Code:
OTL logfile created on: 02.02.2015 18:19:17 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jul\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,80 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 56,33% Memory free
5,60 Gb Paging File | 2,74 Gb Available in Paging File | 48,92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 275,86 Gb Total Space | 37,98 Gb Free Space | 13,77% Space Free | Partition Type: NTFS
Drive D: | 7,78 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 1862,55 Gb Total Space | 942,87 Gb Free Space | 50,62% Space Free | Partition Type: FAT32
Drive X: | 917,07 Gb Total Space | 241,22 Gb Free Space | 26,30% Space Free | Partition Type: NTFS
Computer Name: JUL-01 | User Name: Jul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Jul\Desktop\otl.exe (OldTimer Tools)
PRC - C:\Program Files\CinemaP-1.9cV02.02\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-1-6.exe (Cinema PlusV02.02)
PRC - C:\Program Files\Raptr\raptr_im.exe (Raptr, Inc)
PRC - C:\Program Files\Raptr\raptr.exe (Raptr, Inc)
PRC - C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe ()
PRC - C:\ProgramData\SecurityUtility\ColorMedia.exe (CartCrunch Israel Ltd.)
PRC - C:\Program Files\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
PRC - C:\Program Files\streamWriter\streamwriter.exe (streamwriter.org)
PRC - C:\Users\Jul\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd)
PRC - C:\Users\Jul\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Users\Jul\AppData\Roaming\Spotify\Data\SpotifyHelper.exe ()
PRC - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\CyberGhost 5\Service.exe (CyberGhost S.R.L)
PRC - C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Razer\Razer Game Booster\RzKLService.exe (Razer Inc.)
PRC - C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe (A-Volute)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Easy Display Manager\WifiManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\CyberLink\YouCam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
PRC - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE (Broadcom Corporation)
PRC - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE (Broadcom Corporation)
PRC - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE (Broadcom Corporation)
PRC - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Raptr\ltc_host_ex.dll ()
MOD - C:\Users\Jul\AppData\Roaming\Spotify\Data\libcef.dll ()
MOD - C:\Users\Jul\AppData\Roaming\Spotify\Data\libGLESv2.dll ()
MOD - C:\Users\Jul\AppData\Roaming\Spotify\Data\ffmpegsumo.dll ()
MOD - C:\Users\Jul\AppData\Roaming\Spotify\Data\SpotifyHelper.exe ()
MOD - C:\Users\Jul\AppData\Roaming\Spotify\Data\libEGL.dll ()
MOD - C:\Users\Jul\AppData\Roaming\moters\mentste.dll ()
MOD - C:\Program Files\Raptr\libvlccore.dll ()
MOD - C:\Program Files\Raptr\libvlc.dll ()
MOD - C:\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll ()
MOD - C:\Program Files\Raptr\heliotrope._purple.pyd ()
MOD - C:\Program Files\Raptr\PyQt4.QtCore.pyd ()
MOD - C:\Program Files\Raptr\PyQt4.QtNetwork.pyd ()
MOD - C:\Program Files\Raptr\PyQt4.QtGui.pyd ()
MOD - C:\Program Files\Raptr\PyQt4.QtWebKit.pyd ()
MOD - C:\Program Files\Raptr\sip.pyd ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll ()
MOD - C:\Program Files\Raptr\amd_ags.dll ()
MOD - C:\Program Files\Raptr\liboscar.dll ()
MOD - C:\Program Files\Raptr\plugins\libicq.dll ()
MOD - C:\Program Files\Raptr\plugins\libaim.dll ()
MOD - C:\Program Files\Raptr\libjabber.dll ()
MOD - C:\Program Files\Raptr\libymsg.dll ()
MOD - C:\Program Files\Raptr\plugins\libirc.dll ()
MOD - C:\Program Files\Raptr\plugins\ssl-nss.dll ()
MOD - C:\Program Files\Raptr\plugins\ssl.dll ()
MOD - C:\Program Files\Raptr\plugins\libyahoojp.dll ()
MOD - C:\Program Files\Raptr\plugins\libmsn.dll ()
MOD - C:\Program Files\Raptr\plugins\libxmpp.dll ()
MOD - C:\Program Files\Raptr\plugins\libyahoo.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Raptr\libxml2-2.dll ()
MOD - C:\Program Files\Raptr\sqlite3.dll ()
MOD - C:\Program Files\Raptr\zlib1.dll ()
MOD - C:\Program Files\Raptr\win32gui.pyd ()
MOD - C:\Program Files\Raptr\win32file.pyd ()
MOD - C:\Program Files\Raptr\win32api.pyd ()
MOD - C:\Program Files\Raptr\win32process.pyd ()
MOD - C:\Program Files\Raptr\win32trace.pyd ()
MOD - C:\Program Files\Raptr\gobject._gobject.pyd ()
MOD - C:\Program Files\Raptr\win32com.shell.shell.pyd ()
MOD - C:\Program Files\Raptr\pythoncom26.dll ()
MOD - C:\Program Files\Raptr\pywintypes26.dll ()
MOD - C:\Program Files\Raptr\PIL._imaging.pyd ()
MOD - C:\Program Files\Raptr\_ssl.pyd ()
MOD - C:\Program Files\Raptr\unicodedata.pyd ()
MOD - C:\Program Files\Raptr\_hashlib.pyd ()
MOD - C:\Program Files\Raptr\pyexpat.pyd ()
MOD - C:\Program Files\Raptr\_ctypes.pyd ()
MOD - C:\Program Files\Raptr\_sqlite3.pyd ()
MOD - C:\Program Files\Raptr\_socket.pyd ()
MOD - C:\Program Files\Raptr\select.pyd ()
MOD - C:\Program Files\Raptr\winsound.pyd ()
MOD - C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll ()
MOD - C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()
========== Services (SafeList) ==========
SRV - (ZAtheros Wlan Agent) -- C:\Program Files\Atheros\Ath_WlanAgent.exe File not found
SRV - (Futuremark SystemInfo Service) -- C:\Program Files\Futuremark\Futuremark SystemInfo\FMSISvc.exe File not found
SRV - (globalUpdatem) -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe (globalUpdate)
SRV - (globalUpdate) -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe (globalUpdate)
SRV - (SecurityUtility Service) -- C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe ()
SRV - (ColorMedia) -- C:\ProgramData\SecurityUtility\ColorMedia.exe (CartCrunch Israel Ltd.)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (HiPatchService) -- C:\Program Files\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Origin Client Service) -- C:\Program Files\Origin\OriginClientService.exe (Electronic Arts)
SRV - (IEEtwCollectorService) -- C:\Windows\System32\IEEtwCollector.exe (Microsoft Corporation)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (TunngleService) -- C:\Program Files\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
SRV - (CGVPNCliService) -- C:\Program Files\CyberGhost 5\Service.exe (CyberGhost S.R.L)
SRV - (GalaxyService) -- C:\Program Files\GalaxyClient\GalaxyService.exe (GOG.com)
SRV - (NvStreamSvc) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation)
SRV - (NvNetworkService) -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation)
SRV - (EasyAntiCheat) -- C:\Windows\System32\EasyAntiCheat.exe (EasyAntiCheat Ltd)
SRV - (AVP15.0.0) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe (Kaspersky Lab ZAO)
SRV - (Hamachi2Svc) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (Connectify) -- C:\Program Files\Connectify\ConnectifyService.exe (Connectify)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (LMIGuardianSvc) -- C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (RzKLService) -- C:\Program Files\Razer\Razer Game Booster\RzKLService.exe (Razer Inc.)
SRV - (RzMaelstromVADStreamingService) -- C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe (A-Volute)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TeamViewer8) -- C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Sony PC Companion) -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe (Avanquest Software)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (wltrysvc) -- C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE (Broadcom Corporation)
SRV - (UNS) -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (XDva405) -- C:\Windows\system32\XDva405.sys File not found
DRV - (XDva404) -- C:\Windows\system32\XDva404.sys File not found
DRV - (XDva402) -- C:\Windows\system32\XDva402.sys File not found
DRV - (XDva401) -- C:\Windows\system32\XDva401.sys File not found
DRV - (WinRing0_1_2_0) -- C:\Program Files\Razer\Razer Game Booster\Driver\WinRing0.sys File not found
DRV - (VBoxNetFlt) -- system32\DRIVERS\VBoxNetFlt.sys File not found
DRV - (taphss6) -- system32\DRIVERS\taphss6.sys File not found
DRV - (massfilter) -- system32\drivers\massfilter.sys File not found
DRV - (HSPADataCardusbser) -- system32\DRIVERS\HSPADataCardusbser.sys File not found
DRV - (HSPADataCardusbnmea) -- system32\DRIVERS\HSPADataCardusbnmea.sys File not found
DRV - (HSPADataCardusbmdm) -- system32\DRIVERS\HSPADataCardusbmdm.sys File not found
DRV - (EagleNT) -- C:\Windows\system32\drivers\EagleNT.sys File not found
DRV - (cpuz136) -- C:\Windows\TEMP\cpuz136\cpuz136_x32.sys File not found
DRV - (afdpkjlu) -- File not found
DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys (Malwarebytes Corporation)
DRV - (KLIF) -- C:\Windows\System32\drivers\klif.sys (Kaspersky Lab ZAO)
DRV - (klflt) -- C:\Windows\System32\drivers\klflt.sys (Kaspersky Lab ZAO)
DRV - (MBAMWebAccessControl) -- C:\Windows\System32\drivers\mwac.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (NvStreamKms) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys (NVIDIA Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvpciflt) -- C:\Windows\System32\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV - (klhk) -- C:\Windows\System32\drivers\klhk.sys (Kaspersky Lab ZAO)
DRV - (nvvad_WaveExtensible) -- C:\Windows\System32\drivers\nvvad32v.sys (NVIDIA Corporation)
DRV - (klkbdflt) -- C:\Windows\System32\drivers\klkbdflt.sys (Kaspersky Lab ZAO)
DRV - (kneps) -- C:\Windows\System32\drivers\kneps.sys (Kaspersky Lab ZAO)
DRV - (kltdi) -- C:\Windows\System32\drivers\kltdi.sys (Kaspersky Lab ZAO)
DRV - (ggsemc) -- C:\Windows\System32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) -- C:\Windows\System32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (KLIM6) -- C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV - (kl1) -- C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (cnnctfy3) -- C:\Windows\System32\drivers\cnnctfy3.sys (Connectify)
DRV - (RZMAELSTROMVADService) -- C:\Windows\System32\drivers\RzMaelstromVAD.sys (Windows (R) Win 7 DDK provider)
DRV - (tap0901) -- C:\Windows\System32\drivers\tap0901.sys (The OpenVPN Project)
DRV - (klmouflt) -- C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab ZAO)
DRV - (VBoxNetAdp) -- C:\Windows\System32\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV - (klpd) -- C:\Windows\System32\drivers\klpd.sys (Kaspersky Lab ZAO)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (dc3d) -- C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (tenCapture) -- C:\Windows\System32\drivers\tenCapture.sys (Hajo Krabbenhöft)
DRV - (AMPPAL) -- C:\Windows\System32\drivers\AmpPal.sys (Windows (R) Win 7 DDK provider)
DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (IntcDAud) -- C:\Windows\System32\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV - (Impcd) -- C:\Windows\System32\drivers\Impcd.sys (Intel Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Qualcomm Atheros Communications, Inc.)
DRV - (Netaapl) -- C:\Windows\System32\drivers\netaapl.sys (Apple Inc.)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (clwvd) -- C:\Windows\System32\drivers\clwvd.sys (CyberLink Corporation)
DRV - (BCM42RLY) -- C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (acedrv11) -- C:\Windows\System32\drivers\acedrv11.sys (Protect Software GmbH)
DRV - (SCREAMINGBDRIVER) -- C:\Windows\System32\drivers\ScreamingBAudio.sys (Screaming Bee LLC)
DRV - (HECI) -- C:\Windows\System32\drivers\HECI.sys (Intel Corporation)
DRV - (tap0901t) -- C:\Windows\System32\drivers\tap0901t.sys (Tunngle.net)
DRV - (WSDPrintDevice) -- C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (VCSVADHWSer) -- C:\Windows\System32\drivers\vcsvad.sys (Avnex)
DRV - (scramby_out) -- C:\Windows\System32\drivers\scramby_out.sys (RapidSolution Software AG)
DRV - (AmdLLD) -- C:\Windows\System32\drivers\AmdLLD.sys (AMD, Inc.)
DRV - (scramby) -- C:\Windows\System32\drivers\scramby.sys (RapidSolution Software AG)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?type=hp&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = hxxp://istart.webssearches.com/web/?type=ds&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB&q={searchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=625&r=2014/07/03&hid=1071830447083835621&lg=EN&cc=DE&unqvl=56
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\.DEFAULT\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=IDSS&chn=retail&geo=DE&ver=2014&locale=de_DE&gct=kwd&qsrc=2869
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-18\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=IDSS&chn=retail&geo=DE&ver=2014&locale=de_DE&gct=kwd&qsrc=2869
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=IDSS&chn=retail&geo=DE&ver=2014&locale=de_DE&gct=kwd&qsrc=2869
IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.mail.ru/?ieverfix=1&fr=ieverfix_sg
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes,DefaultScope = {FFEBBF0A-C22C-4172-89FF-45215A135AC7}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325580&octid=EB_ORIGINAL_CTID&ISID=MD4C7E4CF-FE6B-427E-B894-7D9439C0B630&SearchSource=58&CUI=&UM=2&UP=SP1949E65B-F478-4216-93A4-8C77FFFD66C1&q={searchTerms}&SSPV=
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.claro-search.com/?q={searchTerms}&babsrc=SP_ss_wls&mntrId=D2437A7900000000&affID=121232&tt=290713_190&tsp=4958
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes\{310E121A-788D-4D56-94F0-AFC6468A7852}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = hxxp://istart.webssearches.com/web/?type=ds&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB&q={searchTerms}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes\{5BCDEDD9-641B-4373-830C-8F6997D12DBC}: "URL" = https://www.google.com/search?q={searchTerms}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=625&r=2014/07/03&hid=1071830447083835621&lg=EN&cc=DE&unqvl=56
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}: "URL" = hxxp://go.mail.ru/search?q={SearchTerms}&ieverfix=1&fr=ieverfix_dse
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.mail.ru/?ieverfix=1&fr=ieverfix_sg
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes,DefaultScope = {FFEBBF0A-C22C-4172-89FF-45215A135AC7}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325580&octid=EB_ORIGINAL_CTID&ISID=MD4C7E4CF-FE6B-427E-B894-7D9439C0B630&SearchSource=58&CUI=&UM=2&UP=SP1949E65B-F478-4216-93A4-8C77FFFD66C1&q={searchTerms}&SSPV=
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://www.claro-search.com/?q={searchTerms}&babsrc=SP_ss_wls&mntrId=D2437A7900000000&affID=121232&tt=290713_190&tsp=4958
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{310E121A-788D-4D56-94F0-AFC6468A7852}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = hxxp://istart.webssearches.com/web/?type=ds&ts=1422816583&from=cvs4&uid=TOSHIBAXMK3265GSX_217ID6EDBXX217ID6EDB&q={searchTerms}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{5BCDEDD9-641B-4373-830C-8F6997D12DBC}: "URL" = https://www.google.com/search?q={searchTerms}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=625&r=2014/07/03&hid=1071830447083835621&lg=EN&cc=DE&unqvl=56
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}: "URL" = hxxp://go.mail.ru/search?q={SearchTerms}&ieverfix=1&fr=ieverfix_dse
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..extensions.enabledAddons: OIBMBKA115048682%40HYKFIU97176590.com:0.95.56
FF - prefs.js..extensions.enabledAddons: content_blocker%40kaspersky.com:4.0.10.15
FF - prefs.js..extensions.enabledAddons: virtual_keyboard%40kaspersky.com:4.0.10.15
FF - prefs.js..extensions.enabledAddons: anti_banner%40kaspersky.com:4.0.10.15
FF - prefs.js..extensions.enabledAddons: online_banking%40kaspersky.com:4.0.10.15
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:35.0.1
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C:\Program Files\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.60.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@kaspersky.com/content_blocker: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2015.02.02 12:38:16 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@kaspersky.com/online_banking: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2015.02.02 12:38:16 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@kaspersky.com/virtual_keyboard: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2015.02.02 12:38:17 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: File not found
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@onlive.com/OnLiveGameClientDetector,version=1.0.0: C:\Program Files\OnLive\Plugin\npolgdet.dll File not found
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\Jul\AppData\LocalLow\Sony Online Entertainment\npsoe.dll File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Jul\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\Jul\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)
FF - HKCU\Software\MozillaPlugins\sony.com/MediaGoDetector: C:\Program Files\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\ProgramData\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.6.0.73\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\content_blocker@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2015.02.02 12:38:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtual_keyboard@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2015.02.02 12:38:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\url_advisor@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com [2015.02.02 12:38:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\anti_banner@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com [2015.02.02 12:38:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\online_banking@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2015.02.02 12:38:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.3.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.3.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2014.11.17 15:57:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jul\AppData\Roaming\Mozilla\Extensions
[2015.02.02 17:46:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jul\AppData\Roaming\Mozilla\firefox\Profiles\b3izpfhg.default\extensions
[2015.02.02 17:46:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jul\AppData\Roaming\Mozilla\firefox\Profiles\b3izpfhg.default\extensions\jid1-U7omKQ6kQfxMaQ@jetpack
[2015.02.02 15:13:27 | 000,000,000 | ---D | M] ("CinemaP-1.9cV02.02") -- C:\Users\Jul\AppData\Roaming\Mozilla\firefox\Profiles\b3izpfhg.default\extensions\OIBMBKA115048682@HYKFIU97176590.com
[2015.02.02 12:10:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jul\AppData\Roaming\Mozilla\firefox\Profiles\b3izpfhg.default\extensions\staged
[2015.02.02 15:13:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jul\AppData\Roaming\Mozilla\firefox\Profiles\b3izpfhg.default\extensions\OIBMBKA115048682@HYKFIU97176590.com\extensionData
[2015.02.02 15:13:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jul\AppData\Roaming\Mozilla\firefox\Profiles\b3izpfhg.default\extensions\OIBMBKA115048682@HYKFIU97176590.com\extensionData\plugins
[2015.02.02 15:13:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jul\AppData\Roaming\Mozilla\firefox\Profiles\b3izpfhg.default\extensions\OIBMBKA115048682@HYKFIU97176590.com\extensionData\userCode
[2015.02.01 20:51:42 | 000,985,112 | ---- | M] () (No name found) -- C:\Users\Jul\AppData\Roaming\Mozilla\firefox\Profiles\b3izpfhg.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.01.27 00:44:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.01.27 00:44:19 | 000,000,000 | ---D | M] (myCoups) -- C:\Program Files\Mozilla Firefox\extensions\agjqcacdnhemgjev@hclmgodt.org
[2015.02.01 20:34:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2015.02.01 20:34:57 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2015.02.02 12:38:16 | 000,000,000 | ---D | M] (Chặn quảng cáo) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 15.0.0\FFEXT\ANTI_BANNER@KASPERSKY.COM
[2015.02.02 12:38:16 | 000,000,000 | ---D | M] (Ngăn chặn trang web nguy hiểm) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 15.0.0\FFEXT\CONTENT_BLOCKER@KASPERSKY.COM
[2015.02.02 12:38:16 | 000,000,000 | ---D | M] (An toàn giao dịch tài chính) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 15.0.0\FFEXT\ONLINE_BANKING@KASPERSKY.COM
[2015.02.02 12:38:17 | 000,000,000 | ---D | M] (Công cụ kiểm tra liên kết của Kaspersky) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 15.0.0\FFEXT\URL_ADVISOR@KASPERSKY.COM
[2015.02.02 12:38:17 | 000,000,000 | ---D | M] (Bàn phím ảo) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 15.0.0\FFEXT\VIRTUAL_KEYBOARD@KASPERSKY.COM
Hosts file not found
O2 - BHO: (CoupExtenSion) - {104c6270-1cbc-4b65-8f90-ea6cd02ccda2} - C:\ProgramData\CoupExtenSion\erYSIaRuzWHj9I.dll File not found
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (BueesstSaveForYou) - {b1e87602-fbdc-4bbb-9052-cadc1b5d03ee} - C:\ProgramData\BueesstSaveForYou\es2W25OVTuaiAp.dll File not found
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - No CLSID value found.
O3 - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Toolbar\WebBrowser: (no name) - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - No CLSID value found.
O3 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll File not found
O3 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll File not found
O4 - HKLM..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" File not found
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE (Broadcom Corporation)
O4 - HKLM..\Run: [ChicoSys] C:\Windows\System32\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [mbot_de_481] File not found
O4 - HKLM..\Run: [MessengerPlusForSkypeService] "C:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" File not found
O4 - HKLM..\Run: [NvBackend] C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [Raptr] C:\Program Files\Raptr\raptrstub.exe (Raptr, Inc)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ShadowPlay] C:\Windows\System32\nvspcap.dll (NVIDIA Corporation)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [avs reload sys] C:\Users\Jul\AppData\Local\Temp\tnvhwn.exe (oracle enterprises)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [driver restore update] C:\Users\Jul\AppData\Local\Temp\sgtvim.exe (paint effects ltd)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [HP Officejet 6500 E710n-z (NET)] C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [LiveSupport] "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [MailRuUpdater] C:\Users\Jul\AppData\Local\MailRu\MailRuUpdater.exe (Mail.Ru)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [msi system check] %TEMP%\gnbsso.exe File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [SkypeVoiceChanger] C:\Program Files\AthTek\Voice Changer for Skype\SkypeVoiceChanger.exe /auto File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [Sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [Spotify Web Helper] C:\Users\Jul\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000..\Run: [stream system eng] C:\Users\Jul\AppData\Local\Temp\rnbssv.exe (kaz relay systems)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [avs reload sys] C:\Users\Jul\AppData\Local\Temp\tnvhwn.exe (oracle enterprises)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [driver restore update] C:\Users\Jul\AppData\Local\Temp\sgtvim.exe (paint effects ltd)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [HP Officejet 6500 E710n-z (NET)] C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [LiveSupport] "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [MailRuUpdater] C:\Users\Jul\AppData\Local\MailRu\MailRuUpdater.exe (Mail.Ru)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [msi system check] %TEMP%\gnbsso.exe File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [SkypeVoiceChanger] C:\Program Files\AthTek\Voice Changer for Skype\SkypeVoiceChanger.exe /auto File not found
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [Sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [Spotify Web Helper] C:\Users\Jul\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [stream system eng] C:\Users\Jul\AppData\Local\Temp\rnbssv.exe (kaz relay systems)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\Run: [Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}] C:\Users\Public\Downloads\Norton\{NF22-B22-4abb-B07C-C084B04B4F12}\NF_Installer.exe (Symantec Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Jul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Jul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\streamWriter.lnk = C:\Program Files\streamWriter\streamwriter.exe (streamwriter.org)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O8 - Extra context menu item: Zu Anti-Banner hinzufügen - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\ie_banner_deny.htm ()
O9 - Extra Button: Virtuelle Tastatur - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Link-Untersuchung - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\ColorMedia.dll (CartCrunch Israel Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\ColorMedia.dll (CartCrunch Israel Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\ColorMedia.dll (CartCrunch Israel Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\ColorMedia.dll (CartCrunch Israel Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\ColorMedia.dll (CartCrunch Israel Ltd.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..Trusted Domains: clonewarsadventures.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..Trusted Domains: freerealms.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..Trusted Domains: knuddels.de ([www] http in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..Trusted Domains: soe.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000\..Trusted Domains: sony.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: clonewarsadventures.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: freerealms.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: knuddels.de ([www] http in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: soe.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: sony.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2741185204-2122887262-4188245074-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} hxxp://clients.futuremark.com/calico/systeminfodeploy/FMSI_v415.cab (FuturemarkSystemInfoX Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4FB53F10-9E60-4036-A931-DC60F52C3F17}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{88B37941-1342-40D0-BA09-DCFA7D2FF6ED}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C9B2C989-435D-45B0-B450-39D17CBD5391}: DhcpNameServer = 139.7.30.126 139.7.30.125
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (c:\windows\system32\nvinit.dll c:\windows\system32\nvinit.dll) - C:\Windows\System32\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\system32\nvinit.dll) - C:\Windows\System32\nvinit.dll (NVIDIA Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011.02.17 21:55:25 | 000,000,000 | ---D | M] - D:\AutoPlay -- [ CDFS ]
O32 - AutoRun File - [2011.02.17 21:55:34 | 003,057,784 | R--- | M] (UBISOFT) - D:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2011.02.17 21:39:07 | 000,231,798 | R--- | M] () - D:\autorun.ico -- [ CDFS ]
O32 - AutoRun File - [2011.02.17 21:39:07 | 000,000,047 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{054dd5e1-af97-11e3-9437-9b94ad7f775b}\Shell - "" = AutoRun
O33 - MountPoints2\{054dd5e1-af97-11e3-9437-9b94ad7f775b}\Shell\AutoRun\command - "" = F:\Startme.exe
O33 - MountPoints2\{5aa476c5-bd20-11e1-af23-e811324622ab}\Shell - "" = AutoRun
O33 - MountPoints2\{5aa476c5-bd20-11e1-af23-e811324622ab}\Shell\AutoRun\command - "" = F:\Launcher.exe
O33 - MountPoints2\{832b2e42-96ac-11e1-a9af-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{832b2e42-96ac-11e1-a9af-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe -- [2011.02.17 21:55:34 | 003,057,784 | R--- | M] (UBISOFT)
O33 - MountPoints2\{9c0303b7-be8b-11e1-8911-e811324622ab}\Shell - "" = AutoRun
O33 - MountPoints2\{9c0303b7-be8b-11e1-8911-e811324622ab}\Shell\AutoRun\command - "" = F:\Launcher.exe
O33 - MountPoints2\{b2466843-f486-11e3-a8c2-e811324622ab}\Shell - "" = AutoRun
O33 - MountPoints2\{b2466843-f486-11e3-a8c2-e811324622ab}\Shell\AutoRun\command - "" = F:\Startme.exe
O33 - MountPoints2\{ec4c2c5b-31a1-11e3-a38a-8a2832f57e22}\Shell - "" = AutoRun
O33 - MountPoints2\{ec4c2c5b-31a1-11e3-a38a-8a2832f57e22}\Shell\AutoRun\command - "" = E:\windows\Data\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2015.02.02 17:48:09 | 000,114,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2015.02.02 17:47:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2015.02.02 17:46:59 | 000,075,480 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamchameleon.sys
[2015.02.02 17:46:59 | 000,051,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mwac.sys
[2015.02.02 17:46:59 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2015.02.02 17:46:58 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2015.02.02 17:46:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015.02.02 17:37:42 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Jul\Desktop\otl.exe
[2015.02.02 17:18:29 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt
[2015.02.02 15:13:30 | 001,541,080 | ---- | C] (Cinema PlusV02.02) -- C:\Users\Jul\AppData\Roaming\NUB.exe
[2015.02.02 15:13:09 | 002,038,232 | ---- | C] (Cinema PlusV02.02) -- C:\Users\Jul\AppData\Roaming\MTSO.exe
[2015.02.02 15:13:06 | 000,000,000 | ---D | C] -- C:\Program Files\CinemaP-1.9cV02.02
[2015.02.02 15:12:27 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\ConvertAd
[2015.02.02 15:10:00 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\Pirates
[2015.02.02 15:09:50 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\Sparta
[2015.02.01 20:52:32 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\Macromedia
[2015.02.01 20:51:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
[2015.02.01 20:50:00 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Roaming\Sony Network Entertainment International LLC
[2015.02.01 20:49:12 | 000,000,000 | ---D | C] -- C:\Windows\ELAMBKUP
[2015.02.01 20:49:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2015.02.01 20:49:09 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
[2015.02.01 20:48:30 | 000,644,808 | ---- | C] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\klif.sys
[2015.02.01 20:48:30 | 000,112,136 | ---- | C] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\klflt.sys
[2015.02.01 20:48:30 | 000,034,400 | ---- | C] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\klhk.sys
[2015.02.01 20:35:13 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\Mozilla
[2015.02.01 19:54:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SecurityUtilityData
[2015.02.01 19:54:24 | 000,301,168 | ---- | C] (CartCrunch Israel Ltd.) -- C:\Windows\System32\ColorMedia.dll
[2015.02.01 19:54:17 | 000,000,000 | ---D | C] -- C:\ProgramData\SecurityUtility
[2015.02.01 19:54:03 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Roaming\SoftwareUpdater
[2015.02.01 19:54:03 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Roaming\Booster-Web
[2015.02.01 19:54:03 | 000,000,000 | ---D | C] -- C:\Program Files\Booster-Web
[2015.02.01 19:50:59 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\wincheck
[2015.02.01 19:49:00 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Roaming\moters
[2015.02.01 19:48:53 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Roaming\VOPackage
[2015.02.01 19:46:43 | 000,000,000 | ---D | C] -- C:\Program Files\StormWatch
[2015.02.01 19:46:35 | 000,000,000 | ---D | C] -- C:\Program Files\mbot_de_465
[2015.02.01 19:45:46 | 001,960,408 | ---- | C] (Cinema PlusV01.02) -- C:\Users\Jul\AppData\Roaming\OZTQSYNJ.exe
[2015.02.01 19:45:46 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\globalUpdate
[2015.02.01 19:45:46 | 000,000,000 | ---D | C] -- C:\Program Files\globalUpdate
[2015.02.01 19:44:37 | 000,323,720 | ---- | C] (Abengine) -- C:\Windows\System32\abengine.dll
[2015.02.01 19:44:34 | 000,000,000 | ---D | C] -- C:\Program Files\TabNav
[2015.01.28 18:37:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Red AdBlocker
[2015.01.24 17:57:29 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Roaming\LolClient
[2015.01.22 20:40:05 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2015.01.15 15:30:50 | 003,971,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2015.01.15 15:30:50 | 003,916,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2015.01.15 15:30:15 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWbPrxy.exe
[2015.01.13 22:55:00 | 000,000,000 | ---D | C] -- C:\Users\Jul\Documents\MuseScore
[2015.01.13 22:26:55 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Roaming\MusE
[2015.01.13 22:26:37 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\MusE
[2015.01.13 21:29:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MuseScore
[2015.01.13 21:29:18 | 000,000,000 | ---D | C] -- C:\Program Files\MuseScore
[2015.01.13 16:52:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2015.01.10 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Local\Programs
[2015.01.06 21:07:47 | 000,000,000 | ---D | C] -- C:\Users\Jul\AppData\Roaming\Awesomium
[2015.01.06 00:29:57 | 000,000,000 | ---D | C] -- C:\ProgramData\dmhgolipefccdonoakkendijofamdnae
[2015.01.05 20:30:07 | 000,000,000 | ---D | C] -- C:\ProgramData\BueesstSaveForYou
[2015.01.05 20:29:58 | 000,000,000 | ---D | C] -- C:\ProgramData\CoupExtenSion
[2015.01.04 21:05:09 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2014.10.21 13:42:32 | 046,860,733 | ---- | C] (Hi-Rez Studios) -- C:\Users\Jul\InstallHiRezGamesEnglish.exe
[2013.08.17 16:42:48 | 003,979,892 | ---- | C] (The GTK developer community) -- C:\Users\Jul\libgtk-win32-2.0-0.dll
[9 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2015.02.02 18:19:19 | 000,114,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2015.02.02 18:13:23 | 000,003,116 | ---- | M] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-1-6.job
[2015.02.02 18:00:20 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015.02.02 17:47:04 | 000,001,068 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015.02.02 17:37:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jul\Desktop\otl.exe
[2015.02.02 17:31:06 | 000,001,678 | ---- | M] () -- C:\Windows\tasks\OZTQSYNJ.job
[2015.02.02 17:20:08 | 000,000,011 | ---- | M] () -- C:\END
[2015.02.02 15:18:41 | 000,000,958 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2015.02.02 15:18:02 | 000,000,954 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2015.02.02 15:14:04 | 000,002,424 | ---- | M] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-5_user.job
[2015.02.02 15:14:03 | 000,002,424 | ---- | M] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-5.job
[2015.02.02 15:13:34 | 000,003,116 | ---- | M] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-1-7.job
[2015.02.02 15:13:32 | 000,001,324 | ---- | M] () -- C:\Windows\tasks\NUB.job
[2015.02.02 15:13:30 | 001,541,080 | ---- | M] (Cinema PlusV02.02) -- C:\Users\Jul\AppData\Roaming\NUB.exe
[2015.02.02 15:13:21 | 000,004,136 | ---- | M] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-4.job
[2015.02.02 15:13:15 | 000,005,162 | ---- | M] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-11.job
[2015.02.02 15:13:12 | 000,001,326 | ---- | M] () -- C:\Windows\tasks\MTSO.job
[2015.02.02 15:13:09 | 002,038,232 | ---- | M] (Cinema PlusV02.02) -- C:\Users\Jul\AppData\Roaming\MTSO.exe
[2015.02.02 14:11:09 | 000,025,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015.02.02 14:11:09 | 000,025,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015.02.02 14:02:37 | 000,000,013 | ---- | M] () -- C:\NET.INI
[2015.02.02 14:02:22 | 000,005,408 | ---- | M] () -- C:\Windows\System32\ColorMedia.ini
[2015.02.02 14:02:01 | 000,000,428 | -H-- | M] () -- C:\Windows\tasks\Upd Inst-S-1750791845.job
[2015.02.02 14:02:00 | 000,000,460 | -H-- | M] () -- C:\Windows\tasks\GS.Enabler-S-1824435291.job
[2015.02.02 14:02:00 | 000,000,428 | -H-- | M] () -- C:\Windows\tasks\WS_Enabler-S-815932687.job
[2015.02.02 14:01:59 | 000,000,472 | -H-- | M] () -- C:\Windows\tasks\SW-Booster-S-792098896.job
[2015.02.02 14:01:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015.02.02 14:01:00 | 3007,832,064 | -HS- | M] () -- C:\hiberfil.sys
[2015.02.02 12:37:52 | 000,644,808 | ---- | M] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\klif.sys
[2015.02.02 12:37:52 | 000,112,136 | ---- | M] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\klflt.sys
[2015.02.01 20:17:16 | 000,003,408 | ---- | M] () -- C:\bootsqm.dat
[2015.02.01 19:45:46 | 001,960,408 | ---- | M] (Cinema PlusV01.02) -- C:\Users\Jul\AppData\Roaming\OZTQSYNJ.exe
[2015.02.01 19:44:52 | 000,004,800 | ---- | M] () -- C:\Windows\System32\abengine.ini
[2015.02.01 19:44:52 | 000,002,704 | ---- | M] () -- C:\Windows\System32\abengineOff.ini
[2015.02.01 14:21:14 | 000,003,202 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2015.01.30 16:11:53 | 000,710,750 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2015.01.30 16:11:53 | 000,663,826 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2015.01.30 16:11:53 | 000,155,048 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2015.01.30 16:11:53 | 000,126,852 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2015.01.29 20:35:33 | 003,942,608 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2015.01.28 22:40:24 | 000,323,720 | ---- | M] (Abengine) -- C:\Windows\System32\abengine.dll
[2015.01.27 17:31:28 | 000,301,168 | ---- | M] (CartCrunch Israel Ltd.) -- C:\Windows\System32\ColorMedia.dll
[2015.01.25 17:12:14 | 000,002,086 | ---- | M] () -- C:\Users\Jul\AppData\Roaming\NUB
[2015.01.25 17:12:14 | 000,001,248 | ---- | M] () -- C:\Users\Jul\AppData\Roaming\OZTQSYNJ
[2015.01.25 17:12:14 | 000,001,248 | ---- | M] () -- C:\Users\Jul\AppData\Roaming\MTSO
[2015.01.24 23:59:21 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2015.01.24 23:59:20 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2015.01.06 04:36:02 | 000,249,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[9 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015.02.02 17:47:04 | 000,001,068 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015.02.02 15:14:04 | 000,002,424 | ---- | C] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-5_user.job
[2015.02.02 15:14:02 | 000,002,424 | ---- | C] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-5.job
[2015.02.02 15:13:35 | 000,003,116 | ---- | C] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-1-6.job
[2015.02.02 15:13:33 | 000,003,116 | ---- | C] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-1-7.job
[2015.02.02 15:13:31 | 000,001,324 | ---- | C] () -- C:\Windows\tasks\NUB.job
[2015.02.02 15:13:21 | 000,004,136 | ---- | C] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-4.job
[2015.02.02 15:13:13 | 000,005,162 | ---- | C] () -- C:\Windows\tasks\9c3a8fcc-3fa1-4b4c-8c76-a09d270328fb-11.job
[2015.02.02 15:13:11 | 000,001,326 | ---- | C] () -- C:\Windows\tasks\MTSO.job
[2015.02.01 20:35:06 | 000,001,125 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2015.02.01 20:17:16 | 000,003,408 | ---- | C] () -- C:\bootsqm.dat
[2015.02.01 19:54:30 | 000,005,408 | ---- | C] () -- C:\Windows\System32\ColorMedia.ini
[2015.02.01 19:45:48 | 000,000,958 | ---- | C] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2015.02.01 19:45:47 | 000,001,678 | ---- | C] () -- C:\Windows\tasks\OZTQSYNJ.job
[2015.02.01 19:45:47 | 000,000,954 | ---- | C] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2015.02.01 19:44:55 | 000,000,011 | ---- | C] () -- C:\END
[2015.02.01 19:44:47 | 000,004,800 | ---- | C] () -- C:\Windows\System32\abengine.ini
[2015.02.01 19:44:47 | 000,002,704 | ---- | C] () -- C:\Windows\System32\abengineOff.ini
[2015.01.25 17:12:14 | 000,002,086 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\NUB
[2015.01.25 17:12:14 | 000,001,248 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\OZTQSYNJ
[2015.01.25 17:12:14 | 000,001,248 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\MTSO
[2015.01.04 19:13:12 | 000,000,013 | ---- | C] () -- C:\NET.INI
[2014.12.29 20:17:44 | 003,810,012 | ---- | C] () -- C:\Users\Jul\PSX.psv
[2014.12.06 17:15:02 | 000,001,590 | ---- | C] () -- C:\Users\Jul\AppData\Local\recently-used.xbel
[2014.11.14 21:44:24 | 001,333,223 | ---- | C] () -- C:\Windows\unins000.exe
[2014.11.14 21:44:24 | 000,004,770 | ---- | C] () -- C:\Windows\unins000.dat
[2014.10.26 21:15:29 | 000,000,132 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2014.10.03 01:11:56 | 003,826,628 | ---- | C] () -- C:\Windows\System32\nvcoproc.bin
[2014.05.13 17:44:48 | 000,000,253 | ---- | C] () -- C:\Windows\System32\Setup.dll
[2014.05.13 17:15:21 | 000,921,600 | ---- | C] () -- C:\Windows\vorbisenc.dll
[2014.05.13 17:15:21 | 000,237,568 | ---- | C] () -- C:\Windows\OggDS.dll
[2014.05.13 17:15:21 | 000,188,416 | ---- | C] () -- C:\Windows\vorbis.dll
[2014.05.13 17:15:21 | 000,045,056 | ---- | C] () -- C:\Windows\ogg.dll
[2014.05.13 17:15:20 | 000,066,048 | ---- | C] () -- C:\Windows\MP4.dll
[2014.05.13 17:15:20 | 000,023,552 | ---- | C] () -- C:\Windows\mkunicode.dll
[2014.03.01 16:18:02 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2014.02.20 18:14:02 | 000,179,377 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2013.12.20 23:09:42 | 000,012,005 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\alsoft.ini
[2013.09.29 17:07:27 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2013.09.01 12:24:16 | 001,341,859 | ---- | C] () -- C:\Users\Jul\AppData\Local\Tempmusic.ogg
[2013.08.24 11:31:09 | 031,194,939 | ---- | C] () -- C:\Users\Jul\Direwolf20_Server.zip
[2013.08.17 15:48:52 | 002,346,942 | ---- | C] () -- C:\Users\Jul\TechnicLauncher.exe
[2013.08.05 07:15:08 | 000,066,104 | ---- | C] () -- C:\Windows\System32\bdmpegv.dll
[2013.08.05 07:15:06 | 000,023,080 | ---- | C] () -- C:\Windows\System32\bdmjpeg.dll
[2013.07.29 14:34:00 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\LAGARITH.DLL
[2013.04.07 13:15:40 | 000,272,292 | ---- | C] () -- C:\ProgramData\firstlsp.reg.dat
[2013.03.14 20:25:07 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2013.02.23 19:43:45 | 000,000,121 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\D2Info0
[2013.02.23 19:43:45 | 000,000,008 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\DofusAppId0_2
[2013.02.15 21:20:36 | 001,065,984 | ---- | C] () -- C:\Users\Jul\AppData\Local\file__0.localstorage
[2013.02.04 14:05:31 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2013.01.23 15:51:21 | 000,703,104 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\technic-launcher.jar
[2013.01.22 17:15:53 | 000,000,475 | ---- | C] () -- C:\Users\Jul\server.properties
[2013.01.21 13:51:49 | 000,011,418 | ---- | C] () -- C:\Users\Jul\ChunkFixer.jar
[2012.12.22 00:19:43 | 000,000,091 | ---- | C] () -- C:\Users\Jul\AppData\Local\fusioncache.dat
[2012.12.17 05:06:28 | 000,000,337 | ---- | C] () -- C:\Users\Jul\AppData\Local\Perfmon.PerfmonCfg
[2012.10.01 00:14:25 | 112,327,261 | ---- | C] () -- C:\Users\Jul\VTS_01_1.mp4
[2012.07.30 07:25:04 | 000,138,056 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\PnkBstrK.sys
[2012.07.05 23:36:16 | 000,006,144 | ---- | C] () -- C:\Users\Jul\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.12 17:34:08 | 000,003,202 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012.06.09 13:15:29 | 000,000,004 | ---- | C] () -- C:\Users\Jul\AppData\Roaming\steam_md5.dat
[2012.05.26 12:10:52 | 000,007,601 | ---- | C] () -- C:\Users\Jul\AppData\Local\Resmon.ResmonCfg
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.06.25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014.11.23 18:27:35 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\.minecraft
[2014.05.29 15:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\.technic
[2013.01.23 18:26:58 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\.techniclauncher
[2012.07.19 20:04:48 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Activision
[2012.09.29 19:17:58 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\AnvSoft
[2013.02.23 19:43:47 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\app
[2014.07.26 16:41:51 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Arrowhead
[2014.11.15 23:37:29 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Audacity
[2014.11.15 23:37:29 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\avidemux
[2013.04.06 23:14:08 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Avnex
[2015.01.06 21:07:47 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Awesomium
[2013.07.29 14:20:39 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\BabSolution
[2012.10.23 17:05:18 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Babylon
[2014.06.22 14:28:49 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\BANDISOFT
[2013.03.17 11:58:59 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\BigHugeEngine
[2015.01.30 21:25:51 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Bioshock
[2015.01.06 04:05:14 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\BitTorrent
[2013.03.16 16:17:08 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Blender Foundation
[2015.02.02 12:10:36 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Booster-Web
[2014.11.18 13:55:36 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\BrawlhallaAir
[2012.09.29 17:17:26 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Canneverbe Limited
[2014.04.05 18:52:06 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Craften Terminal
[2014.12.29 14:38:18 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Curse Client
[2012.06.09 09:06:49 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\DAEMON Tools Lite
[2012.05.22 14:05:34 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\dclogs
[2013.03.06 12:53:26 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\DisneyInteractiveStudios
[2013.02.23 20:09:20 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Dofus2
[2014.06.21 23:39:29 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\DVDVideoSoft
[2013.06.12 21:13:21 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Electronic Arts
[2013.03.01 12:38:39 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Fatshark
[2014.06.27 13:17:15 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\FEZ
[2014.08.18 16:41:26 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\FiestaOnline
[2013.11.01 23:23:05 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\fltk.org
[2013.08.17 12:43:20 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\ftblauncher
[2012.10.28 13:36:40 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\GetRightToGo
[2014.11.04 19:14:21 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Ice-Pick Lodge
[2012.10.28 13:38:49 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\ImTOO
[2014.10.01 15:09:46 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Injustice
[2013.10.10 15:33:07 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Internet-Manager
[2014.04.25 16:06:08 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\IsolatedStorage
[2013.07.17 12:46:56 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\JAM Software
[2014.08.15 18:25:21 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Kalypso Media
[2012.06.18 10:48:21 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Leadertech
[2012.09.11 16:01:51 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\LEGO Company
[2014.12.07 00:07:14 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\library_dir
[2013.01.23 18:26:50 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\logs
[2015.01.24 17:57:29 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\LolClient
[2012.11.10 20:32:14 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\LucasArts
[2012.06.17 21:35:46 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\m2-multiplayer.com
[2014.10.25 21:35:59 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\MAXON
[2014.11.15 23:37:29 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien
[2014.11.15 23:37:29 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
[2014.04.25 16:40:02 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\MilkShape 3D 1.x.x
[2014.10.20 17:22:29 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Minecraft Skin Viewer
[2014.10.15 17:10:47 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\MMFApplications
[2015.02.01 19:49:00 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\moters
[2013.01.08 20:08:15 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Mount&Blade
[2013.01.13 15:28:00 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Mount&Blade Warband
[2014.10.05 15:01:11 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\mp3DirectCut
[2015.01.13 22:26:55 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\MusE
[2013.08.15 20:37:27 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\NCSOFT
[2014.06.26 15:25:21 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Nidhogg
[2012.07.20 19:03:31 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Notepad++
[2014.11.04 14:54:08 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\olliolli
[2013.02.08 21:09:12 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Omerta Demo
[2012.09.25 15:46:50 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\OnLive App
[2012.05.07 17:43:07 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\OpenOffice.org
[2012.07.04 21:46:56 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Opera
[2014.12.07 00:25:31 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Origin
[2013.01.27 15:58:37 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Petroglyph
[2012.07.20 16:39:41 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\ProtectDISC
[2013.07.15 14:27:20 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\PunkBuster
[2015.02.02 17:56:36 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Raptr
[2013.06.19 19:26:51 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\runic games
[2012.09.29 12:01:55 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\S.A.D
[2014.11.15 23:39:53 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Screaming Bee
[2012.12.25 01:16:43 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\SEE
[2014.04.25 16:49:17 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\SketchUp
[2015.02.01 19:55:35 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\SoftwareUpdater
[2014.03.19 21:53:57 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Sony
[2015.02.01 20:50:00 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Sony Network Entertainment International LLC
[2014.11.15 23:37:28 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\SpaceEngineers
[2015.02.02 19:15:48 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Spotify
[2015.01.16 07:31:24 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\streamWriter
[2014.11.15 23:39:53 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Subversion
[2015.01.25 15:40:09 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Synthesia
[2013.06.19 23:19:35 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\TeamViewer
[2013.03.15 22:00:32 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\TechSmith
[2013.04.23 16:42:21 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\TERA
[2014.09.26 22:31:31 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\The Creative Assembly
[2014.05.23 16:22:44 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Thunderbird
[2014.11.15 23:37:28 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Tropico 4 Demo
[2015.02.01 16:11:21 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\TS3Client
[2012.05.27 09:39:42 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\TuneUp Software
[2014.11.18 20:59:24 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Tunngle
[2013.03.23 14:52:47 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Ubisoft
[2012.12.20 23:06:50 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Unity
[2014.11.04 21:44:19 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Vertical_Drop_Heroes_HD
[2015.02.02 17:15:03 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\VOPackage
[2014.04.07 16:47:01 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\Warner Bros. Interactive Entertainment
[2012.10.25 18:39:15 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\WB Games
[2012.07.06 01:20:08 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\WebApp
[2014.02.05 19:50:01 | 000,000,000 | ---D | M] -- C:\Users\Jul\AppData\Roaming\WizardWars
[2012.06.13 20:01:55 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\DAEMON Tools Lite
[2014.11.15 23:39:52 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\DVDVideoSoft
[2012.05.27 14:13:33 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.05.27 10:43:48 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Opera
[2012.05.27 14:16:56 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\PunkBuster
[2012.06.13 18:37:28 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Tunngle
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:EBAA0CD9
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:FB1B13D8
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:373E1720
< End of report > |