansC.sbi (*)

Alt 06.04.2015, 14:32   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt - Standard

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)




So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 06.04.2015, 14:39   #3
TreeFriends
 
Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt - Standard

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by dom (administrator) on DOM-PC on 06-04-2015 15:35:06
Running from C:\Users\dom\Downloads
Loaded Profiles: dom (Available profiles: dom)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(ABBYY) C:\Program Files\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(ABBYY (BIT Software)) C:\Program Files\ABBYY Lingvo x3\LvAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(InstallShield Software Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(BitTorrent Inc.) C:\Users\dom\AppData\Roaming\uTorrent\uTorrent.exe
(Gainward Co.) C:\Program Files\EXPERTool\TBPANEL.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(VoipConnect) C:\Program Files\VoipConnect.com\VoipConnect\voipconnect.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Microsoft Online Services\MSOIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Microsoft Online Services\MSOIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(ESET) C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Lingvo Launcher] => C:\Program Files\ABBYY Lingvo x3\LvAgent.exe [1774856 2010-09-07] (ABBYY (BIT Software))
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11930696 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] => "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703280 2015-03-10] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2460488 2014-09-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\PE_F_DOM\...\Run: [Google Update] => F:\Users\Dom\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-02-22] (Google Inc.)
HKU\PE_F_DOM\...\Run: [TomTomHOME.exe] => "F:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
HKU\PE_F_DOM\...\Run: [AlcoholAutomount] => F:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [33120 2010-08-20] (Alcohol Soft Development Team)
HKU\PE_F_DOM\...\Run: [uTorrent] => F:\Users\Dom\AppData\Roaming\uTorrent\uTorrent.exe [1377872 2015-02-22] (BitTorrent Inc.)
HKU\PE_F_DOM\...\Run: [Rambler Update] => F:\Users\Dom\AppData\Local\Rambler\RamblerUpdater\RUpdate.exe [1707296 2015-01-21] (Rambler)
HKU\PE_F_DOM\...\Run: [Skype] => F:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
HKU\PE_F_DOM\...\MountPoints2: O - O:\AutoRun.exe
HKU\PE_F_DOM\...\MountPoints2: {06aa0e10-75aa-11e0-babf-0030673e868e} - M:\LaunchU3.exe -a
HKU\PE_F_DOM\...\MountPoints2: {4658bfec-75e8-11e0-b8a9-806e6f6e6963} - H:\talk-now\tlknow32.exe \talk-now\data\startup.ast
HKU\PE_F_DOM\...\MountPoints2: {8e6c3613-1a5d-11e1-abcc-0030673e868e} - O:\AutoRun.exe
HKU\PE_F_DOM\...\MountPoints2: {8e6c3617-1a5d-11e1-abcc-0030673e868e} - O:\AutoRun.exe
HKU\PE_F_UPDATUSUSER\...\Run: [Google Update] => F:\Users\Dom\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-02-22] (Google Inc.)
HKU\PE_F_UPDATUSUSER\...\Run: [AlcoholAutomount] => F:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [31072 2010-05-27] (Alcohol Soft Development Team)
HKU\PE_F_UPDATUSUSER\...\Run: [TomTomHOME.exe] => "F:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
HKU\PE_F_UPDATUSUSER\...\Run: [Rambler Update] => F:\Users\UpdatusUser\AppData\Local\Rambler\RamblerUpdater\RUpdate.exe /startscheduler
HKU\PE_F_UPDATUSUSER\...\RunOnce: [blekkotb] => reg.exe delete "HKCU\Software\AppDataLow\Software\blekkotb" /f
HKU\PE_F_UPDATUSUSER\...\RunOnce: [blekkotb_XP] => reg.exe delete "HKCU\Software\blekkotb" /f
HKU\PE_F_UPDATUSUSER\...\MountPoints2: M - M:\LaunchU3.exe -a
HKU\PE_F_UPDATUSUSER\...\MountPoints2: O - O:\AutoRun.exe
HKU\PE_F_UPDATUSUSER\...\MountPoints2: {06aa0e10-75aa-11e0-babf-0030673e868e} - M:\LaunchU3.exe -a
HKU\PE_F_UPDATUSUSER\...\MountPoints2: {8e6c3613-1a5d-11e1-abcc-0030673e868e} - O:\AutoRun.exe
HKU\PE_F_UPDATUSUSER\...\MountPoints2: {8e6c3617-1a5d-11e1-abcc-0030673e868e} - O:\AutoRun.exe
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [WebCallDirect] => "C:\Program Files\WebCallDirect.com\WebCallDirect\webcalldirect.exe" -nosplash -minimized
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [uTorrent] => C:\Users\dom\AppData\Roaming\uTorrent\uTorrent.exe [1740880 2015-02-14] (BitTorrent Inc.)
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [CheapVoip] => "C:\Program Files\CheapVoip.com\CheapVoip\cheapvoip.exe" -nosplash -minimized
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [Orbitum] => C:\Users\dom\AppData\Local\Orbitum\Application\chrome.exe
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [GAINWARD] => C:\Program Files\EXPERTool\TBPanel.exe [2174976 2009-10-05] (Gainward Co.)
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30877280 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [*LABAL*] => [X]
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [VoipConnect] => C:\Program Files\VoipConnect.com\VoipConnect\voipconnect.exe [31445088 2015-03-29] (VoipConnect)
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\PE_F_DOM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3312375&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP75B244AD-1F7F-4F1F-AFD9-4400056036F9
HKU\PE_F_DOM\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKU\PE_F_UPDATUSUSER\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mail.ru/cnt/8731
HKU\PE_F_UPDATUSUSER\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\PE_F_DOM -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3312375&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP75B244AD-1F7F-4F1F-AFD9-4400056036F9&q={searchTerms}
SearchScopes: HKU\PE_F_DOM -> yandex.ru-162214 URL = hxxp://blekko.com/?source=c3348dd4&tbp=rbox&toolbarid=blekkotb&u=201205014653443AA1E6745FB2FC9D34&q={searchTerms}
SearchScopes: HKU\PE_F_DOM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3312375&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP75B244AD-1F7F-4F1F-AFD9-4400056036F9&q={searchTerms}
SearchScopes: HKU\PE_F_DOM -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://yandex.ru/yandsearch?win=43&clid=1168537-850&text={searchTerms}
SearchScopes: HKU\PE_F_DOM -> {891CF97A-5ADE-4D99-B8BB-D652621603D5} URL = hxxp://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000026&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000
SearchScopes: HKU\PE_F_DOM -> {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
SearchScopes: HKU\PE_F_DOM -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?utf8in=1&fr=ietb&q={SearchTerms}
SearchScopes: HKU\PE_F_UPDATUSUSER -> DefaultScope {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
SearchScopes: HKU\PE_F_UPDATUSUSER -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://blekko.com/?source=c3348dd4&tbp=rbox&toolbarid=blekkotb&u=201205014653443AA1E6745FB2FC9D34&q={searchTerms}
SearchScopes: HKU\PE_F_UPDATUSUSER -> {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
Toolbar: HKU\PE_F_DOM -> No Name - {09900DE8-1DCA-443F-9243-26FF581438AF} -  No File
Toolbar: HKU\PE_F_DOM -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\PE_F_DOM -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\dom\AppData\Roaming\Mozilla\Firefox\Profiles\76bc9bom.default-1428137666770
FF DefaultSearchEngine: Google
FF Homepage: hxxp://www.yandex.ru/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-04-05] ()
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-10-22] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-04] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-04] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\PE_F_DOM: @tools.google.com/Google Update;version=3 -> F:\Users\Dom\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-22] (Google Inc.)
FF Plugin HKU\PE_F_DOM: @tools.google.com/Google Update;version=9 -> F:\Users\Dom\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-22] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-10-22] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mailru.xml [2014-07-23]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\ozonru.xml [2014-07-23]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\priceru.xml [2014-07-23]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yandex-slovari.xml [2014-07-23]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yandex.xml [2014-12-09]

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://mail.ru/"
CHR Plugin: (Shockwave Flash) - c:\PROGRA~1\google\chrome\APPLIC~1\41.0.2272.118\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - c:\PROGRA~1\google\chrome\APPLIC~1\41.0.2272.118\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - c:\PROGRA~1\google\chrome\APPLIC~1\41.0.2272.118\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Profile: C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-10]
CHR Extension: (Google Drive) - C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-10]
CHR Extension: (YouTube) - C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-10]
CHR Extension: (Google Search) - C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-10]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-06]
CHR Extension: (Google Wallet) - C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-10]
CHR Extension: (Gmail) - C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-10]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ABBYY.Licensing.Lingvo.Desktop.14.0; C:\Program Files\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe [816392 2010-05-07] (ABBYY)
S2 AntiVirFirewallService; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [1044784 2015-03-10] (Avira Operations GmbH & Co. KG)
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [804600 2015-03-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2015-03-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-10] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [992504 2015-03-10] (Avira Operations GmbH & Co. KG)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [915784 2014-09-17] (NVIDIA Corporation)
R2 msoidsvc; C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [1590560 2012-05-17] (Microsoft Corp.)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18044744 2014-09-17] (NVIDIA Corporation)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [92448 2013-09-19] (Avira GmbH)
R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [113024 2013-09-19] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-27] (Avira Operations GmbH & Co. KG)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-14] (Ralink Technology Corp.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19272 2014-09-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [32928 2014-09-04] (NVIDIA Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-19] (Avira GmbH)
R2 TBPanel; C:\Windows\system32\Drivers\TBPanel.sys [12256 2007-03-16] (Windows (R) 2000 DDK provider)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-06 15:35 - 2015-04-06 15:36 - 00021601 _____ () C:\Users\dom\Downloads\FRST.txt
2015-04-06 15:34 - 2015-04-06 15:35 - 00000000 ____D () C:\FRST
2015-04-06 15:34 - 2015-04-06 15:34 - 01135104 _____ (Farbar) C:\Users\dom\Downloads\FRST.exe
2015-04-06 15:32 - 2015-04-06 15:32 - 00000000 ____D () C:\Users\dom\Desktop\CoreTemp32
2015-04-06 15:31 - 2015-04-06 15:31 - 00734473 _____ () C:\Users\dom\Downloads\CoreTemp_106.zip
2015-04-06 15:20 - 2015-04-06 15:20 - 00000000 ____D () C:\Users\dom\Documents\ProcAlyzer Dumps
2015-04-06 14:48 - 2015-04-06 14:48 - 02347384 _____ (ESET) C:\Users\dom\Downloads\esetsmartinstaller_deu.exe
2015-04-06 14:48 - 2015-04-06 14:48 - 00000000 ____D () C:\Program Files\ESET
2015-04-06 14:47 - 2015-04-06 14:47 - 00001647 _____ () C:\Users\dom\Desktop\JRT.txt
2015-04-06 14:45 - 2015-04-06 14:45 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DOM-PC-Windows-7-Professional-(32-bit).dat
2015-04-06 14:45 - 2015-04-06 14:45 - 00000000 ____D () C:\RegBackup
2015-04-06 14:44 - 2015-04-06 14:44 - 02691312 _____ (Thisisu) C:\Users\dom\Downloads\JRT.exe
2015-04-06 14:34 - 2015-04-06 14:34 - 02208768 _____ () C:\Users\dom\Downloads\adwcleaner_4.200 (2).exe
2015-04-06 14:34 - 2015-04-06 14:34 - 02208768 _____ () C:\Users\dom\Downloads\adwcleaner_4.200 (1).exe
2015-04-06 13:47 - 2015-02-04 01:57 - 00606920 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe
2015-04-06 13:30 - 2015-04-06 14:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-04-06 13:30 - 2015-04-06 13:33 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2015-04-06 13:30 - 2015-04-06 13:30 - 00002131 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-04-06 13:30 - 2015-04-06 13:30 - 00002119 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2015-04-06 13:30 - 2015-04-06 13:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-04-06 13:30 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2015-04-06 13:27 - 2015-04-06 13:28 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\dom\Downloads\spybot-2.4.exe
2015-04-06 13:06 - 2015-04-06 13:06 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-06 13:05 - 2015-04-06 13:05 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\dom\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-05 11:30 - 2015-04-05 11:30 - 00000000 ____D () C:\ProgramData\McAfee
2015-04-04 14:14 - 2015-04-04 14:14 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 11:02 - 2015-04-04 11:02 - 02208768 _____ () C:\Users\dom\Downloads\adwcleaner_4.200.exe
2015-04-04 10:43 - 2015-04-04 10:43 - 00001485 ___RS () C:\Users\dom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Eхрlorеr.lnk
2015-04-04 10:43 - 2015-04-04 10:43 - 00001291 ___RS () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Мozilla Firefox.lnk
2015-04-04 10:43 - 2015-04-04 10:43 - 00001183 ___RS () C:\Users\Public\Desktop\Gооgle Сhrome.lnk
2015-04-04 10:43 - 2015-04-04 10:43 - 00000000 ____D () C:\Users\dom\AppData\Roaming\SPI
2015-04-04 10:43 - 2015-04-04 10:43 - 00000000 ____D () C:\Users\dom\AppData\Roaming\Browsers
2015-03-29 13:13 - 2015-03-29 13:14 - 01054912 _____ (Adobe) C:\Users\dom\Downloads\install_flashplayer17x32au_mssa_aaa_aih(1).exe
2015-03-28 17:48 - 2015-04-04 21:12 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-14 18:27 - 2015-03-30 13:48 - 00000000 ____D () C:\Users\dom\Desktop\OpenHardwareMonitor
2015-03-14 17:30 - 2015-03-14 17:30 - 00000000 ____D () C:\Users\dom\Documents\openhardwaremonitor-v0.7.1-beta
2015-03-14 17:18 - 2015-03-14 17:18 - 01582736 _____ ( ) C:\Users\dom\Downloads\cpu-z_1.72-en.exe
2015-03-14 17:18 - 2015-03-14 17:18 - 00001022 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2015-03-14 17:18 - 2015-03-14 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2015-03-14 17:18 - 2015-03-14 17:18 - 00000000 ____D () C:\Program Files\CPUID
2015-03-13 10:51 - 2015-03-13 10:52 - 01054912 _____ (Adobe) C:\Users\dom\Downloads\install_flashplayer17x32au_mssa_aaa_aih.exe
2015-03-11 09:01 - 2015-03-06 07:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 09:01 - 2015-03-06 07:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 09:01 - 2015-03-06 07:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 09:01 - 2015-03-06 07:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 09:01 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 09:01 - 2015-03-06 07:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 09:01 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 09:01 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 09:01 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 09:01 - 2015-02-26 05:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 09:01 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 09:01 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 09:01 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 09:01 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 09:01 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 09:01 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 09:01 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 09:01 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 09:01 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 09:01 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 09:01 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 09:01 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 09:01 - 2015-02-20 04:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 09:01 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 09:01 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 09:01 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 09:01 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 09:01 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 09:01 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 09:01 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 09:01 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 09:01 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 09:01 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 09:01 - 2015-02-20 03:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 09:01 - 2015-02-20 03:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 09:01 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 09:01 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 09:01 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 09:01 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 09:01 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 09:01 - 2015-02-20 03:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 09:01 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 09:01 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 09:01 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 09:01 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 09:01 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 09:01 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-11 09:01 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 09:01 - 2015-01-31 05:33 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-11 09:01 - 2015-01-31 05:33 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 09:01 - 2015-01-31 02:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-11 09:01 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 09:00 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-11 09:00 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 09:00 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-11 09:00 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 09:00 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-11 09:00 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-11 09:00 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-11 09:00 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-11 09:00 - 2015-02-03 05:11 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 09:00 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-11 09:00 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 09:00 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-11 09:00 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-11 09:00 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 09:00 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-11 09:00 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-11 09:00 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-11 09:00 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-11 09:00 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 09:00 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-11 09:00 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-11 09:00 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 09:00 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-11 09:00 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-11 09:00 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-06 15:34 - 2013-09-10 21:15 - 00000000 ____D () C:\Users\dom\AppData\Roaming\uTorrent
2015-04-06 15:34 - 2009-07-14 06:34 - 00031808 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-06 15:34 - 2009-07-14 06:34 - 00031808 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-06 15:25 - 2013-09-10 14:01 - 00000000 ____D () C:\Users\dom\AppData\Roaming\Skype
2015-04-06 15:25 - 2013-09-10 13:17 - 01116776 _____ () C:\Windows\WindowsUpdate.log
2015-04-06 15:23 - 2013-09-10 14:37 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-06 15:20 - 2015-01-13 19:42 - 00000000 ____D () C:\AdwCleaner
2015-04-06 14:51 - 2013-09-10 20:41 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-06 14:51 - 2009-07-14 06:39 - 00337054 _____ () C:\Windows\setupact.log
2015-04-06 14:45 - 2010-11-20 23:01 - 01628600 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-06 14:38 - 2013-09-10 20:41 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-06 14:38 - 2013-09-10 13:38 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-06 14:38 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-06 14:31 - 2010-11-20 23:48 - 00212752 _____ () C:\Windows\PFRO.log
2015-04-06 14:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-06 13:47 - 2013-09-10 13:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-04-06 13:47 - 2013-09-10 13:38 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-04-06 13:47 - 2010-10-21 13:08 - 00000000 ____D () C:\Temp
2015-04-06 13:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\IME
2015-04-06 13:06 - 2014-01-29 21:57 - 00002223 _____ () C:\Users\dom\Desktop\Downloads.lnk
2015-04-05 11:30 - 2014-07-25 23:19 - 00000000 ____D () C:\Users\dom\AppData\Local\Adobe
2015-04-05 11:30 - 2013-09-10 14:37 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-05 11:30 - 2013-09-10 14:37 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-05 11:25 - 2013-09-10 13:59 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-04 10:54 - 2014-06-14 21:04 - 00000000 ____D () C:\Users\dom\Desktop\Старые данные Firefox
2015-04-04 10:43 - 2013-09-10 20:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-04-03 20:53 - 2013-09-10 20:42 - 00002125 ____H () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-20 16:15 - 2009-07-14 06:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-12 01:44 - 2014-12-02 18:07 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-03-11 20:01 - 2009-07-14 06:33 - 00435944 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-11 19:18 - 2013-09-10 14:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-11 19:17 - 2013-09-10 15:44 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-11 19:13 - 2013-09-10 15:44 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-11 15:23 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-03-11 14:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-03-11 12:30 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-03-10 15:30 - 2013-09-19 22:04 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-03-10 15:30 - 2013-09-19 22:02 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-03-10 15:30 - 2013-09-19 22:02 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys

==================== Files in the root of some directories =======

2014-06-06 14:50 - 2014-06-06 18:50 - 0018167 _____ () C:\Users\dom\AppData\Local\ramcpuversion.txt

Some content of TEMP:
====================
C:\Users\dom\AppData\Local\Temp\avgnt.exe
C:\Users\dom\AppData\Local\Temp\ose00000.exe
C:\Users\dom\AppData\Local\Temp\ose00001.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-04 13:22

==================== End Of Log ============================
         
--- --- ---




Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by dom at 2015-04-06 15:36:19
Running from C:\Users\dom\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: FireWall (Disabled) {753F9273-B322-2907-AC37-03D0F1702F22}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\PE_F_DOM\...\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
µTorrent (HKU\PE_F_UPDATUSUSER\...\uTorrent) (Version: 1.7.7 - )
µTorrent (HKU\S-1-5-21-402423875-3588787103-3882004954-1000\...\uTorrent) (Version: 3.4.2.38656 - BitTorrent Inc.)
ABBYY Lingvo x3 (HKLM\...\{A1400000-0000-0000-0000-074957833700}) (Version: 14.00.786.6095 - ABBYY)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Russian (HKLM\...\{AC76BA86-7AD7-1049-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Avira Internet Security (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.8.532 - Avira)
Avira SearchFree Toolbar (HKLM\...\{41564952-412D-5637-00A7-A758B70C1500}) (Version: 12.21.0.3946 - APN, LLC)
calibre (HKLM\...\{B5D724AD-AC50-46B4-AAA7-62EF18F0CDFE}) (Version: 1.44.0 - Kovid Goyal)
CanoScan Toolbox Ver4.9 (HKLM\...\{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}) (Version:  - )
CPUID CPU-Z 1.72 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version:  - )
EXPERTool 7.6 (HKLM\...\EXPERTool_is1) (Version:  - Gainward Co., Ltd)
Google Chrome (HKLM\...\Google Chrome) (Version: 41.0.2272.118 - Google Inc.)
Google Chrome (HKU\PE_F_DOM\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
Google Chrome (HKU\PE_F_UPDATUSUSER\...\Google Chrome) (Version: 18.0.1025.168 - Google Inc.)
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Online Services-Anmeldeassistent (HKLM\...\{C89AD07D-CAA0-4BF2-A2E8-A851B71FD698}) (Version: 7.250.4303.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 37.0.1 (x86 ru) (HKLM\...\Mozilla Firefox 37.0.1 (x86 ru)) (Version: 37.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 320.49 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 320.49 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 341.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.44 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.2 - NVIDIA Corporation)
NVIDIA Grafiktreiber 341.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.13.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0604 - NVIDIA Corporation)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version:  - Microsoft)
SHIELD Streaming (Version: 3.1.200 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.42 - NVIDIA Corporation) Hidden
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
VoipConnect (HKLM\...\VoipConnect_is1) (Version: 4.14 build 760 - Finarea S.A. Switzerland)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-402423875-3588787103-3882004954-1000_Classes\CLSID\{935D6757-C96A-A61D-C321-764C155D718C}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation)

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {026B5736-FBF8-43AD-8870-F222B0C727E1} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {089F330B-797A-4DC3-859E-4407148BD408} - System32\Tasks\Microsoft Office 15 Sync Maintenance for dom-PC-dom dom-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
Task: {34585C96-3A56-46B6-B607-A44D1E28C293} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {3C749DAA-6A9C-45CF-BB34-F57F857EA850} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-05] (Adobe Systems Incorporated)
Task: {3EF0559E-BC89-4CFD-B82A-7A8694497105} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-09-10] (Google Inc.)
Task: {5A87C3E7-41B0-462E-985E-39E27B660908} - System32\Tasks\{F6BB6642-A8FE-4D86-9DFF-68F8433F918A} => pcalua.exe -a C:\Users\dom\Downloads\setup_de(3).exe -d C:\Users\dom\Downloads
Task: {667FADBA-0EAA-4131-8069-169B307AD67A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {875AE6D3-CB7A-4F13-877A-DDAD4EC9C6BF} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {9C21B2DA-2DAE-4CC0-B2F3-9EA2C29BA50E} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {9DE6220F-5517-463A-975A-2EA1600593FB} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {A2CEABD7-9B93-4230-87C8-BBB3FF408FDC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {A4359769-E110-46C1-A803-44DDB5228CE8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {B27B755F-7835-49E3-9341-19AEB625E8B6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
Task: {CB028534-29D7-4E9D-8D67-75883F15465A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {DA9F00C1-38A0-4C7B-847D-C6244F9E1BB0} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {E40E6D8D-5CC8-4936-BEC4-E7DDAD57C396} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {E4912B61-BA2D-41AE-A254-4875BF04AF09} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-09-10] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2013-09-10 13:38 - 2015-02-04 04:05 - 00106640 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2015-04-06 13:30 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-04-06 13:30 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2015-04-06 13:30 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-07-27 13:41 - 1998-10-31 10:55 - 00005120 _____ () C:\Program Files\EXPERTool\TBManage.dll
2015-04-06 13:30 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
2015-04-06 13:30 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2015-04-03 20:53 - 2015-03-30 23:07 - 01174856 _____ () c:\Program Files\Google\Chrome\Application\41.0.2272.118\libglesv2.dll
2015-04-03 20:53 - 2015-03-30 23:07 - 00080200 _____ () c:\Program Files\Google\Chrome\Application\41.0.2272.118\libegl.dll
2015-04-03 20:53 - 2015-03-30 23:07 - 09279304 _____ () c:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll
2015-04-03 20:53 - 2015-03-30 23:07 - 14974280 _____ () c:\Program Files\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\PE_F_DOM\Control Panel\Desktop\\Wallpaper -> F:\Users\Dom\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-402423875-3588787103-3882004954-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\dom\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-402423875-3588787103-3882004954-500 - Administrator - Disabled)
dom (S-1-5-21-402423875-3588787103-3882004954-1000 - Administrator - Enabled) => C:\Users\dom
Gast (S-1-5-21-402423875-3588787103-3882004954-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-402423875-3588787103-3882004954-1002 - Limited - Enabled)

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/06/2015 03:21:14 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm SDTools.exe, Version 2.4.40.157 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: b84

Startzeit: 01d0706c77685589

Endzeit: 19

Anwendungspfad: C:\Program Files\Spybot - Search & Destroy 2\SDTools.exe

Berichts-ID: c93bcfbb-dc5f-11e4-bd0a-00306757e7db


System errors:
=============
Error: (04/06/2015 03:25:56 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%-2140993535

Error: (04/06/2015 03:25:56 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: 
%%-2140993535

Error: (04/06/2015 03:25:56 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%-2140993535

Error: (04/06/2015 03:25:56 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: 
%%-2140993535

Error: (04/06/2015 03:25:56 PM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: 0x80630801

Error: (04/06/2015 03:25:56 PM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: 0x80630801

Error: (04/06/2015 03:25:52 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%-2140993535

Error: (04/06/2015 03:25:52 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: 
%%-2140993535

Error: (04/06/2015 03:25:52 PM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: 0x80630801

Error: (04/06/2015 03:25:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%-2140993535


Microsoft Office Sessions:
=========================
Error: (04/06/2015 03:21:14 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: SDTools.exe2.4.40.157b8401d0706c7768558919C:\Program Files\Spybot - Search & Destroy 2\SDTools.exec93bcfbb-dc5f-11e4-bd0a-00306757e7db


==================== Memory info =========================== 

Processor: Pentium(R) Dual-Core CPU E6300 @ 2.80GHz
Percentage of memory in use: 51%
Total physical RAM: 3071.3 MB
Available physical RAM: 1492.94 MB
Total Pagefile: 6140.9 MB
Available Pagefile: 4249.84 MB
Total Virtual: 2047.88 MB
Available Virtual: 1893.58 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:64.01 GB) (Free:22.19 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:356.68 GB) (Free:62.67 GB) NTFS
Drive e: () (Fixed) (Total:233.53 GB) (Free:46.1 GB) NTFS
Drive f: () (Fixed) (Total:45.07 GB) (Free:3.21 GB) NTFS
Drive g: () (Fixed) (Total:232.22 GB) (Free:22.13 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: EF11EF11)
Partition 1: (Active) - (Size=64 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=356.7 GB) - (Type=OF Extended)
Partition 3: (Not Active) - (Size=45.1 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 465.8 GB) (Disk ID: C3EB0719)
Partition 2: (Active) - (Size=465.8 GB) - (Type=05)

==================== End Of Log ============================
         
__________________

Alt 06.04.2015, 18:15   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt - Standard

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 07.04.2015, 12:06   #5
TreeFriends
 
Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt - Standard

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt



Hey,

danke erst einmal für die Hilfe bis jetzt. Combofix läuft jetzt schon etwas über eine Stunde und macht nicht den Eindruck bald fertig zu werden. Ist das normal oder habe ich hier ein Problem?


Alt 07.04.2015, 17:46   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt - Standard

Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt



Kommt drauf an. Wo genau steht er? AV Programm ist aus? Wenn es immer noch läuft dann bitte beenden und Rechner neu starten. Frisches FRST log bitte.
__________________
--> Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt

Antwort

Themen zu Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt
browser, computer, dll, einstellungen, entfernen, escan, explorer, explorer.exe, fehler, file, firefox, flash player, google, helper.exe, infizierte, installation, internet explorer, log, microsoft, problem, programme, registry key, s3.amazonaws.com, scan, server, tan, wallpaper, window 7, windows



Ähnliche Themen: Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt


  1. Windows 7/8: Continue Live Installation (und mehr?) eingefangen
    Plagegeister aller Art und deren Bekämpfung - 02.10.2015 (15)
  2. Continue Live Installation erscheint immer wieder...
    Log-Analyse und Auswertung - 12.04.2015 (11)
  3. Continue live installation
    Plagegeister aller Art und deren Bekämpfung - 22.03.2015 (17)
  4. Continue Live Installation meldung
    Log-Analyse und Auswertung - 22.03.2015 (17)
  5. Continue Live Installation lässt sich nicht entfernen.
    Log-Analyse und Auswertung - 16.03.2015 (13)
  6. Continue Live Installation
    Plagegeister aller Art und deren Bekämpfung - 27.02.2015 (13)
  7. continue live installation/windows version installer bei Windows7
    Log-Analyse und Auswertung - 22.02.2015 (15)
  8. Windows 8: Werbung im Browser/ unerwünschte Installation: Continue Live Installation
    Log-Analyse und Auswertung - 20.02.2015 (24)
  9. Win7 Umbenennung Chrome Browser, Installation Continue Live Installation
    Log-Analyse und Auswertung - 01.01.2015 (11)
  10. Windows 8.1: Continue Live Installation
    Log-Analyse und Auswertung - 19.11.2014 (12)
  11. Continue Live Installation Entfernen
    Log-Analyse und Auswertung - 22.10.2014 (1)
  12. Windows 7 : Windows Version Installer Overlay und Continue Live Installation.exe verschwindet nicht.
    Log-Analyse und Auswertung - 09.10.2014 (9)
  13. Continue Live Installation
    Plagegeister aller Art und deren Bekämpfung - 01.10.2014 (17)
  14. AdWare (via Traffic Junky) lässt sich trotz Malwarebytes und AdwCleaner nicht entfernen
    Plagegeister aller Art und deren Bekämpfung - 17.08.2014 (13)
  15. Webssearches lässt sich nicht entfernen - AdwCleaner und Malwarebytes Anti-Malware stürzen ab (Windows 8.1)
    Plagegeister aller Art und deren Bekämpfung - 17.06.2014 (11)
  16. Firefox Startseite http://www.searchnu.com/406 lässt sich nicht mehr ändern!
    Log-Analyse und Auswertung - 29.11.2012 (13)
  17. Live Security Platinum lässt sich nicht entfernen
    Plagegeister aller Art und deren Bekämpfung - 10.07.2012 (1)

Zum Thema Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt - Guten Tag liebes trojaner-board. Der pC an dem ich Sitze hat das Problem, dass wenn ich den Browser aufrufe automatisch die Internetseite "hxxp://gotut.ru/" geöffnet wird. Ich habe bereits in den - Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt...
Archiv
Du betrachtest: Window 7 http gotut.ru lässt sich als Startseite nicht entfernen + Continue Live Installation von adwcleaner erkannt und entfernt auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.