Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Unbekannter Schädling(blockiert Malwarebytes&Antivir&Systemwiederherstellung) (https://www.trojaner-board.de/151818-unbekannter-schaedling-blockiert-malwarebytes-antivir-systemwiederherstellung.html)

Crohero 31.03.2014 23:17

Unbekannter Schädling(blockiert Malwarebytes&Antivir&Systemwiederherstellung)
 
Schönen guten Abend zusammen.

Ich habe heute Dummes getan.

Um mir in einem Spiel einen Vorteil zu schaffen ladete ich von einer bekannter Seite ein Hilfsprogramm runter (machte ich schon 500x).

*Ich befinde mich jetzt auf meinem LapTop der keinen Schaden erlitt*

Dies besteht immer aus einer **.dll Datei und einem Injector.

Die heutige Datei aber war verheerend. Ich schaute nicht auf den Namen der .dll Datei die "ixplorer.dll" oder ähnlich hiess. Ich schaltete meinen Antivir temporär(für 10min) aus(macht man immer, da er sonst den Injector hindert, was sonst schlecht ist aber heute schlau gewesen wäre). Ich startete den Injector und nach etwa 2 Sekunden war es getan. Ich sah den Namen der DLL Datei und war verunsichert. Ich wollte mein Antivir wieder einschalten, ging aber nicht, da Zugriff verwehrt war. Also wagte ich einen Neustart. Und siehe da, AVG startete nicht einmal. Und Malwerbytes, welches sich auf dem Desktop befand, wollte auch nicht so recht gehen. Das Symbol war so grau und der Zugriff natürlich verwehrt. Ich fuhr den PC herunter, schob so eine Anti BOOt-Netz CD aus einem PC Magazin rein und liess ihn 3 Stunden laufen. 127 Schädlinge gefunden (von denen ich wusste, die gar keine waren) aber das Problem war immer noch nicht gelöst. Ich nehme an, die .dll Datei setzte sich irgendwo tief im System fest.

Auch im abgesichertem Modus lässt sich Malwarebytes nicht starten (eventuell bei Neuinstallation). Es kann natürlich sein, dass der Virus die Installation verhindert usw.

Was soll ich nun machen? Leider habe ich den Braten nicht rechtzeitig gerochen :)

Freundliche Grüsse

Crohero

schrauber 01.04.2014 06:12

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Crohero 01.04.2014 16:21

Liste der Anhänge anzeigen (Anzahl: 1)
Hallo Freunde der Sonne!


Hier habe ich die Logfiles! Ich hoffe ich habe sie richtig eingebettet.

Ausserdem ein Bild der Fehlermeldung wenn ich Malwarebytes oder mein Antivir anklicken möchte!

Ich bin bereit für neue Scans :daumenhoc

lG,

Crohero

PS:

ich habe die Virus-dll Datei auf meinem PC frei im Ordner stehen. Ich kann sie hochladen, wenn es euch hilfreich sein könnte.

Crohero 01.04.2014 18:57

Moin,

habe gerade noch einen Scan gemacht mit ADW Cleaner!
+ JRT

*ausserdem habe ich soeben versucht Malwarebytes zu installieren. Weder im normalen Modus noch im abgesichertem Modus ging es.

Fehlermeldung: " Das Setup konnte den Ordner C:/xxx Anti Malware" nicht erstellen.
Fehler 5: Zugriff verweigert."

Ich glaub es nicht...


JRT Bericht:
Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by zagreb on 01.04.2014 at 20:00:21.44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\ib updater
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ToolbarConduit_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ToolbarConduit_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsPal_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsPal_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\pricepeep_40001_0101_20130402_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\pricepeep_40001_0101_20130402_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ToolbarConduit_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ToolbarConduit_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LyricsPal_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LyricsPal_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\pricepeep_40001_0101_20130402_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\pricepeep_40001_0101_20130402_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{119FDAA3-DFDA-41F0-8B00-88A9D64473DE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5496A292-190B-4936-A4AD-6F52751F3A84}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\zagreb\appdata\locallow\datamngr"
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{00E468BA-07B0-4C09-B496-E18D0541D99B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{00E5F519-6367-436A-A5D2-46FBDC85ABBB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{01D79006-616C-404B-845E-6D00DEE2D30A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0207D6C7-B92E-4AFA-B3E1-9CA4DA32EFBD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0259130F-51FE-4071-A105-C3ECAA4F907D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{02869A3C-8C9F-4C1E-81FC-052B50BFA4DB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{029339AB-B20D-4CAB-9132-8350D561CFBF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0294BEF7-07A6-411C-A49B-AB1243E6A8CC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{036774FD-F0FB-4E17-949B-54B9F7280BF5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{03BD8F2E-17B2-4D51-B0B7-D57F5F3DCB9D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{048E1F22-DEA0-4D7C-9408-061211AE2DF1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{04C69118-B10F-40F1-BA65-E9338DAE25AA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{04DA17EA-C90E-4850-9FC4-B8CFE3A837B8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0574F42E-97F6-470B-A7B1-28F1BC943382}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{05A29333-F2A7-45AA-985D-FBBFBB4A703C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{05B07532-3D69-4E19-9F6A-E3D445EE1B77}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{05E980A0-576E-4162-B610-29B68808D3C7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{05EAA858-2D5C-41A6-8CCC-F318FEB18482}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{06299D2A-5598-428B-8026-FA727650F927}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0642B6BC-EEE7-4DCA-B86C-EDCE961A841D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{067F1AC1-9FF7-4A78-9A4D-CC032310142C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{06B3330C-1E65-4F86-9948-5894C08F3690}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{06B9A7E6-BC6F-4AD6-A3A2-35C055E1B87C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{07AE3433-9E1D-48D6-B342-B311FB77347B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{07C62178-C9EC-4A8B-859A-FECF655F11C9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0815230F-7084-47E7-A7AA-3E31C8D483E6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{083021A4-D1EC-4C1A-97F0-4654422F1FBA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{08AA1E28-A17B-4812-8C41-6B47DFF2EDE6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{08DB8EFD-4940-4D7B-A907-9D8E16CFAA02}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0917CD36-09F6-4D11-BF40-20F48DFFF53D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{092E7251-7F51-4FCA-B00C-185AC30C168E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{09B6CECF-B0EA-4491-A22E-F0A1D9E39D4C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{09E67BD0-B80B-40AE-8FA7-EA1E0EFA9FE2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0A5F1322-42A9-4DB5-9A1A-37C9613EE6E5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0A71FB15-C597-4196-9CDF-0A50A5FC9B8B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0A88E20C-D55F-47DF-AFD0-C626C55C5876}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0AABB23E-2BCC-4E09-A670-12648D215476}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0AABF380-F159-4ED8-B9D1-B984AEA31292}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0ABD009F-4FE2-47EB-A8B4-71BE729D101A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0B0DB3A8-F1A3-4254-95F1-8CBBBDE06E00}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0BF01A5A-DA55-4D85-A959-0C22451DA2A9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0C7B04E1-23F3-4A96-A87E-BC27FA16CBB1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0CF31C97-1D02-4310-AF69-A74F1E537D60}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0D9EE6BA-0E0E-4D8F-A2C7-349A5AD329F1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0DC3C1DD-19BE-4131-97E0-9547740D48CB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0DF6689B-8565-41BC-937C-E69914EE243D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0ED601E5-EC18-41AA-93F6-253265593B1E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{0FD936DE-0BB6-4C0E-9831-9028CF59AF71}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1054481E-3729-454D-AA40-6FAC1A136CEA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{10EDCF87-2C4A-4F8C-86E6-9851B99F5CCD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{14233F47-FE7E-40E6-8A4D-641CBF2AEAC2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{148640F3-9DA5-42A8-B94D-F37E513FAA70}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{14FEA988-54F0-4D78-ADC7-6E48E42D466B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{153D3958-D2DB-4F57-BFC8-264DC0D92BAD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{161AF938-BC46-4042-866B-33B46A58DE13}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{16348441-48E6-4B71-8FC0-6EF189871384}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{168DE0E7-4284-490F-AC6D-6242BE7053B1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{16EE7DAF-01AD-404C-BF33-BBD5E456055E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1727CC99-3A4E-4B3B-98A0-D13EC14D9982}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1792A9E6-ECED-4C31-BC9A-C17D09A872AB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{17BE3716-3E75-42D2-9903-DBCA3474C6D2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{17BF9E74-005B-4596-96AE-B8ADFA7C0435}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{187ACD1E-DBF5-47D8-B1AD-923435AB2CAE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{18B81D45-3430-4567-88CC-F9E021BE803A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{19775A50-0160-475F-8391-406A78B14AD7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{19AF9BED-3932-4D7F-A725-242E09BE9D61}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1ADB0FDA-ECEC-4C0E-B137-DB228E42D0F3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1AF46CF2-913C-480F-9F59-64BE2FDE9A35}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1D4D4385-EC5C-41D9-90EC-8A4388D63D35}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1D9AAF41-DB72-493A-9EAC-96EE283DDC10}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1DB16FA6-2987-4801-866D-596149756903}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1EE3BA4E-7727-4E1C-B3A5-3BB3C5B9305B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{1F1713FF-FC35-491D-9FB6-87CF657B9F42}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{20286FFD-070A-4CB4-B5F4-AE34C8ED8352}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{20483938-4B19-46DA-83AD-AACFA0863F7F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{20E7CB65-B591-47E7-BA1E-0359F36D33E0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{21545213-A146-4889-BAFA-16CB41069D4E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2171DD80-255A-4193-852F-006E7B0989F2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2198AAE4-BA9C-48B6-AF9F-67A231AFD18B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{229979D9-54F6-4AA1-B8DE-A3EFCD2F708E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{24028D36-7EB5-4F94-B2BD-B7D658F54F35}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{246BA6F2-3BD5-4FF1-99D4-6F1AA17120A0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{24A60788-00D2-485C-A2EE-577008C2C8A6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{251A9AB1-1FA5-44D4-88D9-6740C3E8F183}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{25C2FFD1-BA08-4B89-A1C2-58B1D3E45146}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{25DE301E-447B-4C57-A8C8-B42A079C10F4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2692C773-0E7D-4990-9297-89D464BEF391}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{269F496C-7DA7-4DCE-9AFD-3ED3D128B8C2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{27A657C2-6CDC-46C1-AC01-C783858C52D1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{27AFDB31-7DF8-43EE-8C11-675DCF828B6B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{28574FE9-8F32-40D7-AA5C-9A010FE4999B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{295C3A39-3F12-4CD8-B40D-403FFB2BD28A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2988FA60-97AE-48E1-BDCC-2B81C586BF4F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{29C53EDB-BAC4-4FFD-BC4C-B7FCA543E223}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{29EB631C-20E0-4984-A0DE-48FB0AB07EEC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2A2525F9-519C-4E37-BE72-9B219D24F9DB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2A338A4E-73A6-4380-BFE7-7C99B9FFF7E7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2AA4EA5A-92A7-4DD7-817B-8D0672709915}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2B26BFA6-814C-4D2F-9166-4BE4CD7E7345}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2B91DB9F-6F33-48F7-9B2F-1724458F26C8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2BF7FFBD-3A29-4A92-944A-B737F52ABC63}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2C1FD850-F252-4772-A40A-35080DA9B22D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2C286355-2F4E-48E1-9425-7777B6849803}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2C2F9D54-098C-430C-B7B9-20282CE82FC6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2C63E637-AC20-4C7F-B277-E2EE415890F5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2D3AD09B-E502-4C77-B474-DDA1A9AD74C3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2D5557F5-5BFC-4615-B310-E69E17C658A5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2D5B0543-5F16-42AC-864F-F93370F79219}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2E2A553C-58FF-4D1B-96AC-027B94039137}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2E3FA636-B70C-42F9-878A-4DFED72D087B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2E4776F8-A3AA-49B3-B0A0-83B5059DB536}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2E6E8B09-4E3A-46CD-A7A2-D604EB458CCD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2F5BAF11-6F5B-4B13-AA1A-38FF9AC175BD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2F9BD86B-049D-4D80-93CA-F52B8FAD31EA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2FDC4794-036F-4633-B4A1-ABFC331016F4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{2FECD489-B90F-4549-9355-335E3928986A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3053D223-6F17-4915-B046-0978E95DAF1A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{30FC7FA6-7B1D-479F-910E-EAAF85E76716}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{31BEAA21-DE88-4B8E-81E8-CECBCF2F4924}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{322E1F12-B0E0-423C-A1AA-A2817CCE3DD9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{32C9672D-3FBA-4F37-B87B-98C74133F7C3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3322AADD-9E8B-4BEE-A17D-B4363035B97D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{333E69A0-F874-4EB4-BF6C-256ACDD885B8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{33F0A981-242D-4C63-90A7-D798371C54C1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3420AD29-64C9-4D42-B23A-D05BEE8CF0B5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3448C5FF-997B-4DB6-B0CE-BF15739C3A76}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{345D7CE5-741E-4ABA-AFD0-D1B4D9BF97EE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3474DB9D-F191-493A-BADC-4F1C74702795}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3484FF49-A004-4BE7-930C-7F05999E9200}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3498A57E-6B4D-48E8-B17C-8EF5FD749E9A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{35072613-485F-4353-937C-1DE43D760D5E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{36DC89D9-A59F-41B3-9538-100B7CDC55DE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3731D6C1-40C6-49B8-B088-985C52A50EE7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3783350B-3E26-48FB-BCDA-ADC01B05B0BC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{378D350D-D8EA-476F-AA52-45C23744F201}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{37E739FD-0932-450E-AA50-355EDCB8A432}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{386484BC-8B50-4D96-92B2-5DC1EA5BEB0E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{388A7289-8C45-4018-B197-752027296334}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{38C34649-919E-4A12-A5CF-CF60B2BA0379}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{39567378-7D4C-4314-8303-948147EC4863}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3A9BFBE5-1C9E-431F-A0F4-0F0D8292E230}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3B3E1709-AAEE-41A7-BA20-2E08630C7C3E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3B7520C0-A3EE-48BF-BEB9-AB0159159F4A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3C47CE28-B94C-4009-8F2F-8FE1DC9D7AE2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3CB860A8-0D1D-4CD4-9D4D-2794D921F2E0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3D2E8265-4A5C-4771-94BC-0B1C1AF33E82}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3D2EB3E3-1407-41BB-977A-E24F4CEDD52F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3D44C2BA-E96A-4B88-8B75-D03DDA804B15}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3E314117-CE1B-407D-B832-55A9731EBF26}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3F5C99C0-5B82-4242-9B57-FB8E67D9547F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3F9C7F50-7FD9-4038-9D23-C75F96876197}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{3FCBFC75-375A-4B3D-8B1B-AD4B77F17571}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4058B143-475D-47D6-A2E6-D106EEDF4DFC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{41EC7494-0F16-4B23-9CAE-3EC2CB2C5EB0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{42BBF6FE-D7C1-4582-A705-248469DFAD58}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{431BB4B4-9C64-4539-A727-0692F8C5418B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{432A260B-5F54-4480-8AC5-0CD9F02349A4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{43876158-883E-4B88-8092-13CF79DC8366}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{43D93171-3FF1-4C82-B064-19ACFA1BC76D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{442C9BA4-5E6C-4C3B-9396-BDDF8BA1FB7E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{444E75E7-4495-4705-9FDD-B7B1627A7BF1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{444FBAC5-C418-445E-90C7-DC102271B0CB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{449729FE-D39F-42F7-B3D8-1ACAE177BFC9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{45226106-E192-4B79-A43A-C412D95D2408}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{465156A4-6BC9-4483-A250-45CDE102D9D0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{466D4901-6370-46D0-A180-93C1BA74D7C0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{46AFE763-40D3-4581-832C-1DF18542EB03}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{46DC70BA-9C8D-4EC1-8FE7-9124A5BA18B2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{47C7B759-AC22-4498-B470-4D6F28071D49}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{47DC59EB-BED6-4539-A000-48FC2DC7D570}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{48844E27-2E05-48AD-8B15-0DE8E5CD3B29}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{492FFBAB-DD6E-4131-8925-77DFBC9C0DEB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{494562E2-E20A-4A57-8935-763BC9D31E54}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4A007C95-121A-48C2-9BE0-A8803DB0A30F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4AE67954-4975-4EF0-8C02-02F19B9685DD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4B4741FC-7494-4FD9-A589-6C4629DB8CB0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4BA2B0A8-A50A-4B5D-BDC2-0E15B33706E9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4BA7AE56-4C6C-4BFC-B999-238E63821F06}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4BC03F3A-AF3F-4781-8668-FBCF44AEE5CA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4C2B5B34-88D8-4284-965F-9064F5E65930}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4C68AC71-1FE5-4582-9C5A-77DEDA04CBF0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4CA93454-1BEA-4BD6-8795-4D7C31DE9C2D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4CDE2A03-AA1C-4E75-AD20-13A510861E84}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4CE3CBCA-F202-497F-B6C4-BF04E79FC351}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4CF4F636-BA78-445B-B6BB-0388CF50BD77}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4D52C329-AE61-48F1-BA5D-B95B4628085C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4D9C90D8-C714-4651-8010-5953CC5E972B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4E4D2BD8-BE87-463E-8344-6F78B99E835A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4E94F4B5-6470-44CB-9CCE-93A2A8E55D98}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4ECFCAF2-27CC-439D-8634-785E9CD90900}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4EF1C9A1-85A6-4AA6-9385-759A9453B0CE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4F1A534F-08D7-4D6E-BD2D-AA5C49689D92}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4F6E6513-D295-40BE-A92A-F3AABCCBC5DB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{4FBA6A3E-71DD-421A-B82E-9063B75C7FEE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{501551B3-0D07-47B0-A884-B0541437A392}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{501FA1A8-3DEA-472F-AF51-F5F0222CBE82}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{50448E26-8D91-4006-97AC-EC7521DF1057}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{50D0AE02-C51F-4227-820C-4FD7B7E15952}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{51556788-96EF-40F2-B2E8-465E695B93A2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{51695696-1F17-4629-B918-9901B9BFAC48}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{51772CF7-BB72-47F9-81EE-298DDDEFE8DE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{518F4D9B-0692-48CF-93C3-FAC4F46A527B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{52230A79-8915-4C7F-8B7F-72049DE1F453}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{52A8E7CE-14B4-47F7-BC6C-944DD917CC0A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{52D5C589-FCC7-465E-B289-FB609B060C9B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{52E253B3-7798-49C7-AFEA-BC97E4564978}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{52F22FDF-5079-4927-BC28-9E5A873DAB99}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5336633E-8CE3-4507-8F6B-B631FCABDCBB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5427AD39-6F3A-4D39-9881-B0BAA13A2D00}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{543A7D22-F018-47BF-BE87-8748E32B21C2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{54D4E348-A8CC-4129-911B-E36B6244BC8F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{550014AB-C53E-4AE6-9A56-88760D363A52}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{552D9A9A-6086-491E-AA24-06C9F6805BEB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{55DB993A-87AD-469F-956C-65D938DCD922}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{566CDCFA-CB85-4D4B-B3A5-EECC7A28ECE0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{567C40EF-4EB4-49BC-9C3E-93CAB353F9C9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{56BD1EC9-9C31-4E6A-A7F5-C4C096088BF7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{56C4A7FE-C155-4688-958B-19EB5204064A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{56C97EC0-45C2-4107-8B68-9CC9D5AB0D3C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{570027B1-BF0A-45D9-BD22-354E479E6F66}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{57C8014A-98D7-45DE-83BB-D474396E7F6E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{58BC250F-453A-4F48-91B4-1DE645AF1387}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{58F78975-61E1-4A04-A3A0-20BD7CC2E0F0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5924440A-D39F-4D0C-80FD-C42E0901382D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{598782FE-DBEE-4B25-B1A9-C5D6B839F9BF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{59D40F4A-3569-428E-83B2-A25BA0F05F57}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5A08C130-F3C7-4447-9D79-8CCA4B499F4D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5A2EC34A-8D32-4E22-9A58-B163BBD435FA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5A773340-8BBE-4809-B22B-DCDD475AF9DD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5A997F31-F325-4C18-9428-24291FF09E5A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5AE250C3-3E5C-4D0E-B323-C01034705A11}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5B36FF07-BAC2-4B1C-A632-74112638A12B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5B3823ED-BBF3-45B6-AC70-D5F1A74372C6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5B3C734C-4318-4A71-B088-AD312F375490}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5BB4663C-B381-474B-83CA-305612CDF4A1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5C124CF2-9893-4A56-A826-E3678C61784D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5C9E94B1-EF63-46AA-A4BF-AC0D3647D665}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5CB11F6C-1636-4748-8C8F-EA7F6A6486C7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5CDC80A9-6FB9-4EA2-833B-0CB7D3723D52}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5D64D120-0C02-4DE7-B011-45AA95F08832}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5D689E60-1214-48BA-AF03-B8A4A342692E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5D7B8C8D-9384-4042-A84A-60494A08A132}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5DD5B4A1-2224-436B-AFB4-016EFF466673}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5E47015A-F12B-4F40-83DF-1DA824D8718D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5E685632-018B-47D1-8A91-78B5365EB878}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5EEB7CE5-EA4D-4D25-88AB-0B887AA7BEBA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5EF84283-C871-4E94-86C7-CB86741CCFEE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5F287EBC-B5C5-4E6F-9404-98189BFE4216}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{5F444451-DA3F-4BF8-9AAD-C57300E1A354}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{606E3002-7666-4A52-B321-A484FBCAF53F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{60791E57-DB71-44CC-8818-07707465140D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{610B8229-6668-448C-ADC4-9ACF2C5E3C7B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{613F41E0-A102-43F3-B5E2-983438A6F95F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{61B08F2B-5ED9-4043-9583-1681EBF1860B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{622E04AA-C945-412E-B370-6B0F26C5B59E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6237AD69-CFF3-4F67-9913-2D6589433DF2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{62579694-D249-437B-B0CB-6D0B0EF41CA5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{630BB800-0D6F-4B9C-8895-E0B5F6798C28}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{63181FCC-B40A-4BA2-8F6E-E3C5CEE472C5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{633F374E-4A67-49BB-98E0-C2B2F1EC9B68}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{63471BB4-7384-4764-98D1-F03793259DB2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{637CE98F-0D3A-4B4C-8049-51C61B70B369}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{63D50323-8261-482A-ABFB-787093AFDADF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{653F51B5-6598-42B8-8DA3-3BF06BF26DA0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{65954CF8-ABFE-4FC6-A822-C6708ADB3C9A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{66093A49-2E02-452B-B613-BEF5F2AC5F88}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6756CA82-57F5-4B5E-82A4-17FABBB91477}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6760238B-0C5F-4D3A-96B4-A2CA2B0D740D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{67AC30ED-E7FE-4C74-87EF-BC1CD879114D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{67F7F879-E923-42EE-A849-F49EEEB9666F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{680E6838-ABD0-4408-9F85-5443A6449684}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{684B30E6-8784-470B-87E2-236DF369C1EF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{68A105A4-70DD-4F8B-AAD9-3EEFD0BC5F84}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{68B765BF-1D83-4FD9-BBB8-3285C866B04D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{68D3F40D-5FA1-495D-ACC6-72032846FE3C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{68E67F61-B9B2-4E5F-9933-33D26AEEEE8D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6A10CC27-FA1C-47E1-912A-259545629FD1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6A3838AC-10AB-4C6B-ABAA-58966493A021}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6B27A9F4-F4B8-4443-8524-DE97226AB215}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6B4626DE-50B7-4973-BED8-450F6EA321D8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6B81F7FA-3884-43E0-97F3-81CB636A6A5B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6B87EFEE-14F8-4411-AFED-5C3D80A44013}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6B8B5ACE-1728-45DF-9E74-C428EFC58CB2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6BBC2163-F878-43E7-A88C-EA641CCAC96D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6C2DEC47-0D14-4B10-9F43-417B445379C5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6C622FE1-341C-4EC1-9EBD-56402EF7737B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6C6F103A-153A-4542-BE64-CFEDCCD8FDA1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6C83BBE3-2BAF-4BB3-9B4A-C210764CD691}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6D0F4BBC-6BEA-4AD3-822B-0894638102C2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6DC16DEC-5701-4DE4-B332-05346F769A7D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6E06AEAA-3A11-43FB-B635-B3F44D5E1670}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6E3F6452-D0B5-4E13-BCBF-293B033EBBB4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6E6C2C24-CBF9-4F96-B97C-3C6DC1627961}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6EF853B0-4C03-4706-A1A1-87F7AAEFF1C3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6F179006-3D41-40C0-8EE5-256BB44045FE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6F37B8F7-81B5-4CB9-A4E5-76748FFBF3BD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6FDA9218-9CB0-41AC-A366-4FD09B5A0C62}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{6FFD2CCA-5E31-4C56-9DA9-A6B83B9DCF21}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{70485A54-2116-4BD8-95A9-141678AD7DAB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{70AE335C-B5FB-4B31-A3BF-74641E3E9FB4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{70FF3276-C0FB-4457-938C-C396B08E2FBB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{716F9D0C-FEE2-420A-9955-6414C811E5F4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7175FCE5-6EE0-4861-B5DA-917138393820}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{71844F71-5499-464D-8DA9-CB16B59CAF50}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{727E9694-CDCD-4703-BCCD-E19DCAEE945F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{72BCF452-97CF-41DF-87F5-0C7D9467D053}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{733B2C08-5359-4718-B34D-AD38EAE70B64}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{738D0919-CDEF-4C50-9538-19711589D23D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{744DD21A-2571-47D9-ADC7-ECCDD0C979DB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{74500696-78ED-4896-8144-FBC41C769304}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{74961D4F-5851-43C4-986D-D338B5782819}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{74C1D64D-423A-452B-A15C-9C46752AA040}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{74DA3273-5D00-4A81-AA8D-EF7146EF82C8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{753152AD-EBB3-4847-B5EF-14E76A94E926}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7565A7AC-B500-44A7-9F65-08C6BC88DFA1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{757ACF13-7B04-410A-B139-3926E989721C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{757C73AA-DF57-4ACD-849B-78898B96308C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{75E578DD-9EDA-4C6F-8481-5272386EF1AA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{76D47843-7F98-4E53-B4D1-6B80857E9C52}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{76EE5301-4A17-4426-90FF-D14096A5D3FA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{76EF32BB-FAD0-4935-B399-99D578499F12}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{779322A9-1C19-418C-8908-AD9715F64490}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{789C85EF-E5F8-4BF8-87F8-FD5E4DDEF33C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{79D5CB7C-2D75-44FC-9779-95D19525B2C9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7A2EF317-65D5-4119-8407-F3BBD8EB9116}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7A735C63-C04E-4C88-91CE-34CF4F18667C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7AE51808-5DA4-45FB-9D9E-C8681EFD409B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7BAD9AC7-6DD4-479F-9A76-4E94D2C745CE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7BB09927-2221-41D4-A1D5-97B0F998E4F7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7BE298E8-BA2A-4588-8197-59E16EA36EEC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7C761D6E-C179-4A94-BF64-0EF867BF980B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7D2CB706-4CDC-4AC7-AD80-0418FBB153E5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7D5C17B4-2AB3-4E49-A031-28CFBE0C9803}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7E52CB37-B78C-48B6-BA4F-B60CB8FFF66B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7F8F14F8-DA79-4178-B5FE-3E734E2107AF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{7FA2ED22-3C34-4C44-87F7-060DCEFCC720}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{80150CD0-D0DC-4D63-90B8-A1F53371616D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8064A9B6-759B-43A7-8DC4-593057E2FA23}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{80BC94A2-7330-46A5-97B0-2651D219BAF9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{81316F4F-E9B7-491D-BA2B-D8D2A4FE52B0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{81EB4717-963C-47F0-8B18-36EC2C4A5698}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{827E33C1-A74D-477E-B896-5F689E27FFBC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8305E6B8-BC95-4183-9212-4D99C2518FB5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{830B21FF-4432-4792-88F3-6828D6DC10EB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8330610F-9C79-479A-A7EC-8911FC9A7A85}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8345F18E-876B-4B9A-A80A-D3B9F2D409A4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8349C86E-E0AF-4250-881A-1A48BD4FFD1F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{835F5CE5-547F-4640-9705-A5C4DDC900E0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8472DF4E-E053-4CAF-82CC-58F69B5A1D65}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{849994B4-968B-4249-998F-5669567F8468}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{849DFAF5-B4C1-4BEC-93A2-958C3A662DF4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8664B5A6-4D58-4A5D-81B1-339C33E59E24}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{866AE864-BD07-4B1B-9320-EE771120DD06}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{86CA8CFB-6DD4-4757-85E2-9F6BD35E18FE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{86D23BE7-87DC-485A-B59B-47F4293D9147}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{870A1DB2-BE1E-45A1-81F3-74DF32689746}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8798296D-F2AF-4FA3-ADD3-0A271CBD3480}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{884FC05D-AD8E-4C68-B00E-54682F0F3725}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{88677B1C-76EB-4722-B856-4C22AB7E8C4B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{892502E4-BC40-4C58-B0EA-A9E572D1EEA7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8977B6AE-15FA-4730-A3EA-483C4A7A0864}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{898593C1-5F94-4ABA-B49E-ABDFEC986E10}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8A6B5365-1BB5-4562-A93E-38C2DF9A4286}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8B8156DC-BC2B-4AC4-A66D-676E4C54DCD3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8C131178-4012-4884-B390-DC40A55F4AA4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8C264E82-5EFE-4574-869D-EEFB43C1046D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8C432F8B-8CA1-4FF8-A59A-1AAC52D1E2EC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8C7595A3-3311-4726-910E-0E443F230912}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8C955486-E903-42A1-8FC2-27DD720BC21F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8CEF097B-9ADD-404D-B526-51AC0C431635}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8DF00756-20E7-4546-98B3-D81379CAD6E0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8EB8D90C-7337-4C22-A445-D4DAC6F3E7E6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8F02D63E-F2D1-403A-817C-C235EAD960FE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{8FF1B52E-24C8-4A71-8778-E328417F7E0B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{906FD9D8-1233-40BE-9FBD-E7C02E7E036A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{90C61206-2257-4F2F-BC0D-1083565D8CAE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{913BFCF3-7316-4462-B11C-0A27EDE1AC57}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{92AF59C0-70ED-4938-85DC-98F8FD86E0B4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9388AA12-2048-4AB3-9F6E-1DE8D2751AE0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{93BC2AF2-AC28-4B06-8090-00810FBE85B9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{93F1175E-14D7-494E-A6F3-93A7DACB251B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{93F760D6-9652-42CE-A816-6BF807859138}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{954483C5-7301-483F-B755-320103E1D352}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{956E1DFC-8338-47B1-B9D8-8C034DA60413}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{956F91EF-769D-4BBB-8330-D9AC21F6384D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9631366E-D5E3-47AB-A209-32E4A27343B0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{96DBC06A-4074-478B-8B9F-AAC1E43E3F83}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{96E9FCD0-BD0D-4DE1-8C32-132181156127}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{978BCDC6-66DD-415E-9274-3DED7784D0D7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{97B4EE35-8DEF-4AFB-ABB5-4E1F04C4E0C3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{984BBD0E-5227-4A78-998B-92A37E3829E1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{991973AA-6CFB-4340-B712-56E82CFE3153}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{994EFD70-1CE0-430D-9A45-1E77603FA78D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{996CC35F-9E80-4511-972E-4B4A66D550CE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9981C723-C08D-4007-A028-7E513E29EE24}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{99A623F7-3019-4DDE-9144-7377D9434556}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{99DB4372-EAC4-435A-9CE6-47724AA92BAE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9A683143-4D52-4B09-9AAB-C43FD8B23F94}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9A6BB7C5-A6DC-451E-BE96-4C4360752599}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9B0B1257-7376-4129-BC26-164498EDDB03}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9BEB1A79-32F5-4491-803D-8F0382A7DEDD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9CD188E7-A3B4-4C13-9C3C-B3605D1C7754}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9CDCEF7B-3D39-4B8A-9327-9C2186B62786}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9EA88FCE-6CB0-40D5-ACC9-925119B098A8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9EAD53FE-7EAC-4408-B3C0-E574D49221E3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9EC49F22-9E07-487B-AEFB-FCD0B595E783}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9F0349CB-A4E2-4370-B44F-D69F48874CFF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{9F0BB53C-8E1A-4518-9578-83C570EED12B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A1598965-31A5-403C-84D5-032563DF29F3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A1911BA4-7551-4380-869C-DBCBD6E2AAC9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A1BC38B8-9DC1-42FD-92BE-D016287880F0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A1E04A83-DA15-4991-989E-1FFB53A6CA8B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A1E42B10-E72D-480F-B187-FC642964AD12}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A2807B29-46A8-4A3D-BF69-05CA596C7EED}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A326F6D4-9CFD-441E-98E3-5293405FC6D8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A3517432-3878-4F8C-A590-10B8256A656C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A3693143-6142-4610-A5AC-1CE5CCA400A8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A3A260BA-DA2B-4EAC-A73A-1A2D5F6008A9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A41B9DB2-085D-4857-A6E4-D43438FB45A6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A61B59F3-8C24-4566-917C-97B108B3BD37}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A6470323-0411-4069-B3E1-3AB403A63D13}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A6559805-EA20-4DA4-99E6-55E336D9AFA5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A6AABE53-DF62-428D-8176-FB837BE591FB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A6EC7917-78BD-4E79-8C77-979961CD782A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A7906250-69C2-487A-9A32-1B298DD4B3FE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A829E412-31FD-4955-93AE-3B95DAC246C0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A8984333-910C-4329-8FC7-7AC0319E7F42}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A90168C2-487D-41BF-80A1-A59D225DC611}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A96116FC-3D3F-4152-B74C-17DC5BBB4DE5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A9C9D651-5D09-44DB-8215-9CCF9CBCAD83}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{A9FBDB0C-4586-45EE-998D-CF58333DF265}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AAF8D00F-F516-4DC1-AD43-9319E5920B32}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ABDF75BA-C399-4FD4-A54C-96CA2F7F5775}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AC26974A-90DC-4CFE-A8F7-7E1E063D4AAE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AC3AC70D-625C-4ED2-BFC3-224BB200EE26}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AC727551-7C07-4B7F-A174-6BD6D797234F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ACD80028-31E3-4344-B9B4-07CE502CB856}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AD87168C-2D16-4C22-99F1-CA685D94FC89}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ADA303B5-920E-4836-A7DE-40A3314B8C30}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ADB0C5E4-B5F6-4BF3-A0C5-A1EA191B090D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ADB9A914-1660-42B8-AA2E-ABDF27314FD9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ADF39408-6D65-4C95-81D8-038DABDC1A2D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AEB6713B-2A8C-4FCB-A22A-49219D719885}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AEC52862-DC1F-4370-A258-B9A580EFE4B5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AEE0479E-1925-4B65-937C-E27F05C7FEE7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AF6D19A3-CFD2-449E-B249-E80DA6272E57}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AF9559DC-7672-4F6B-BEBD-656C4904A5E5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{AFEC0966-B638-45FB-87D3-40A6FF3C4E14}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B05157CC-CCCE-42A2-8F2D-EAB806D4EBA1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B09B2800-8091-40C6-AB83-3DEFB468DED8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B0AFD860-C5E0-402B-8682-830A81635D15}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B0B50547-7BD8-4F26-92CB-5B9458A24E6E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B0F333DB-47F9-490D-BACF-220A866724E7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B1D0A763-CEAA-401D-BDFB-A01A36DB4DB2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B1E8CA7A-ED9A-43CC-857D-90F2E12CE6A9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B252498B-5831-460C-9CD8-B46AF3FD169C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B30FBE00-7663-4D79-954A-9A0E662D56C6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B31B42FA-0455-4B2E-AA0F-39FC1B4E07CD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B3269963-5DD8-42D3-BA66-9C701F1CFA89}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B3E5DD3B-E450-4428-971C-949A0629B875}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B4D95B68-CC68-4619-AD06-CFFAE60C3066}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B554AAEE-064C-40AF-AE0C-C943EF86E3C1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B64647F7-97DD-48F8-8DA1-7F0116D2C314}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B65C04E0-8C71-480F-A672-1112798A54A3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B6660E19-1B11-4234-B532-C8215B729C1C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B6759017-D167-44EA-95FA-934FDA3783E6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B694D25C-8072-48A5-8945-03538AE0C2E6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B6F547E4-F5CA-4DD4-BFEF-D8173BBAB36E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B74E2092-7E24-45C7-96EC-BAF3956CAB78}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B76BDA56-FD58-4B4D-B252-85FBCD1C4B71}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B774BFE8-3E13-43BE-869C-5E08015E7F62}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B7AD4595-9193-4BF1-8DDD-D982488E408C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B81C9A82-8872-4874-ACB4-2E720145636C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B824576A-64D3-41A2-A65D-A50FCD9C196B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B9E186EB-2D7D-4F08-AAB9-1661754EF991}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{B9EB6360-5E5E-4DBB-B473-768258FFD3CD}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BA451994-753C-426D-84BE-1622527F764B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BAA5F1AD-1CEF-4C04-8588-F9425679D0FA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BC4910D3-21A8-4AE9-8BE5-E0C1BCA7E7BF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BC516938-58DA-4E12-8E59-685340C3CA19}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BCAEACA5-BAEE-419D-A4D7-3ABA24763F15}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BCCFAB61-3957-4BC5-9751-17B0C0649FBB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BDA77F19-1B0D-44F7-8979-D5E6EEF7EFD9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BDFF2192-EFE0-4E18-BD81-2A4939DC13E3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BE4F502C-33CD-4E56-9C04-C2CCA7037065}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BE62381F-4F12-4973-A474-77B1FD366B14}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BF59EB76-7B55-4565-B0F1-594D4ABB5D61}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BF7CD79F-2401-4859-A232-E56D7AC03405}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{BF8686D0-B101-4F7C-80BC-38B18EB803D1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C09BB679-84E9-42B6-A75F-C15CA1EAACE0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C0A5EEBF-0D4B-44F8-9C33-D491CF47225A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C1236B2C-C9BA-44D7-B56F-A0212115C8EA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C23A586C-933D-4506-B8CC-9DA1982DF58A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C23C4732-2BD4-4C43-9E42-A397B9657AE2}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C2C9C9BF-EBAD-4B48-887C-B8C99872ED88}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C2CF362A-3E37-4E28-B9CE-A061010E601E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C2DEAB59-7D34-44D4-BC0A-CE500A28ED5A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C33F57D1-04AC-4CDD-B9BF-C7673CD2ECDF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C340F62C-779C-49D3-A31A-942BC0CDAA76}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C4EB1B23-F85A-4641-A7D5-367AE21A6E39}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C4F3F66F-1347-4C49-B1B0-DA1C9781D865}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C5036545-750A-4B1E-BD74-C2E7ACAFAFFE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C51ADCB1-5487-4FE5-9128-9CA34D13A62C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C57799DA-CBE8-4F16-A000-7BBE9EB83C51}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C5D1379B-26BA-4D08-B75D-FF2FC7148F97}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C7111B8C-B643-4CA3-B708-F87F50C445D4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C7395055-7409-46B4-889F-97D4245E3AF8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C792E382-3F4C-4E4E-A7D6-690A2FC71267}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C7BB476F-B734-4125-BED7-3676D718F0D0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C7BFDDDD-3032-4D3F-9CF3-EC136EAAB00A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C7F82A25-7AE2-4C10-B815-F0377FA46855}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C80CB9A7-0236-40C2-BD15-12DE29FDF508}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C859C190-2DA6-4963-B068-3078B218A1B8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C89ACCF0-2360-49DA-BCDA-195A3F0D0530}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C8AF516D-DD28-4FA8-B18A-BEEA62120CAC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{C933C3A1-2D61-425D-8231-78DDA1648CE8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CA1B2FD3-1CDC-4E30-832D-2F08E0F414C0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CA2C2E3B-728F-48C3-9DDB-4319B288B6EC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CA98BEF2-D7C4-4C6D-B1B4-B20B05DD80FF}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CAAD9251-EC2A-412C-92BA-F5DDB8DCB1E1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CAFA6520-3E79-4791-976F-BDA09E1A6588}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CB56ACB7-22BD-48F6-8873-518EC1897C81}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CB6E0A2F-DF4B-4C3A-A88D-70E753E7ADF1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CE46787C-BB2E-45C1-8346-FEC6FB5896E3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CEF326A8-7A63-46EF-97B1-AD3CD2E50E46}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CF4BC3FB-8FBA-4ACA-B96C-BD678C8400CC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{CF9E8476-E53E-4F21-9AD8-D3FF011A25C6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D08CD3F9-B442-4EE9-A72C-B2405ACEB4B0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D18128B9-BBF0-4986-A348-6FFCAD28492C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D1BF06E6-9BB9-4856-9998-08225AB82AD7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D23ECFCD-A759-48A9-9DA6-B998B3F26E22}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D25928A7-BEC8-4DC8-A63B-6B34A548173D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D32D7199-3B34-41D9-8170-637EF7F01B81}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D34B9A39-B6B4-4B44-BDA0-2116CF29A086}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D390F8BF-06AC-4CA4-A123-10AB47C74DDA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D4913585-FB10-469A-9A15-E11543F27239}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D5FFF2A7-E185-4AC4-A4C3-A320EC7BAF77}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D68E9F90-9507-4C6F-A95B-9715CD6B442C}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D6DB928B-CB84-4A78-9810-64D9D1F4BEC3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D806AF35-413B-47AA-AAD9-55B8B0A9790F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D975CDD2-4A9F-4C7E-85B4-52E4367D7773}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{D9F075A5-2C57-407E-B456-4AC558097E27}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DA09C7AA-73C8-4351-B0DD-28AF50340909}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DAC0E5BF-228A-43C3-A267-BE8ECB80B536}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DAED78DA-BB4E-4F31-9F63-C3B61F1E161E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DB554340-3FCB-4C7A-959B-2E7DFC27C696}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DB69E634-E675-4452-AC22-C489114950CE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DBA1DF86-EC01-495E-945F-3E2E516A7F66}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DC238856-1866-4E7B-A69B-07B5791F81B5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DCA008EE-DC0D-4BB8-8131-C2DB7E02BB69}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DD2FFE78-3E22-43A0-8EA0-396846E6A911}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DD8D820E-3D70-4C46-86D9-B156CDDDF56E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DDFA5A89-2CC4-4FC8-A63A-99943A8052E6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DE55B753-D2A6-487F-AD78-60C5DC588808}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DE71997B-C888-4A98-9964-583147059315}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DECE783C-951A-42A5-A810-FEDDF7D7141B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DEEB7B05-FFBB-4FD0-BD77-C082B60DA209}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DF69BF72-7A71-4039-9AC3-1334A56E41A1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DFD3D948-B358-4360-B809-1FD4DB9496CB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DFDC42DE-0E63-487B-AA1A-9DB7B5533194}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{DFE5A0A1-E85C-48E2-80D1-B9E69E114D4A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E062572F-D81D-4AEB-A076-95A40D57FFB4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E062732E-189A-433F-BE76-F6BB2593899A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E0685289-4808-4197-A5F6-EEE111436293}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E113CC48-F0C1-4B4E-B1F2-3C5E9CDF3225}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E11E5D36-BBB5-49E0-9A18-36DF398277D7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E122EEC0-6A7E-47BD-932E-D722C8800D12}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E170C735-CD90-46C1-8FC5-1943A9F51E6F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E1818F54-D257-48CA-92CA-A5ECF500413B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E24BD36D-F823-4B25-BAED-0B78B63D0EA5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E2B6E7EF-10BA-4BB1-9467-CBE9EF978EB3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E345CB96-5267-4512-B7C1-3AE31542D43A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E3D4165E-CE16-4E1B-BAF8-490AFF7E996B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E6FF3DE1-8AD0-4EFD-8B1B-5C2FE6A7CB09}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E7DA20AB-D8B4-46B0-9188-C04A07472156}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E80B87F1-EFBB-4B7B-95AF-0D468010DE7E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E89DDA22-AF1A-4869-A747-3B5167EBBCD1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E8B75664-A40D-4295-B767-81DB3369AAE1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E9542075-E7C4-4568-A7A8-5908503FCDAE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{E9BADA5E-A6C7-463F-B6D1-D3E66C1F3A29}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EA460791-B0AF-423C-AF2A-0C26416269A1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EA8460AB-193A-4263-9F54-AC73E4A8370E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EAD144A3-BFA5-48C6-B69A-0CCA824609EE}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EB898793-4564-49E9-8CD3-10BDE52E21D8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EBC55274-AEA9-47C8-951C-8BF036DC163F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EBE54B03-EFD1-4401-8D34-74495C69EAAC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EBFF3A57-2ADC-4476-83E7-D05E32705646}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EC151525-02FE-4C38-9A14-2EC4C598A336}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EC57B8ED-6EC7-46C9-A1F8-24D80CE9E973}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EC8650E1-019B-401F-BAB3-74E1B748BBDB}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ECA5E5B5-2014-4498-80D2-CF1AF148928E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ECBED516-6F91-48B4-B74F-70593AA1E218}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ED132918-3243-4740-BBF8-9AD412EB72C9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{ED6EE351-1B18-446B-A0AC-D216B435E885}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EDB2AC5C-616D-4481-8BE2-3A2D233B1130}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EDDE1786-6AD9-4F9B-82C4-0FD9F83ABD93}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EE117D34-B3CC-4776-A82E-1BF403C8480E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EE5E3C91-7929-4BAB-9530-BD05E0EFE598}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EF04383C-C877-4614-90D4-45890B35B7E5}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EF295C2E-6A5B-46E5-A328-57846F614178}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EF592E30-1021-40AD-857C-FBB31A8129B9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{EFC9A0B4-6A87-4239-AEDA-2817FF4AABCA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F2817DDD-9D7A-4CD9-A724-CBF8C5A75BC6}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F2F9D7D2-DD1A-4D32-8014-1837138362A0}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F3DFA07E-64E8-4F06-BA88-5CB2EEC0E475}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F46FA893-90ED-4131-A1C7-08D5F1DFD4E3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F498E988-C5AD-4694-BAF3-3EEF263B2875}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F4DB36D4-3BBB-42A0-A9C2-7865EAA471F3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F5E08B4C-4C07-4CBC-8A2A-4482F275412E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F65C7D07-DDEE-425F-94E8-0C58E36A9B9B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F6976689-C57E-4E53-AF57-EE63721D8E51}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F6DA84C3-14A3-45B5-85B2-C7D74E7F73E4}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F7464B4F-BA1C-4ADE-9D43-52F94C68205E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F7850471-1FA1-464A-A2A6-5AA0A4CC715B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F787C894-5906-4F12-9003-2020F722F289}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F82309FA-2554-4683-952C-286CBB2CD7F9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F8757C3E-69EB-4359-B2FF-EE2219461EA7}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F89DF79B-BAC6-4874-8EF3-7948C67C76CA}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F8AC281C-BC8D-49CC-A01A-2F77E4F2007A}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F8F6338B-96CB-413C-96CA-A56F397FB155}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{F9A44D09-0B81-4D96-9CC2-D0CC2643D9F1}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FA43D88C-9EE5-41C2-8635-853706C7037E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FB05BBB4-9122-4F29-A472-526359E20154}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FB1338BE-7AFF-4151-80BF-BDE44D77A19E}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FB242827-0B17-4F97-BD22-B3BB13C2F5D8}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FB51784E-58A3-4B78-85CE-42EEB7D87DEC}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FC058F47-3CAE-4FC4-9967-9F9207BA763B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FC2321B9-294E-46C6-A9EF-EC7A49F9591B}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FC73B086-DE60-4C9B-A289-BF5C71B6A760}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FCE05419-F56D-4B28-ABBD-3D4BCB3AC380}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FD13B2D9-9C77-4367-A478-D52ECF914FD3}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FD2C65AE-EDEA-4EDA-A9D6-F32EB177E033}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FDE65F55-579C-4573-8CF7-4DC8A47D8D2F}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FE0C9D97-0EBC-4A25-AC69-5BB742908FC9}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FE383521-076E-4391-810C-601CC9B8535D}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FE68649B-0F83-456A-9A46-0047FFB1C549}
Successfully deleted: [Empty Folder] C:\Users\zagreb\appdata\local\{FE829520-58A7-49F5-8B11-BD7E53884E76}



~~~ FireFox

Successfully deleted the following from C:\Users\zagreb\AppData\Roaming\mozilla\firefox\profiles\l8936yk6.default\prefs.js

user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=FA2500FFD6377B11&affID=127894&tsp=5160");
user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=FA2500FFD6377B11&affID=127894&tsp=5160");
Emptied folder: C:\Users\zagreb\AppData\Roaming\mozilla\firefox\profiles\l8936yk6.default\minidumps [23 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.04.2014 at 20:01:45.07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


ADW Cleaner:
Code:

# AdwCleaner v3.023 - Bericht erstellt am 01/04/2014 um 19:46:26
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : zagreb - ZAGREB-PC
# Gestartet von : C:\Users\zagreb\Desktop\adwcleaner\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

[#] Ordner Gelöscht : C:\ProgramData\AVG SafeGuard toolbar
[#] Ordner Gelöscht : C:\ProgramData\AVG Secure Search
[#] Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\DSearchLink
Ordner Gelöscht : C:\ProgramData\IePluginService
Ordner Gelöscht : C:\ProgramData\StarApp
Ordner Gelöscht : C:\ProgramData\WPM
[#] Ordner Gelöscht : C:\Program Files (x86)\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Program Files (x86)\PricePeep
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Program Files (x86)\WebConnect
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin
[!] Ordner Gelöscht : C:\Users\zagreb\AppData\Local\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Users\zagreb\AppData\Local\torch
Ordner Gelöscht : C:\Users\zagreb\AppData\Local\webplayer
Ordner Gelöscht : C:\Users\zagreb\AppData\LocalLow\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Users\zagreb\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\zagreb\AppData\Roaming\BitLord
Ordner Gelöscht : C:\Users\zagreb\AppData\Roaming\PerformerSoft
Ordner Gelöscht : C:\Users\zagreb\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\zagreb\Documents\BitLord
Ordner Gelöscht : C:\Users\zagreb\Documents\Optimizer Pro
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
Datei Gelöscht : C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\jid0-O6MIff3eO5dIGf5Tcv8RsJDKxrs@jetpack.xpi
Datei Gelöscht : C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\lightningnewtab@gmail.com.xpi
Datei Gelöscht : C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\pricepeep@getpricepeep.com.xpi
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\zagreb\Desktop\Search.lnk
Datei Gelöscht : C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\invalidprefs.js
Datei Gelöscht : C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\ask-web-search.xml
Datei Gelöscht : C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\buenosearch.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
Datei Gelöscht : C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\user.js
Datei Gelöscht : C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage
Datei Gelöscht : C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_free-youtube-download.softonic.de_0.localstorage-journal
Datei Gelöscht : C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.babylon.com_0.localstorage-journal
Datei Gelöscht : C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www1.delta-search.com_0.localstorage-journal

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403A-B9D2-65C292C39087}]
Wert Gelöscht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [lightningnewtab@gmail.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\niogeckbkdcabhnapjbkeiklablhjoca
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\PricePeep.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\iMesh_V11_en_Setup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\iMeshV11.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\desk365_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\desk365_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iMesh_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iMesh_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iMesh_V11_en_Setup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iMesh_V11_en_Setup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IMPlayCDAudioOnArrival
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IMRipCDAudioOnArrival
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IMShowCDAudioOnArrival
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\IMShowVolumeOnArrival
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\d57dcdcb669ed43
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_super_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_super_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2316C625-B487-4410-A1A5-FF040B65245F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7C28CEF1-A4A6-4B6A-8B97-C44F1267753C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D8CAF2DF-52D3-42CF-9DDB-F4FF828DB4F8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316C625-B487-4410-A1A5-FF040B65245F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2316C625-B487-4410-A1A5-FF040B65245F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{828DC97A-2277-4E10-92A9-4907FA0922A9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2316C625-B487-4410-A1A5-FF040B65245F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{828DC97A-2277-4E10-92A9-4907FA0922A9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7C28CEF1-A4A6-4B6A-8B97-C44F1267753C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Schlüssel Gelöscht : HKCU\Software\AVG SafeGuard toolbar
Schlüssel Gelöscht : HKCU\Software\DataMngr
[#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\torch
Schlüssel Gelöscht : HKCU\Software\WebConnect
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\Software\AVG SafeGuard toolbar
Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\hdcode
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\sweet-pageSoftware
Schlüssel Gelöscht : HKLM\Software\torch
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\WebConnect
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\IB Updater
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Speedchecker Limited
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebConnect
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\1A594BF8F3A4D1C4DB72F3A32B6E7636
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\1A594BF8F3A4D1C4DB72F3A32B6E7636
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - 127.0.0.1:9421;*.local;<local>

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16521

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v28.0 (de)

[ Datei : C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\prefs.js ]

Zeile gelöscht : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "AVG Secure Search");
Zeile gelöscht : user_pref("extensions.enabledAddons", "gmailnoads%40mywebber.com:3.9.1,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:28.0");
Zeile gelöscht : user_pref("extensions.mywebsearch.prevDefaultEngine", "Google");
Zeile gelöscht : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Zeile gelöscht : user_pref("extensions.mywebsearch.prevSelectedEngine", "Google");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=559C51F1-BDBC-4038-8250-DF4ABD418901&n=77fd565b&p2=^HJ^xdm255^YYA^ch&si=CKfm-Z6vy7kCFcm23godLkoAF[...]
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.hp.enabled", true);
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.initialized", true);
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.contextKey", "");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.installDate", "2013091419");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerId", "^HJ^xdm255^YYA^ch");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerSubId", "CKfm-Z6vy7kCFcm23godLkoAFQ");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.success", true);
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.toolbarId", "559C51F1-BDBC-4038-8250-DF4ABD418901");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1379178258346");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.options.defaultSearch", true);
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.options.homePageEnabled", true);
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.options.keywordEnabled", true);
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.options.tabEnabled", true);
Zeile gelöscht : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Zeile gelöscht : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "videodownloadconverter@mindspark.com");
Zeile gelöscht : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");

*************************

AdwCleaner[R0].txt - [25125 octets] - [01/04/2014 19:42:38]
AdwCleaner[S0].txt - [21735 octets] - [01/04/2014 19:46:26]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [21796 octets] ##########

mfg

schrauber 02.04.2014 13:35

Frische FRST Logs bitte, und bitte nicht anhängen.

Crohero 02.04.2014 14:39

Ist erledigt.
Addition:

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
Ran by zagreb at 2014-04-02 15:33:36
Running from C:\Users\zagreb\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

µTorrent (HKLM-x32\...\uTorrent) (Version: 3.1.3 - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Acer System Information (HKLM-x32\...\{72199E33-4F2A-4B7F-8E25-95DDDD50A678}) (Version: 1.0.0 - Acer)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.7.0.2090 - Adobe Systems Incorporated) Hidden
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.)
Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated)
Adobe Reader X (10.1.9) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.9 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.8.638 - Adobe Systems, Inc.)
Advanced Wheel Mouse 6.0.0.002 (HKLM-x32\...\WheelMouse) (Version:  - )
Age of Empires 2 & The Conquerors v1.1 Userpatch AiO version 0.2 (HKLM-x32\...\{0CEC2F82-AEB2-4C4B-B450-62C6CEF159FE}_is1) (Version: 0.2 - line0)
Age of Empires III - The Asian Dynasties (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden
Akamai NetSession Interface (HKCU\...\Akamai) (Version:  - Akamai Technologies, Inc)
All Slots Casino (HKLM-x32\...\allslots) (Version: 16.7.0.242 - )
ANNO 2070 (HKLM-x32\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft)
AntiBrowserSpy (HKLM-x32\...\{F78B5B4F-075A-4C81-AA27-E707861EB5B7}_is1) (Version: 3.6.106 - Abelssoft)
Apple Application Support (HKLM-x32\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}) (Version: 5.1.1.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo Photo Optimizer (HKLM-x32\...\Ashampoo Photo Optimizer_is1) (Version: 3.12.0 - ashampoo GmbH & Co. KG)
Ashampoo Snap (HKLM-x32\...\Ashampoo Snap_is1) (Version: 3.4.0 - ashampoo GmbH & Co. KG)
Ashampoo WinOptimizer 2012 v.8.1.4 (HKLM-x32\...\Ashampoo WinOptimizer 2012_is1) (Version: 8.1.4 - Ashampoo GmbH & Co. KG)
Assassin's Creed ® III (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.00 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassins Creed IV Black Flag Digital Deluxe Edition MULTI-5 1.01 (HKLM-x32\...\Assassins Creed IV Black Flag Digital Deluxe Edition MULTI-5 1.01) (Version:  - )
Assassin's Creed Revelations (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.00 - Ubisoft)
Assassin's Creed Revelations (HKLM-x32\...\Assassin's Creed Revelations_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
AVG 2014 (Version: 14.0.3614 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.3722 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4335 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4355 - AVG Technologies) Hidden
AVI ReComp 1.5.5 (HKLM-x32\...\AVI ReComp) (Version: 1.5.5 - Mateusz Gola (aka Prozac))
AviSynth 2.5 (HKLM-x32\...\Avisynth) (Version:  - )
BalTax 2013 9.0.2 (HKLM-x32\...\5828-3850-9371-1595) (Version: 9.0.2 - Information Factory AG)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.2 - EA Digital Illusions CE AB)
Biet-O-Matic v2.14.12 (HKLM-x32\...\Biet-O-Matic v2.14.12) (Version: 2.14.12 - BOM Development Team)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Borderlands 2_is1) (Version:  - )
Borderlands 2 All in One Update - Pack 1.00 (HKLM-x32\...\Borderlands 2 All in One Update - Pack 1.00) (Version: 1.00 - .x.X.RIDDICK.X.x.)
Borderlands 2 Ultimate Vault Hunter Edition (Game of the Year) 1.5.0 (HKLM-x32\...\Borderlands 2 Ultimate Vault Hunter Edition (Game of the Year) 1.5.0) (Version:  - )
Brother P-touch Address Book 1.1 (HKLM-x32\...\InstallShield_{B2023017-DEE4-44F7-8A71-CA6084BF534C}) (Version: 1.1.100 - Brother Industries, Ltd.)
Brother P-touch Address Book 1.1 (x32 Version: 1.1.100 - Brother Industries, Ltd.) Hidden
Brother P-touch Editor 5.0 (HKLM-x32\...\InstallShield_{DF9A6075-9308-4572-8932-A4316243C4D9}) (Version: 5.0.110 - Brother Industries, Ltd.)
Brother P-touch Editor 5.0 (x32 Version: 5.0.110 - Brother Industries, Ltd.) Hidden
Brother QL-Series Software User's Guide (HKLM-x32\...\InstallShield_{A242CAB2-870C-4AC9-8AFE-34379D9383CD}) (Version: 1.00.0000 - Brother Industries, Ltd.)
Brother QL-Series Software User's Guide (x32 Version: 1.00.0000 - Brother Industries, Ltd.) Hidden
Call of Duty: Black Ops II - Multiplayer (HKLM-x32\...\Steam App 202990) (Version:  - )
Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32\...\Steam App 10190) (Version:  - Infinity Ward)
Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version:  - Infinity Ward)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version:  - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version:  - )
Canon MP Navigator EX 3.0 (HKLM-x32\...\MP Navigator EX 3.0) (Version:  - )
Canon MP560 series Benutzerregistrierung (HKLM-x32\...\Canon MP560 series Benutzerregistrierung) (Version:  - )
Canon MP560 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series) (Version:  - )
Canon Utilities Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon Utilities My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Utilities Solution Menu (HKLM-x32\...\CanonSolutionMenu) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 3.09 - Piriform)
CDDRV_Installer (x32 Version: 1.00.0000 - Logitech) Hidden
Cheat Engine 6.1 (HKLM-x32\...\Cheat Engine 6.1_is1) (Version:  - Dark Byte)
Cheat Engine 6.3 (HKLM-x32\...\Cheat Engine 6.3_is1) (Version:  - Cheat Engine)
COMPUTERBILD Alles-Öffner (HKLM-x32\...\{777C64A3-5909-4DBC-B917-F5AD8DFB9B09}) (Version: 1.0.8 - J3S)
COMPUTERBILD Alles-Öffner (x32 Version: 1.0.8 - J3S) Hidden
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.)
CyberLink Power2Go (x32 Version: 6.1.3802 - CyberLink Corp.) Hidden
CyberLink PowerDVD Copy (HKLM-x32\...\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.5.1306 - CyberLink Corp.)
CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0314 - DT Soft Ltd)
Debugging Tools for Windows (x86) (HKLM-x32\...\{48F95CE7-69D9-4967-81F7-D763CABFBD53}) (Version: 6.10.3.233 - Microsoft Corporation)
Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BED39C88-768C-4345-BF11-58436C984F2A}) (Version:  - Microsoft)
Die*Sims*Mittelalter (HKLM-x32\...\{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}) (Version: 2.0.113 - Electronic Arts)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.8 - DivX, LLC)
Duden-Rechtschreibprüfung PLUS (HKLM-x32\...\{45C5C113-AD43-414B-867D-7C0AF54276CB}) (Version: 8.01 - Bibliographisches Institut GmbH)
Easy Video Splitter 1.28 (HKLM-x32\...\Easy Video Splitter_is1) (Version:  - DoEasier Tech Inc)
Erazer Control Center (HKLM-x32\...\Erazer Control Center_is1) (Version: 1.0.0.8 - Medion AG)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
Explorer Suite III (HKLM\...\Explorer Suite_is1) (Version:  - )
Facebook Video Calling 1.2.0.287 (HKLM-x32\...\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
Far Cry 3 (HKLM-x32\...\{3E7F5A51-7657-43D6-A9B3-C3A21473834B}_is1) (Version: 1.01 - RAF)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Formatwandler 5 (HKLM-x32\...\{CC5A25E6-7564-48FF-0001-D4DD055B2886}) (Version: 5.0.12.711 - S.A.D.)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
FoxTab MP3 Converter (HKCU\...\FoxTab MP3 Converter) (Version:  - ) <==== ATTENTION
FoxTab Music Converter (HKCU\...\FoxTab Music Converter) (Version:  - ) <==== ATTENTION
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free YouTube to MP3 Converter version 3.12.9.725 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.9.725 - DVDVideoSoft Ltd.)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
GamersFirst LIVE! (HKCU\...\GamersFirst LIVE!) (Version:  - GamersFirst)
GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
GIMP 2.8.4 (HKLM\...\GIMP-2_is1) (Version: 2.8.4 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
HL-2270DW (HKLM-x32\...\{E2A97415-BD97-4867-B906-05E39E9EE51F}) (Version: 1.0.5.0 - Brother Industries, Ltd.)
HTC BMP USB Driver (HKLM-x32\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM-x32\...\{6D6664A9-3342-4948-9B7E-034EFE366F0F}) (Version: 3.0.0.003 - HTC Corporation)
HTC Sync (HKLM-x32\...\{6B0A8356-2312-497F-B11D-0839D0BDB7CE}) (Version: 3.0.5439 - HTC)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle)
Java 7 Update 9 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417009FF}) (Version: 7.0.90 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 24 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
KhalInstallWrapper (Version: 4.00.121 - Logitech) Hidden
K-Lite Codec Pack 7.0.0 (Standard) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.0.0 - )
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM-x32\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version: 15.4.5722.2 - Microsoft Corporation)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Litecoin (HKCU\...\Litecoin) (Version: 0.8.5.1 - Litecoin project)
Logitech Desktop Messenger (HKLM-x32\...\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}) (Version: 2.52.18 - Logitech, Inc.)
Logitech SetPoint (HKLM-x32\...\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}) (Version: 4.00 - Logitech)
M2Fish 4.2 (HKLM-x32\...\M2Fish) (Version: 4.2 - ErpeL)
Mafia II (HKLM-x32\...\Mafia II_is1) (Version:  - )
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.141.11 - McAfee, Inc.)
Medal of Honor Deutsch und Uncut Patch 64bit (HKLM-x32\...\Medal of Honor Deutsch und Uncut Patch 64bit) (Version: 1.0.1 - ChrisXPS)
Medal of Honor Deutsch und Uncut Patch 64bit (Version: 1.0.1 - ChrisXPS) Hidden
Medion Home Cinema (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.)
Medion Home Cinema (x32 Version: 8.0.2227 - CyberLink Corp.) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Metin2 (HKLM-x32\...\Metin2_is1) (Version:  - Gameforge 4D GmbH)
Metro 2033 (HKLM-x32\...\Steam App 43110) (Version:  - THQ)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Access MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft DCF MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Excel MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{59E4543A-D49D-4489-B445-473D763C79AF}) (Version: 2.0.672.0 - Microsoft Corporation)
Microsoft Groove MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Lync MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office 32-bit Components 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft OneNote MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{aec97477-921a-4289-985a-9e29506625b6}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Word MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Minecraft1.6.4 (HKLM-x32\...\Minecraft1.6.4) (Version:  - )
Minecraft1.7.2 (HKLM-x32\...\Minecraft1.7.2) (Version:  - )
Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
MSI Afterburner 2.1.0 (HKLM-x32\...\Afterburner) (Version: 2.1.0 - MSI Co., LTD)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Nexon Game Manager (HKLM-x32\...\{289AC7E0-0AEE-4a7b-913C-709D9803D23E}) (Version:  - )
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.44.1 - Black Tree Gaming)
NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.82 - NVIDIA Corporation)
NVIDIA GeForce Experience 1.7.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7.1 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA ShadowPlay 9.3.21 (Version: 9.3.21 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3182 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden
NVIDIA Update 9.3.21 (Version: 9.3.21 - NVIDIA Corporation) Hidden
NVIDIA Update Components (Version: 9.3.21 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.9 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.9 - NVIDIA Corporation)
Open Freely (HKLM\...\{1BF14E04-85DE-480C-9A04-EB36744C66C3}_is1) (Version: 1.0 - Download Freely, LLC)
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 8.5.0.4554 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.6 - Pando Networks Inc.)
PC Tools Registry Mechanic 11.0 (HKLM-x32\...\Registry Mechanic_is1) (Version: 11.0 - PC Tools)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PFPortChecker 1.0.39 (HKLM-x32\...\PFPortChecker) (Version: 1.0.39 - Portforward.com)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6602 - Realtek Semiconductor Corp.)
Red Orchestra 2: Heroes of Stalingrad Beta (HKLM-x32\...\Steam App 104320) (Version:  - )
Registry Repair 4.1.0.388 (HKLM-x32\...\Registry Repair) (Version: 4.1.0.388 - Glarysoft Ltd)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0 - Renesas Electronics Corporation) Hidden
SanDiskSecureAccess_Manager.exe (HKCU\...\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)
Security Task Manager 1.8g (HKLM-x32\...\Security Task Manager) (Version: 1.8g - Neuber Software)
SHIELD Streaming (Version: 1.6.53 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.9.9216 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
SmartPCFixer 4.2 (HKLM\...\{2C5927BD-3F65-4207-8FB5-8EDF638A3511}_is1) (Version: 4.2 - LionSea Software) <==== ATTENTION
Spelling Dictionaries Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-A00000000004}) (Version: 10.0.0 - Adobe Systems Incorporated)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
SUPER © v2011.build.49 (July 1st, 2011) Version v2011.build.49 (HKLM-x32\...\{B93DCF58-AA57-41EC-8D69-B05C66C6312D}_is1) (Version: v2011.build.49 - eRightSoft)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Requirements Lab CYRI (HKLM-x32\...\{E362724E-9320-4946-AF34-874E7B6B2927}) (Version: 6.0.7.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.13.1 - TeamSpeak Systems GmbH)
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.15723 - TeamViewer)
The Elder Scrolls V Skyrim All in One DLC-Pack Deutsche Version Plus Update 11 (1.8.151.0.7) 1.8.151.0.7 (HKLM-x32\...\The Elder Scrolls V Skyrim All in One DLC-Pack Deutsche Version Plus Update 11 (1.8.151.0.7) 1.8.151.0.7) (Version: 1.8.151.0.7 - .x.X.RIDDICK.X.x.)
Total War ROME II (HKLM-x32\...\VG90YWxXYXJST01FSUk=_is1) (Version: 1 - )
TreeSize Free V2.7 (HKLM-x32\...\TreeSize Free_is1) (Version: 2.7 - JAM Software)
Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version:  - Tunngle.net GmbH)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for Microsoft Access 2013 (KB2768008) 64-Bit Edition (HKLM\...\{90150000-0015-0407-1000-0000000FF1CE}_Office15.PROPLUS_{47F15B72-AB15-4B81-BDB8-28B204596EB7}) (Version:  - Microsoft)
Update for Microsoft Access 2013 (KB2827233) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{614E655F-A0ED-435A-8E0C-A81EE4BA7BC7}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2013 (KB2837648) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{5E759A69-FA72-4B3C-BE2F-D1194764D31E}) (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2817678) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{237834D6-FA98-44E1-8739-ABD56DDADC59}) (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2863908) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{259F7CA1-7A87-4E60-85A9-0A55E60FF254}) (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2863908) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{259F7CA1-7A87-4E60-85A9-0A55E60FF254}) (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2863908) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{8D84B988-2A7A-4DB6-A7A5-08DA7B3DE9EE}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{43EB1F58-DAA0-4F61-A4EE-C5651F85A047}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{43EB1F58-DAA0-4F61-A4EE-C5651F85A047}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{76CACE05-7A19-4EAC-87D7-5BFF63AF7CDF}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{76CACE05-7A19-4EAC-87D7-5BFF63AF7CDF}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{79469196-F138-4CF0-8681-F1889D53B56B}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2738038) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{FEFF9FF6-FF61-455E-A8CC-3A1311A657AD}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760224) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3FF4EA9F-3505-4726-A974-6593A968FFCC}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760242) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9406D70B-2D9C-4613-A75A-F35B66BA8AFA}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760267) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CA390537-AA88-450F-A240-5FB4648A124A}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760539) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C8D57F4A-0824-4043-89E7-3C6280B67A47}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760553) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{AC4470FB-8011-4F16-B5D4-E0A34DE10C87}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D8B3D175-48B8-413F-8484-4D81E744B51C}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{526C9E5A-A734-4DC0-B829-ED1CDE793C6B}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2767845) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8587E5B1-6279-4396-B9AC-20B334F4FF88}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2768016) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{30C13416-B124-46AB-9E44-96CEFFA893F9}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817314) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C809B1D6-BD31-4496-BCFE-4567E0854F5F}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{4FD8F672-3206-469C-B9F0-D6E72F7ACAB2}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{1A789784-5825-4B26-BB57-71FF7D3484CB}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{856D47BC-036C-4692-8702-D6CCA8F428D0}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CA0554C4-62FE-4F66-BC87-1EE1EAC675EF}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CA0554C4-62FE-4F66-BC87-1EE1EAC675EF}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817626) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{F33ABF6A-3007-47E8-8E38-506A18E54641}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2826004) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{B38036CB-BAF6-41D4-8810-FD016453ABB9}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827225) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{2A286156-257B-4528-9DB5-B4D4D53211BC}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition (HKLM\...\{90150000-001F-0407-1000-0000000FF1CE}_Office15.PROPLUS_{B5E3E636-7913-4775-BC9B-E4B56F4ED73B}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition (HKLM\...\{90150000-001F-0409-1000-0000000FF1CE}_Office15.PROPLUS_{92833C80-DC88-4A22-8630-407F810EF57B}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}_Office15.PROPLUS_{602346D6-8E2F-4B0E-820A-CD62AC5B0DC9}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition (HKLM\...\{90150000-001F-0410-1000-0000000FF1CE}_Office15.PROPLUS_{869B93B9-E75A-44DE-8AC5-A030A7A21FDD}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827230) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{F2187E8D-C68A-4655-8551-1932878A5581}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827239) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9353CD85-4B19-45C4-8DBA-1391926351F6}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2827239) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9353CD85-4B19-45C4-8DBA-1391926351F6}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2837626) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6EE51F51-57B1-4DC7-96C2-857DB7F0BE93}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2837637) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{0A90C645-3F9A-4CF9-BF62-2609602E3DAB}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2837638) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3A48DE63-607B-4FEA-A862-B52669C4433C}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C4B559C7-AA71-4B77-ACA3-50BEA8B4241B}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{34F51E79-0110-4B49-A245-81319F58453E}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C4B559C7-AA71-4B77-ACA3-50BEA8B4241B}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2850066) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{000791D2-642D-418E-A3E9-96E72D8C67B8}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2850066) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{000791D2-642D-418E-A3E9-96E72D8C67B8}) (Version:  - Microsoft)
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CF6FBF49-BE22-4B98-9D7D-CB2A3236BC44}) (Version:  - Microsoft)
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition (HKLM\...\{90150000-00A1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{05D8C7F6-9A93-4925-B2B3-7D6507AD2FC9}) (Version:  - Microsoft)
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CF6FBF49-BE22-4B98-9D7D-CB2A3236BC44}) (Version:  - Microsoft)
Update for Microsoft Outlook 2013 (KB2863911) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{DF3798F3-F45C-44DA-83B7-229A9EBC9654}) (Version:  - Microsoft)
Update for Microsoft Outlook 2013 (KB2863911) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{DAEE93F9-D258-45E4-AFD3-12AC5ED04693}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2013 (KB2767850) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6FF949A3-1C3F-41C2-9464-933E885ECB53}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2013 (KB2767850) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CA014CB4-B26F-4D27-BF26-C994CC3428E5}) (Version:  - Microsoft)
Update for Microsoft Project 2013 (KB2727085) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BBD4F4CE-65D4-4CEB-AE19-E5296A57AA6C}) (Version:  - Microsoft)
Update for Microsoft Publisher 2013 (KB2837635) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{2837C624-A972-43CF-BCE5-0AE2EFED72E3}) (Version:  - Microsoft)
Update for Microsoft Publisher 2013 (KB2837635) 64-Bit Edition (HKLM\...\{90150000-0019-0407-1000-0000000FF1CE}_Office15.PROPLUS_{E9172003-60C1-447B-9569-7AA9FADE26B0}) (Version:  - Microsoft)
Update for Microsoft SkyDrive Pro (KB2817495) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{A3417E9E-5B94-4BFF-AAA4-933B1AE46306}) (Version:  - Microsoft)
Update for Microsoft SkyDrive Pro (KB2817495) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{A3417E9E-5B94-4BFF-AAA4-933B1AE46306}) (Version:  - Microsoft)
Update for Microsoft SkyDrive Pro (KB2837652) 64-Bit Edition (HKLM\...\{90150000-00BA-0407-1000-0000000FF1CE}_Office15.PROPLUS_{AAB7E20E-E896-495E-AD19-1A0EF515DCED}) (Version:  - Microsoft)
Update for Microsoft SkyDrive Pro (KB2837652) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{AAB7E20E-E896-495E-AD19-1A0EF515DCED}) (Version:  - Microsoft)
Update for Microsoft Visio 2013 (KB2817306) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{F16E7B82-23FE-4054-AB73-EAE53965251C}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2013 (KB2768338) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D1F1940B-94DF-4DCB-BF82-9530D7FBB1BF}) (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{A96FBD56-0376-465E-8A60-7E73B9C51658}) (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{A96FBD56-0376-465E-8A60-7E73B9C51658}) (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{A96FBD56-0376-465E-8A60-7E73B9C51658}) (Version:  - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\...\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version: 15.4.5722.2 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.2 (HKLM-x32\...\VLC media player) (Version: 2.0.2 - VideoLAN)
VobSub 2.23 (HKLM-x32\...\VobSub) (Version: 2.23 - Gabest)
War Rock (HKLM-x32\...\GamersFirst War Rock) (Version:  - GamersFirst)
WarRock (HKLM-x32\...\Warrock EU) (Version:  - )
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM-x32\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
Windows Media Encoder 9 Series (x32 Version: 9.00.2980 - Microsoft Corporation) Hidden
WinRAR 5.00 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
Xfire 2.0 (HKLM-x32\...\{43ADAE00-A4ED-4379-A76D-A1FF5D9D334A}_is1) (Version: 2.0 - Xfire, Inc.)
Xfire Codec (remove only) (HKLM-x32\...\XfireCodec) (Version:  - )
Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.0) (Version: 1.3.2 - Xvid Team)
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Restore Points  =========================

01-04-2014 20:31:47 Datei in Quarantäne Ordner verschieben: Microsoft® Windows Live

==================== Hosts content: ==========================

2009-07-14 04:34 - 2012-11-10 12:36 - 00000851 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 www.google-analytics.com
127.0.0.1 google-analytics.com


==================== Scheduled Tasks (whitelisted) =============

Task: {004886C8-AF56-4D68-9B9B-133507B3546C} - \{34B3CBDA-6636-44F4-BCA5-A00C94929B8A} No Task File
Task: {28085726-3585-4E1A-9F49-D0EAD59CD976} - \{816039DB-B3FA-40A5-A5EF-B38ECCDD7121} No Task File
Task: {293B631B-C4CB-46F9-AB0C-5451D0892208} - \{ACC07C8A-39BF-414F-B5F2-8C03CCE2163C} No Task File
Task: {31749116-94B8-46DC-85C4-A180A44012B7} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: {42C446F4-8F91-47CA-900E-178D136A400A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {45F5BEB4-1213-40AC-98E7-966C4697D17C} - \{C6A51CC2-A4DE-4087-BE7B-8666435796B0} No Task File
Task: {4BDC7808-2AD9-4B8F-82C9-3AF73E23693D} - \{E8C44BAD-7A12-4E1C-A458-F68F8E0EE709} No Task File
Task: {55AC1321-B1C6-4BDB-8E7F-5AB029FD48D8} - \{41D7729F-E604-4EA5-A37B-E83F69D1BFC6} No Task File
Task: {576CADC9-E32B-4713-B9A3-0C1CDF00910C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-15] (Adobe Systems Incorporated)
Task: {5AA12477-64EC-4B4E-9FBA-677496E1CEA6} - \AdobeAAMUpdater-1.0-zagreb-PC-zagreb No Task File
Task: {5CA325B0-8DF5-4BE9-9404-2E8BD0D4C4DF} - \YourFile Update No Task File
Task: {625A603B-4270-4CC1-A7FE-03F9796A8286} - \Desk 365 RunAsStdUser No Task File
Task: {635F647E-A596-490E-A3A3-F69815A46012} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {654A9439-E821-4FFA-BA93-76E34483DB23} - System32\Tasks\Microsoft Office 15 Sync Maintenance for zagreb-PC-zagreb zagreb-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2013-09-10] (Microsoft Corporation)
Task: {69FEFDA6-071E-4185-AB57-28E6B42C0B9D} - \{FFB02AE1-860D-4E7B-9D37-6CF3E3FD572E} No Task File
Task: {7749DF46-4D0D-482E-9DAE-E9FF120EFB70} - \{5D7E3345-7310-4CEE-BCC7-CA8AFE4AC1D5} No Task File
Task: {7ADADFFC-F31F-4540-8B2C-333DB15FDA8B} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {7E9F78E5-ED54-4885-BF73-46D9402EF213} - \FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA No Task File
Task: {7F4C79F6-0629-4D0A-951F-02B0DE86916F} - \RMSmartUpdate No Task File
Task: {8D4A78E9-EAD4-4F2D-BB5F-D00BF0047F47} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-07-05] (Google Inc.)
Task: {8E69BB3F-800D-4814-9D09-448EE733EC73} - \SidebarExecute No Task File
Task: {9761D63A-D7A3-4F7B-8A11-F155EDBE73AE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {97E71C04-08CD-4F24-A7C4-74EC8492C723} - \SpottyFiles Update No Task File
Task: {A43F18A4-6C93-4359-8A2F-91ADB7CF6949} - \Launch HTC Sync Loader No Task File
Task: {B43D034C-717C-4CC0-ABB0-C935B5EEE74F} - \Software Updater No Task File
Task: {B8F5DB32-ECF6-4776-9A65-779C46E47C1A} - \{B7A8EF40-EDA0-4115-87C4-FC1419BC10B9} No Task File
Task: {BF5EEC15-0E23-4018-8392-C9468C94C4C8} - \{458FD381-D3C9-4AF8-8BFF-00F6F4A345F0} No Task File
Task: {C03C3137-4F2D-46A5-8DCE-42BD5F4DEF85} - \{627A0A91-B0D8-42EB-A0B5-60A3F82DFCD0} No Task File
Task: {D3CB96E9-B093-4916-B46A-C3560FE3E051} - \{2ECC1939-87C2-4E96-B5C4-26B4591505EB} No Task File
Task: {DE53E348-3D85-41C0-8AB7-EB49C70989FD} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {DFD0D48D-91BA-4048-8D56-66A4AB967CAE} - \{33D13DE0-1032-49D3-9102-466FE8F60B68} No Task File
Task: {E2BF8265-1EA5-43A3-812E-B8003D0230D0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {E637E36D-4193-422B-833C-1CE554274D5A} - \{886AC7C4-30FF-414D-8DB5-C03573E32B6C} No Task File
Task: {EE553C6D-6035-4045-B30C-607F47D303A2} - \{893CCFA6-9D18-4406-A43D-4C6E506AECF7} No Task File
Task: {F1D6BF43-F886-4387-9822-02BBAC3A4FEF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-07-05] (Google Inc.)
Task: {F2467958-10BA-41E2-B0B3-719906D01992} - \{B83F92D8-FD00-4764-8E2C-356E54CF629A} No Task File
Task: {F2E14D90-D428-4553-98DD-984838A07650} - \FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001Core No Task File
Task: {F6063693-2250-4315-B65A-148E573AD5D3} - \{EAC89B10-3FC4-4B1C-A7EB-82DCB7572A88} No Task File
Task: {F9898964-C6B2-4720-B67B-41BB7B89D678} - \DealPly No Task File
Task: {FD2AD733-52E3-4130-824D-EA97CE5E5505} - \Software Updater Ui No Task File
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001Core.job => C:\Users\zagreb\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job => C:\Users\zagreb\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-11-13 20:38 - 2013-11-11 17:02 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2011-09-25 19:04 - 2009-02-10 18:01 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2010-09-07 17:01 - 2010-09-07 17:01 - 00079872 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2011-09-23 16:04 - 2013-10-22 23:57 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2010-09-08 19:00 - 2010-09-08 19:00 - 00249856 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
2014-03-31 18:46 - 2014-04-01 19:45 - 00319488 _____ () C:\ProgramData\Windows Manager\winmgr.exe
2011-09-25 19:09 - 2007-04-23 04:00 - 00077824 _____ () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
2014-02-15 11:05 - 2014-02-15 11:05 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\0a0467413a424068d1471448ff6ca6cc\IsdiInterop.ni.dll
2011-02-25 02:01 - 2010-11-06 09:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2012-02-15 01:05 - 2012-02-15 01:37 - 11796096 _____ () C:\Users\zagreb\AppData\Roaming\SanDisk\My Vaults\dmBackup.dll
2010-09-08 19:00 - 2010-09-08 19:00 - 00516599 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll
2010-09-08 19:00 - 2010-09-08 19:00 - 00094208 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll
2010-09-08 19:00 - 2010-09-08 19:00 - 00348160 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\HtcDetect.dll
2010-09-08 19:00 - 2010-09-08 19:00 - 00139264 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll
2010-09-08 19:00 - 2010-09-08 19:00 - 00139264 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll
2010-09-08 19:00 - 2010-09-08 19:00 - 01507328 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dll
2014-04-02 15:26 - 2014-04-02 15:26 - 00098816 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32api.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00110080 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\pywintypes27.dll
2014-04-02 15:26 - 2014-04-02 15:26 - 00364544 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\pythoncom27.dll
2014-04-02 15:26 - 2014-04-02 15:26 - 00044032 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\_socket.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 01157120 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\_ssl.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00320512 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32com.shell.shell.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00712192 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\_hashlib.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 01175040 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\wx._core_.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00805888 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\wx._gdi_.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00811008 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\wx._windows_.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 01062400 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\wx._controls_.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00735232 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\wx._misc_.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00128512 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\_elementtree.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00127488 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\pyexpat.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00557056 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\pysqlite2._sqlite.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00087040 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\_ctypes.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00119808 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32file.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00108544 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32security.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00018432 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32event.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00038912 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32inet.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00122368 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\wx._wizard.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00070656 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\wx._html2.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00026624 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\_multiprocessing.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00010240 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\select.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00024064 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32pipe.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00686080 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\unicodedata.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00025600 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32pdh.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00525640 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\windows._lib_cacheinvalidation.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00011264 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32crypt.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00035840 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32process.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00017408 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32profile.pyd
2014-04-02 15:26 - 2014-04-02 15:26 - 00022528 _____ () C:\Users\zagreb\AppData\Local\Temp\_MEI32122\win32ts.pyd

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============

MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: Browser Manager => 2
MSCONFIG\Services: BrYNSvc => 3
MSCONFIG\Services: BstHdAndroidSvc => 2
MSCONFIG\Services: BstHdLogRotatorSvc => 2
MSCONFIG\Services: Fax => 3
MSCONFIG\Services: IB Updater => 2
MSCONFIG\Services: SbieSvc => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: TeamViewer7 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk => C:\Windows\pss\GamersFirst LIVE!.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^zagreb^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\Windows\pss\An OneNote senden.lnk.Startup
MSCONFIG\startupfolder: C:^Users^zagreb^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk => C:\Windows\pss\GamersFirst LIVE!.lnk.Startup
MSCONFIG\startupreg: AdobeBridge => "D:\Programme\photo best\Adobe Bridge CS5.1\Bridge.exe" -stealth
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon
MSCONFIG\startupreg: chromium => C:\Users\zagreb\AppData\Local\Torch\Application\torch.exe --no-startup-window
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: Facebook Update => "C:\Users\zagreb\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: facemoods => "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: msnmsgr => ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: RGSC => D:\Games\GTA 4\game\Rockstar Games Social Club\RGSCLauncher.exe /silent
MSCONFIG\startupreg: SandboxieControl => "D:\Programme\Sandboxie\SbieCtrl.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "D:\steam\steam.exe" -silent
MSCONFIG\startupreg: SweetIM => C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
MSCONFIG\startupreg: uTorrent => "D:\Programme\Torrent\uTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: Xvid => D:\Programme\DivX\CheckUpdate.exe

==================== Faulty Device Manager Devices =============

Name: avast! Firewall NDIS Filter Miniport
Description: avast! Firewall NDIS Filter Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ALWIL Software
Service: aswNdis
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: avast! Firewall NDIS Filter Miniport
Description: avast! Firewall NDIS Filter Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ALWIL Software
Service: aswNdis
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter
Description: Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek Semiconductor Corp.
Service: RTL8192su
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/02/2014 03:27:50 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/01/2014 10:23:48 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/01/2014 08:22:48 PM) (Source: Office 2013 Licensing Service) (User: )
Description: Subscription licensing service failed: -1073418154

Error: (04/01/2014 08:15:09 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (04/02/2014 03:29:22 PM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (04/02/2014 03:27:00 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (04/02/2014 03:26:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "vToolbarUpdater18.0.5" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/02/2014 03:25:59 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "AVG WatchDog" wurde aufgrund folgenden Fehlers nicht gestartet:
%%5

Error: (04/02/2014 03:25:59 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "AVGIDSAgent" wurde aufgrund folgenden Fehlers nicht gestartet:
%%5

Error: (04/01/2014 08:15:08 PM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (04/01/2014 08:13:47 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (04/01/2014 08:12:47 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "vToolbarUpdater18.0.5" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/01/2014 08:12:46 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "AVG WatchDog" wurde aufgrund folgenden Fehlers nicht gestartet:
%%5

Error: (04/01/2014 08:12:46 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "AVGIDSAgent" wurde aufgrund folgenden Fehlers nicht gestartet:
%%5


Microsoft Office Sessions:
=========================
Error: (04/02/2014 03:27:50 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/01/2014 10:23:48 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestD:\Games\Warrock\hacks\esetsmartinstaller_deu.exe

Error: (04/01/2014 08:22:48 PM) (Source: Office 2013 Licensing Service)(User: )
Description: Subscription licensing service failed: -1073418154

Error: (04/01/2014 08:15:09 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


==================== Memory info ===========================

Percentage of memory in use: 27%
Total physical RAM: 8173.7 MB
Available physical RAM: 5957.07 MB
Total Pagefile: 16345.57 MB
Available Pagefile: 14067.79 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (Boot) (Fixed) (Total:58.53 GB) (Free:3.43 GB) NTFS
Drive d: (Data) (Fixed) (Total:891 GB) (Free:62.78 GB) NTFS
Drive e: (Recover) (Fixed) (Total:40.51 GB) (Free:21.97 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 60 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=59 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=1 GB) - (Type=12)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 6B4F62F8)
Partition 1: (Not Active) - (Size=891 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=41 GB) - (Type=07 NTFS)

==================== End Of Log ============================



FRST:


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by zagreb (administrator) on ZAGREB-PC on 02-04-2014 15:33:23
Running from C:\Users\zagreb\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Gemalto N.V.) C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corp.) C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\ProgramData\Windows Manager\winmgr.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MsoSync.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-12-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1064224 2013-11-14] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [WheelMouse] - C:\Advanced Wheel Mouse\wh_exec.exe [98304 2007-11-10] ()
HKLM-x32\...\Run: [SSDMonitor] - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-02-03] (PC Tools)
HKLM-x32\...\Run: [HTC Sync Loader] - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [AVG_UI] - "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer [155648 2012-01-31] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
HKU\.DEFAULT\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-07-05] (Google Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [SanDiskSecureAccess_Manager.exe] - C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-02-15] (Gemalto N.V.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [AVG-Secure-Search-Update_0214c] - C:\Users\zagreb\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=1ed79a26778147d0adbbbd2b2ba3efdd-1416bf5a74d896ef371f57add3e8e9966d2fe943 /CMPID=0214c
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Akamai NetSession Interface] - C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Winlogon] - C:\Users\zagreb\AppData\Roaming\svchost.exe [196608 2014-04-01] ()
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Windows Applicatiion] - C:\Users\zagreb\AppData\Roaming\svchost.exe [196608 2014-04-01] ()
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Windows Application] - C:\Users\zagreb\AppData\Roaming\svchost.exe [196608 2014-04-01] ()
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [MicroUpdate] - C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe [674304 2014-04-01] (Microsoft Corp.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\RunOnce: [WindowsUpdate] - C:\ProgramData\Windows Manager\winmgr.exe [319488 2014-04-01] ()
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <===== ATTENTION
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
IFEO\AvastSvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\AvastUI.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avcenter.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avconfig.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgcsrvx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgidsagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgnt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgrsx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avguard.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgwdsvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avp.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avscan.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\bdagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ccuac.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ComboFix.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\egui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\hijackthis.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\instup.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\keyscrambler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbam.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbampt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamscheduler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamservice.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MpCmdRun.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MSASCui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MsMpEng.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\msseces.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\rstrui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\spybotsd.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\wireshark.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\zlclient.exe: [Debugger] C:\Windows\system32\Microsoft.com

==================== Internet (Whitelisted) ====================

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost64.dll (BestOffers)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost.dll (BestOffers)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1

FireFox:
========
FF ProfilePath: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default
FF Homepage: https://www.google.ch/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\zagreb\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\gmailnoads@mywebber.com.xpi [2013-11-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-04-23]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Google Drive) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (convert2mp3.net Online Video Converter) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhklmhadmpdfcgimodhdapodbllnjjll [2013-09-07]
CHR Extension: (YouTube) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (McAfee Security Scan+) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-22]
CHR Extension: (Battlefield Heroes) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-10-22]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-12-18]
CHR Extension: (Google-Suche) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (DVDVideoSoft) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-08-13]
CHR Extension: (Google Mail) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\zagreb\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-03-30]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\zagreb\AppData\Local\Temp\tbch.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-02-03] (PC Tools)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-22] ()
S3 TunngleService; D:\Games\tunngle lan game crack\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH)
S2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe" [X]
S2 avgwd; "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe" [X]
S2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [49952 2014-03-21] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-08] (DT Soft Ltd)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 XFDriver64; C:\Program Files (x86)\Xfire2\XFDriver64.sys [17160 2013-03-14] (XFire)
U3 DfSdkS;
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va005; \??\C:\Users\zagreb\AppData\Local\Temp\005DD1A.tmp [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-01 22:30 - 2014-04-01 22:35 - 00000000 ____D () C:\ProgramData\SecTaskMan
2014-04-01 22:29 - 2014-04-01 22:30 - 00000000 ____D () C:\Program Files (x86)\Security Task Manager
2014-04-01 22:25 - 2014-04-01 22:25 - 00000000 ____D () C:\Users\zagreb\Documents\MSDCSC
2014-04-01 21:58 - 2014-04-01 21:58 - 00196608 ___SH () C:\Users\zagreb\AppData\Roaming\svchost.exe
2014-04-01 20:01 - 2014-04-01 20:01 - 00072310 _____ () C:\Users\zagreb\Desktop\JRT.txt
2014-04-01 20:00 - 2014-04-01 20:00 - 00000000 ____D () C:\Windows\ERUNT
2014-04-01 19:47 - 2014-04-01 19:47 - 00000874 _____ () C:\Windows\PFRO.log
2014-04-01 19:42 - 2014-04-01 19:46 - 00000000 ____D () C:\AdwCleaner
2014-04-01 19:40 - 2014-04-01 19:54 - 00000000 ____D () C:\Users\zagreb\Desktop\adwcleaner
2014-04-01 17:04 - 2014-04-01 17:04 - 00067775 _____ () C:\Users\zagreb\Desktop\Addition.txt
2014-04-01 17:03 - 2014-04-02 15:33 - 00029476 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-04-01 17:03 - 2014-04-02 15:33 - 00000000 ____D () C:\FRST
2014-04-01 17:02 - 2014-04-01 16:12 - 02157056 _____ (Farbar) C:\Users\zagreb\Desktop\FRST64.exe
2014-04-01 16:50 - 2014-04-02 15:26 - 00000952 _____ () C:\Windows\setupact.log
2014-04-01 16:50 - 2014-04-01 16:50 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-31 23:17 - 2014-04-02 15:30 - 00117924 _____ () C:\Windows\WindowsUpdate.log
2014-03-31 18:54 - 2014-03-31 18:54 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-31 18:46 - 2014-04-01 19:45 - 00000000 __SHD () C:\ProgramData\Windows Manager
2014-03-31 18:46 - 2014-03-30 17:03 - 00249856 __RSH () C:\Windows\SysWOW64\Microsoft.com
2014-03-31 18:46 - 2014-03-30 17:03 - 00249856 __RSH () C:\ProgramData\Microsoft.com
2014-03-30 21:59 - 2014-04-02 15:26 - 00000000 ___RD () C:\Users\zagreb\Google Drive
2014-03-30 21:59 - 2014-03-30 21:59 - 00001723 _____ () C:\Users\zagreb\Desktop\Google Drive.lnk
2014-03-30 14:09 - 2014-03-30 14:09 - 00000182 _____ () C:\Users\Public\Desktop\WarRock.url
2014-03-30 14:06 - 2014-03-30 14:06 - 00000000 ____D () C:\ProgramData\NexonEU
2014-03-30 12:11 - 2014-03-30 12:11 - 00001990 _____ () C:\Users\Public\Desktop\BalTax 2013.lnk
2014-03-30 12:06 - 2014-03-30 12:07 - 61221984 _____ (Information Factory AG) C:\Users\zagreb\BalTax2013_installieren.exe
2014-03-29 13:13 - 2014-03-29 18:54 - 00000056 _____ () C:\Program Files (x86)GamersFirstWar Rock2222222222222.txt
2014-03-29 13:07 - 2014-03-29 13:08 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Akamai
2014-03-20 00:26 - 2014-04-01 19:47 - 00000000 ____D () C:\Users\zagreb\AppData\Local\AVG SafeGuard toolbar
2014-03-20 00:26 - 2014-03-21 12:52 - 00049952 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-03-20 00:26 - 2014-03-21 12:52 - 00003743 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-03-15 16:25 - 2014-03-30 13:45 - 00000000 ____D () C:\Users\zagreb\Documents\Steuerfaelle_BalTax 2013
2014-03-15 16:25 - 2014-03-30 12:11 - 00000000 ____D () C:\Program Files (x86)\BalTax 2013
2014-03-15 16:23 - 2014-03-15 16:24 - 61167712 _____ (Information Factory AG) C:\Users\zagreb\Downloads\prgr-baltax-2013-v.9.0.1-windows-mjre.exe
2014-03-15 09:42 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-15 09:42 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-15 09:42 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-15 09:42 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-15 09:41 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-15 09:41 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-15 09:41 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-15 09:41 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-15 09:41 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-15 09:41 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-15 09:41 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-15 09:41 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-15 09:41 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-15 09:41 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-15 09:41 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-15 09:41 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-15 09:41 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-15 09:41 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-15 09:41 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-15 09:41 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-15 09:41 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-15 09:41 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-15 09:41 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-15 09:41 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-15 09:41 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-15 09:41 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-15 09:41 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-15 09:41 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-15 09:41 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-15 09:41 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-15 09:41 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-15 09:41 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-15 09:41 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-15 09:41 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-15 09:41 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-15 09:41 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-15 09:41 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-15 09:41 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-15 09:41 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-15 09:41 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-15 09:41 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-15 09:41 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-15 09:41 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-15 09:41 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-15 09:41 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-15 09:41 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-15 09:41 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-15 09:41 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll

==================== One Month Modified Files and Folders =======

2014-04-02 15:33 - 2014-04-01 17:03 - 00029476 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-04-02 15:33 - 2014-04-01 17:03 - 00000000 ____D () C:\FRST
2014-04-02 15:32 - 2011-02-10 21:25 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-04-02 15:32 - 2011-02-10 21:25 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-04-02 15:32 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-02 15:30 - 2014-03-31 23:17 - 00117924 _____ () C:\Windows\WindowsUpdate.log
2014-04-02 15:27 - 2014-02-25 21:50 - 00005128 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for zagreb-PC-zagreb zagreb-PC
2014-04-02 15:26 - 2014-04-01 16:50 - 00000952 _____ () C:\Windows\setupact.log
2014-04-02 15:26 - 2014-03-30 21:59 - 00000000 ___RD () C:\Users\zagreb\Google Drive
2014-04-02 15:26 - 2011-07-06 20:45 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Adobe
2014-04-02 15:26 - 2011-07-05 20:56 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-02 15:25 - 2013-05-24 21:06 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-04-02 15:25 - 2011-10-23 12:33 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job
2014-04-02 15:25 - 2011-03-22 21:00 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-02 15:25 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-01 22:35 - 2014-04-01 22:30 - 00000000 ____D () C:\ProgramData\SecTaskMan
2014-04-01 22:30 - 2014-04-01 22:29 - 00000000 ____D () C:\Program Files (x86)\Security Task Manager
2014-04-01 22:25 - 2014-04-01 22:25 - 00000000 ____D () C:\Users\zagreb\Documents\MSDCSC
2014-04-01 22:22 - 2011-07-05 20:56 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-01 21:58 - 2014-04-01 21:58 - 00196608 ___SH () C:\Users\zagreb\AppData\Roaming\svchost.exe
2014-04-01 21:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-04-01 21:41 - 2012-04-08 20:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-01 20:20 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-01 20:20 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-01 20:01 - 2014-04-01 20:01 - 00072310 _____ () C:\Users\zagreb\Desktop\JRT.txt
2014-04-01 20:00 - 2014-04-01 20:00 - 00000000 ____D () C:\Windows\ERUNT
2014-04-01 19:54 - 2014-04-01 19:40 - 00000000 ____D () C:\Users\zagreb\Desktop\adwcleaner
2014-04-01 19:47 - 2014-04-01 19:47 - 00000874 _____ () C:\Windows\PFRO.log
2014-04-01 19:47 - 2014-03-20 00:26 - 00000000 ____D () C:\Users\zagreb\AppData\Local\AVG SafeGuard toolbar
2014-04-01 19:46 - 2014-04-01 19:42 - 00000000 ____D () C:\AdwCleaner
2014-04-01 19:45 - 2014-03-31 18:46 - 00000000 __SHD () C:\ProgramData\Windows Manager
2014-04-01 17:04 - 2014-04-01 17:04 - 00067775 _____ () C:\Users\zagreb\Desktop\Addition.txt
2014-04-01 17:03 - 2013-11-16 18:24 - 00000000 ____D () C:\Users\zagreb\Desktop\Replikation
2014-04-01 16:50 - 2014-04-01 16:50 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-01 16:12 - 2014-04-01 17:02 - 02157056 _____ (Farbar) C:\Users\zagreb\Desktop\FRST64.exe
2014-03-31 19:11 - 2011-12-13 22:28 - 00000000 ____D () C:\Users\zagreb\Desktop\Brunc
2014-03-31 19:00 - 2013-12-01 13:07 - 00002139 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-03-31 19:00 - 2013-01-17 20:09 - 00001274 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-03-31 19:00 - 2011-07-05 21:09 - 00000995 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-03-31 18:54 - 2014-03-31 18:54 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-31 18:46 - 2014-02-26 16:12 - 00000000 ____D () C:\Users\zagreb\Desktop\BZG
2014-03-31 18:35 - 2012-03-08 21:24 - 00000000 ____D () C:\Users\zagreb\AppData\Local\PMB Files
2014-03-31 17:19 - 2013-09-23 18:47 - 00000000 ____D () C:\ProgramData\MFAData
2014-03-31 17:04 - 2012-03-08 21:24 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-31 16:08 - 2013-09-23 18:52 - 00001022 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-03-30 21:59 - 2014-03-30 21:59 - 00001723 _____ () C:\Users\zagreb\Desktop\Google Drive.lnk
2014-03-30 21:59 - 2011-07-05 20:59 - 00000000 ____D () C:\Users\zagreb
2014-03-30 18:42 - 2011-07-05 20:59 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Google
2014-03-30 17:03 - 2014-03-31 18:46 - 00249856 __RSH () C:\Windows\SysWOW64\Microsoft.com
2014-03-30 17:03 - 2014-03-31 18:46 - 00249856 __RSH () C:\ProgramData\Microsoft.com
2014-03-30 14:09 - 2014-03-30 14:09 - 00000182 _____ () C:\Users\Public\Desktop\WarRock.url
2014-03-30 14:06 - 2014-03-30 14:06 - 00000000 ____D () C:\ProgramData\NexonEU
2014-03-30 13:45 - 2014-03-15 16:25 - 00000000 ____D () C:\Users\zagreb\Documents\Steuerfaelle_BalTax 2013
2014-03-30 12:11 - 2014-03-30 12:11 - 00001990 _____ () C:\Users\Public\Desktop\BalTax 2013.lnk
2014-03-30 12:11 - 2014-03-15 16:25 - 00000000 ____D () C:\Program Files (x86)\BalTax 2013
2014-03-30 12:07 - 2014-03-30 12:06 - 61221984 _____ (Information Factory AG) C:\Users\zagreb\BalTax2013_installieren.exe
2014-03-30 08:49 - 2014-02-15 11:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 23:45 - 2011-08-13 12:29 - 00000000 ____D () C:\Users\zagreb\AppData\Roaming\Skype
2014-03-29 22:17 - 2013-10-11 21:57 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-29 22:17 - 2013-10-11 21:57 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-29 18:54 - 2014-03-29 13:13 - 00000056 _____ () C:\Program Files (x86)GamersFirstWar Rock2222222222222.txt
2014-03-29 13:08 - 2014-03-29 13:07 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Akamai
2014-03-26 21:10 - 2013-03-19 22:05 - 00000000 ____D () C:\Users\zagreb\AppData\Roaming\vlc
2014-03-26 20:24 - 2011-09-28 16:00 - 00000000 ____D () C:\ProgramData\CanonIJ
2014-03-26 20:24 - 2011-09-25 19:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-03-26 14:31 - 2012-10-28 18:34 - 00000000 ____D () C:\Users\zagreb\Desktop\Mama
2014-03-21 12:52 - 2014-03-20 00:26 - 00049952 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-03-21 12:52 - 2014-03-20 00:26 - 00003743 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-03-18 18:33 - 2013-08-15 22:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 18:32 - 2011-02-10 22:56 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-18 18:31 - 2011-08-29 16:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-15 16:25 - 2012-05-18 20:04 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Information Factory
2014-03-15 16:24 - 2014-03-15 16:23 - 61167712 _____ (Information Factory AG) C:\Users\zagreb\Downloads\prgr-baltax-2013-v.9.0.1-windows-mjre.exe
2014-03-15 14:05 - 2013-09-24 18:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-15 14:05 - 2012-04-08 20:24 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-15 14:05 - 2011-07-13 21:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-15 14:03 - 2009-07-14 06:45 - 05015560 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-15 14:02 - 2013-03-13 23:35 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-15 14:02 - 2013-03-13 23:35 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-15 10:04 - 2009-07-14 04:34 - 00000478 _____ () C:\Windows\win.ini
2014-03-14 17:09 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-06 21:25 - 2011-08-13 12:29 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 21:25 - 2011-08-13 12:29 - 00000000 ____D () C:\ProgramData\Skype

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.6408.dll
C:\Users\zagreb\BalTax2013_installieren.exe


Some content of TEMP:
====================
C:\Users\zagreb\AppData\Local\Temp\000562e7.exe
C:\Users\zagreb\AppData\Local\Temp\000dc36d.exe
C:\Users\zagreb\AppData\Local\Temp\00607e35.exe
C:\Users\zagreb\AppData\Local\Temp\0068cf32.exe
C:\Users\zagreb\AppData\Local\Temp\00796e4e.exe
C:\Users\zagreb\AppData\Local\Temp\abcs.exe
C:\Users\zagreb\AppData\Local\Temp\androo.exe
C:\Users\zagreb\AppData\Local\Temp\http2.exe
C:\Users\zagreb\AppData\Local\Temp\i4jdel0.exe
C:\Users\zagreb\AppData\Local\Temp\NGMDll.dll
C:\Users\zagreb\AppData\Local\Temp\NGMResource.dll
C:\Users\zagreb\AppData\Local\Temp\NGMSetup.exe
C:\Users\zagreb\AppData\Local\Temp\po.exe
C:\Users\zagreb\AppData\Local\Temp\Quarantine.exe
C:\Users\zagreb\AppData\Local\Temp\unicows.dll
C:\Users\zagreb\AppData\Local\Temp\updaa.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-30 15:20

==================== End Of Log ============================

--- --- ---

--- --- ---


Dankeschön :daumenhoc

schrauber 03.04.2014 09:54


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme? :)

Crohero 07.04.2014 10:37

Liste der Anhänge anzeigen (Anzahl: 3)
Hallo Schrauber,

konnte einige Tage nicht antworten, da ich in Berlin war.

Hier das Logfile von Eset:

Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=834b1acfa536dc48aed5e8c64e030e9c
# engine=17742
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-03 11:09:21
# local_time=2014-04-04 01:09:21 (+0100, Mitteleuropäische Sommerzeit)
# country="Switzerland"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1023 16777215 0 0 0 0 0 0
# compatibility_mode=5893 16776574 100 94 2351359 148196411 0 0
# scanned=413754
# found=135
# cleaned=0
# scan_time=20992
sh=C2422D604E0D4A84E084EEC8748C5BCD2F471888 ft=1 fh=c12d3f2d2b969b92 vn="MSIL/TrojanDownloader.Agent.OR trojan" ac=I fn="C:\ProgramData\Microsoft.com"
sh=C2422D604E0D4A84E084EEC8748C5BCD2F471888 ft=1 fh=c12d3f2d2b969b92 vn="MSIL/TrojanDownloader.Agent.OR trojan" ac=I fn="C:\Users\All Users\Microsoft.com"
sh=FCC3251CCF9EEF0F6CD3819E98C270294F9DAAA7 ft=1 fh=45230079646557bb vn="a variant of MSIL/Injector.DGF trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\000562e7.exe"
sh=672376760A1DCC5B5AAE33A5C89228CD134D962D ft=1 fh=1b939c0870032837 vn="a variant of MSIL/Injector.DGF trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\000dc36d.exe"
sh=E0B43887460D35F7C37E2867F2CF569B92FDCFE6 ft=1 fh=8514c9e5ec143825 vn="a variant of MSIL/Injector.DGF trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\00607e35.exe"
sh=CC7791C58314E24F097A065CF1325D57AB5DA921 ft=1 fh=02e80b8a320e6e82 vn="Win32/AutoRun.Agent.AFJ worm" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\0068cf32.exe"
sh=FBD71A427E3D2952CCDCBC0C7FADAB71403B57A9 ft=1 fh=f72238a6ed3a48ad vn="Win32/Fynloski.AA trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\00796e4e.exe"
sh=C2422D604E0D4A84E084EEC8748C5BCD2F471888 ft=1 fh=c12d3f2d2b969b92 vn="MSIL/TrojanDownloader.Agent.OR trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\4430"
sh=C2422D604E0D4A84E084EEC8748C5BCD2F471888 ft=1 fh=c12d3f2d2b969b92 vn="MSIL/TrojanDownloader.Agent.OR trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\6324"
sh=BE617A0A607C21D40B856AA1808B30A7177F93C0 ft=1 fh=bc29c6f0e852b459 vn="MSIL/TrojanDownloader.Agent.OR trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\7454"
sh=67F736E382141E3A6F540B0BE9792A63F330D269 ft=1 fh=b93872c9800a5709 vn="Win32/TrojanDownloader.Wauchos.A trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\abcs.exe"
sh=930970447931F02FCCA79BF0DF649C61E3EA0F6A ft=1 fh=6811dbfdab313952 vn="a variant of MSIL/Injector.DGF trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\androo.exe"
sh=975A0E18B66B3F568CAD5836FF4718149E93A0B8 ft=1 fh=176e2025b4754c4d vn="a variant of MSIL/Injector.DGF trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\po.exe"
sh=BFC64421AF986655B05C07877334A4D141770125 ft=1 fh=7d89ff5588216f19 vn="a variant of MSIL/Injector.DGF trojan" ac=I fn="C:\Users\zagreb\AppData\Local\Temp\updaa.exe"
sh=E0B43887460D35F7C37E2867F2CF569B92FDCFE6 ft=1 fh=8514c9e5ec143825 vn="a variant of MSIL/Injector.DGF trojan" ac=I fn="C:\Users\zagreb\AppData\Roaming\svchost.exe"
sh=06860151986F664F5B0EF5D8BC3042909B5C3E28 ft=0 fh=0000000000000000 vn="VBS/CoinMiner.AE trojan" ac=I fn="C:\Users\zagreb\AppData\Roaming\WindowsHelp\killer.bat"
sh=FBD71A427E3D2952CCDCBC0C7FADAB71403B57A9 ft=1 fh=f72238a6ed3a48ad vn="Win32/Fynloski.AA trojan" ac=I fn="C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe"
sh=44D175A6BB9C43B6DBFB42209AEE50B5FF4E3E2A ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAH trojan" ac=I fn="C:\Users\zagreb\Downloads\BordL2+28Tr-LNG_v1.5.xx.rar.vir"
sh=930970447931F02FCCA79BF0DF649C61E3EA0F6A ft=1 fh=6811dbfdab313952 vn="a variant of MSIL/Injector.DGF trojan" ac=I fn="C:\Users\zagreb\Local Settings\Temp\msaywrqi.scr"
sh=67F736E382141E3A6F540B0BE9792A63F330D269 ft=1 fh=b93872c9800a5709 vn="Win32/TrojanDownloader.Wauchos.A trojan" ac=I fn="C:\Users\zagreb\Local Settings\Temp\msirowwuu.pif"
sh=C2422D604E0D4A84E084EEC8748C5BCD2F471888 ft=1 fh=c12d3f2d2b969b92 vn="MSIL/TrojanDownloader.Agent.OR trojan" ac=I fn="C:\Windows\System32\Microsoft.com"
sh=C2422D604E0D4A84E084EEC8748C5BCD2F471888 ft=1 fh=c12d3f2d2b969b92 vn="MSIL/TrojanDownloader.Agent.OR trojan" ac=I fn="C:\Windows\SysWOW64\Microsoft.com"
sh=CDF84B698C5A2AF7EC0BF0A4073DD397EEC0F8ED ft=1 fh=029942c1fb98a746 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="D:\$RECYCLE.BIN\S-1-5-21-3224943155-1584954436-3819599901-1001\$RA97UO9.dll.vir"
sh=73A9729E184CCA61231B7C8D9C5B99A853A565F9 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\Games\FarCry3\Far Cry 3\Far Cry 3 Multiplayer Crack v1.05 All No-DVD.rar"
sh=A0F595B37A3BE34612D90A1388693BE6BC38F7AB ft=1 fh=82fb424c5a90beff vn="a variant of Generik.KQMZJAY trojan" ac=I fn="D:\Games\m2p\InviDropper (Vista & 7).dll.vir"
sh=FE96E544AB316478CE16398A13E5DBF32EC4089B ft=1 fh=f42184cedafe93d8 vn="a variant of Generik.BJWOCRA trojan" ac=I fn="D:\Games\m2p\InviDropper (XP).dll"
sh=349B68E402EC3AC2598CEBEA9A10BB71FE701417 ft=1 fh=778871d9ee5c38a6 vn="a variant of Generik.JANUPVC trojan" ac=I fn="D:\Games\m2p\PickUp-Bot (Vista & 7).dll.vir"
sh=9374ADC2A70173B14A88981C89C2F9CCC35E7526 ft=1 fh=778871d9799bff63 vn="a variant of Generik.EEFABPC trojan" ac=I fn="D:\Games\m2p\PickUp-Bot (XP).dll.vir"
sh=A63769988B6D28A769483CE99120A0B12C21F934 ft=1 fh=cae7910b5b08d5e1 vn="a variant of Generik.JLSNXBX trojan" ac=I fn="D:\Games\m2p\Spam-Bot (Vista & 7).dll.vir"
sh=6B47F29C01AE0592EE0FA2B589C1C3F842B4AED3 ft=1 fh=063c83341b0d043d vn="a variant of Generik.ESIZNLJ trojan" ac=I fn="D:\Games\m2p\Switch-Bot (Vista & 7).dll.vir"
sh=F2DC73EC1DAA21A4836C3042B5628FE013D23FA3 ft=1 fh=73ca037c4158e0c4 vn="multiple threats" ac=I fn="D:\Games\m2p\Tools by Unpublished.exe.vir"
sh=CDF84B698C5A2AF7EC0BF0A4073DD397EEC0F8ED ft=1 fh=029942c1fb98a746 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="D:\Games\Warrock\hacks\gsdfgdfgdf.dll.vir"
sh=CDF84B698C5A2AF7EC0BF0A4073DD397EEC0F8ED ft=1 fh=029942c1fb98a746 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="D:\Games\Warrock\hacks\iexplore.dll.vir"
sh=54BE06C41292D7C2D6FCF02DCAF66FE77EDFCBBB ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\Games\Warrock\hacks\iexplorer.rar.vir"
sh=E8654C8FC7813E52F228EFECF752122628AA249D ft=1 fh=5a0e3b820b2d2180 vn="Win32/RiskWare.HackAV.KQ application" ac=I fn="D:\Programme\eset\med\ESET Product Activator 2013.exe"
sh=0DB59766F3BBB67B364F9C35C5BA4D47563498D7 ft=0 fh=0000000000000000 vn="JS/TrojanClicker.Agent.NCI.Gen trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2011-09-05 165858\Backup Files 2011-09-11 190001\Backup files 1.zip"
sh=3D43435E8B457DF3CA2A9198C18180E7F23CE59C ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAN trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-01-19 155108\Backup Files 2012-03-11 190001\Backup files 2.zip.vir"
sh=E45FDA2DB50AA3A7C3E65B2E9FCF2855B2297A93 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAN trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-01-19 155108\Backup Files 2012-03-11 190001\Backup files 3.zip.vir"
sh=28A847BE95CDE95EE33ADB810F9CEE27500E4D4E ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-01-19 155108\Backup Files 2012-03-18 190001\Backup files 15.zip.vir"
sh=4D8B385DA3FF831782C0F8F7A582E61A4C6E869C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-01-19 155108\Backup Files 2012-03-18 190001\Backup files 3.zip.vir"
sh=CCAAB0BB608B9400E7E08FFC863B984312A8D5B0 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-01-19 155108\Backup Files 2012-03-18 190001\Backup files 5.zip.vir"
sh=2CD2FCB10D96A8AF161BBC8F33C55562227977B7 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-01-19 155108\Backup Files 2012-03-26 085729\Backup files 2.zip.vir"
sh=631ED37FE1BEB4B0C239A3D8C9AD3F789B6A814E ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAN trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-01-19 155108\Backup Files 2012-03-26 085729\Backup files 5.zip.vir"
sh=867CDD742A662350982124C18F904ACAFB2692BE ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-04-15 190002\Backup Files 2012-04-15 190002\Backup files 10.zip.vir"
sh=9091FB9FF7682305CB9CBF2C29504B189BAA590B ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-04-15 190002\Backup Files 2012-04-15 190002\Backup files 11.zip.vir"
sh=214DA999179CBA12F40FAAA32FEC6169C89F0B2C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-04-15 190002\Backup Files 2012-04-15 190002\Backup files 20.zip.vir"
sh=74CCB4BB426A36A2592D134BDA90818ED219DFD6 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-04-15 190002\Backup Files 2012-04-29 190008\Backup files 1.zip.vir"
sh=112C4067C96EB6A0BCE712A8AF2E75A5DD10F20B ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-04-15 190002\Backup Files 2012-05-20 190008\Backup files 4.zip.vir"
sh=B9A358951919F305F44BEC342E6D58D604437DC5 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-05-27 190001\Backup Files 2012-05-27 190001\Backup files 44.zip.vir"
sh=B235C681E77CEA40C84BE325BE7D1E3AEF960156 ft=0 fh=0000000000000000 vn="Win32/Adware.Bundlore application" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-05-27 190001\Backup Files 2012-05-27 190001\Backup files 7.zip.vir"
sh=100A1B79F00480B5BF2B4CDBC43E6F739DFB7AD6 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-07-15 190008\Backup Files 2012-07-15 190008\Backup files 46.zip.vir"
sh=64802B38EF2ACFA36A5BEA6AA7D3915FC3CCBBFA ft=0 fh=0000000000000000 vn="Win32/Adware.Bundlore application" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-07-15 190008\Backup Files 2012-07-15 190008\Backup files 9.zip.vir"
sh=BA19253CA68A3D89BD1497A2BADF0DCEC47BE859 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-07-15 190008\Backup Files 2012-09-02 190001\Backup files 1.zip.vir"
sh=7F623CBF5FCE48EA21E1AE8CD689BE2E6A1FEE2A ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-07-15 190008\Backup Files 2012-09-02 190001\Backup files 2.zip.vir"
sh=686724CE9BD7AA5B693375C7D73163135FA78126 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-07-15 190008\Backup Files 2012-09-09 203511\Backup files 1.zip.vir"
sh=4B93ADCC32378E52D3423B4D0EA48BD3AC6C6B30 ft=0 fh=0000000000000000 vn="Win32/Adware.Bundlore application" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-07-15 190008\Backup Files 2012-09-16 200711\Backup files 1.zip.vir"
sh=7938A7D3B28345F7ED64C27D5E3A6548C1472666 ft=0 fh=0000000000000000 vn="Win32/Adware.Bundlore application" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-09-23 190001\Backup Files 2012-09-23 190001\Backup files 10.zip.vir"
sh=97F548AEF50F706818EC46C5672250C752824176 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-09-23 190001\Backup Files 2012-09-23 190001\Backup files 49.zip.vir"
sh=4498E23A11E6B0A6840735CAFCD0C5A187F0753D ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-09-23 190001\Backup Files 2012-09-23 190001\Backup files 9.zip.vir"
sh=A26501CE0277B8F9B5DCEF6C2B4E229E211F320F ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-10-14 194325\Backup Files 2012-10-14 194325\Backup files 3.zip.vir"
sh=DCB52B9C5F468B27799A65083738B6FB1064DFDD ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-10-28 190001\Backup Files 2012-10-28 190001\Backup files 13.zip.vir"
sh=C86EE3B7FAF9E17CDE79BCA313155875632CA271 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAN trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-10-28 190001\Backup Files 2012-10-28 190001\Backup files 17.zip.vir"
sh=DA279E7C168F136B269E3D8499D5B47999986F2B ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-10-28 190001\Backup Files 2012-10-28 190001\Backup files 5.zip.vir"
sh=A7AA725D5B0B573BF3F41E0E5BE90FCAB52A47D8 ft=0 fh=0000000000000000 vn="Win32/Adware.1ClickDownload.K application" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-10-28 190001\Backup Files 2012-11-04 190002\Backup files 1.zip.vir"
sh=50E17B5F9B589DD10CB489052AD384A8B1907D89 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAH trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-10-28 190001\Backup Files 2012-11-11 190008\Backup files 6.zip.vir"
sh=497DE8AFF01D45D1042BC7553A3C61739FB7C0FB ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-18 190002\Backup Files 2012-11-18 190002\Backup files 17.zip.vir"
sh=E8C205173EE4751C1C2565BD0212786951530960 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAH trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-18 190002\Backup Files 2012-11-18 190002\Backup files 18.zip.vir"
sh=B35D06AA8EF441A99BA7102AD3F1D7B19A24333F ft=0 fh=0000000000000000 vn="Win32/Adware.1ClickDownload.K application" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-18 190002\Backup Files 2012-11-18 190002\Backup files 2.zip.vir"
sh=5BA2A5D5AE134A63625721D78C2F1ACA6E053D8A ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAN trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-18 190002\Backup Files 2012-11-18 190002\Backup files 25.zip.vir"
sh=50E5AA217D5DE5F6872A1454A4671C196E403A9C ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-18 190002\Backup Files 2012-11-18 190002\Backup files 7.zip.vir"
sh=4495AF90D2B38BF7F8127B548469548B5CF477B7 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-25 193959\Backup Files 2012-11-25 193959\Backup files 17.zip.vir"
sh=DAD43DB396D90C92409781F5416EF92BB622ABBF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-25 193959\Backup Files 2012-11-25 193959\Backup files 2.zip.vir"
sh=99C0BB6AA00BEEA7433B580E27B2A4C82457BB2B ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAN trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-25 193959\Backup Files 2012-11-25 193959\Backup files 24.zip.vir"
sh=8179753718ADA8B2E5A331EF264B42AAE1D21DDE ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-25 193959\Backup Files 2012-11-25 193959\Backup files 6.zip.vir"
sh=B7F32741C410A22A9D49860EE0AC00445984B3AC ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-11-25 193959\Backup Files 2012-12-02 190002\Backup files 1.zip.vir"
sh=B1AF913AF8146806D2773EA48B45F5CAE42C5339 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-12-16 190002\Backup Files 2012-12-16 190002\Backup files 12.zip.vir"
sh=27B3BCBB960D40ECCFF3E05AB314B722D07B235C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-12-16 190002\Backup Files 2012-12-16 190002\Backup files 2.zip.vir"
sh=C0DCD42C43A4C2CEE954B3BAB8EDE428F5D87B14 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-12-16 190002\Backup Files 2012-12-16 190002\Backup files 3.zip.vir"
sh=D7D51B18FF89B8B0EBDB034E8C875FA86E386EA3 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-12-16 190002\Backup Files 2012-12-16 190002\Backup files 6.zip.vir"
sh=7D1227947757A6DB36FA91CE988B46CC25BC263D ft=0 fh=0000000000000000 vn="Win32/Adware.1ClickDownload.AM application" ac=I fn="D:\ZAGREB-PC\Backup Set 2012-12-16 190002\Backup Files 2013-01-21 082644\Backup files 1.zip.vir"
sh=D0FB073C5078750356144FE8E58B36A90C3621F9 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-01-27 190008\Backup Files 2013-01-27 190008\Backup files 12.zip.vir"
sh=640676CDCC9BDC330244AC0F445704D08885D97F ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAH trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-01-27 190008\Backup Files 2013-01-27 190008\Backup files 13.zip.vir"
sh=BF35A1FF2FA584680238CA3FEAB9805E9E518AB4 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-01-27 190008\Backup Files 2013-01-27 190008\Backup files 2.zip.vir"
sh=49F8CB779E871F6024C6DF264C24F093614A2E92 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-01-27 190008\Backup Files 2013-01-27 190008\Backup files 3.zip.vir"
sh=D2B53FBAB1B22E5E59A4EC7E93616023F559E569 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-01-27 190008\Backup Files 2013-01-27 190008\Backup files 6.zip.vir"
sh=22065CAE548FD8884A7B1D8141131299A700607F ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-02-18 140226\Backup Files 2013-02-18 140226\Backup files 12.zip.vir"
sh=FF179FF19E55B932A3AB83C1B8411A0B28C82C7C ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAH trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-02-18 140226\Backup Files 2013-02-18 140226\Backup files 13.zip.vir"
sh=520D6B712A93760DE0D1D1A3E18C49DF8806B1B7 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-02-18 140226\Backup Files 2013-02-18 140226\Backup files 2.zip.vir"
sh=8867ACBA48170EAF21555F248DF08DA9973C8B40 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-02-18 140226\Backup Files 2013-02-18 140226\Backup files 3.zip.vir"
sh=59AFC28CF53A6ECDFFEA847F24B18A1D07E3762A ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-02-18 140226\Backup Files 2013-02-18 140226\Backup files 6.zip.vir"
sh=0E04C62D806732DE53B6F724057ACE011462CE20 ft=0 fh=0000000000000000 vn="Win32/Adware.1ClickDownload.W application" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-02-18 140226\Backup Files 2013-02-24 190002\Backup files 1.zip.vir"
sh=3E4CD05A4DB0474EBA9189C26478C5B60FA62A88 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-03-10 190003\Backup Files 2013-03-10 190003\Backup files 14.zip.vir"
sh=40E05466C3386DE9B17A1C6F4402F55CA3F1703C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-03-10 190003\Backup Files 2013-03-10 190003\Backup files 3.zip.vir"
sh=41977BD234EE31EF36343D03F3E6E6D32ED6A86B ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-03-10 190003\Backup Files 2013-03-26 185029\Backup files 2.zip.vir"
sh=F8A2753D2313D03ECD32CC34A212C7B86B5C273A ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-03-10 190003\Backup Files 2013-04-14 190002\Backup files 1.zip.vir"
sh=7219BB7E3B802C1DB0EE04BF41426A130B0F4B5D ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-03-10 190003\Backup Files 2013-04-14 190002\Backup files 7.zip.vir"
sh=65F76FE4D11ED4CE5555790614836B7A64C651CB ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-04-28 190005\Backup Files 2013-04-28 190005\Backup files 20.zip.vir"
sh=08DFF8C1788D9598CC5AC3A515B9920B5AF2159C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-04-28 190005\Backup Files 2013-04-28 190005\Backup files 27.zip.vir"
sh=243533B42B1B70BBB65CB609AD7659EC9B905698 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-04-28 190005\Backup Files 2013-04-28 190005\Backup files 3.zip.vir"
sh=E4019D6A75ACC78314B3FB97081F84921D74556C ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-04-28 190005\Backup Files 2013-04-28 190005\Backup files 30.zip.vir"
sh=31A264C0B71762A683539A835641369B78B7C3D0 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-04-28 190005\Backup Files 2013-04-28 190005\Backup files 4.zip.vir"
sh=624ACF2D0B40CD0F6054749EFD491DD72CF1FBF0 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-04-28 190005\Backup Files 2013-04-28 190005\Backup files 8.zip.vir"
sh=6A5B1EB803EA3B566AD522EA2EC5C03F4D854000 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-05-12 190003\Backup Files 2013-05-12 190003\Backup files 20.zip.vir"
sh=A647F3EDC3E723E6E37850D82C41FD62B37C7443 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-05-12 190003\Backup Files 2013-05-12 190003\Backup files 21.zip.vir"
sh=043BEA52F49CEAE09E661382C94AAC6C35E34A69 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-05-12 190003\Backup Files 2013-05-12 190003\Backup files 3.zip.vir"
sh=66E97CACE2B9163B2385A07A1F6B0F18A02CD69A ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-05-12 190003\Backup Files 2013-05-12 190003\Backup files 4.zip.vir"
sh=C24F98335BB3AE3D4E375E749329407D6070E4E6 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-05-12 190003\Backup Files 2013-05-12 190003\Backup files 5.zip.vir"
sh=BF11D005DDE0E20696659581CFACA6AD9FAEE02B ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-05-12 190003\Backup Files 2013-05-12 190003\Backup files 9.zip.vir"
sh=8B7185F76279B9A71E015D051B16596D41152501 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-06-03 162230\Backup Files 2013-06-03 162230\Backup files 3.zip.vir"
sh=EF6DFB86FDF63681EEEC63174F260DC105445A9D ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-06-03 162230\Backup Files 2013-06-03 162230\Backup files 4.zip.vir"
sh=3B6359AD39F2631935D716225AC767CF80B97C73 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-06-03 162230\Backup Files 2013-06-03 162230\Backup files 5.zip.vir"
sh=33EC19A348B0D55C38DF5558105445DF964B6B49 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-06-03 162230\Backup Files 2013-06-03 162230\Backup files 52.zip.vir"
sh=1AAA4E019BD553D644B80DF2D9E77C1753CCF064 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-06-03 162230\Backup Files 2013-06-03 162230\Backup files 53.zip.vir"
sh=2AB33E3AA832C210B49A3728EC7D0A4883A238DF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-06-03 162230\Backup Files 2013-06-03 162230\Backup files 6.zip.vir"
sh=F00A8EBB082568E52879DB55C98709F4275E7E42 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-07-07 190002\Backup Files 2013-07-07 190002\Backup files 2.zip.vir"
sh=925AD435E4955140717AB0458341A53812880FDC ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-07-07 190002\Backup Files 2013-07-07 190002\Backup files 23.zip.vir"
sh=7E6FB8FB6690D6DD2DE26E6D57F7535C4554D34C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-07-07 190002\Backup Files 2013-07-07 190002\Backup files 24.zip.vir"
sh=1EB06E50EA74442833A391407DA6382607339C94 ft=0 fh=0000000000000000 vn="Win32/Adware.1ClickDownload.AI application" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-07-07 190002\Backup Files 2013-07-07 190002\Backup files 3.zip.vir"
sh=1CE61C701A1978690D685FFFFF1ECCD19F1BCF70 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-07-07 190002\Backup Files 2013-07-07 190002\Backup files 4.zip.vir"
sh=BE48BF066AD914324E6A5F7702816237D24ADBD0 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-07-07 190002\Backup Files 2013-07-07 190002\Backup files 5.zip.vir"
sh=BCD7DD7E30AE8D7F49B34A74FF35CF4B113EBBB0 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-08-25 190009\Backup Files 2013-08-25 190009\Backup files 24.zip.vir"
sh=65C5E7DD537B644F40AFA5389825E62C82A241D3 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-08-25 190009\Backup Files 2013-08-25 190009\Backup files 25.zip.vir"
sh=64B7012476E03E06CC7D33B00C61AD10E7D68010 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-08-25 190009\Backup Files 2013-08-25 190009\Backup files 3.zip.vir"
sh=C804B1E1776C872C7372EB982A5E3E76C866C7AA ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-08-25 190009\Backup Files 2013-08-25 190009\Backup files 4.zip.vir"
sh=149DA2DF18ADE3636A376B402940772D7A01A842 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-08-25 190009\Backup Files 2013-08-25 190009\Backup files 5.zip.vir"
sh=78FB79F765F51EBAC0E9505957A1C5E03B88FFE5 ft=0 fh=0000000000000000 vn="Win32/AdWare.1ClickDownload.AR application" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-08-25 190009\Backup Files 2013-10-13 190008\Backup files 2.zip"
sh=3D885EFD6297AC0B18FC21118C2077093C9C6C8C ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-08-25 190009\Backup Files 2013-10-20 190008\Backup files 1.zip"
sh=DE3D0A6569AF364E963E8EB7BDD343A008B3E687 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-08-25 190009\Backup Files 2013-10-20 190008\Backup files 6.zip"
sh=91DD6BCD68EF1AF726D02673D97FBDA31CDBFF22 ft=0 fh=0000000000000000 vn="VBS/CoinMiner.AE trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-11-24 190001\Backup Files 2013-11-24 190001\Backup files 5.zip"
sh=4108813CECE6097D58FC1A121A030EB4F01EF33D ft=0 fh=0000000000000000 vn="Win32/AdWare.1ClickDownload.AR application" ac=I fn="D:\ZAGREB-PC\Backup Set 2013-11-24 190001\Backup Files 2013-11-24 190001\Backup files 6.zip"
sh=ECE4BCFE83EE10464D42FA16B246C91AE809B97B ft=0 fh=0000000000000000 vn="VBS/CoinMiner.AE trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2014-01-04 125902\Backup Files 2014-01-04 125902\Backup files 6.zip"
sh=9AAA5CEAF45662CEC6BDF0CE0D19957761CFA9B6 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAH trojan" ac=I fn="D:\ZAGREB-PC\Backup Set 2014-01-04 125902\Backup Files 2014-01-26 220000\Backup files 2.zip.vir"
sh=5F1FA7BBF2014F08B7FD5A7BCE700ABEFDD95746 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="G:\iexplorer.rar"
sh=54BE06C41292D7C2D6FCF02DCAF66FE77EDFCBBB ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="G:\Farb\iexplorer.rar.vir"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Win32/Fynloski.AA trojan" ac=I fn="${Memory}"


Also den Eset Scan habe ich am Abend gemacht, an dem ich verreist bin. Mein Vater hat darauf gewartet, dass es zum "finish" kommt. Er hat FInish gedrückt und der PC hat sich ausgeschlaten. Bis jetzt wurde der PC nicht angefasst. Beim Systemstart kam gleich eine Meldung.

Dann versuchte ich Sec. Check auszuführen. Ich Lud die Datei runter, auf mein Stick vom Laptop aus und kopierte es auf den PC. Da kam nochmals die Fehlermeldung(1). Also vom Desktop aus geht es nicht. Als 2es versuchte ich vom USB Stick aus.. in etwas die gleiche Fehlereldung(2).

Ich habe eigentlich Admin Rechte..

Liebe Grüsse!

Crohero 07.04.2014 20:10

Apropos, kannst du mir eventuell sagen, was ich mir da eingefangen habe?

Danke

schrauber 08.04.2014 12:10

Alle backups auf D und F und G und was sonst noch da is löschen, formatieren. Von mir aus auch verbrennen und mit nem dicken Magneten drüber. Das ist ja der Wahnsinn.

Bei dem ganzen Scheiss auf den Platten müsste ich dich eigentlich als Lerneffekt formatieren schicken.....


Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Crohero 08.04.2014 12:36

Wenigstens hast du mich jetzt zum lachen gebracht^^

Also irgendwelche Dateien in der Regedit.exe löschen würde nix bringen?

Deiner Meinung nach also jede Festplatte ganz löschen oder wie? Komme nicht so ganz mit.

Und Dann Windows mit den Discs neu installieren?

Danke

schrauber 09.04.2014 09:56

Es reicht wenn Du die die Backups löschst, die ESET anmeckert, Windows bekommen wir schon wieder hin, ausser Du willst unbedingt formatieren :)

Crohero 10.04.2014 20:19

Hallo

Habe gerade damit angefangen aber da würde ich ja praktisch alle löschen die ich habe^^

Und Combofix kann ich nicht starten :headbang:

Auf dem Desktop kommt die Meldung, dass auf den Pfad nicht zugegriffen werden kann und Berechtigung blabla

Und wenn ich es über den Stick versuche, dann kommt sowas wie "konnte nicht gefunden werden...Stellen sie sicher, dass sie den Namen richtig eingegeben haben "

Mannoo :D

schrauber 13.04.2014 13:38

Die Backups musst Du löschen, oder du infizierst den Rechner immer wieder neu.

Crohero 03.05.2014 19:36

Zitat:

Zitat von schrauber (Beitrag 1283889)
Die Backups musst Du löschen, oder du infizierst den Rechner immer wieder neu.

Hallo!

War eine Zeit lang weg vom Fenster.

Hab nun praktisch alle Backups gelöscht die auf dem PC waren.

Combofic kann ich nicht ausführen (Weder vom Stick aus noch vom abgesicht. Modus)
Es wird mir verwehrt.

liebe Grüsse

Crohero

schrauber 04.05.2014 07:52

Geht das ein wenig genauer? Fehlermeldung?

Crohero 04.05.2014 14:20

Zitat:

Zitat von schrauber (Beitrag 1295111)
Geht das ein wenig genauer? Fehlermeldung?

Es kommen immer die gleichen Fehlermeldungen ( die Bilder von denen habe ich schon auf die Seite raufgeladen)

Das ist zwar jetzt nicht vom starten vom Combofix aber es ist das genau gleiche..

http://www.trojaner-board.de/attachm...g-imag2947.jpg

http://www.trojaner-board.de/attachm...rmeldung-2.jpg

http://www.trojaner-board.de/attachm...rmeldung-1.jpg

Ich habe eigentlich Admin Rechte usw.

lG

schrauber 05.05.2014 11:52

Poste mal bitte ein frisches FRST log. Wenn das nix wird musste doch alle Platten formatieren und neu anfangen.

Crohero 07.05.2014 11:59

Zitat:

Zitat von schrauber (Beitrag 1295686)
Poste mal bitte ein frisches FRST log. Wenn das nix wird musste doch alle Platten formatieren und neu anfangen.

So, hier habe ich den frischen log.

lG



FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-05-2014
Ran by zagreb (administrator) on ZAGREB-PC on 07-05-2014 12:53:50
Running from C:\Users\zagreb\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Gemalto N.V.) C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corp.) C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
() C:\ProgramData\Windows Manager\winmgr.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Gemalto N.V.) G:\RunSanDiskSecureAccess_Win.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-12-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1064224 2013-11-14] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [WheelMouse] => C:\Advanced Wheel Mouse\wh_exec.exe [98304 2007-11-10] ()
HKLM-x32\...\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-02-03] (PC Tools)
HKLM-x32\...\Run: [HTC Sync Loader] => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer [155648 2012-01-31] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
HKU\.DEFAULT\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-07-05] (Google Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-02-15] (Gemalto N.V.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Akamai NetSession Interface] => C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [MicroUpdate] => C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe [674304 2014-04-01] (Microsoft Corp.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\RunOnce: [WindowsUpdate] - C:\ProgramData\Windows Manager\winmgr.exe [249856 2014-03-30] ()
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <===== ATTENTION
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
IFEO\AvastSvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\AvastUI.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avcenter.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avconfig.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgcsrvx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgidsagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgnt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgrsx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avguard.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgwdsvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avp.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avscan.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\bdagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ccuac.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ComboFix.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\egui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\hijackthis.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\instup.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\keyscrambler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbam.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbampt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamscheduler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamservice.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MpCmdRun.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MSASCui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MsMpEng.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\msseces.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\rstrui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\spybotsd.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\wireshark.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\zlclient.exe: [Debugger] C:\Windows\system32\Microsoft.com
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)

==================== Internet (Whitelisted) ====================

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost64.dll (BestOffers)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost.dll (BestOffers)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1

FireFox:
========
FF ProfilePath: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default
FF Homepage: https://www.google.ch/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\zagreb\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\gmailnoads@mywebber.com.xpi [2013-11-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-04-23]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Google Drive) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (YouTube) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (McAfee Security Scan+) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-22]
CHR Extension: (Google-Suche) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (DVDVideoSoft) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-08-13]
CHR Extension: (Google Mail) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\zagreb\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-03-30]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\zagreb\AppData\Local\Temp\tbch.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-02-03] (PC Tools)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-22] ()
S3 TunngleService; D:\Games\tunngle lan game crack\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH)
S2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe" [X]
S2 avgwd; "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe" [X]
S2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [49952 2014-03-21] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-08] (DT Soft Ltd)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 XFDriver64; C:\Program Files (x86)\Xfire2\XFDriver64.sys [17160 2013-03-14] (XFire)
U3 DfSdkS;
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va005; \??\C:\Users\zagreb\AppData\Local\Temp\005DD1A.tmp [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-07 12:53 - 2014-05-07 12:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion
2014-04-10 21:16 - 2014-04-10 21:12 - 05196025 _____ () C:\Users\zagreb\Desktop\ComboFix.exe
2014-04-10 21:08 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-10 21:08 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-10 21:08 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-10 21:08 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-10 21:07 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-10 21:07 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-10 21:07 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-10 21:07 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-10 21:07 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-10 21:07 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-10 21:07 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-10 21:07 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-10 21:07 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-10 21:07 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-10 21:07 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-10 21:07 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-10 21:07 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-10 21:07 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-10 21:07 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-10 21:07 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-10 21:07 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-10 20:55 - 2014-05-07 12:49 - 01663620 _____ () C:\Windows\WindowsUpdate.log
2014-04-10 20:53 - 2014-05-07 12:53 - 00001344 _____ () C:\Windows\setupact.log
2014-04-10 20:53 - 2014-04-10 20:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-07 11:22 - 2014-04-07 11:21 - 00987442 _____ () C:\Users\zagreb\Desktop\SecurityCheck.exe

==================== One Month Modified Files and Folders =======

2014-05-07 12:53 - 2014-05-07 12:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion
2014-05-07 12:53 - 2014-04-10 20:53 - 00001344 _____ () C:\Windows\setupact.log
2014-05-07 12:53 - 2014-04-01 17:03 - 00028424 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-05-07 12:53 - 2014-04-01 17:03 - 00000000 ____D () C:\FRST
2014-05-07 12:53 - 2014-04-01 17:02 - 02063872 _____ (Farbar) C:\Users\zagreb\Desktop\FRST64.exe
2014-05-07 12:53 - 2014-03-30 21:59 - 00000000 ___RD () C:\Users\zagreb\Google Drive
2014-05-07 12:53 - 2013-05-24 21:06 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-05-07 12:53 - 2012-04-08 20:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-07 12:53 - 2011-10-23 12:33 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job
2014-05-07 12:53 - 2011-07-05 20:56 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-07 12:53 - 2011-03-22 21:00 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-07 12:53 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-07 12:49 - 2014-04-10 20:55 - 01663620 _____ () C:\Windows\WindowsUpdate.log
2014-05-07 12:49 - 2011-12-13 22:28 - 00000000 ____D () C:\Users\zagreb\Desktop\Brunc
2014-05-07 12:49 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-07 12:49 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-07 12:44 - 2011-02-10 21:25 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-05-07 12:44 - 2011-02-10 21:25 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-05-07 12:44 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-07 12:41 - 2013-09-24 18:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-07 12:41 - 2012-04-08 20:24 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-07 12:41 - 2011-07-13 21:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-07 12:40 - 2011-07-06 20:45 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Adobe
2014-05-03 20:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-05-03 20:23 - 2011-07-05 20:56 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-03 20:11 - 2014-03-29 13:07 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Akamai
2014-04-24 10:24 - 2011-08-29 16:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-24 10:16 - 2011-09-25 19:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-04-11 15:57 - 2014-03-31 18:46 - 00000000 __SHD () C:\ProgramData\Windows Manager
2014-04-11 00:05 - 2012-12-09 01:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-04-11 00:02 - 2013-08-15 22:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-11 00:02 - 2011-02-10 22:56 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-10 23:19 - 2013-11-16 18:24 - 00000000 ____D () C:\Users\zagreb\Desktop\Replikation
2014-04-10 21:12 - 2014-04-10 21:16 - 05196025 _____ () C:\Users\zagreb\Desktop\ComboFix.exe
2014-04-10 20:53 - 2014-04-10 20:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-07 11:21 - 2014-04-07 11:22 - 00987442 _____ () C:\Users\zagreb\Desktop\SecurityCheck.exe

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.6408.dll
C:\Users\zagreb\BalTax2013_installieren.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-10 21:36

==================== End Of Log ============================

--- --- ---

schrauber 08.05.2014 08:27

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <===== ATTENTION
C:\ProgramData\Microsoft.com
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
IFEO\AvastSvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\AvastUI.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avcenter.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avconfig.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgcsrvx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgidsagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgnt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgrsx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avguard.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgwdsvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avp.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avscan.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\bdagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ccuac.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ComboFix.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\egui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\hijackthis.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\instup.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\keyscrambler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbam.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbampt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamscheduler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamservice.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MpCmdRun.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MSASCui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MsMpEng.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\msseces.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\rstrui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\spybotsd.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\wireshark.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\zlclient.exe: [Debugger] C:\Windows\system32\Microsoft.com


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Crohero 08.05.2014 18:49

Hier der Fixlog

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-05-2014
Ran by zagreb at 2014-05-08 19:45:12 Run:1
Running from C:\Users\zagreb\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <===== ATTENTION C:\ProgramData\Microsoft.com HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] () IFEO\AvastSvc.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\AvastUI.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avcenter.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avconfig.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avgcsrvx.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avgidsagent.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avgnt.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avgrsx.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avguard.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avgui.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avgwdsvc.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avp.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\avscan.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\bdagent.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\ccuac.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\ComboFix.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\egui.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\hijackthis.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\instup.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\keyscrambler.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\mbam.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\mbamgui.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\mbampt.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\mbamscheduler.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\mbamservice.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\MpCmdRun.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\MSASCui.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\MsMpEng.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\msseces.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\rstrui.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\spybotsd.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\wireshark.exe: [Debugger] C:\Windows\system32\Microsoft.com IFEO\zlclient.exe: [Debugger] C:\Windows\system32\Microsoft.com
*****************

HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <===== ATTENTION C:\ProgramData\Microsoft.com HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKCU => Value not found.

==== End of Fixlog ====


lG

schrauber 09.05.2014 15:58

Wäre auch cool wenn Du den kompletten Fix benutzen würdest, den poste ich nit aus Spass ;)

Crohero 10.05.2014 11:05

Zitat:

Zitat von schrauber (Beitrag 1297670)
Wäre auch cool wenn Du den kompletten Fix benutzen würdest, den poste ich nit aus Spass ;)


So ich hoffe , dass ich es jetzt richtig gemacht hab :D


Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-05-2014
Ran by zagreb at 2014-05-10 12:02:59 Run:2
Running from G:\FRST
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <=====
ATTENTION
C:\ProgramData\Microsoft.com
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
IFEO\AvastSvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\AvastUI.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avcenter.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avconfig.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgcsrvx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgidsagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgnt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgrsx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avguard.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgwdsvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avp.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avscan.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\bdagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ccuac.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ComboFix.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\egui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\hijackthis.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\instup.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\keyscrambler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbam.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbampt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamscheduler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamservice.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MpCmdRun.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MSASCui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MsMpEng.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\msseces.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\rstrui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\spybotsd.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\wireshark.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\zlclient.exe: [Debugger] C:\Windows\system32\Microsoft.com
*****************

HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => Value was restored successfully.
C:\ProgramData\Microsoft.com => Moved successfully.
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKCU => Value deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AvastSvc.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AvastUI.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avgidsagent.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avguard.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avp.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avscan.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bdagent.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ccuac.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ComboFix.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\hijackthis.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\instup.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\keyscrambler.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbam.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbamgui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbampt.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbamscheduler.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbamservice.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MpCmdRun.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MsMpEng.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rstrui.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\spybotsd.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wireshark.exe => Key deleted successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\zlclient.exe => Key deleted successfully.

==== End of Fixlog ====

lG

schrauber 11.05.2014 06:32

Frisches FRST log bitte.

Crohero 11.05.2014 12:23

Zitat:

Zitat von schrauber (Beitrag 1298328)
Frisches FRST log bitte.

Bitteschön


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014
Ran by zagreb (administrator) on ZAGREB-PC on 11-05-2014 13:18:37
Running from C:\Users\zagreb\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Gemalto N.V.) C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corp.) C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
() C:\ProgramData\Windows Manager\winmgr.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-12-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1064224 2013-11-14] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [WheelMouse] => C:\Advanced Wheel Mouse\wh_exec.exe [98304 2007-11-10] ()
HKLM-x32\...\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-02-03] (PC Tools)
HKLM-x32\...\Run: [HTC Sync Loader] => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer [155648 2012-01-31] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
HKU\.DEFAULT\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-07-05] (Google Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-02-15] (Gemalto N.V.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Akamai NetSession Interface] => C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [MicroUpdate] => C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe [674304 2014-04-01] (Microsoft Corp.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\RunOnce: [WindowsUpdate] - C:\ProgramData\Windows Manager\winmgr.exe [249856 2014-03-30] ()
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <===== ATTENTION
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)

==================== Internet (Whitelisted) ====================

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost64.dll (BestOffers)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost.dll (BestOffers)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1

FireFox:
========
FF ProfilePath: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default
FF Homepage: https://www.google.ch/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\zagreb\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\gmailnoads@mywebber.com.xpi [2013-11-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-04-23]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Google Drive) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (YouTube) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (McAfee Security Scan+) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-22]
CHR Extension: (Google-Suche) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (DVDVideoSoft) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-08-13]
CHR Extension: (Google Mail) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\zagreb\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-03-30]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\zagreb\AppData\Local\Temp\tbch.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-02-03] (PC Tools)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-22] ()
S3 TunngleService; D:\Games\tunngle lan game crack\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH)
S2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe" [X]
S2 avgwd; "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe" [X]
S2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [49952 2014-03-21] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-08] (DT Soft Ltd)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 XFDriver64; C:\Program Files (x86)\Xfire2\XFDriver64.sys [17160 2013-03-14] (XFire)
U3 DfSdkS;
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va005; \??\C:\Users\zagreb\AppData\Local\Temp\005DD1A.tmp [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-11 13:17 - 2014-03-30 17:03 - 00249856 __RSH () C:\ProgramData\Microsoft.com
2014-05-10 12:04 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-10 12:04 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-10 12:04 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-10 12:04 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-10 11:53 - 2014-05-10 12:02 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:47 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-08 19:47 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-08 19:47 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-08 19:47 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-08 19:47 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-08 19:47 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-08 19:47 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-08 19:47 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-08 19:47 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-08 19:47 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-08 19:47 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-08 19:47 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-08 19:45 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-08 19:45 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-07 12:53 - 2014-05-11 13:18 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion

==================== One Month Modified Files and Folders =======

2014-05-11 13:18 - 2014-05-07 12:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion
2014-05-11 13:18 - 2014-04-01 17:03 - 00026216 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-05-11 13:18 - 2014-04-01 17:03 - 00000000 ____D () C:\FRST
2014-05-11 13:18 - 2014-04-01 17:02 - 02066432 _____ (Farbar) C:\Users\zagreb\Desktop\FRST64.exe
2014-05-11 13:17 - 2014-04-10 20:53 - 00001848 _____ () C:\Windows\setupact.log
2014-05-11 13:17 - 2014-03-30 21:59 - 00000000 ___RD () C:\Users\zagreb\Google Drive
2014-05-11 13:17 - 2013-05-24 21:06 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-05-11 13:17 - 2011-07-06 20:45 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Adobe
2014-05-11 13:17 - 2011-07-05 20:56 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-11 13:17 - 2011-03-22 21:00 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-11 13:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-10 12:04 - 2014-04-10 20:55 - 01939540 _____ () C:\Windows\WindowsUpdate.log
2014-05-10 12:02 - 2014-05-10 11:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST
2014-05-10 11:54 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-10 11:54 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-10 11:53 - 2011-02-10 21:25 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-05-10 11:53 - 2011-02-10 21:25 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-05-10 11:53 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-10 11:49 - 2012-04-08 20:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-10 11:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-05-10 11:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:41 - 2013-09-24 18:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-08 19:41 - 2012-04-08 20:24 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-08 19:41 - 2011-07-13 21:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-07 12:53 - 2011-10-23 12:33 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job
2014-05-07 12:49 - 2011-12-13 22:28 - 00000000 ____D () C:\Users\zagreb\Desktop\Brunc
2014-05-03 20:23 - 2011-07-05 20:56 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-03 20:11 - 2014-03-29 13:07 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Akamai
2014-04-29 16:01 - 2014-05-10 12:04 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-10 12:04 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-24 10:24 - 2011-08-29 16:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-24 10:16 - 2011-09-25 19:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-04-14 04:24 - 2014-05-08 19:45 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-05-08 19:45 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-11 15:57 - 2014-03-31 18:46 - 00000000 __SHD () C:\ProgramData\Windows Manager
2014-04-11 00:05 - 2012-12-09 01:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-04-11 00:04 - 2013-08-15 22:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-11 00:02 - 2011-02-10 22:56 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.6408.dll
C:\Users\zagreb\BalTax2013_installieren.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-10 21:36

==================== End Of Log ============================

--- --- ---



Wie siehts aus?


lG

schrauber 12.05.2014 11:22

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <===== ATTENTION
 C:\ProgramData\Microsoft.com


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Frisches FRST Log bitte. Das Ding erstellt sich immer wieder neu.


Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Crohero 12.05.2014 13:00

Alles gemacht!

Der erste Fixlog:
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-05-2014 01
Ran by zagreb at 2014-05-12 13:02:32 Run:3
Running from C:\Users\zagreb\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\Microsoft.com <===== ATTENTION C:\ProgramData\Microsoft.com
*****************

HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => Value was restored successfully.

==== End of Fixlog ====


Dann der FRST Log:


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01
Ran by zagreb (administrator) on ZAGREB-PC on 12-05-2014 13:03:24
Running from C:\Users\zagreb\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Gemalto N.V.) C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corp.) C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
() C:\ProgramData\Windows Manager\winmgr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-12-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1064224 2013-11-14] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [WheelMouse] => C:\Advanced Wheel Mouse\wh_exec.exe [98304 2007-11-10] ()
HKLM-x32\...\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-02-03] (PC Tools)
HKLM-x32\...\Run: [HTC Sync Loader] => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer [155648 2012-01-31] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
HKU\.DEFAULT\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-07-05] (Google Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-02-15] (Gemalto N.V.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Akamai NetSession Interface] => C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [MicroUpdate] => C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe [674304 2014-04-01] (Microsoft Corp.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\RunOnce: [WindowsUpdate] - C:\ProgramData\Windows Manager\winmgr.exe [249856 2014-03-30] ()
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)

==================== Internet (Whitelisted) ====================

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost64.dll (BestOffers)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost.dll (BestOffers)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1

FireFox:
========
FF ProfilePath: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default
FF Homepage: https://www.google.ch/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\zagreb\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\gmailnoads@mywebber.com.xpi [2013-11-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-04-23]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Google Drive) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (YouTube) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (McAfee Security Scan+) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-22]
CHR Extension: (Google-Suche) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (DVDVideoSoft) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-08-13]
CHR Extension: (Google Mail) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\zagreb\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-03-30]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\zagreb\AppData\Local\Temp\tbch.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-02-03] (PC Tools)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-22] ()
S3 TunngleService; D:\Games\tunngle lan game crack\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH)
S2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe" [X]
S2 avgwd; "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe" [X]
S2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [49952 2014-03-21] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-08] (DT Soft Ltd)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 XFDriver64; C:\Program Files (x86)\Xfire2\XFDriver64.sys [17160 2013-03-14] (XFire)
U3 DfSdkS;
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va005; \??\C:\Users\zagreb\AppData\Local\Temp\005DD1A.tmp [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-11 13:17 - 2014-03-30 17:03 - 00249856 __RSH () C:\ProgramData\Microsoft.com
2014-05-10 12:04 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-10 12:04 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-10 12:04 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-10 12:04 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-10 11:53 - 2014-05-10 12:02 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:47 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-08 19:47 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-08 19:47 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-08 19:47 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-08 19:47 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-08 19:47 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-08 19:47 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-08 19:47 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-08 19:47 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-08 19:47 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-08 19:47 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-08 19:47 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-08 19:45 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-08 19:45 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-07 12:53 - 2014-05-12 13:01 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion

==================== One Month Modified Files and Folders =======

2014-05-12 13:03 - 2014-04-01 17:03 - 00025956 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-05-12 13:03 - 2014-04-01 17:03 - 00000000 ____D () C:\FRST
2014-05-12 13:03 - 2011-02-10 21:25 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-05-12 13:03 - 2011-02-10 21:25 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-05-12 13:03 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-12 13:01 - 2014-05-07 12:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion
2014-05-12 13:01 - 2014-04-01 17:02 - 02066944 _____ (Farbar) C:\Users\zagreb\Desktop\FRST64.exe
2014-05-12 12:59 - 2014-04-10 20:53 - 00002016 _____ () C:\Windows\setupact.log
2014-05-12 12:59 - 2014-03-30 21:59 - 00000000 ___RD () C:\Users\zagreb\Google Drive
2014-05-12 12:59 - 2013-05-24 21:06 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-05-12 12:59 - 2011-07-05 20:56 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-12 12:59 - 2011-03-22 21:00 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-12 12:59 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-11 13:21 - 2014-04-10 20:55 - 01984027 _____ () C:\Windows\WindowsUpdate.log
2014-05-11 13:21 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-11 13:21 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-11 13:17 - 2011-07-06 20:45 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Adobe
2014-05-10 12:02 - 2014-05-10 11:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST
2014-05-10 11:49 - 2012-04-08 20:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-10 11:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-05-10 11:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:41 - 2013-09-24 18:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-08 19:41 - 2012-04-08 20:24 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-08 19:41 - 2011-07-13 21:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-07 12:53 - 2011-10-23 12:33 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job
2014-05-07 12:49 - 2011-12-13 22:28 - 00000000 ____D () C:\Users\zagreb\Desktop\Brunc
2014-05-03 20:23 - 2011-07-05 20:56 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-03 20:11 - 2014-03-29 13:07 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Akamai
2014-04-29 16:01 - 2014-05-10 12:04 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-10 12:04 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-24 10:24 - 2011-08-29 16:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-24 10:16 - 2011-09-25 19:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-04-14 04:24 - 2014-05-08 19:45 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-05-08 19:45 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.6408.dll
C:\Users\zagreb\BalTax2013_installieren.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-10 21:36

==================== End Of Log ============================

--- --- ---

--- --- ---



Jetzt der Logfile vom Anti Rook Kit:

Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2014.05.12.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.17105
zagreb :: ZAGREB-PC [administrator]

12.05.2014 13:06:29
mbar-log-2014-05-12 (13-06-29).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 320486
Time elapsed: 15 minute(s), 34 second(s)

Memory Processes Detected: 2
C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe (Backdoor.Agent.DCRSAGen) -> 2280 -> Delete on reboot.
C:\ProgramData\Windows Manager\winmgr.exe (Backdoor.Agent.WUGen) -> 1216 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 3
HKCU\SOFTWARE\DC3_FEXEC (Malware.Trace) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\WINMGR.EXE (Backdoor.Agent.WUGen) -> Delete on reboot.
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\WINMGR.EXE (Backdoor.Agent.WUGen) -> Delete on reboot.

Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MicroUpdate (Backdoor.Agent.DCRSAGen) -> Data: C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe -> Delete on reboot.
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WindowsUpdate (Backdoor.Agent.WUGen) -> Data: "C:\ProgramData\Windows Manager\winmgr.exe" -> Delete on reboot.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\zagreb\AppData\Roaming\dclogs (Stolen.Data) -> Delete on reboot.

Files Detected: 20
C:\Users\zagreb\Documents\MSDCSC\msdcsc.exe (Backdoor.Agent.DCRSAGen) -> Delete on reboot.
C:\Users\zagreb\Local Settings\Temp\msaywrqi.scr (Trojan.Reconyc) -> Delete on reboot.
C:\Windows\SysWOW64\Microsoft.com (Trojan.Agent.CMO) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-01-3.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-02-4.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-03-5.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-05-7.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-07-2.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-09-4.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-10-5.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-11-6.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-04-24-5.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-05-03-7.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-05-07-4.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-05-08-5.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-05-10-7.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-05-11-1.dc (Stolen.Data) -> Delete on reboot.
C:\Users\zagreb\AppData\Roaming\dclogs\2014-05-12-2.dc (Stolen.Data) -> Delete on reboot.
C:\ProgramData\Windows Manager\winmgr.exe (Backdoor.Agent.WUGen) -> Delete on reboot.

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Dann habe ich einen zweiten Durchlauf machen lasse aber er hat nix gefunden.


Und nach dem zweiten Durchlauf habe ich einen frischen FRST Log machen lassen:


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01
Ran by zagreb (administrator) on ZAGREB-PC on 12-05-2014 13:53:05
Running from C:\Users\zagreb\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Gemalto N.V.) C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-12-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1064224 2013-11-14] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [WheelMouse] => C:\Advanced Wheel Mouse\wh_exec.exe [98304 2007-11-10] ()
HKLM-x32\...\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-02-03] (PC Tools)
HKLM-x32\...\Run: [HTC Sync Loader] => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer [155648 2012-01-31] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
HKU\.DEFAULT\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-07-05] (Google Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-02-15] (Gemalto N.V.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Akamai NetSession Interface] => C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)

==================== Internet (Whitelisted) ====================

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost64.dll (BestOffers)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost.dll (BestOffers)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1

FireFox:
========
FF ProfilePath: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default
FF Homepage: https://www.google.ch/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\zagreb\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\gmailnoads@mywebber.com.xpi [2013-11-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-04-23]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Google Drive) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (YouTube) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (McAfee Security Scan+) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-22]
CHR Extension: (Google-Suche) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (DVDVideoSoft) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-08-13]
CHR Extension: (Google Mail) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\zagreb\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-03-30]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\zagreb\AppData\Local\Temp\tbch.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-02-03] (PC Tools)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-22] ()
S3 TunngleService; D:\Games\tunngle lan game crack\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH)
S2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe" [X]
S2 avgwd; "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe" [X]
S2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [49952 2014-03-21] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-08] (DT Soft Ltd)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 XFDriver64; C:\Program Files (x86)\Xfire2\XFDriver64.sys [17160 2013-03-14] (XFire)
U3 DfSdkS;
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va005; \??\C:\Users\zagreb\AppData\Local\Temp\005DD1A.tmp [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-12 13:24 - 2014-05-12 13:24 - 00005200 _____ () C:\Windows\PFRO.log
2014-05-12 13:06 - 2014-05-12 13:49 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-05-12 13:06 - 2014-05-12 13:29 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 13:04 - 2014-05-12 13:28 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 13:04 - 2014-05-12 13:04 - 00000000 ____D () C:\Users\zagreb\Desktop\RootKit
2014-05-11 13:17 - 2014-03-30 17:03 - 00249856 __RSH () C:\ProgramData\Microsoft.com
2014-05-10 12:04 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-10 12:04 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-10 12:04 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-10 12:04 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-10 11:53 - 2014-05-10 12:02 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:47 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-08 19:47 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-08 19:47 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-08 19:47 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-08 19:47 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-08 19:47 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-08 19:47 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-08 19:47 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-08 19:47 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-08 19:47 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-08 19:47 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-08 19:47 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-08 19:45 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-08 19:45 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-07 12:53 - 2014-05-12 13:01 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion

==================== One Month Modified Files and Folders =======

2014-05-12 13:53 - 2014-04-01 17:03 - 00025419 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-05-12 13:53 - 2014-04-01 17:03 - 00000000 ____D () C:\FRST
2014-05-12 13:52 - 2011-02-10 21:25 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-05-12 13:52 - 2011-02-10 21:25 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-05-12 13:52 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-12 13:49 - 2014-05-12 13:06 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-05-12 13:41 - 2012-04-08 20:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-12 13:31 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-12 13:31 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-12 13:29 - 2014-05-12 13:06 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 13:29 - 2014-03-30 21:59 - 00000000 ___RD () C:\Users\zagreb\Google Drive
2014-05-12 13:29 - 2013-06-01 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-05-12 13:29 - 2011-07-05 20:56 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-12 13:28 - 2014-05-12 13:04 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 13:28 - 2011-07-05 20:56 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-12 13:27 - 2014-04-10 20:55 - 02010843 _____ () C:\Windows\WindowsUpdate.log
2014-05-12 13:24 - 2014-05-12 13:24 - 00005200 _____ () C:\Windows\PFRO.log
2014-05-12 13:24 - 2014-04-10 20:53 - 00002184 _____ () C:\Windows\setupact.log
2014-05-12 13:24 - 2014-04-01 22:25 - 00000000 ____D () C:\Users\zagreb\Documents\MSDCSC
2014-05-12 13:24 - 2014-03-31 18:46 - 00000000 __SHD () C:\ProgramData\Windows Manager
2014-05-12 13:24 - 2013-05-24 21:06 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-05-12 13:24 - 2011-07-06 20:45 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Adobe
2014-05-12 13:24 - 2011-03-22 21:00 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-12 13:24 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\addins
2014-05-12 13:24 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-12 13:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-05-12 13:23 - 2013-10-11 21:57 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-12 13:23 - 2013-10-11 21:57 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-12 13:04 - 2014-05-12 13:04 - 00000000 ____D () C:\Users\zagreb\Desktop\RootKit
2014-05-12 13:01 - 2014-05-07 12:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion
2014-05-12 13:01 - 2014-04-01 17:02 - 02066944 _____ (Farbar) C:\Users\zagreb\Desktop\FRST64.exe
2014-05-10 12:02 - 2014-05-10 11:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST
2014-05-10 11:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:41 - 2013-09-24 18:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-08 19:41 - 2012-04-08 20:24 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-08 19:41 - 2011-07-13 21:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-07 12:53 - 2011-10-23 12:33 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job
2014-05-07 12:49 - 2011-12-13 22:28 - 00000000 ____D () C:\Users\zagreb\Desktop\Brunc
2014-05-03 20:11 - 2014-03-29 13:07 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Akamai
2014-04-29 16:01 - 2014-05-10 12:04 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-10 12:04 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-24 10:24 - 2011-08-29 16:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-24 10:16 - 2011-09-25 19:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-04-14 04:24 - 2014-05-08 19:45 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-05-08 19:45 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.6408.dll
C:\Users\zagreb\BalTax2013_installieren.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-10 21:36

==================== End Of Log ============================

--- --- ---

--- --- ---


lG

schrauber 13.05.2014 09:53

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
2014-05-11 13:17 - 2014-03-30 17:03 - 00249856 __RSH () C:\ProgramData\Microsoft.com


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Frisches FRST log bitte.

Crohero 13.05.2014 11:08

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-05-2014 01
Ran by zagreb at 2014-05-13 12:04:57 Run:4
Running from C:\Users\zagreb\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
2014-05-11 13:17 - 2014-03-30 17:03 - 00249856 __RSH () C:\ProgramData\Microsoft.com
       
*****************

HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* => Key not found.
HKCR\CLSID\ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* => Key not found.
C:\ProgramData\Microsoft.com => Moved successfully.

==== End of Fixlog ====

Diese ganzen Sonderzeichen kommen mir spanisch vor haha



FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01
Ran by zagreb (administrator) on ZAGREB-PC on 13-05-2014 12:05:34
Running from C:\Users\zagreb\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Gemalto N.V.) C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-12-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1064224 2013-11-14] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [WheelMouse] => C:\Advanced Wheel Mouse\wh_exec.exe [98304 2007-11-10] ()
HKLM-x32\...\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-02-03] (PC Tools)
HKLM-x32\...\Run: [HTC Sync Loader] => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer [155648 2012-01-31] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
HKU\.DEFAULT\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-07-05] (Google Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-02-15] (Gemalto N.V.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Akamai NetSession Interface] => C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)

==================== Internet (Whitelisted) ====================

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost64.dll (BestOffers)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost.dll (BestOffers)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1

FireFox:
========
FF ProfilePath: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default
FF Homepage: https://www.google.ch/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\zagreb\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\gmailnoads@mywebber.com.xpi [2013-11-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-04-23]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Google Drive) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (YouTube) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (McAfee Security Scan+) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-22]
CHR Extension: (Google-Suche) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (DVDVideoSoft) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-08-13]
CHR Extension: (Google Mail) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\zagreb\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-03-30]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\zagreb\AppData\Local\Temp\tbch.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-02-03] (PC Tools)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-22] ()
S3 TunngleService; D:\Games\tunngle lan game crack\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH)
S2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe" [X]
S2 avgwd; "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe" [X]
S2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [49952 2014-03-21] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-08] (DT Soft Ltd)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 XFDriver64; C:\Program Files (x86)\Xfire2\XFDriver64.sys [17160 2013-03-14] (XFire)
U3 DfSdkS;
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va005; \??\C:\Users\zagreb\AppData\Local\Temp\005DD1A.tmp [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-12 13:24 - 2014-05-12 13:24 - 00005200 _____ () C:\Windows\PFRO.log
2014-05-12 13:06 - 2014-05-12 13:29 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 13:04 - 2014-05-12 13:28 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 13:04 - 2014-05-12 13:04 - 00000000 ____D () C:\Users\zagreb\Desktop\RootKit
2014-05-10 12:04 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-10 12:04 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-10 12:04 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-10 12:04 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-10 11:53 - 2014-05-10 12:02 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:47 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-08 19:47 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-08 19:47 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-08 19:47 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-08 19:47 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-08 19:47 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-08 19:47 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-08 19:47 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-08 19:47 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-08 19:47 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-08 19:47 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-08 19:47 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-08 19:45 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-08 19:45 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-07 12:53 - 2014-05-12 13:01 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion

==================== One Month Modified Files and Folders =======

2014-05-13 12:05 - 2014-04-01 17:03 - 00025539 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-05-13 12:05 - 2014-04-01 17:03 - 00000000 ____D () C:\FRST
2014-05-13 12:01 - 2014-04-10 20:53 - 00002352 _____ () C:\Windows\setupact.log
2014-05-13 12:01 - 2014-03-30 21:59 - 00000000 ___RD () C:\Users\zagreb\Google Drive
2014-05-13 12:01 - 2013-05-24 21:06 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-05-13 12:01 - 2011-07-05 20:56 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-13 12:01 - 2011-03-22 21:00 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-13 12:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-12 14:02 - 2014-04-10 20:55 - 02042036 _____ () C:\Windows\WindowsUpdate.log
2014-05-12 13:54 - 2011-02-10 21:25 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-05-12 13:54 - 2011-02-10 21:25 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-05-12 13:54 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-12 13:41 - 2012-04-08 20:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-12 13:31 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-12 13:31 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-12 13:29 - 2014-05-12 13:06 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 13:29 - 2013-06-01 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-05-12 13:29 - 2011-07-05 20:56 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-12 13:28 - 2014-05-12 13:04 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 13:24 - 2014-05-12 13:24 - 00005200 _____ () C:\Windows\PFRO.log
2014-05-12 13:24 - 2014-04-01 22:25 - 00000000 ____D () C:\Users\zagreb\Documents\MSDCSC
2014-05-12 13:24 - 2014-03-31 18:46 - 00000000 __SHD () C:\ProgramData\Windows Manager
2014-05-12 13:24 - 2011-07-06 20:45 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Adobe
2014-05-12 13:24 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\addins
2014-05-12 13:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-05-12 13:23 - 2013-10-11 21:57 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-12 13:23 - 2013-10-11 21:57 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-12 13:04 - 2014-05-12 13:04 - 00000000 ____D () C:\Users\zagreb\Desktop\RootKit
2014-05-12 13:01 - 2014-05-07 12:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST-OlderVersion
2014-05-12 13:01 - 2014-04-01 17:02 - 02066944 _____ (Farbar) C:\Users\zagreb\Desktop\FRST64.exe
2014-05-10 12:02 - 2014-05-10 11:53 - 00000000 ____D () C:\Users\zagreb\Desktop\FRST
2014-05-10 11:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:41 - 2013-09-24 18:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-08 19:41 - 2012-04-08 20:24 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-08 19:41 - 2011-07-13 21:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-07 12:53 - 2011-10-23 12:33 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job
2014-05-07 12:49 - 2011-12-13 22:28 - 00000000 ____D () C:\Users\zagreb\Desktop\Brunc
2014-05-03 20:11 - 2014-03-29 13:07 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Akamai
2014-04-29 16:01 - 2014-05-10 12:04 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-10 12:04 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-24 10:24 - 2011-08-29 16:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-24 10:16 - 2011-09-25 19:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-04-14 04:24 - 2014-05-08 19:45 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-05-08 19:45 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.6408.dll
C:\Users\zagreb\BalTax2013_installieren.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-10 21:36

==================== End Of Log ============================

--- --- ---


Und, erstellt er sich wieder neu?

lG

schrauber 14.05.2014 11:14

Bis jetzt nicht. Wie läuft die Kiste?

Crohero 15.05.2014 13:18

Liste der Anhänge anzeigen (Anzahl: 4)
Also einige Sachen wurden behoben, andere jedoch nicht.

Als der PC voller Viren war, und ich z.B. Combofix auf den Destktop gezogen habe, wurde es gleich so grau und es kam beim klicken die Fehlermeldung (Bild Zugriffsverweigerung)
Jetzt aber ist das alte Combofixsymbol nicht löschbar (Bild Admin Rechte).
Wenn ich dann auf fortsetzen klicke kommt (Bild Rechte 2).
Das Problem also, ein Paar Symbole lassen sich nicht verschieben oder löschen, da ich anscheinend keine Admin Rechte habe (obwohl ich der Admin bin und es nur 1 Konto auf dem PC gibt)
Und malwarebytes lässt sich nicht Installieren :D (Bild Malware)

Dann versuchte ich neu vom USB auf den PC OTL zu schieben, wuhuu, das ging. Also
machte ich gleich ein Scan..so wie es hier beschrieben wird
HTML-Code:

[URL]http://www.trojaner-board.de/85104-otl-otlogfile-by-oldtimer.html[/URL]


Der OTL Logfile ist zu lange, also musste ich ihn leider so hochladen.




Nach dem hat es mich einfach gezuckt ob ob das gleiche mit Combofix erledigen kann..und es ging (Ich weiss, man darf des nicht benutzen ohne eine Anweisung aber ich war ziemlich wütend und das ganze regt mich langsam auf :rofl: )

Also startete ich Combofix und es ging..

Code:

ComboFix 14-05-13.01 - zagreb 15.05.2014  13:38:35.1.8 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.41.1031.18.8174.6167 [GMT 2:00]
ausgeführt von:: c:\users\zagreb\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Free Games 111\ScRIpthost.dll
c:\users\Public\AlexaNSISPlugin.6408.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\_ctypes.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\_elementtree.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\_hashlib.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\_multiprocessing.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\_socket.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\_ssl.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\pyexpat.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\pysqlite2._sqlite.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\python27.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\pythoncom27.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\PyWinTypes27.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\select.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\unicodedata.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32api.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32com.shell.shell.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32crypt.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32event.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32file.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32gui.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32inet.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32pdh.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32pipe.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32process.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32profile.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32security.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\win32ts.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\windows._lib_cacheinvalidation.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wx._animate.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wx._controls_.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wx._core_.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wx._gdi_.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wx._html2.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wx._misc_.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wx._windows_.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wx._wizard.pyd
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wxbase294u_net_vc90.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wxbase294u_vc90.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wxmsw294u_adv_vc90.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wxmsw294u_core_vc90.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wxmsw294u_html_vc90.dll
c:\users\zagreb\AppData\Local\Temp\_MEI39962\wxmsw294u_webview_vc90.dll
c:\users\zagreb\AppData\Roaming\WindowsHelp
c:\users\zagreb\AppData\Roaming\WindowsHelp\coinutil.dll
c:\users\zagreb\AppData\Roaming\WindowsHelp\killer.bat
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\compile.bat
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part10
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part11
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part12
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part13
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part14
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part15
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part16
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part17
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part18
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part19
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part2
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part20
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part21
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part22
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part23
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part24
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part25
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part26
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part27
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part28
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part29
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part3
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part30
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part31
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part32
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part33
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part34
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part35
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part36
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part37
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part38
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part39
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part4
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part40
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part41
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part42
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part43
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part44
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part45
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part46
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part47
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part48
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part49
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part5
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part50
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part51
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part52
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part53
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part54
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part55
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part56
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part57
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part58
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part59
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part6
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part60
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part61
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part62
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part63
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part64
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part65
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part66
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part67
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part68
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part69
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part7
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part70
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part71
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part72
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part73
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part74
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part75
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part76
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part77
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part78
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part79
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part8
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part80
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part81
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part82
c:\users\zagreb\AppData\Roaming\WindowsHelp\macro\macromedia.exe_part9
c:\users\zagreb\AppData\Roaming\WindowsHelp\macromedia.exe
c:\users\zagreb\AppData\Roaming\WindowsHelp\miner.dll
c:\users\zagreb\AppData\Roaming\WindowsHelp\openssl.dll
c:\users\zagreb\AppData\Roaming\WindowsHelp\phatk.cl
c:\users\zagreb\AppData\Roaming\WindowsHelp\phatk.ptx
c:\users\zagreb\AppData\Roaming\WindowsHelp\puts.vbs
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\compile.bat
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part10
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part11
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part12
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part13
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part14
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part15
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part16
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part17
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part18
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part19
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part2
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part20
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part21
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part22
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part23
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part24
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part25
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part26
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part27
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part28
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part29
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part3
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part30
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part31
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part32
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part33
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part34
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part35
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part36
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part37
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part38
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part39
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part4
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part40
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part41
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part42
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part43
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part44
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part45
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part46
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part47
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part48
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part49
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part5
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part50
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part51
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part52
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part53
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part54
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part55
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part56
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part57
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part58
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part59
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part6
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part60
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part61
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part62
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part63
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part64
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part65
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part66
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part67
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part68
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part69
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part7
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part70
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part71
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part72
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part73
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part74
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part75
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part76
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part77
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part78
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part79
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part8
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part80
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part81
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part82
c:\users\zagreb\AppData\Roaming\WindowsHelp\shel\shell.exe_part9
c:\users\zagreb\AppData\Roaming\WindowsHelp\shell.exe
c:\users\zagreb\AppData\Roaming\WindowsHelp\usft_ext.dll
c:\users\zagreb\BalTax2013_installieren.exe
c:\windows\RazorDOX
c:\windows\RazorDOX\RazorDOX.dll
D:\install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2014-04-15 bis 2014-05-15  ))))))))))))))))))))))))))))))
.
.
2014-05-13 10:06 . 2014-05-13 10:22        --------        d-----w-        c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-05-12 11:06 . 2014-05-13 10:06        119000        ----a-w-        c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-12 11:04 . 2014-05-13 10:06        91352        ----a-w-        c:\windows\system32\drivers\mbamchameleon.sys
2014-05-10 10:04 . 2014-04-29 14:01        23547904        ----a-w-        c:\windows\system32\mshtml.dll
2014-05-10 10:04 . 2014-04-29 13:40        2724864        ----a-w-        c:\windows\system32\mshtml.tlb
2014-05-10 10:04 . 2014-04-29 12:34        2724864        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2014-05-08 17:45 . 2014-04-14 02:24        465408        ----a-w-        c:\windows\system32\aepdu.dll
2014-05-08 17:45 . 2014-04-14 02:19        424448        ----a-w-        c:\windows\system32\aeinv.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-15 10:41 . 2012-04-08 18:24        692400        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-15 10:41 . 2011-07-13 19:59        70832        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-10 22:02 . 2011-02-10 20:56        90655440        ----a-w-        c:\windows\system32\MRT.exe
2014-03-21 10:52 . 2014-03-19 22:26        49952        ----a-w-        c:\windows\system32\drivers\avgtpx64.sys
2014-03-04 09:44 . 2014-04-10 19:07        362496        ----a-w-        c:\windows\system32\wow64win.dll
2014-03-04 09:44 . 2014-04-10 19:07        243712        ----a-w-        c:\windows\system32\wow64.dll
2014-03-04 09:44 . 2014-04-10 19:07        13312        ----a-w-        c:\windows\system32\wow64cpu.dll
2014-03-04 09:44 . 2014-04-10 19:07        16384        ----a-w-        c:\windows\system32\ntvdm64.dll
2014-03-04 09:44 . 2014-04-10 19:07        1163264        ----a-w-        c:\windows\system32\kernel32.dll
2014-03-04 09:17 . 2014-04-10 19:07        14336        ----a-w-        c:\windows\SysWow64\ntvdm64.dll
2014-03-04 09:17 . 2014-04-10 19:07        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
2014-03-04 09:16 . 2014-04-10 19:07        25600        ----a-w-        c:\windows\SysWow64\setup16.exe
2014-03-04 09:16 . 2014-04-10 19:07        5120        ----a-w-        c:\windows\SysWow64\wow32.dll
2014-03-04 08:09 . 2014-04-10 19:07        7680        ----a-w-        c:\windows\SysWow64\instnm.exe
2014-03-04 08:09 . 2014-04-10 19:07        2048        ----a-w-        c:\windows\SysWow64\user.exe
2014-02-17 00:32 . 2014-03-07 18:00        10536864        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{1C564539-BC91-4061-8BA0-30527BE89AC7}\mpengine.dll
2012-05-11 13:16 . 2012-05-11 13:16        171520        ----a-w-        c:\program files (x86)\Common Files\dsfOggDemux2.dll
2011-04-18 21:51 . 2011-04-18 21:51        653136        ----a-w-        c:\program files (x86)\Common Files\MSVCR90.dll
2011-04-18 21:51 . 2011-04-18 21:51        569680        ----a-w-        c:\program files (x86)\Common Files\MSVCP90.dll
2011-01-12 01:00 . 2011-01-12 01:00        30208        ----a-w-        c:\program files (x86)\Common Files\wmpinfo.dll
2011-01-12 01:00 . 2011-01-12 01:00        240128        ----a-w-        c:\program files (x86)\Common Files\dsfVorbisDecoder.dll
2011-01-12 01:00 . 2011-01-12 01:00        146944        ----a-w-        c:\program files (x86)\Common Files\dsfFLACDecoder.dll
2011-01-12 01:00 . 2011-01-12 01:00        221184        ----a-w-        c:\program files (x86)\Common Files\dsfFLACEncoder.dll
2011-01-12 01:00 . 2011-01-12 01:00        204800        ----a-w-        c:\program files (x86)\Common Files\dsfNativeFLACSource.dll
2010-12-16 20:39 . 2010-12-16 20:39        302592        ----a-w-        c:\program files (x86)\Common Files\webmmux.dll
2010-12-16 20:39 . 2010-12-16 20:39        701440        ----a-w-        c:\program files (x86)\Common Files\vp8encoder.dll
2010-12-16 20:39 . 2010-12-16 20:39        412672        ----a-w-        c:\program files (x86)\Common Files\vp8decoder.dll
2010-12-16 20:39 . 2010-12-16 20:39        292352        ----a-w-        c:\program files (x86)\Common Files\webmsplit.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-03-12 18:13        1728216        ----a-w-        c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-03-12 18:13        1728216        ----a-w-        c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-03-12 18:13        1728216        ----a-w-        c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-05 39408]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2009-07-14 44544]
"SanDiskSecureAccess_Manager.exe"="c:\users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe" [2012-02-14 30705792]
"Akamai NetSession Interface"="c:\users\zagreb\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2014-04-25 22415552]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2010-06-10 2621440]
"WheelMouse"="c:\advanc~1\wh_exec.exe" [2007-11-10 98304]
"SSDMonitor"="c:\program files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2012-02-03 103896]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2010-09-08 249856]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Duden Korrektor SysTray"="c:\program files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe" [2011-07-14 332432]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-9-25 1041920]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.141\SSScheduler.exe [2014-1-16 329944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\persistentroutes]
"62.75.206.182,255.255.255.255,10.0.0.12,1"=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2014\avgidsagent.exe;c:\program files (x86)\AVG\AVG2014\avgidsagent.exe [x]
R2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 vToolbarUpdater18.0.5;vToolbarUpdater18.0.5;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.141\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.141\McCHSvc.exe [x]
R3 mv91xx;mv91xx;c:\windows\system32\drivers\mv91xx.sys;c:\windows\SYSNATIVE\drivers\mv91xx.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TunngleService;TunngleService;d:\games\tunngle lan game crack\Tunngle\TnglCtrl.exe;d:\games\tunngle lan game crack\Tunngle\TnglCtrl.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\drivers\WSDScan.sys;c:\windows\SYSNATIVE\drivers\WSDScan.sys [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R3 X6va005;X6va005;c:\users\zagreb\AppData\Local\Temp\005DD1A.tmp;c:\users\zagreb\AppData\Local\Temp\005DD1A.tmp [x]
R3 XFDriver64;XFDriver64;c:\program files (x86)\Xfire2\XFDriver64.sys;c:\program files (x86)\Xfire2\XFDriver64.sys [x]
R4 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe [x]
R4 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]
S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe;c:\program files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\6de2ed6f-0b56-4d57-b0f0-551ec8cbb27f]
2011-07-01 09:38        153232        ---ha-w-        c:\programdata\Duden\DKReg.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{07e84f41-11d5-4615-aaf6-368df0762b41}]
2011-07-01 09:38        153232        ---ha-w-        c:\programdata\Duden\DKReg.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-03 18:22        1078088        ----a-w-        c:\program files (x86)\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-05-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 10:41]
.
2014-04-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001Core.job
- c:\users\zagreb\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-23 04:39]
.
2014-05-15 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job
- c:\users\zagreb\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-23 04:39]
.
2014-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-05 18:56]
.
2014-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-05 18:56]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-03-12 18:10        2333400        ----a-w-        c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-03-12 18:10        2333400        ----a-w-        c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-03-12 18:10        2333400        ----a-w-        c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-04-25 08:03        777032        ----a-w-        c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-04-25 08:03        777032        ----a-w-        c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-04-25 08:03        777032        ----a-w-        c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-04-25 08:03        777032        ----a-w-        c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-04-25 08:03        777032        ----a-w-        c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-04-25 08:03        777032        ----a-w-        c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-12-11 12459112]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-11-14 1064224]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\persistentroutes]
"62.75.206.182,255.255.255.255,10.0.0.12,1"=""
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
mCustomizeSearch = hxxp://www.google.com
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/5222-72748-17534-1/4
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 10.0.0.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.ch/
FF - prefs.js: keyword.URL -
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{C45EC9F0-8333-465D-9728-074BD41985C9} - c:\program files (x86)\Free Games 111\ScriptHost.dll
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - (no file)
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
AddRemove-Biet-O-Matic v2.14.12 - c:\progra~2\BIET-O~1\UNWISE.EXE
AddRemove-Cheat Engine 6.1_is1 - c:\program files (x86)\Cheat Engine 6.1\unins000.exe
AddRemove-GamersFirst War Rock - d:\games\Warrock\wr2\War Rock\uninstall.exe
AddRemove-PunkBusterSvc - d:\games\pbsvc_heroes.exe
AddRemove-FoxTab MP3 Converter - c:\program files (x86)\FoxTabMP3Converter\Uninstall\Uninstall.exe
AddRemove-FoxTab Music Converter - c:\program files (x86)\FoxTabMusicConverter\Uninstall\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\zagreb\AppData\Local\Temp\005DD1A.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\SecuROM\License information*]
"datasecu"=hex:d4,29,37,e9,56,4d,2d,f4,9b,1f,c4,83,94,d2,cd,19,0d,9a,f3,e6,3b,
  37,6a,a4,4b,73,04,0a,52,bb,f8,d2,b9,32,57,6c,61,55,7f,a3,e3,57,6f,56,08,ef,\
"rkeysecu"=hex:a4,22,89,a0,a3,36,58,50,80,18,84,9a,7a,dd,59,e7
.
[HKEY_USERS\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\d:\Programme\Games\Battlefield 3\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]
"qgif4.dll"=multi:"2011-10-10T17:42\00gif\00\00"
"qico4.dll"=multi:"2011-10-10T17:42\00ico\00\00"
"qjpeg4.dll"=multi:"2011-10-10T17:42\00jpeg\00jpg\00\00"
.
[HKEY_USERS\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:\d:\Programme\Games\Battlefield 3\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]
"qcncodecs4.dll"=multi:"2011-10-10T17:42\00GB18030\00GBK\00GB2312\00CP936\00MS936\00windows-936\00MIB: 114\00MIB: 113\00MIB: 2025\00\00"
"qkrcodecs4.dll"=multi:"2011-10-10T17:42\00EUC-KR\00cp949\00MIB: 38\00MIB: -949\00\00"
"qtwcodecs4.dll"=multi:"2011-10-10T17:42\00Big5\00Big5-HKSCS\00Big5-ETen\00CP950\00MIB: 2026\00MIB: 2101\00\00"
.
[HKEY_USERS\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\d:\programme\Games\Battlefield 3\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]
"qcncodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qjpcodecs4.dll"=multi:"40602\000\00Windows msvc release full-config\002011-10-10T17:42\00\00"
"qjpcodecsd4.dll"=multi:"40703\001\00Windows msvc debug full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qkrcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qtwcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
.
[HKEY_USERS\S-1-5-21-3224943155-1584954436-3819599901-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\d:\programme\Games\Battlefield 3\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]
"Microsoft.VC80.CRT.manifest"=multi:"0\001\00unknown\002011-10-10T17:42\00\00"
"msvcr80.dll"=multi:"0\001\00unknown\002011-10-10T17:42\00\00"
"qgif4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qico4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qjpeg4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Canon\IJPLM\IJPLMSVC.EXE
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-05-15  13:52:01 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2014-05-15 11:51
.
Vor Suchlauf: 490'708'992 Bytes frei
Nach Suchlauf: 742'805'504 Bytes frei
.
- - End Of File - - BCBC67F63EC55950022F75C238A8F631


Und dann wie gewohnt ein FRST

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01
Ran by zagreb (administrator) on ZAGREB-PC on 15-05-2014 13:58:21
Running from C:\Users\zagreb\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Gemalto N.V.) C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Akamai Technologies, Inc.) C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
() C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-12-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1064224 2013-11-14] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [WheelMouse] => C:\Advanced Wheel Mouse\wh_exec.exe [98304 2007-11-10] ()
HKLM-x32\...\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2012-02-03] (PC Tools)
HKLM-x32\...\Run: [HTC Sync Loader] => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer [155648 2012-01-31] ()
HKU\.DEFAULT\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-07-05] (Google Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\zagreb\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-02-15] (Gemalto N.V.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [Akamai NetSession Interface] => C:\Users\zagreb\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google)
HKU\S-1-5-21-3224943155-1584954436-3819599901-1003\...\Run: [Duden Korrektor SysTray] => C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-14] (Expert System S.p.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost.dll No File
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} -  No File
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1

FireFox:
========
FF ProfilePath: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default
FF Homepage: https://www.google.ch/
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\zagreb\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\zagreb\AppData\Roaming\Mozilla\Firefox\Profiles\l8936yk6.default\Extensions\gmailnoads@mywebber.com.xpi [2013-11-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-04-23]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-01]
CHR Extension: (Google Drive) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (YouTube) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-01]
CHR Extension: (McAfee Security Scan+) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-22]
CHR Extension: (Google-Suche) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01]
CHR Extension: (DVDVideoSoft) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-08-13]
CHR Extension: (Google Mail) - C:\Users\zagreb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-01]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\zagreb\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-03-30]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\zagreb\AppData\Local\Temp\tbch.crx [2013-08-10]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2012-02-03] (PC Tools)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-22] ()
S3 TunngleService; D:\Games\tunngle lan game crack\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH)
S2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe" [X]
S2 avgwd; "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe" [X]
S2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [49952 2014-03-21] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-08] (DT Soft Ltd)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 XFDriver64; C:\Program Files (x86)\Xfire2\XFDriver64.sys [17160 2013-03-14] (XFire)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U3 DfSdkS;
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va005; \??\C:\Users\zagreb\AppData\Local\Temp\005DD1A.tmp [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-15 13:52 - 2014-05-15 13:52 - 00046984 _____ () C:\ComboFix.txt
2014-05-15 13:37 - 2014-05-15 13:52 - 00000000 ____D () C:\Qoobox
2014-05-15 13:37 - 2014-05-15 13:50 - 00000000 ____D () C:\Windows\erdnt
2014-05-15 13:37 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-15 13:37 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-15 13:37 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-15 13:37 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-15 13:37 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-15 13:37 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-15 13:37 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-15 13:37 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-15 13:36 - 2014-05-15 13:36 - 05200050 ____R (Swearware) C:\Users\zagreb\Desktop\ComboFix.exe
2014-05-15 13:34 - 2014-05-15 13:34 - 00136882 _____ () C:\Users\zagreb\Desktop\Extras.Txt
2014-05-15 13:34 - 2014-05-15 13:34 - 00136048 _____ () C:\Users\zagreb\Desktop\OTL.Txt
2014-05-15 13:14 - 2014-05-15 13:58 - 00025567 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-05-15 13:05 - 2014-05-15 13:07 - 00000000 ____D () C:\Users\zagreb\Desktop\maö
2014-05-13 12:06 - 2014-05-13 12:22 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-05-12 13:24 - 2014-05-15 13:46 - 00005752 _____ () C:\Windows\PFRO.log
2014-05-12 13:06 - 2014-05-13 12:06 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 13:04 - 2014-05-13 12:06 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 13:04 - 2014-05-12 13:04 - 00000000 ____D () C:\Users\zagreb\Desktop\RootKit
2014-05-10 12:04 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-10 12:04 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-10 12:04 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-10 12:04 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 19:47 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-08 19:47 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-08 19:47 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-08 19:47 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-08 19:47 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-08 19:47 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-08 19:47 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-08 19:47 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-08 19:47 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-08 19:47 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-08 19:47 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-08 19:47 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-08 19:47 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-08 19:47 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-08 19:47 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-08 19:47 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-08 19:47 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-08 19:47 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-08 19:47 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-08 19:47 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-08 19:47 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-08 19:47 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-08 19:47 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-08 19:47 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-08 19:47 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-08 19:47 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-08 19:47 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-08 19:47 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-08 19:45 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-08 19:45 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll

==================== One Month Modified Files and Folders =======

2014-05-15 13:58 - 2014-05-15 13:14 - 00025567 _____ () C:\Users\zagreb\Desktop\FRST.txt
2014-05-15 13:58 - 2014-04-01 17:03 - 00000000 ____D () C:\FRST
2014-05-15 13:55 - 2013-01-14 14:50 - 00002060 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-05-15 13:55 - 2012-08-18 11:42 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-05-15 13:54 - 2014-04-10 20:53 - 00003024 _____ () C:\Windows\setupact.log
2014-05-15 13:54 - 2014-03-30 21:59 - 00000000 ___RD () C:\Users\zagreb\Google Drive
2014-05-15 13:54 - 2013-05-24 21:06 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-05-15 13:54 - 2011-07-05 20:56 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-15 13:54 - 2011-03-22 21:00 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-15 13:54 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-15 13:53 - 2014-04-10 20:55 - 01170038 _____ () C:\Windows\WindowsUpdate.log
2014-05-15 13:53 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-15 13:53 - 2009-07-14 06:45 - 00021296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-15 13:52 - 2014-05-15 13:52 - 00046984 _____ () C:\ComboFix.txt
2014-05-15 13:52 - 2014-05-15 13:37 - 00000000 ____D () C:\Qoobox
2014-05-15 13:50 - 2014-05-15 13:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-15 13:50 - 2011-02-10 21:25 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-05-15 13:50 - 2011-02-10 21:25 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-05-15 13:50 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-15 13:46 - 2014-05-12 13:24 - 00005752 _____ () C:\Windows\PFRO.log
2014-05-15 13:46 - 2011-10-23 12:33 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3224943155-1584954436-3819599901-1001UA.job
2014-05-15 13:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-05-15 13:46 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-15 13:42 - 2014-02-17 00:14 - 00000000 ____D () C:\Program Files (x86)\Free Games 111
2014-05-15 13:42 - 2011-07-05 20:59 - 00000000 ____D () C:\Users\zagreb
2014-05-15 13:41 - 2012-04-08 20:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-15 13:36 - 2014-05-15 13:36 - 05200050 ____R (Swearware) C:\Users\zagreb\Desktop\ComboFix.exe
2014-05-15 13:34 - 2014-05-15 13:34 - 00136882 _____ () C:\Users\zagreb\Desktop\Extras.Txt
2014-05-15 13:34 - 2014-05-15 13:34 - 00136048 _____ () C:\Users\zagreb\Desktop\OTL.Txt
2014-05-15 13:28 - 2011-07-05 20:56 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-15 13:07 - 2014-05-15 13:05 - 00000000 ____D () C:\Users\zagreb\Desktop\maö
2014-05-15 13:05 - 2011-12-13 22:28 - 00000000 ____D () C:\Users\zagreb\Desktop\Brunc
2014-05-15 12:41 - 2013-09-24 18:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-15 12:41 - 2012-04-08 20:24 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-15 12:41 - 2011-07-13 21:59 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-15 12:32 - 2012-12-09 01:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-05-15 12:32 - 2011-08-29 16:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 12:32 - 2009-07-14 04:34 - 00000478 _____ () C:\Windows\win.ini
2014-05-15 12:29 - 2011-07-06 20:45 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Adobe
2014-05-13 12:22 - 2014-05-13 12:06 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-05-13 12:06 - 2014-05-12 13:06 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-13 12:06 - 2014-05-12 13:04 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 13:29 - 2013-06-01 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-05-12 13:24 - 2014-04-01 22:25 - 00000000 ____D () C:\Users\zagreb\Documents\MSDCSC
2014-05-12 13:24 - 2014-03-31 18:46 - 00000000 __SHD () C:\ProgramData\Windows Manager
2014-05-12 13:24 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\addins
2014-05-12 13:23 - 2013-10-11 21:57 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-12 13:23 - 2013-10-11 21:57 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-12 13:04 - 2014-05-12 13:04 - 00000000 ____D () C:\Users\zagreb\Desktop\RootKit
2014-05-12 13:01 - 2014-04-01 17:02 - 02066944 _____ (Farbar) C:\Users\zagreb\Desktop\FRST64.exe
2014-05-10 11:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-08 19:47 - 2014-05-08 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-03 20:11 - 2014-03-29 13:07 - 00000000 ____D () C:\Users\zagreb\AppData\Local\Akamai
2014-04-29 16:01 - 2014-05-10 12:04 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-10 12:04 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-10 12:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-24 10:16 - 2011-09-25 19:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-10 21:36

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

--- --- ---


Ich hoffe du regst dich nicht auf, da ich das ganze auf eigene Hand gemacht hab. Naja eigentlich musst du dich nicht aufregen, habe höchstens mir Schaden angerichtet :D

lG

schrauber 16.05.2014 11:11

Bitte mal das machen:
http://www.trojaner-board.de/126216-...epair-aio.html


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:31 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131