Alles klar, hier der Log    Code:  
 Zoek.exe Version 4.0.0.2 Updated 22-June-2013 
Tool run by Nico on 24.06.2013 at  0:22:09,06. 
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x64 
Running in: Normal Mode Internet Access Detected   
==== Reset Hosts File ======================   
# Copyright (c) 1993-2006 Microsoft Corp.  
#  
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.  
#  
# This file contains the mappings of IP addresses to host names. Each  
# entry should be kept on an individual line. The IP address should  
# be placed in the first column followed by the corresponding host name.  
# The IP address and the host name should be separated by at least one  
# space.  
#  
# Additionally, comments (such as these) may be inserted on individual  
# lines or following the machine name denoted by a '#' symbol.  
#  
# For example:  
#  
#      102.54.94.97     rhino.acme.com          # source server  
#       38.25.63.10     x.acme.com              # x client host  
  
# localhost name resolution is handle within DNS itself.  
127.0.0.1       localhost  
::1             localhost    
==== Deleting CLSID Registry Keys ======================     
==== Deleting CLSID Registry Values ======================     
==== FireFox Fix ======================   
Deleted from C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\quo0cvwf.default\prefs.js: 
user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=hp&installDate=01/01/1970"); 
user_pref("browser.newtab.url", "about:blank"); 
user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=ds&installDate=01/01/1970&q=");   
Added to C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\quo0cvwf.default\prefs.js: 
user_pref("browser.startup.homepage", "hxxp://www.google.com"); 
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); 
user_pref("browser.newtab.url", "hxxp://www.google.com/"); 
user_pref("browser.search.defaultengine", "Google"); 
user_pref("browser.search.defaultenginename", "Google"); 
user_pref("browser.search.selectedEngine", "Google"); 
user_pref("browser.search.order.1", "Google"); 
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); 
user_pref("browser.search.suggest.enabled", true); 
user_pref("browser.search.useDBForOrder", true);   
ProfilePath: C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\quo0cvwf.default   
user.js not found 
---- Lines snapdo removed from prefs.js ----     
---- Lines snapdo modified from prefs.js ----     
---- FireFox user.js and prefs.js backups ----    
prefs__0025_.backup   
==== Deleting Files \ Folders ======================   
"C:\Program Files (x86)\Common Files\DVDVideoSoft\bin" deleted 
"C:\Windows\SysWow64\searchplugins" deleted 
"C:\Windows\SysWow64\Extensions" deleted   
==== Firefox Extensions ======================   
ProfilePath: C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\quo0cvwf.default 
- Telekom YouTube Turbo - %ProfilePath%\extensions\info@maltegoetz.de.xpi 
- Magic Actions for YouTube - %ProfilePath%\extensions\jid0-UVAeBCfd34Kk5usS8A1CBiobvM8@jetpack.xpi 
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi   
==== Firefox Plugins ======================   
Profilepath: C:\Users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\quo0cvwf.default 
3D76B5C0E02ECC19C1F5756E8FD97F72        - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll -        Shockwave Flash 
ADC539F67D3198679F480974EE203678        - C:\Windows\SysWOW64\npDeployJava1.dll -        Java Deployment Toolkit 7.0.210.11 
15E298B5EC5B89C5994A59863969D9FF        - C:\Windows\SysWOW64\npmproxy.dll -        Microsoft® Windows® Operating System     
==== Chrome Look ======================   
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions 
dchlnpcodkpfdpacogkljefecpegganj - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx[25.10.2012 12:44] 
hakdifolhalapjijoafobooafbilfakh - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx[25.10.2012 12:44] 
hghkgaeecgjhjkannahfamoehjmkjail - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx[25.10.2012 12:44] 
jagncdcchgajhfhijbbhecadmaiegcmh - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx[28.04.2013 14:28] 
pjldcfjmnllhmgjclecdnfampinooman - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx[25.10.2012 12:44]   
Facebook Disconnect - Nico - Default\Extensions\ejpepffjfmamnambagiibghpglaidiec 
ProxMate - Improve your Internet - Nico - Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm 
Auto Replay for YouTube - Nico - Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb 
Turbo for YouTube - Nico - Default\Extensions\lhgnmngkgolhffjjdaipkkjbmbnpefef 
Twitch Now - Nico - Default\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk   
==== Chrome Fix ======================   
C:\Users\Nico\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ableton-live.softonic.de_0.localstorage-journal deleted successfully   
==== Set IE to Default ======================   
Old Values: 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] 
"Search Page"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=ds&q={searchTerms}&installDate=01/01/1970" 
"Search Bar"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=ds&q={searchTerms}&installDate=01/01/1970" 
"Use Search Asst"="yes" 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] 
"Default"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=ds&q={searchTerms}&installDate=01/01/1970" 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] 
"Default"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=ds&q={searchTerms}&installDate=01/01/1970" 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] 
"Default"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=ds&q={searchTerms}&installDate=01/01/1970" 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] 
"Default_Search_URL"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=ds&q={searchTerms}&installDate=01/01/1970" 
"SearchAssistant"="hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=5958e550-4886-4cff-88be-39c48297ee73&searchtype=ds&q={searchTerms}&installDate=01/01/1970" 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] 
No DefaultScope Set For HKCU   
New Values: 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] 
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" 
"Use Search Asst"="no" 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] 
"(Default)"="hxxp://search.msn.com/results.asp?q=%s" 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] 
"(Default)"="hxxp://search.msn.com/results.asp?q=%s" 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] 
"(Default)"="hxxp://search.msn.com/results.asp?q=%s" 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] 
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" 
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] 
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"   
==== All HKCU SearchScopes ======================   
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes 
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH" 
{23D660C7-1774-4a7e-9A0E-F51FB25A8A3B} Yahoo  Url="hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV" 
{483830EE-A4CD-4b71-B0A3-3D82E62A6909} Unknown  Url="Not_Found" 
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" 
{9BAAF3E3-64CB-4796-B1E7-4FED8532A5CA} Google  Url="hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms}"   
==== Reset Google Chrome ======================   
C:\users\Nico\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully 
C:\users\Nico\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully   
==== Deleting CLSID Registry Keys ======================   
HKEY_USERS\S-1-5-21-3337975632-725608183-240556253-1000\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} deleted successfully   
==== Deleting CLSID Registry Values ======================     
==== shortcuts on Users Desktops ======================   
C:\Users\Nico\Desktop\Audacity.lnk - C:\Program Files (x86)\Audacity\audacity.exe  
C:\Users\Nico\Desktop\Free Audio Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free Audio Converter\FreeAudioConverter.exe  
C:\Users\Nico\Desktop\Free YouTube Download.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe  
C:\Users\Nico\Desktop\Metro Last Light.lnk - C:\Program Files (x86)\Metro Last Light\MetroLL.exe    
==== shortcuts on All Users Desktop ======================   
C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe  
C:\Users\Public\Desktop\DAEMON Tools Lite.lnk - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe  
C:\Users\Public\Desktop\DS3 Tool.lnk - C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe  
C:\Users\Public\Desktop\FL Studio 11.lnk - C:\Program Files (x86)\Image-Line\FL Studio 11\FL.exe  
C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe  
C:\Users\Public\Desktop\Game Booster 3.lnk - C:\Program Files (x86)\IObit\Game Booster 3\GameBooster.exe  
C:\Users\Public\Desktop\GAME CENTER.lnk - C:\Program Files (x86)\OXXOGames\GPlayer\GPlayer.exe  
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  
C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\starter_avp.exe  
C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe  
C:\Users\Public\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe  
C:\Users\Public\Desktop\Switch to Gaming Mode.lnk - C:\Program Files (x86)\IObit\Game Booster 3\GameBooster.exe -game 
C:\Users\Public\Desktop\World of Warcraft.lnk - C:\Program Files (x86)\World of Warcraft\World of Warcraft Launcher.exe    
==== shortcuts in Users Start Menu ======================   
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Social Games.lnk -   
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe  -extoff 
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\IL Download Manager.lnk - C:\Program Files (x86)\Image-Line\Downloader\ILDownloadManager.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\More....lnk - C:\Program Files (x86)\Image-Line\Shared\Start  
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Benutzerhandbuch für die Konsolenversion von RAR.lnk -   
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Hilfe zu WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm  
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe    
==== shortcuts in All Users Start Menu ======================   
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metro Last Light.lnk - C:\Program Files (x86)\Metro Last Light\MetroLL.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk - C:\Program Files\CCleaner\uninst.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DTGadget.lnk - C:\Program Files (x86)\DAEMON Tools Lite\DT.gadget  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk - C:\Program Files (x86)\DAEMON Tools Lite\SPTDinst-x64.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT\DEUTSCHLAND SPIELT ONLINE.lnk -   
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT\GAME CENTER.lnk - C:\Program Files (x86)\OXXOGames\GPlayer\GPlayer.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT\Spiele\Ritter Arthur II - Collectors Edition.lnk - C:\Program Files (x86)\DEUTSCHLAND SPIELT\RitterArthur2CollectorsEditionCD\RitterArthur2CollectorsEdition_og.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT\Spiele\Ritter Arthur III.lnk - C:\Program Files (x86)\DEUTSCHLAND SPIELT\RitterArthur3CD\RitterArthur3_og.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT\Spiele\Ritter Arthur.lnk - C:\Program Files (x86)\DEUTSCHLAND SPIELT\RitterArthurCD\RitterArthur_og.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Free Studio Manager.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\FreeStudioManager.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Log Report.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\DVSSysReport.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Rocket Subscription.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\SubscriptionOffer.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Uninstall.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\Uninstall.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free YouTube Download.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Benutzerhandbuch für die Konsolenversion von RAR.lnk -   
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Hilfe zu WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe    
==== shortcuts in Quick Launch ======================   
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -   
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -   
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -   
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -   
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -   
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -   
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\League of Legends spielen .lnk - C:\Program Files (x86)\Riot Games\League of Legends\lol.launcher.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\mIRC.lnk - C:\Program Files (x86)\mIRC\mirc.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\OpenOffice.org 3.4.1.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamSpeak 3 Client.lnk - C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe  
C:\Users\Nico\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 
C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -   
C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -     
==== Silent Runners ======================   
"Silent Runners.vbs", revision 69.2, hxxp://www.silentrunners.org/ 
Output limited to non-default values, except where indicated by "{++}"     
Startup items buried in registry: 
---------------------------------   
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} 
Sidebar = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [MS] 
DAEMON Tools Lite = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [Disc Soft Ltd]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} 
RtHDVCpl = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [Realtek Semiconductor] 
IgfxTray = C:\Windows\system32\igfxtray.exe [Intel Corporation] 
HotKeysCmds = C:\Windows\system32\hkcmd.exe [Intel Corporation] 
Persistence = C:\Windows\system32\igfxpers.exe [Intel Corporation]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ {++} 
RPMKickstart = C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [Gigabyte Technology CO., LTD.]   
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ {++} 
UpdReg = C:\Windows\UpdReg.EXE [Creative Technology Ltd.] 
Sound Blaster Z-Series Control Panel = "C:\Program Files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe" /r [null data] 
AVP = "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [Kaspersky Lab ZAO] 
IAStorIcon = C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [null data] 
STCAgent = "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [file not found] 
ZyngaGamesAgent = "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [file not found]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\   
{45d30484-7ded-43d9-957a-d2fd1f046511}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = GBHO.BHO 
                   \InProcServer32\(Default) = mscoree.dll [MS]   
{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}\(Default) = ContentBlockerBrowserHelperObject 
  -> {HKLM...CLSID} = Content Blocker Plugin 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = Content Blocker Plugin 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [Kaspersky Lab ZAO]   
{73455575-E40C-433C-9784-C78DC7761455}\(Default) = VirtualKeyboardBrowserHelperObject 
  -> {HKLM...CLSID} = Virtual Keyboard Plugin 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = Virtual Keyboard Plugin 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [Kaspersky Lab ZAO]   
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = Java(tm) Plug-In SSV Helper 
                   \InProcServer32\(Default) = C:\Program Files\Java\jre7\bin\ssv.dll [Oracle Corporation] 
  -> {HKLM...Wow...CLSID} = Java(tm) Plug-In SSV Helper 
                         \InProcServer32\(Default) =  [file not found]   
{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = Windows Live ID Sign-in Helper 
                   \InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [MS] 
  -> {HKLM...Wow...CLSID} = Windows Live ID Sign-in Helper 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [MS]   
{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}\(Default) = Safe Money Plugin 
  -> {HKLM...CLSID} = Safe Money Plugin 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = Safe Money Plugin 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [Kaspersky Lab ZAO]   
{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = Java(tm) Plug-In 2 SSV Helper 
                   \InProcServer32\(Default) = C:\Program Files\Java\jre7\bin\jp2ssv.dll [Oracle Corporation] 
  -> {HKLM...Wow...CLSID} = Java(tm) Plug-In 2 SSV Helper 
                         \InProcServer32\(Default) =  [file not found]   
{E33CF602-D945-461A-83F0-819F76A199F8}\(Default) = link filter bho 
  -> {HKLM...CLSID} = URL Advisor Plugin 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = URL Advisor Plugin 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [Kaspersky Lab ZAO]   
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\   
{0347C33E-8762-4905-BF09-768834316C61}\(Default) = HP Print Enhancer 
  -> {HKLM...Wow...CLSID} = HP Print Enhancer 
                         \InProcServer32\(Default) = C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [Hewlett-Packard Co.]   
{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}\(Default) = ContentBlockerBrowserHelperObject 
  -> {HKLM...CLSID} = Content Blocker Plugin 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = Content Blocker Plugin 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [Kaspersky Lab ZAO]   
{73455575-E40C-433C-9784-C78DC7761455}\(Default) = VirtualKeyboardBrowserHelperObject 
  -> {HKLM...CLSID} = Virtual Keyboard Plugin 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = Virtual Keyboard Plugin 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [Kaspersky Lab ZAO]   
{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = Windows Live ID Sign-in Helper 
                   \InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [MS] 
  -> {HKLM...Wow...CLSID} = Windows Live ID Sign-in Helper 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [MS]   
{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}\(Default) = Safe Money Plugin 
  -> {HKLM...CLSID} = Safe Money Plugin 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = Safe Money Plugin 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [Kaspersky Lab ZAO]   
{E33CF602-D945-461A-83F0-819F76A199F8}\(Default) = link filter bho 
  -> {HKLM...CLSID} = URL Advisor Plugin 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = URL Advisor Plugin 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [Kaspersky Lab ZAO]   
{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}\(Default) = HP Smart BHO Class 
  -> {HKLM...Wow...CLSID} = HP Smart BHO Class 
                         \InProcServer32\(Default) = C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [Hewlett-Packard Co.]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\   
{A70C977A-BF00-412C-90B7-034C51DA2439} = NvCpl DesktopContext Class 
  -> {HKLM...CLSID} = DesktopContext Class 
                   \InProcServer32\(Default) = C:\Program Files\NVIDIA Corporation\Display\nvui.dll [NVIDIA Corporation]   
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} = NVIDIA Play On My TV Context Menu Extension 
  -> {HKLM...CLSID} = NVIDIA CPL Context Menu Extension 
                   \InProcServer32\(Default) = C:\Windows\system32\nvshext.dll [NVIDIA Corporation]   
{dd230880-495a-11d1-b064-008048ec2fc5} = Scan with Kaspersky Anti-Virus 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\shellex.dll [Kaspersky Lab ZAO]   
{B41DB860-64E4-11D2-9906-E49FADC173CA} = WinRAR shell extension 
  -> {HKLM...CLSID} = WinRAR 
                   \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]   
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\   
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = WinRAR shell extension 
  -> {HKLM...Wow...CLSID} = WinRAR 
                         \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]   
{dd230880-495a-11d1-b064-008048ec2fc5} = Scan with Kaspersky Anti-Virus 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\shellex.dll [Kaspersky Lab ZAO]   
{AE424E85-F6DF-4910-A6A9-438797986431} = OpenOffice.org Property Handler 
  -> {HKLM...Wow...CLSID} = OpenOffice.org Property Handler 
                         \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll [Apache Software Foundation]   
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} = OpenOffice.org Column Handler 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]   
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} = OpenOffice.org Infotip Handler 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]   
{63542C48-9552-494A-84F7-73AA6A7C99C1} = OpenOffice.org Property Sheet Handler 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]   
{3B092F0C-7696-40E3-A80F-68D74DA84210} = OpenOffice.org Thumbnail Viewer 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]   
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ 
<<!>> AppInit_DLLs = C:\Windows\system32\nvinitx.dll [NVIDIA Corporation]   
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\ 
<<!>> AppInit_DLLs = c:\windows\syswow64\nvinit.dll [NVIDIA Corporation]   
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\   
Kaspersky Anti-Virus\(Default) = {dd230880-495a-11d1-b064-008048ec2fc5} 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\shellex.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\shellex.dll [Kaspersky Lab ZAO]   
WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} 
  -> {HKLM...CLSID} = WinRAR 
                   \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]   
WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} 
  -> {HKLM...Wow...CLSID} = WinRAR 
                         \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]   
HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\   
GB3ContextMenu\(Default) = {3A488FE8-9916-4F36-BDFF-3DED559142E5} 
  -> {HKLM...CLSID} = GBContextMenu Class 
                   \InProcServer32\(Default) = C:\Program Files (x86)\IObit\Game Booster 3\GBV3ContextMenu.dll [IObit]   
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\   
Kaspersky Anti-Virus\(Default) = {dd230880-495a-11d1-b064-008048ec2fc5} 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\shellex.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\shellex.dll [Kaspersky Lab ZAO]   
WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} 
  -> {HKLM...CLSID} = WinRAR 
                   \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]   
WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} 
  -> {HKLM...Wow...CLSID} = WinRAR 
                         \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]   
HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\   
WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} 
  -> {HKLM...CLSID} = WinRAR 
                   \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]   
WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} 
  -> {HKLM...Wow...CLSID} = WinRAR 
                         \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]   
HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\   
igfxcui\(Default) = {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} 
  -> {HKLM...CLSID} = GraphicsShellExt Class 
                   \InProcServer32\(Default) = C:\Windows\system32\igfxpph.dll [Intel Corporation]   
NvCplDesktopContext\(Default) = {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} 
  -> {HKLM...CLSID} = NVIDIA CPL Context Menu Extension 
                   \InProcServer32\(Default) = C:\Windows\system32\nvshext.dll [NVIDIA Corporation]   
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\   
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = OpenOffice.org Column Handler 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]   
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\   
Kaspersky Anti-Virus\(Default) = {dd230880-495a-11d1-b064-008048ec2fc5} 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\shellex.dll [Kaspersky Lab ZAO] 
  -> {HKLM...Wow...CLSID} = (no title provided) 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\shellex.dll [Kaspersky Lab ZAO]   
WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} 
  -> {HKLM...CLSID} = WinRAR 
                   \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]   
WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} 
  -> {HKLM...Wow...CLSID} = WinRAR 
                         \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]   
HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\   
WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} 
  -> {HKLM...CLSID} = WinRAR 
                   \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]   
WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} 
  -> {HKLM...Wow...CLSID} = WinRAR 
                         \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]     
Active Desktop and Wallpaper: 
-----------------------------   
Active Desktop may be disabled at this entry: 
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState   
Displayed if Active Desktop disabled and wallpaper not set by Group Policy: 
HKCU\Control Panel\Desktop\ 
Wallpaper = C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg     
Windows Portable Device AutoPlay Handlers 
-----------------------------------------   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\   
HPAutoplayPSE\ 
Provider = HP Photosmart Essential 3.5 
InvokeProgID = HpqPSApl.Autoplay 
InvokeVerb = Play 
HKLM\SOFTWARE\Classes\HpqPSApl.Autoplay\shell\Play\DropTarget\CLSID = {A6873065-D632-4615-A3A9-C5F05EE109C1} 
  -> {HKLM...CLSID} = (no title provided) 
                   \LocalServer32\(Default) = C:\Program Files (x86)\HP\Digital Imaging\bin\HpqPsApl.exe [Hewlett-Packard]   
MSPlayCDAudioOnArrival\ 
Provider = @wmploc.dll,-6502 
InvokeProgID = WMP.AudioCD 
InvokeVerb = play 
HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L" [MS]   
MSPlayDVDMovieOnArrival\ 
Provider = @wmploc.dll,-6502 
InvokeProgID = WMP.DVD 
InvokeVerb = play 
HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L" [MS]   
MSPlaySuperVideoCDMovieOnArrival\ 
Provider = @wmploc.dll,-6502 
InvokeProgID = WMP.VCD 
InvokeVerb = play 
HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS]   
MSPlayVideoCDMovieOnArrival\ 
Provider = @wmploc.dll,-6502 
InvokeProgID = WMP.VCD 
InvokeVerb = play 
HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS]   
MSWMPBurnCDOnArrival\ 
Provider = @wmploc.dll,-6502 
InvokeProgID = WMP.BurnCD 
InvokeVerb = Burn 
HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" [MS]   
VLCPlayCDAudioOnArrival\ 
Provider = VideoLAN VLC media player 
InvokeProgID = VLC.CDAudio 
InvokeVerb = Open 
HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\Open\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file cdda:///%1 [VideoLAN]   
VLCPlayDVDAudioOnArrival\ 
Provider = VideoLAN VLC media player 
InvokeProgID = VLC.OPENFolder 
InvokeVerb = Open 
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe" %1 [VideoLAN]   
VLCPlayDVDMovieOnArrival\ 
Provider = VideoLAN VLC media player 
InvokeProgID = VLC.DVDMovie 
InvokeVerb = Open 
HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\Open\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file dvd:///%1 [VideoLAN]   
VLCPlayMusicFilesOnArrival\ 
Provider = VideoLAN VLC media player 
InvokeProgID = VLC.OPENFolder 
InvokeVerb = Open 
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe" %1 [VideoLAN]   
VLCPlaySVCDMovieOnArrival\ 
Provider = VideoLAN VLC media player 
InvokeProgID = VLC.SVCDMovie 
InvokeVerb = Open 
HKLM\SOFTWARE\Classes\VLC.SVCDMovie\shell\Open\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file vcd:///%1 [VideoLAN]   
VLCPlayVCDMovieOnArrival\ 
Provider = VideoLAN VLC media player 
InvokeProgID = VLC.VCDMovie 
InvokeVerb = Open 
HKLM\SOFTWARE\Classes\VLC.VCDMovie\shell\Open\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file vcd:///%1 [VideoLAN]   
VLCPlayVideoFilesOnArrival\ 
Provider = VideoLAN VLC media player 
InvokeProgID = VLC.OPENFolder 
InvokeVerb = Open 
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe" %1 [VideoLAN]   
WIA_{17924AE8-2BFF-4B2A-897C-3119641F72DF}\ 
Provider = HP Photosmart Essential 3.5 
CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24} 
InitCmdLine = /WiaCmd;C:\Program Files (x86)\HP\Digital Imaging\bin\HpqPsApl.exe; 
  -> {HKLM...CLSID} = WPDShextAutoplay 
                   \LocalServer32\(Default) = C:\Windows\system32\WPDShextAutoplay.exe [MS]     
Startup items in "Nico" & "All Users" startup folders: 
------------------------------------------------------   
C:\Users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup {++} 
<<!>> CurseClientStartup.ccip [null data]     
Windows Sidebar Gadgets: {++} 
------------------------   
C:\Users\Nico\AppData\Local\Microsoft\Windows Sidebar\Settings.ini 
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CShared%20Gadgets%5CKaspersky13.Gadget"     
Non-disabled Scheduled Tasks: {++} 
-----------------------------   
C:\Windows\System32\Tasks 
Adobe Flash Player Updater ->  launches: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [Adobe Systems Incorporated] 
CCleanerSkipUAC ->  launches: "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0) [Piriform Ltd] 
Game_Booster_AutoUpdate ->  launches: C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe /AUTORUN [empty string] 
GoogleUpdateTaskMachineCore ->  launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c [Google Inc.] 
GoogleUpdateTaskMachineUA ->  launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler [Google Inc.] 
{F8EEECBA-F492-47A8-B31D-8B2A9DCC06A2} ->  launches: C:\Windows\system32\pcalua.exe -a C:\Users\Nico\Downloads\zoek.exe -d C:\Users\Nico\Downloads [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client 
AD RMS Rights Policy Template Management (Manual) ->  launches: {BF5CB148-7C77-4d8a-A53E-D81C70CF743C} 
  -> {HKLM...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler 
                   \InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS] 
  -> {HKLM...Wow...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler 
                         \InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience 
AitAgent ->  launches: aitagent [MS] 
ProgramDataUpdater ->  launches: %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Autochk 
Proxy ->  launches: %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth 
UninstallDeviceTask ->  launches: BthUdTask.exe $(Arg0) [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient 
SystemTask ->  launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} 
  -> {HKLM...CLSID} = Certificate Services Client Task Handler 
                   \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] 
  -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler 
                         \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] 
UserTask ->  launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} 
  -> {HKLM...CLSID} = Certificate Services Client Task Handler 
                   \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] 
  -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler 
                         \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program 
Consolidator ->  launches: %SystemRoot%\System32\wsqmcons.exe [MS] 
KernelCeipTask -> (HIDDEN!) launches: {e7ed314f-2816-4c26-aeb5-54a34d02404c} 
  -> {HKLM...CLSID} = KernelCeipCustomHandler 
                   \InProcServer32\(Default) = C:\Windows\System32\kernelceip.dll [MS] 
UsbCeip -> (HIDDEN!) launches: {c27f6b1d-fe0b-45e4-9257-38799fa69bc8} 
  -> {HKLM...CLSID} = UsbCeip 
                   \InProcServer32\(Default) = C:\Windows\System32\usbceip.dll [MS] 
  -> {HKLM...Wow...CLSID} = UsbCeip 
                         \InProcServer32\(Default) = C:\Windows\System32\usbceip.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Defrag 
ScheduledDefrag ->  launches: %windir%\system32\defrag.exe -c [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Diagnosis 
Scheduled -> (HIDDEN!) launches: {c1f85ef8-bcc2-4606-bb39-70c523715eb3} 
  -> {HKLM...CLSID} = ScheduledDiagnosticCustomHandler 
                   \InProcServer32\(Default) = C:\Windows\System32\sdiagschd.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Location 
Notifications ->  launches: %windir%\System32\LocationNotifications.exe [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance 
WinSAT ->  launches: {A9A33436-678B-4C9C-A211-7CC38785E79D} 
  -> {HKLM...CLSID} = WinSAT Task Manger Task 
                   \InProcServer32\(Default) = C:\Windows\system32\WinSATAPI.dll [MS] 
  -> {HKLM...Wow...CLSID} = WinSAT Task Manger Task 
                         \InProcServer32\(Default) = C:\Windows\system32\WinSATAPI.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\MemoryDiagnostic 
CorruptionDetector -> (HIDDEN!) launches: {190BA3F6-0205-4f46-B589-95C6822899D2} 
  -> {HKLM...CLSID} = MemoryDiagnosticCustomHandler 
                   \InProcServer32\(Default) = C:\Windows\System32\memdiag.dll [MS] 
DecompressionFailureDetector -> (HIDDEN!) launches: {190BA3F6-0205-4f46-B589-95C6822899D2} 
  -> {HKLM...CLSID} = MemoryDiagnosticCustomHandler 
                   \InProcServer32\(Default) = C:\Windows\System32\memdiag.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\MUI 
LPRemove ->  launches: %windir%\system32\lpremove.exe [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia 
SystemSoundsService ->  launches: {2DEA658F-54C1-4227-AF9B-260AB5FC3543} 
  -> {HKLM...CLSID} = Microsoft PlaySoundService Class 
                   \InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS] 
  -> {HKLM...Wow...CLSID} = Microsoft PlaySoundService Class 
                         \InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\NetTrace 
GatherNetworkInfo ->  launches: %windir%\system32\gatherNetworkInfo.vbs [null data]   
C:\Windows\System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics 
AnalyzeSystem ->  launches: %SystemRoot%\System32\powercfg.exe -energy -auto [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\RAC 
RacTask -> (HIDDEN!) launches: {42060D27-CA53-41f5-96E4-B1E8169308A6} 
  -> {HKLM...CLSID} = ReliabilityAnalysisCustomHandler 
                   \InProcServer32\(Default) = C:\Windows\system32\RacEngn.dll [MS] 
  -> {HKLM...Wow...CLSID} = ReliabilityAnalysisCustomHandler 
                         \InProcServer32\(Default) = C:\Windows\system32\RacEngn.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Ras 
MobilityManager ->  launches: {c463a0fc-794f-4fdf-9201-01938ceacafa} 
  -> {HKLM...CLSID} = RasMobilityManager 
                   \InProcServer32\(Default) = C:\Windows\system32\rasmbmgr.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Registry 
RegIdleBackup -> (HIDDEN!) launches: {ca767aa8-9157-4604-b64b-40747123d5f2} 
  -> {HKLM...CLSID} = RegistryIdleBackupHandler 
                   \InProcServer32\(Default) = C:\Windows\System32\regidle.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance 
RemoteAssistanceTask -> (HIDDEN!) launches: %windir%\system32\RAServer.exe /offerraupdate [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore 
SR ->  launches: %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Task Manager 
Interactive -> (HIDDEN!) launches: {855fec53-d2e4-4999-9e87-3414e9cf0ff4} 
  -> {HKLM...CLSID} = RunTask 
                   \InProcServer32\(Default) = C:\Windows\system32\wdc.dll [MS] 
  -> {HKLM...Wow...CLSID} = RunTask 
                         \InProcServer32\(Default) = C:\Windows\system32\wdc.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip 
IpAddressConflict1 ->  launches: %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem [MS] 
IpAddressConflict2 ->  launches: %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework 
MsCtfMonitor -> (HIDDEN!) launches: {01575cfe-9a55-4003-a5e1-f38d1ebdcbe1} 
  -> {HKLM...CLSID} = MsCtfMonitor task handler 
                   \InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS] 
  -> {HKLM...Wow...CLSID} = MsCtfMonitor task handler 
                         \InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization 
SynchronizeTime ->  launches: %windir%\system32\sc.exe start w32time task_started [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\UPnP 
UPnPHostConfig ->  launches: sc.exe config upnphost start= auto [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\WDI 
ResolutionHost -> (HIDDEN!) launches: {900be39d-6be8-461a-bc4d-b0fa71f5ecb1} 
  -> {HKLM...CLSID} = DiagnosticInfrastructureCustomHandler 
                   \InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS] 
  -> {HKLM...Wow...CLSID} = DiagnosticInfrastructureCustomHandler 
                         \InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting 
QueueReporting ->  launches: %windir%\system32\wermgr.exe -queuereporting [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform 
BfeOnServiceStartTypeChange -> (HIDDEN!) launches: %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Media Sharing 
UpdateLibrary ->  launches: "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows\WindowsBackup 
ConfigNotification ->  launches: %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION [MS]   
C:\Windows\System32\Tasks\Microsoft\Windows Defender 
MP Scheduled Scan -> (HIDDEN!) launches: c:\program files\windows defender\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan [MS]   
C:\Windows\System32\Tasks\WPD 
SqmUpload_S-1-5-21-3337975632-725608183-240556253-1000 -> (HIDDEN!) launches: %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 [MS]     
Winsock2 Service Provider DLLs: 
-------------------------------   
Namespace Service Providers   
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 
000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 
000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 
000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 
000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 
000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 
000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] 
000000000007\LibraryPath = C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [MS] 
000000000008\LibraryPath = C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [MS]   
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\ {++} 
000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 
000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 
000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 
000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 
000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 
000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] 
000000000007\LibraryPath = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [MS] 
000000000008\LibraryPath = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [MS]   
Transport Service Providers   
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: 
%SystemRoot%\system32\mswsock.dll [MS], 01 - 10   
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries64\ {++} 
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: 
%SystemRoot%\system32\mswsock.dll [MS], 01 - 10     
Toolbars, Explorer Bars, Extensions: 
------------------------------------   
Toolbars   
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ 
{1D09C093-F71E-43C3-B948-19316CBD695E} = Smart Recovery 2 
  -> {HKLM...CLSID} = Smart Recovery 2 
                   \InProcServer32\(Default) = mscoree.dll [MS]   
Explorer Bars   
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Explorer Bars\   
{555D4D79-4BD2-4094-A395-CFC534424A05}\(Default) = (no title provided) 
  -> {HKLM...Wow...CLSID} = HP Smart Web Printing 
                         \InProcServer32\(Default) = C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll [Hewlett-Packard Co.]   
Extensions (Tools menu items, main toolbar menu buttons)   
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ 
{0C4CC089-D306-440D-9772-464E226F6539}\ 
ButtonText = Virtuelle Tastatur 
CLSIDExtension = {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} 
  -> {HKLM...CLSID} = VirtualKeyboardToolbarButtonHandler Class 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [Kaspersky Lab ZAO]   
{CCF151D8-D089-449F-A5A4-D9909053F20F}\ 
ButtonText = Links untersuchen 
CLSIDExtension = {CCF151D8-D089-449F-A5A4-D9909053F20F} 
  -> {HKLM...CLSID} = FilterButtonHandler Class 
                   \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [Kaspersky Lab ZAO]   
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\ 
{0C4CC089-D306-440D-9772-464E226F6539}\ 
ButtonText = Virtuelle Tastatur 
CLSIDExtension = {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} 
  -> {HKLM...Wow...CLSID} = VirtualKeyboardToolbarButtonHandler Class 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [Kaspersky Lab ZAO]   
{CCF151D8-D089-449F-A5A4-D9909053F20F}\ 
ButtonText = Links untersuchen 
CLSIDExtension = {CCF151D8-D089-449F-A5A4-D9909053F20F} 
  -> {HKLM...Wow...CLSID} = FilterButtonHandler Class 
                         \InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [Kaspersky Lab ZAO]   
{DDE87865-83C5-48C4-8357-2F5B1AA84522}\ 
ButtonText = HP Smart Web Printing ein- oder ausblenden 
CLSIDExtension = {DDE87865-83C5-48c4-8357-2F5B1AA84522} 
  -> {HKLM...Wow...CLSID} = ClipBookBtn Class 
                         \InProcServer32\(Default) = C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [Hewlett-Packard Co.]     
Running Services (Display Name, Service Name, Path {Service DLL}): 
------------------------------------------------------------------   
Creative Audio Service, CTAudSvcService, C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [Creative Technology Ltd] 
HP CUE DeviceDiscovery Service, hpqddsvc, C:\Windows\system32\svchost.exe -k hpdevmgmt {C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [Hewlett-Packard Co.]} 
hpqcxs08, hpqcxs08, C:\Windows\system32\svchost.exe -k hpdevmgmt {C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [Hewlett-Packard Co.]} 
Intel(R) Management and Security Application Local Management Service, LMS, C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [Intel Corporation] 
Intel(R) Management and Security Application User Notification Service, UNS, "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [Intel Corporation] 
Intel(R) Rapid Storage Technology, IAStorDataMgrSvc, "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" [null data] 
Kaspersky Anti-Virus Service, AVP, "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" -r [Kaspersky Lab ZAO] 
Net Driver HPZ12, Net Driver HPZ12, C:\Windows\System32\svchost.exe -k HPZ12 {C:\Windows\system32\HPZinw12.dll [Hewlett-Packard]} 
NVIDIA Display Driver Service, nvsvc, "C:\Windows\system32\nvvsvc.exe" [NVIDIA Corporation] 
NVIDIA Stereoscopic 3D Driver Service, Stereo Service, "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" [NVIDIA Corporation] 
NVIDIA Update Service Daemon, nvUpdatusService, "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" [NVIDIA Corporation] 
Pml Driver HPZ12, Pml Driver HPZ12, C:\Windows\System32\svchost.exe -k HPZ12 {C:\Windows\system32\HPZipm12.dll [Hewlett-Packard]} 
Sound Blaster Audio Service, CtHdaSvc, C:\Windows\sysWow64\CtHdaSvc.exe [Creative Technology Ltd] 
Splashtop Connect Service, SCBackService, C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe [Splashtop Inc.] 
Steam Client Service, Steam Client Service, C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService [Valve Corporation] 
Windows Live ID Sign-in Assistant, wlidsvc, "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" [MS]     
Keyboard Driver Filters: 
------------------------   
HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\ 
<<!>> UpperFilters = <<!>> klkbdflt [Kaspersky Lab],kbdclass [MS]     
Print Monitors: 
---------------   
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ 
PCL hpz3l5mu\Driver = hpz3l5mu.dll [Hewlett-Packard Company]         
==== Empty IE Cache ======================   
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully 
C:\Users\Nico\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully 
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully 
C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully 
C:\Users\Nico\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RFNUE65H will be deleted at reboot 
C:\Users\Nico\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot   
==== Empty FireFox Cache ======================   
No FireFox Cache found   
==== Empty Chrome Cache ======================   
C:\users\Nico\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully 
C:\users\Nico\AppData\Local\Google\Chrome\User Data\Default\Application Cache\Cache emptied successfully   
==== Empty All Flash Cache ======================   
Flash Cache Emptied Successfully   
==== Empty All Java Cache ======================   
Java Cache cleared successfully   
==== After Reboot ======================   
==== Empty Temp Folders ======================   
C:\Windows\Temp successfully emptied 
C:\Users\Nico\AppData\Local\Temp successfully emptied   
==== Empty Recycle Bin ======================   
C:\$RECYCLE.BIN successfully emptied   
==== Deleting Files / Folders ======================   
"C:\Users\Nico\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found 
"C:\Users\Nico\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RFNUE65H" not found   
==== EOF on 24.06.2013 at  0:28:57,15 ======================      |