Fixlog von Otl :
All processes killed
========== OTL ==========
C:\Windows\System32\UpdSvc.dll moved successfully.
========== FILES ==========
C:\Users\power\AppData\LocalLow\StumbleUpon\IE folder moved successfully.
C:\Users\power\AppData\LocalLow\StumbleUpon\CHROME folder moved successfully.
C:\Users\power\AppData\LocalLow\StumbleUpon folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Joosoft.com\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\\Update-Service-Installer-Service deleted successfully.
Registry key HKEY_CURRENT_USER\Software\AppDataLow\Software\StumbleUpon\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Software\StumbleUpon\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\StumbleUpon\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\StumbleUpon.DLL\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\StumbleUpon.QTimeCpio\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\StumbleUpon.QTimeCpio.1\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\pgifblbjgdjhcelbanblbhkhmbnnmhfg\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgifblbjgdjhcelbanblbhkhmbnnmhfg\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\StumbleUponUpdater\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3662886436-2550715429-2728409154-1000\Software\AppDataLow\Software\StumbleUpon\ not found.
Registry key HKEY_USERS\S-1-5-21-3662886436-2550715429-2728409154-1000\Software\StumbleUpon\ not found.
Registry key HKEY_USERS\S-1-5-21-3662886436-2550715429-2728409154-1000\Software\Software\StumbleUpon\ not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: power
->Temp folder emptied: 882435 bytes
->Temporary Internet Files folder emptied: 43434739 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 492 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3500 bytes
RecycleBin emptied: 1167788 bytes
Total Files Cleaned = 43,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 04202013_161112
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot... Log von MBAM:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
Malwarebytes : Free anti-malware download
Datenbank Version: v2013.04.20.05
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
power :: POWER-PC [Administrator]
Schutz: Aktiviert
20.04.2013 16:25:42
mbam-log-2013-04-20 (16-25-42).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 204374
Laufzeit: 13 Minute(n), 47 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 1
HKCU\SOFTWARE\CYBER (Backdoor.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 1
HKCU\Software\Cyber|FirstExecution (Backdoor.Trace) -> Daten: 04/12/2012 -- 15:33 -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
C:\Users\power\AppData\Roaming\Facebook Account Hacker v.5.2.exe (Spyware.Password) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) Log von ESET
C:\Program Files\Ultimate Facebook Hacker\ufacebookhacker_v351.exe MSIL/Hoax.FakeHack.B application
C:\Users\power\Virus\Wallhack\EnhancedAim Cracked CS1.6\EnhancedAim_CS1.6.dll a variant of Win32/Kryptik.AY trojan
D:\POWER-PC\Backup Set 2013-03-01 141938\Backup Files 2013-04-02 020610\Backup files 1.zip a variant of Java/Exploit.Agent.NPJ trojan Log von OtlOTL Logfile: Code:
OTL logfile created on: 20.04.2013 20:38:33 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\power\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 50,97% Memory free
3,98 Gb Paging File | 2,87 Gb Available in Paging File | 72,05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 100,00 Gb Total Space | 65,19 Gb Free Space | 65,19% Space Free | Partition Type: NTFS
Drive D: | 117,87 Gb Total Space | 66,19 Gb Free Space | 56,16% Space Free | Partition Type: NTFS
Drive E: | 14,92 Gb Total Space | 7,44 Gb Free Space | 49,84% Space Free | Partition Type: FAT32
Computer Name: POWER-PC | User Name: power | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.04.19 22:47:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\power\Desktop\OTL.exe
PRC - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013.04.04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013.03.29 20:39:17 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2013.03.29 20:38:47 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2013.03.29 20:38:42 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.03.29 20:38:41 | 000,345,312 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.03.13 22:00:44 | 000,706,776 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe
PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012.09.19 12:29:44 | 001,869,152 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
PRC - [2012.09.19 12:29:42 | 001,699,168 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
PRC - [2012.06.11 17:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
PRC - [2011.11.20 08:37:00 | 001,204,224 | ---- | M] (IslamicFinder: Accurate Prayer Times, Athan (Azan), Mosques (Masjids), Islamic Center, Muslim Owned Businesses, Hijri Calendar, Islamic Directory worldwide.) -- C:\Program Files\Athan\Athan.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011.02.15 18:01:48 | 000,019,968 | ---- | M] (Fork Ltd.) -- C:\Prey\platform\windows\cronsvc.exe
PRC - [2010.10.28 10:10:40 | 000,189,776 | ---- | M] (DATA BECKER GmbH & Co KG) -- C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe
========== Modules (No Company Name) ==========
MOD - [2012.02.17 20:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll
MOD - [2010.03.08 22:08:28 | 000,282,697 | ---- | M] () -- C:\Program Files\Athan\vbp.dll
MOD - [2004.12.25 13:37:22 | 000,258,121 | ---- | M] () -- C:\Program Files\Athan\vbh.dll
MOD - [2004.03.20 14:49:40 | 000,229,444 | ---- | M] () -- C:\Program Files\Athan\vbq.dll
========== Services (SafeList) ==========
SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013.03.29 20:39:17 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013.03.29 20:38:42 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013.03.13 22:00:46 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.09.19 12:29:42 | 001,699,168 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.09.19 12:29:40 | 000,029,536 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2012.06.11 17:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe -- (BBUpdate)
SRV - [2012.06.11 17:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe -- (BBSvc)
SRV - [2012.05.26 23:56:01 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.11.29 21:04:56 | 000,013,592 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2011.02.15 18:01:48 | 000,019,968 | ---- | M] (Fork Ltd.) [Auto | Running] -- C:\Prey\platform\windows\cronsvc.exe -- (CronService)
SRV - [2010.10.28 10:10:40 | 000,189,776 | ---- | M] (DATA BECKER GmbH & Co KG) [Auto | Running] -- C:\Program Files\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\L1C62x86.sys -- (L1C)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt -- (EverestDriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\power\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwrchid.sys -- (btwrchid)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwl2cap.sys -- (btwl2cap)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwavdt.sys -- (btwavdt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwaudio.sys -- (btwaudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwampfl.sys -- (btwampfl)
DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013.03.29 20:39:28 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2013.03.29 20:39:28 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2013.03.29 20:39:28 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2013.01.31 11:50:58 | 000,022,656 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcaudrv.sys -- (mcaudrv_simple)
DRV - [2012.11.15 03:36:52 | 000,035,592 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss6.sys -- (taphss6)
DRV - [2012.11.09 08:51:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2012.10.11 05:08:10 | 000,034,432 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcvidrv.sys -- (ManyCam)
DRV - [2012.09.19 11:50:50 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2011.12.15 21:29:42 | 000,026,624 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2011.06.27 01:37:12 | 002,191,872 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2011.02.14 02:42:36 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2011.02.14 02:42:34 | 000,025,216 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2011.02.14 02:42:32 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.05.12 03:23:04 | 000,016,896 | ---- | M] (Danish Wireless Design A/S) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\FlashUSB.sys -- (FlashUSB)
DRV - [2010.03.31 03:40:20 | 000,011,520 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsUpIO.sys -- (AsUpIO)
DRV - [2010.02.24 12:22:10 | 000,185,472 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2009.07.20 11:29:40 | 000,013,880 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\..\URLSearchHook: - No CLSID value found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = https://www.google.de/
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\power\Desktop
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Google [binary data]
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\..\SearchScopes,Backup.Old.DefaultScope = {22644C40-4FC2-4E7A-BDAD-71EA5ED16FC5}
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
[2012.11.16 22:52:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
O1 HOSTS File: ([2013.04.19 22:33:17 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [Athan] C:\Program Files\Athan\Athan.exe (IslamicFinder: Accurate Prayer Times, Athan (Azan), Mosques (Masjids), Islamic Center, Muslim Owned Businesses, Hijri Calendar, Islamic Directory worldwide.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3662886436-2550715429-2728409154-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{944B51EF-99A8-45A3-B485-B1EF1EE4B67A}: DhcpNameServer = 192.168.178.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.04.20 18:26:04 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013.04.20 16:46:03 | 002,347,384 | ---- | C] (ESET) -- C:\Users\power\Desktop\esetsmartinstaller_enu.exe
[2013.04.20 16:22:09 | 000,000,000 | ---D | C] -- C:\Users\power\AppData\Roaming\Malwarebytes
[2013.04.20 16:21:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.04.20 16:21:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.04.20 16:21:43 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2013.04.20 16:21:42 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.04.20 16:21:31 | 000,000,000 | ---D | C] -- C:\Users\power\AppData\Local\Programs
[2013.04.20 14:22:35 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.04.20 12:44:05 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.04.20 10:29:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2013.04.20 10:29:23 | 000,000,000 | --SD | C] -- C:\ComboFix
[2013.04.19 23:46:46 | 000,000,000 | ---D | C] -- C:\Users\power\18.01.2013
[2013.04.19 22:47:27 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\power\Desktop\OTL.exe
[2013.04.19 22:37:44 | 000,000,000 | ---D | C] -- C:\windows\temp
[2013.04.19 22:13:59 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2013.04.19 22:13:59 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2013.04.19 22:13:40 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.04.19 22:13:06 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2013.04.18 15:05:43 | 000,000,000 | ---D | C] -- C:\Users\power\AppData\Local\TubeBox
[2013.04.18 15:04:12 | 000,000,000 | ---D | C] -- C:\Users\power\Documents\TubeBox
[2013.04.18 15:03:04 | 000,000,000 | ---D | C] -- C:\Program Files\SoftwareUpdater
[2013.04.12 16:27:03 | 000,000,000 | ---D | C] -- C:\Users\power\GTA
[2013.04.12 06:31:52 | 000,000,000 | ---D | C] -- C:\Users\power\Desktop\Bilder
[2013.04.12 06:31:19 | 000,000,000 | ---D | C] -- C:\Users\power\Musik
[2013.04.07 00:28:23 | 000,000,000 | ---D | C] -- C:\Users\power\AppData\Local\CXSoftware
[2013.04.07 00:09:37 | 000,000,000 | ---D | C] -- C:\Users\power\Neuer Ordner
[2013.04.06 22:02:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain
[2013.04.05 17:44:47 | 000,000,000 | ---D | C] -- C:\GM750
[2013.04.05 17:00:42 | 000,000,000 | ---D | C] -- C:\GS290
[2013.04.05 16:45:53 | 000,016,896 | ---- | C] (Danish Wireless Design A/S) -- C:\windows\System32\drivers\FlashUSB.sys
[2013.04.05 16:45:53 | 000,000,000 | ---D | C] -- C:\ifx
[2013.04.05 16:35:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LGMobile Support Tool
[2013.04.05 16:34:52 | 000,000,000 | ---D | C] -- C:\ProgramData\LGMOBILEAX
[2013.04.05 16:25:11 | 000,000,000 | ---D | C] -- C:\Users\power\AppData\Roaming\XMedia Recode
[2013.04.05 16:23:10 | 000,000,000 | ---D | C] -- C:\Program Files\LG Electronics
[2013.04.05 16:15:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XMedia Recode
[2013.04.05 16:15:39 | 000,000,000 | ---D | C] -- C:\Program Files\XMedia Recode
[2013.03.25 18:58:13 | 000,000,000 | ---D | C] -- C:\videooutput
[2013.03.25 18:54:10 | 000,000,000 | ---D | C] -- C:\Users\power\AppData\Roaming\vlc
========== Files - Modified Within 30 Days ==========
[2013.04.20 20:44:45 | 000,000,029 | ---- | M] () -- C:\windows\System32\TempWmicBatchFile.bat
[2013.04.20 20:40:14 | 000,001,096 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.04.20 20:26:47 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013.04.20 20:00:01 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013.04.20 18:31:55 | 007,063,150 | ---- | M] () -- C:\windows\System32\perfh007.dat
[2013.04.20 18:31:55 | 002,209,142 | ---- | M] () -- C:\windows\System32\perfc007.dat
[2013.04.20 18:31:55 | 000,335,858 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2013.04.20 18:31:55 | 000,052,274 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2013.04.20 16:50:36 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.20 16:50:36 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.20 16:46:45 | 000,065,536 | ---- | M] () -- C:\windows\System32\Ikeext.etl
[2013.04.20 16:46:25 | 002,347,384 | ---- | M] (ESET) -- C:\Users\power\Desktop\esetsmartinstaller_enu.exe
[2013.04.20 16:43:01 | 000,001,092 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.04.19 22:47:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\power\Desktop\OTL.exe
[2013.04.19 22:33:17 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2013.04.19 06:44:10 | 000,265,936 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2013.04.16 18:34:58 | 000,007,878 | ---- | M] () -- C:\Users\power\Documents\tabelle.ods
[2013.04.05 17:57:36 | 000,002,413 | ---- | M] () -- C:\windows\System32\lgAxconfig.ini
[2013.04.05 14:48:32 | 000,009,130 | ---- | M] () -- C:\Users\power\Documents\Untitled 1.odt
[2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2013.03.29 20:39:28 | 000,135,136 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avipbb.sys
[2013.03.29 20:39:28 | 000,084,744 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avgntflt.sys
[2013.03.29 20:39:28 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\System32\drivers\avkmgr.sys
========== Files Created - No Company Name ==========
[2013.04.20 16:46:45 | 000,065,536 | ---- | C] () -- C:\windows\System32\Ikeext.etl
[2013.04.19 22:13:59 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2013.04.19 22:13:59 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2013.04.19 22:13:59 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2013.04.19 22:13:59 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2013.04.19 22:13:59 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2013.04.16 18:34:56 | 000,007,878 | ---- | C] () -- C:\Users\power\Documents\tabelle.ods
[2013.04.05 16:35:23 | 000,053,248 | ---- | C] () -- C:\windows\System32\CommonDL.dll
[2013.04.05 16:35:23 | 000,002,413 | ---- | C] () -- C:\windows\System32\lgAxconfig.ini
[2013.04.05 14:48:31 | 000,009,130 | ---- | C] () -- C:\Users\power\Documents\Untitled 1.odt
[2013.03.18 05:43:24 | 000,265,936 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2012.12.16 21:43:38 | 000,293,889 | ---- | C] () -- C:\windows\System32\drivers\RTAIODAT.DAT
[2012.06.11 08:15:54 | 000,017,408 | ---- | C] () -- C:\Users\power\AppData\Local\WebpageIcons.db
[2012.04.25 16:33:54 | 000,650,752 | ---- | C] () -- C:\windows\System32\xvidcore.dll
[2012.04.25 16:33:54 | 000,243,200 | ---- | C] () -- C:\windows\System32\xvidvfw.dll
[2012.01.22 02:44:08 | 000,007,610 | ---- | C] () -- C:\Users\power\AppData\Local\Resmon.ResmonCfg
[2012.01.11 17:12:33 | 000,098,304 | ---- | C] () -- C:\windows\System32\redmonnt.dll
[2011.09.10 12:16:36 | 000,010,240 | ---- | C] () -- C:\Users\power\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.08.24 20:28:17 | 000,005,576 | ---- | C] () -- C:\windows\Language.ini
[2011.08.24 20:25:47 | 000,000,520 | ---- | C] () -- C:\windows\System32\drivers\RTEQEX0.dat
[2011.08.24 20:25:03 | 000,004,692 | ---- | C] () -- C:\windows\System32\drivers\SamSfPa.dat
[2011.08.24 20:25:03 | 000,000,008 | ---- | C] () -- C:\windows\System32\drivers\rtkhdaud.dat
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011.02.10 07:52:06 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\ASUS WebStorage
[2011.02.10 07:33:04 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\E-Cam
[2011.02.10 07:52:06 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\ASUS WebStorage
[2011.02.10 07:33:04 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\E-Cam
[2013.02.22 17:55:22 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\.minecraft
[2013.02.16 17:18:40 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\Acronis
[2011.02.10 07:52:06 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\ASUS WebStorage
[2013.03.18 05:38:27 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\Azureus
[2013.02.08 17:43:16 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\DVDVideoSoft
[2012.01.09 12:51:04 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\E-Cam
[2012.12.16 19:18:09 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\Easeware
[2012.09.13 14:48:26 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\ExpressFiles
[2012.12.17 21:51:54 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\FreeHideIP
[2013.04.18 16:27:49 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\ICQ
[2012.12.04 20:19:42 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\install
[2012.12.18 15:36:14 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\JonDo
[2013.03.18 02:52:46 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\ManyCam
[2011.09.11 19:39:57 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\OpenOffice.org
[2013.04.18 16:28:57 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\PhotoScape
[2012.11.12 17:53:17 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\ProtectDisc
[2012.11.16 21:50:50 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\RGE
[2012.06.12 22:01:22 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\Solveig Multimedia
[2012.01.22 19:56:01 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\Systweak
[2012.11.03 21:19:02 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\TuneUp Software
[2012.09.13 21:52:35 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\Ubam
[2011.11.10 17:12:43 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\Windows Live Writer
[2013.04.05 16:25:11 | 000,000,000 | ---D | M] -- C:\Users\power\AppData\Roaming\XMedia Recode
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012.05.18 16:25:48 | 000,000,059 | ---- | M] ()(C:\windows\System32\??) -- C:\windows\System32\dž
[2012.05.18 16:25:48 | 000,000,059 | ---- | C] ()(C:\windows\System32\??) -- C:\windows\System32\dž
< End of report > --- --- --- |