Anti-Malwar Logfile: Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.01.08.04
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16750
Charlie :: CHARLIE-VAIO [Administrator]
08.01.2014 15:13:42
mbam-log-2014-01-08 (15-13-42).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|M:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 619014
Laufzeit: 2 Stunde(n), 47 Minute(n), 15 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 25
HKCR\CLSID\{2C805D62-2703-F2E5-DCD4-0239AEA49A03} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C805D62-2703-F2E5-DCD4-0239AEA49A03} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2C805D62-2703-F2E5-DCD4-0239AEA49A03} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2C805D62-2703-F2E5-DCD4-0239AEA49A03} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2C805D62-2703-F2E5-DCD4-0239AEA49A03} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{1576E68C-2DA7-962E-2453-0A5827EF7F4C} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1576E68C-2DA7-962E-2453-0A5827EF7F4C} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1576E68C-2DA7-962E-2453-0A5827EF7F4C} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1576E68C-2DA7-962E-2453-0A5827EF7F4C} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1576E68C-2DA7-962E-2453-0A5827EF7F4C} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{77CA3678-3090-C527-7918-27D7B78D4A8E} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77CA3678-3090-C527-7918-27D7B78D4A8E} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{77CA3678-3090-C527-7918-27D7B78D4A8E} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77CA3678-3090-C527-7918-27D7B78D4A8E} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{77CA3678-3090-C527-7918-27D7B78D4A8E} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{E62BCD8F-2460-7E01-529D-3EB6E8EF3C72} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E62BCD8F-2460-7E01-529D-3EB6E8EF3C72} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E62BCD8F-2460-7E01-529D-3EB6E8EF3C72} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E62BCD8F-2460-7E01-529D-3EB6E8EF3C72} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E62BCD8F-2460-7E01-529D-3EB6E8EF3C72} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} (PUP.Optional.GreatSaver.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{4102A1B4-22BB-A431-A4CF-D6C3E2D7A547} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4102A1B4-22BB-A431-A4CF-D6C3E2D7A547} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{F2B2A7FF-B93B-2F87-4D95-C16E16A6DB01} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F2B2A7FF-B93B-2F87-4D95-C16E16A6DB01} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 13
C:\ProgramData\SHaoppDRop\H7YuTsJgnw.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\HappY2Save\bGeK_PvhbO.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\CoupExtenesiOn\q.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\SavERExtension\4IPdsdMDGz.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\CoupExtenesiOn\q.x64.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\DealExpreSs\tG8_DB8qO.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\DealExpreSs\tG8_DB8qO.x64.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\HappY2Save\bGeK_PvhbO.x64.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\SavERExtension\4IPdsdMDGz.x64.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\SaverExxtuension\MGEP_.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\SaverExxtuension\MGEP_.x64.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\SHaoppDRop\H7YuTsJgnw.x64.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Charlie\AppData\Local\Temp\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) Hitman Pro Log: Code:
HitmanPro 3.7.8.208
www.hitmanpro.com
Computer name . . . . : CHARLIE-VAIO
Windows . . . . . . . : 6.1.1.7601.X64/4
User name . . . . . . : Charlie-VAIO\Charlie
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2014-01-08 19:47:29
Scan mode . . . . . . : Normal
Scan duration . . . . : 23m 41s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 2
Traces . . . . . . . : 80
Objects scanned . . . : 2.570.799
Files scanned . . . . : 167.435
Remnants scanned . . : 987.981 files / 1.415.383 keys
Malware _____________________________________________________________________
C:\ProgramData\Win sys filter\Winsysfilter.dll
Size . . . . . . . : 4.270.592 bytes
Age . . . . . . . : 8.3 days (2013-12-31 11:26:02)
Entropy . . . . . : 7.1
SHA-256 . . . . . : 2C5B2F2B7090BEFB39AA3CA124CDCEEFB4A758FCD24B10DCB087F75F16A4C16A
> Kaspersky . . . . : HEUR:Trojan.Win32.Generic
Fuzzy . . . . . . : 103.0
Forensic Cluster
-0.0s C:\ProgramData\Win sys filter\
0.0s C:\ProgramData\Win sys filter\Winsysfilter.dll
3.2s C:\ProgramData\Win sys filter\Winsysfilter_x64.dll
3.7s C:\ProgramData\Win sys filter\WinsysfilterSvc.dll
5.0s C:\Windows\Prefetch\DN1EDE.TMP-1E10FACE.pf
6.5s C:\Users\Charlie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I35YJHG6\statusCA6VAPYH.json
C:\Users\Charlie\AppData\Local\Temp\dnE699.tmp
Size . . . . . . . : 4.776.448 bytes
Age . . . . . . . : 8.8 days (2013-12-31 01:09:19)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 14F1F92178661F746D628BF4FE8ECF6ABC5BCE4F8C2504399E952B2CF864F89E
> Bitdefender . . . : Gen:Variant.Kazy.316599
Fuzzy . . . . . . : 114.0
Forensic Cluster
-0.4s C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.665.Crwl
0.0s C:\Users\Charlie\AppData\Local\Temp\dnE699.tmp
Cookies _____________________________________________________________________
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad-emea.doubleclick.net
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.123-template.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.ad-srv.net
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.zanox.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.creative-serving.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.escinteractive.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.p161.net
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.yahoo.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserverpub.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising-support.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:de.sitestat.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:eas.apm.emediate.eu
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:emjcd.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:pool-eu-ie.creative-serving.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:premiumtv.122.2o7.net
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:statcounter.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:tradedoubler.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ww251.smartadserver.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:www6.smartadserver.com
C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Cookies:xiti.com
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\2OFVBP8F.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\3LCB7HJV.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\9ROO2WI0.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\9YKYZ137.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\B3UDWRQE.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\DTELU11K.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\PAIT0UY3.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\PQCJP6OM.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\QV69PBEM.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\R9L9AQFL.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\SVDHDMBF.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\T65DL2E1.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\TTB8Y5LB.txt
C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Cookies\WBZY9K8I.txt
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:ad.yieldmanager.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:ad.zanox.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:adtech.de
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:advertising.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:apmebf.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:atdmt.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:doubleclick.net
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:ero-advertising.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:invitemedia.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:mediaplex.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:premiumtv.122.2o7.net
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:revsci.net
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:sexad.net
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:stats.betradar.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:statse.webtrendslive.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:streamate.doublepimp.com
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:track.adform.net
C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\cookies.sqlite:www.etracker.de defogger log: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 21:06 on 08/01/2014 (Charlie)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Log:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014 01
Ran by Charlie (administrator) on CHARLIE-VAIO on 08-01-2014 20:26:56
Running from C:\Users\Charlie\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
() C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Firebird Project) C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
() C:\Windows\SysWOW64\HsMgr.exe
() C:\Windows\system\HsMgr64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Dropbox, Inc.) C:\Users\Charlie\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Google Inc.) C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
(Firebird Project) C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Google Inc.) C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Google Inc.) C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Google Inc.) C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-29] (Conexant Systems, Inc.)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [790176 2011-03-31] (Atheros Communications)
HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [657056 2011-03-31] (Atheros Commnucations)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [226672 2011-02-17] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [Cm112Sound] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm112.dll,CMICtrlWnd
HKLM\...\Run: [Cm112GX] - C:\Windows\SysWOW64\HsMgr.exe [200704 2008-07-11] ()
HKLM\...\Run: [Cm112GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] ()
HKLM\...\Run: [Cm108Sound] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [2757312 2011-02-15] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-26] (Sony Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-26] (AVAST Software)
HKCU\...\Run: [Google Update] - C:\Users\Charlie\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-08-27] (Google Inc.)
AppInit_DLLs: C:\ProgramData\Win sys filter\Winsysfilter_x64.dll [4539904 2013-12-31] ()
AppInit_DLLs-x32: c:\progra~3\webtect\webtect.dll c:\progra~3\winsys~1\winsys~1.dll [ ] ()
Startup: C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Charlie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE9475A899D9ECE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://startsear.ch/?aff=1&q={searchTerms}
SearchScopes: HKCU - {408B6B9F-154A-48A3-8E6A-92804D1F51B0} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKCU - {7C2F6073-2FC5-43D2-9D96-8840CFA6F129} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-21/4?satitle={searchTerms}
SearchScopes: HKCU - {AC457CC2-2E7A-4F6A-825D-25123C566EF2} URL = hxxp://de.shopping.com/?linkin_id=8056363
BHO: HappY2Save - {1576E68C-2DA7-962E-2453-0A5827EF7F4C} - C:\ProgramData\HappY2Save\bGeK_PvhbO.x64.dll No File
BHO: SHaoppDRop - {2C805D62-2703-F2E5-DCD4-0239AEA49A03} - C:\ProgramData\SHaoppDRop\H7YuTsJgnw.x64.dll No File
BHO: CoupExtenesiOn - {77CA3678-3090-C527-7918-27D7B78D4A8E} - C:\ProgramData\CoupExtenesiOn\q.x64.dll No File
BHO: SavERExtension - {E62BCD8F-2460-7E01-529D-3EB6E8EF3C72} - C:\ProgramData\SavERExtension\4IPdsdMDGz.x64.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default
FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", "");
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", "");
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Keyword.URL: user_pref("keyword.URL", "");
FF Homepage: user_pref("browser.startup.homepage", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - M:\Programme\Pdfviewer\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - M:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - M:\Programme\Pdfviewer\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - M:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - M:\Programme\WebDivix\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - M:\Programme\WebDivix\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - M:\Programme\Pdfviewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll No File
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - M:\Programme\Pdfviewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Charlie\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Charlie\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Charlie\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Charlie\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Extension: No Name - C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\vz8eyhrb.default\Extensions\staged
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - M:\Programme\WebDivix\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - M:\Programme\WebDivix\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
Chrome:
=======
CHR HomePage:
CHR RestoreOnStartup: ""
CHR Plugin: (Shockwave Flash) - C:\Users\Charlie\AppData\Local\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Charlie\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Charlie\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (PDF-XChange Viewer) - C:\Program Files (x86)\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (vShare.tv plug-in) - C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U4) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Live\u00C3\u0082\u00C2\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Facebook Desktop) - C:\Users\Charlie\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Charlie\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Google Update) - C:\Users\Charlie\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (TVU Web Player for FireFox) - C:\Windows\system32\TVUAx\npTVUAx.dll No File
CHR Plugin: (DivX VOD Helper Plug-in) - M:\Programme\WebDivix\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - M:\Programme\WebDivix\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (iTunes Application Detector) - M:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Veetle TV Player) - M:\Programme\veetle\Player\npvlc.dll No File
CHR Plugin: (Veetle TV Core) - M:\Programme\veetle\plugins\npVeetle.dll No File
CHR Extension: (AdBlock) - C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Google Wallet) - C:\Users\Charlie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - M:\Programme\WebDivix\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Charlie\AppData\Local\Google\Chrome\Application\chrome.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 05837205; C:\Windows\system32\rundll32.exe [45568 2009-07-14] (Microsoft Corporation)
R2 05837205; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation)
R2 25e4f9bf; C:\Windows\system32\rundll32.exe [45568 2009-07-14] (Microsoft Corporation)
R2 25e4f9bf; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation)
R2 5717af3d; C:\Windows\system32\rundll32.exe [45568 2009-07-14] (Microsoft Corporation)
R2 5717af3d; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation)
S2 8ffb8f2d; C:\Windows\system32\rundll32.exe [45568 2009-07-14] (Microsoft Corporation)
S2 8ffb8f2d; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-03-31] (Atheros)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-26] (AVAST Software)
S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [26600 2013-10-08] (CyberGhost S.R.L)
S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.)
R2 FirebirdGuardianDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe [98304 2011-10-03] (Firebird Project)
R3 FirebirdServerDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe [3764224 2011-10-03] (Firebird Project)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 Microsoft SharePoint Workspace Audit Service; M:\Programme\Microsoft Office 2010\Office14\GROOVE.EXE [50899608 2012-09-20] (Microsoft Corporation)
S3 OpenVPNService; C:\Program Files (x86)\FH-Aachen OpenVPN\bin\openvpnserv.exe [38926 2011-05-20] ()
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [994360 2011-07-29] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [399416 2011-07-29] (Secunia)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1368624 2013-08-01] (Sony Corporation)
S3 w7Svc; C:\Program Files (x86)\webcam 7\wService.exe [4999680 2011-07-27] (Moonware Studios)
==================== Drivers (Whitelisted) ====================
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
S3 ASUSU1; C:\Windows\System32\drivers\cm11264.sys [1312256 2010-12-15] (C-Media Electronics Inc)
R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-11-26] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-11-26] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-26] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-26] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-11-26] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-26] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-11-26] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-11-26] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-07-01] (DT Soft Ltd)
S3 GemCCID; C:\Windows\System32\DRIVERS\GemCCID.sys [129792 2013-04-24] (Gemalto)
R3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32512 2014-01-08] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-08 20:26 - 2014-01-08 20:27 - 00024969 _____ C:\Users\Charlie\Downloads\FRST.txt
2014-01-08 20:26 - 2014-01-08 20:26 - 00000000 ____D C:\FRST
2014-01-08 20:25 - 2014-01-08 20:25 - 01931770 _____ (Farbar) C:\Users\Charlie\Downloads\FRST64.exe
2014-01-08 20:21 - 2014-01-08 20:21 - 00290728 _____ C:\Windows\Minidump\010814-40841-01.dmp
2014-01-08 20:21 - 2014-01-08 20:21 - 00032512 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2014-01-08 20:17 - 2014-01-08 20:17 - 00000000 ____D C:\Users\Charlie\AppData\Local\{97F2033A-87F9-41FB-B554-FDAC6358B2C3}
2014-01-08 20:16 - 2014-01-08 20:16 - 00000406 _____ C:\Windows\system32\.crusader
2014-01-08 20:13 - 2014-01-08 20:13 - 00017780 _____ C:\Users\Charlie\Desktop\HitmanPro_20140108_2013.log
2014-01-08 19:47 - 2014-01-08 19:47 - 00000000 ____D C:\Program Files\HitmanPro
2014-01-08 19:45 - 2014-01-08 20:16 - 00000000 ____D C:\ProgramData\HitmanPro
2014-01-08 19:45 - 2014-01-08 19:46 - 10264904 _____ (SurfRight B.V.) C:\Users\Charlie\Downloads\HitmanPro_x64.exe
2014-01-08 19:44 - 2014-01-08 19:45 - 09452704 _____ (SurfRight B.V.) C:\Users\Charlie\Downloads\HitmanPro3.7.8.208.exe
2014-01-08 15:04 - 2014-01-08 15:14 - 00000000 ____D C:\AdwCleaner
2014-01-08 15:04 - 2014-01-08 15:04 - 01233962 _____ C:\Users\Charlie\Downloads\adwcleaner.exe
2014-01-05 13:25 - 2014-01-05 13:27 - 00000000 ____D C:\Users\Charlie\AppData\Local\{2059D271-0CF8-4B5A-823E-56D6BC952300}
2014-01-04 16:00 - 2014-01-04 16:02 - 00000000 ____D C:\Users\Charlie\AppData\Local\{F1A5136E-6AAA-4A48-ABDC-CB9891134841}
2014-01-03 23:40 - 2014-01-03 23:40 - 00000000 ____D C:\Users\Charlie\AppData\Local\{F90FAB0F-B667-492E-89D6-28084726F2F8}
2014-01-03 11:38 - 2014-01-03 11:40 - 00000000 ____D C:\Users\Charlie\AppData\Local\{0E800A4D-405D-4963-8F40-D7134BF0BF07}
2014-01-02 10:38 - 2014-01-02 10:38 - 00000000 ____D C:\Users\Charlie\AppData\Local\{CD978F99-34B2-418D-92D1-B8899C3BA276}
2014-01-01 16:17 - 2014-01-08 19:33 - 00000000 ____D C:\ProgramData\SHaoppDRop
2014-01-01 16:17 - 2014-01-08 19:33 - 00000000 ____D C:\ProgramData\SavERExtension
2014-01-01 16:17 - 2014-01-08 19:33 - 00000000 ____D C:\ProgramData\HappY2Save
2014-01-01 16:17 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\phmpmlianadbfifbhfcijdlhgcnfjccn
2014-01-01 16:17 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\daedbbfaebjgclnoijiekplilobacoia
2014-01-01 16:17 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\bddnngaocglmnfhcpcjmoomohjiobgoo
2014-01-01 16:17 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\22542c9f2b1e72fe
2014-01-01 16:16 - 2014-01-08 19:33 - 00000000 ____D C:\ProgramData\SaverExxtuension
2014-01-01 16:16 - 2014-01-08 19:33 - 00000000 ____D C:\ProgramData\DealExpreSs
2014-01-01 16:16 - 2014-01-08 19:33 - 00000000 ____D C:\ProgramData\CoupExtenesiOn
2014-01-01 16:05 - 2014-01-01 16:06 - 00000000 ____D C:\Users\Charlie\AppData\Local\{5DD9B7D8-4BD4-4788-96FA-8385C4ECAAE9}
2014-01-01 16:05 - 2014-01-01 16:05 - 00000000 ____D C:\ProgramData\Browser Enhancer
2013-12-31 13:38 - 2013-12-31 13:38 - 00000000 ____D C:\Users\Charlie\AppData\Local\{779DC68C-497B-4966-AF57-9A257C318056}
2013-12-31 13:18 - 2013-12-31 13:18 - 00000000 ____D C:\ProgramData\Browser faster
2013-12-31 11:26 - 2014-01-08 20:20 - 00000000 ____D C:\ProgramData\Win sys filter
2013-12-31 01:09 - 2013-12-31 01:09 - 00000000 ____D C:\ProgramData\WebTect
2013-12-30 18:46 - 2013-12-30 18:46 - 00000000 ____D C:\Users\Charlie\AppData\Local\{4E2AB506-78A4-44D3-850A-51ED90F674CA}
2013-12-26 00:11 - 2013-12-26 00:12 - 00000000 ____D C:\Users\Charlie\AppData\Local\{848A083E-E5BA-4B32-AA7E-2CC0CF71BE60}
2013-12-24 20:13 - 2014-01-06 22:23 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\ihelper
2013-12-24 19:54 - 2013-12-24 19:55 - 00000000 ____D C:\Users\Charlie\AppData\Local\{5B7B4DC7-F531-4488-A335-8F9F1CA01076}
2013-12-18 08:28 - 2013-12-18 08:28 - 00000000 ____D C:\Users\Charlie\AppData\Local\{D3FAEEC9-0596-42A1-A0ED-3B90A006DFE2}
2013-12-17 15:38 - 2013-12-17 15:38 - 01640448 _____ C:\Users\Charlie\Downloads\371800_Hausubung9_b.fem
2013-12-15 17:14 - 2013-12-15 17:14 - 00000000 ____D C:\Users\Charlie\AppData\Local\{AFEA1299-9DAD-4C77-B85A-DD2173B9E0F0}
2013-12-14 15:10 - 2013-12-16 21:21 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\.ACEStream
2013-12-14 15:09 - 2013-12-15 16:28 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\ACEStream
2013-12-12 17:57 - 2013-12-12 17:57 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\AVAST Software
2013-12-12 13:36 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 13:36 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 13:36 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 13:36 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 13:34 - 2014-01-06 21:18 - 00029514 _____ C:\Windows\IE11_main.log
2013-12-12 13:33 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 13:33 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 13:33 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 13:33 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-12 13:33 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 13:33 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 13:33 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-12 13:33 - 2013-10-25 07:17 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 13:33 - 2013-10-25 07:17 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-12 13:33 - 2013-10-25 07:17 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 13:33 - 2013-10-25 07:17 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 13:33 - 2013-10-25 07:17 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 13:33 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 13:33 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 13:33 - 2013-10-25 05:43 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-12 13:33 - 2013-10-25 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 13:33 - 2013-10-25 04:41 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 13:33 - 2013-10-25 04:17 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-12 13:33 - 2013-10-25 03:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-12 13:32 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 13:32 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 13:32 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 13:32 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 08:59 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 08:59 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 08:59 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 08:59 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 08:59 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 08:59 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 08:59 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 08:59 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 08:59 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 08:59 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 08:59 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 08:59 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 08:59 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 08:59 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 08:59 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 08:59 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 08:58 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 08:58 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 08:58 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Charlie\AppData\Local\{D6D40D54-5338-4C4D-9571-B3F13089D9CC}
2013-12-10 08:54 - 2013-12-10 08:56 - 00000000 ____D C:\Users\Charlie\AppData\Local\{66ED8E0A-8D23-4A1A-8ED7-5EF04F98519A}
2013-12-09 10:47 - 2013-12-09 10:47 - 00000000 ____D C:\Users\Charlie\AppData\Local\{E1561607-14F8-404D-956F-2982AD0A7D96}
2013-12-09 10:43 - 2013-12-09 10:43 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-12-09 10:43 - 2013-12-09 10:43 - 00000000 ____D C:\Program Files\iTunes
2013-12-09 10:43 - 2013-12-09 10:43 - 00000000 ____D C:\Program Files\iPod
==================== One Month Modified Files and Folders =======
2014-01-08 20:27 - 2014-01-08 20:26 - 00024969 _____ C:\Users\Charlie\Downloads\FRST.txt
2014-01-08 20:26 - 2014-01-08 20:26 - 00000000 ____D C:\FRST
2014-01-08 20:26 - 2011-07-01 17:45 - 01462751 _____ C:\Windows\WindowsUpdate.log
2014-01-08 20:25 - 2014-01-08 20:25 - 01931770 _____ (Farbar) C:\Users\Charlie\Downloads\FRST64.exe
2014-01-08 20:25 - 2011-11-26 12:18 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\Dropbox
2014-01-08 20:22 - 2011-11-26 12:20 - 00000000 ___RD C:\Users\Charlie\Dropbox
2014-01-08 20:21 - 2014-01-08 20:21 - 00290728 _____ C:\Windows\Minidump\010814-40841-01.dmp
2014-01-08 20:21 - 2014-01-08 20:21 - 00032512 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2014-01-08 20:21 - 2012-11-21 19:38 - 673884333 _____ C:\Windows\MEMORY.DMP
2014-01-08 20:21 - 2012-11-18 12:11 - 00034261 _____ C:\Windows\setupact.log
2014-01-08 20:21 - 2011-07-15 06:59 - 00000000 ____D C:\Windows\Minidump
2014-01-08 20:21 - 2011-05-10 04:36 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-08 20:21 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-08 20:20 - 2013-12-31 11:26 - 00000000 ____D C:\ProgramData\Win sys filter
2014-01-08 20:17 - 2014-01-08 20:17 - 00000000 ____D C:\Users\Charlie\AppData\Local\{97F2033A-87F9-41FB-B554-FDAC6358B2C3}
2014-01-08 20:16 - 2014-01-08 20:16 - 00000406 _____ C:\Windows\system32\.crusader
2014-01-08 20:16 - 2014-01-08 19:45 - 00000000 ____D C:\ProgramData\HitmanPro
2014-01-08 20:13 - 2014-01-08 20:13 - 00017780 _____ C:\Users\Charlie\Desktop\HitmanPro_20140108_2013.log
2014-01-08 20:02 - 2011-08-27 13:28 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000UA.job
2014-01-08 19:57 - 2013-09-13 22:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-08 19:47 - 2014-01-08 19:47 - 00000000 ____D C:\Program Files\HitmanPro
2014-01-08 19:46 - 2014-01-08 19:45 - 10264904 _____ (SurfRight B.V.) C:\Users\Charlie\Downloads\HitmanPro_x64.exe
2014-01-08 19:45 - 2014-01-08 19:44 - 09452704 _____ (SurfRight B.V.) C:\Users\Charlie\Downloads\HitmanPro3.7.8.208.exe
2014-01-08 19:44 - 2009-07-14 05:45 - 00020928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-08 19:44 - 2009-07-14 05:45 - 00020928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-08 19:35 - 2013-01-11 23:53 - 00050274 _____ C:\Windows\PFRO.log
2014-01-08 19:33 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\SHaoppDRop
2014-01-08 19:33 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\SavERExtension
2014-01-08 19:33 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\HappY2Save
2014-01-08 19:33 - 2014-01-01 16:16 - 00000000 ____D C:\ProgramData\SaverExxtuension
2014-01-08 19:33 - 2014-01-01 16:16 - 00000000 ____D C:\ProgramData\DealExpreSs
2014-01-08 19:33 - 2014-01-01 16:16 - 00000000 ____D C:\ProgramData\CoupExtenesiOn
2014-01-08 19:33 - 2012-10-22 11:07 - 00000660 _____ C:\Windows\Tasks\WebContent AutoUpdate 2012.job
2014-01-08 19:33 - 2011-10-12 17:25 - 00000642 _____ C:\Windows\Tasks\WebContent AutoUpdate 2011.job
2014-01-08 19:33 - 2011-05-10 14:19 - 00697082 _____ C:\Windows\system32\perfh007.dat
2014-01-08 19:33 - 2011-05-10 14:19 - 00148346 _____ C:\Windows\system32\perfc007.dat
2014-01-08 19:33 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-08 17:53 - 2011-07-06 23:44 - 00001146 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000UA.job
2014-01-08 15:14 - 2014-01-08 15:04 - 00000000 ____D C:\AdwCleaner
2014-01-08 15:11 - 2012-08-05 03:26 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2014-01-08 15:04 - 2014-01-08 15:04 - 01233962 _____ C:\Users\Charlie\Downloads\adwcleaner.exe
2014-01-08 14:30 - 2011-07-01 17:47 - 00000000 ___RD C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-08 14:29 - 2011-11-26 12:19 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-08 09:16 - 2011-07-06 23:44 - 00001124 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000Core.job
2014-01-08 09:08 - 2012-10-22 11:07 - 00000504 _____ C:\Windows\Tasks\AutoUpdate Allplan 2012.job
2014-01-08 09:08 - 2011-10-12 17:25 - 00000496 _____ C:\Windows\Tasks\Allplan AutoUpdate 2011-1.job
2014-01-08 09:07 - 2011-08-27 13:28 - 00001076 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000Core.job
2014-01-08 09:07 - 2011-07-01 17:52 - 00003954 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{2ABB2932-AA29-4351-B409-8136CB98F6A6}
2014-01-06 22:23 - 2013-12-24 20:13 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\ihelper
2014-01-06 21:18 - 2013-12-12 13:34 - 00029514 _____ C:\Windows\IE11_main.log
2014-01-06 00:02 - 2011-07-15 07:39 - 00007446 _____ C:\test.xml
2014-01-05 13:27 - 2014-01-05 13:25 - 00000000 ____D C:\Users\Charlie\AppData\Local\{2059D271-0CF8-4B5A-823E-56D6BC952300}
2014-01-04 16:07 - 2013-08-31 11:25 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\vlc
2014-01-04 16:02 - 2014-01-04 16:00 - 00000000 ____D C:\Users\Charlie\AppData\Local\{F1A5136E-6AAA-4A48-ABDC-CB9891134841}
2014-01-03 23:40 - 2014-01-03 23:40 - 00000000 ____D C:\Users\Charlie\AppData\Local\{F90FAB0F-B667-492E-89D6-28084726F2F8}
2014-01-03 11:40 - 2014-01-03 11:38 - 00000000 ____D C:\Users\Charlie\AppData\Local\{0E800A4D-405D-4963-8F40-D7134BF0BF07}
2014-01-02 10:38 - 2014-01-02 10:38 - 00000000 ____D C:\Users\Charlie\AppData\Local\{CD978F99-34B2-418D-92D1-B8899C3BA276}
2014-01-01 16:17 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\phmpmlianadbfifbhfcijdlhgcnfjccn
2014-01-01 16:17 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\daedbbfaebjgclnoijiekplilobacoia
2014-01-01 16:17 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\bddnngaocglmnfhcpcjmoomohjiobgoo
2014-01-01 16:17 - 2014-01-01 16:17 - 00000000 ____D C:\ProgramData\22542c9f2b1e72fe
2014-01-01 16:06 - 2014-01-01 16:05 - 00000000 ____D C:\Users\Charlie\AppData\Local\{5DD9B7D8-4BD4-4788-96FA-8385C4ECAAE9}
2014-01-01 16:05 - 2014-01-01 16:05 - 00000000 ____D C:\ProgramData\Browser Enhancer
2013-12-31 13:38 - 2013-12-31 13:38 - 00000000 ____D C:\Users\Charlie\AppData\Local\{779DC68C-497B-4966-AF57-9A257C318056}
2013-12-31 13:18 - 2013-12-31 13:18 - 00000000 ____D C:\ProgramData\Browser faster
2013-12-31 01:09 - 2013-12-31 01:09 - 00000000 ____D C:\ProgramData\WebTect
2013-12-30 18:46 - 2013-12-30 18:46 - 00000000 ____D C:\Users\Charlie\AppData\Local\{4E2AB506-78A4-44D3-850A-51ED90F674CA}
2013-12-26 00:12 - 2013-12-26 00:11 - 00000000 ____D C:\Users\Charlie\AppData\Local\{848A083E-E5BA-4B32-AA7E-2CC0CF71BE60}
2013-12-24 19:55 - 2013-12-24 19:54 - 00000000 ____D C:\Users\Charlie\AppData\Local\{5B7B4DC7-F531-4488-A335-8F9F1CA01076}
2013-12-18 09:18 - 2013-11-20 12:38 - 00000000 ____D C:\Users\Charlie\.maplesoft
2013-12-18 08:28 - 2013-12-18 08:28 - 00000000 ____D C:\Users\Charlie\AppData\Local\{D3FAEEC9-0596-42A1-A0ED-3B90A006DFE2}
2013-12-17 15:38 - 2013-12-17 15:38 - 01640448 _____ C:\Users\Charlie\Downloads\371800_Hausubung9_b.fem
2013-12-16 21:21 - 2013-12-14 15:10 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\.ACEStream
2013-12-15 17:14 - 2013-12-15 17:14 - 00000000 ____D C:\Users\Charlie\AppData\Local\{AFEA1299-9DAD-4C77-B85A-DD2173B9E0F0}
2013-12-15 16:28 - 2013-12-14 15:09 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\ACEStream
2013-12-15 13:51 - 2013-09-13 22:17 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-15 13:51 - 2013-03-03 13:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-15 13:51 - 2011-07-02 00:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-15 13:31 - 2013-08-22 20:30 - 00000000 ____D C:\Windows\system32\MRT
2013-12-15 03:01 - 2011-07-01 19:06 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-14 15:35 - 2011-07-02 00:52 - 00000000 ____D C:\Users\Charlie\AppData\Local\CrashDumps
2013-12-13 12:43 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-13 11:39 - 2011-07-01 17:45 - 00000000 ____D C:\Users\Charlie
2013-12-12 17:57 - 2013-12-12 17:57 - 00000000 ____D C:\Users\Charlie\AppData\Roaming\AVAST Software
2013-12-12 17:56 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-12 17:51 - 2009-07-14 05:45 - 00556072 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-12 13:32 - 2011-07-01 20:19 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Charlie\AppData\Local\{D6D40D54-5338-4C4D-9571-B3F13089D9CC}
2013-12-10 17:31 - 2013-11-29 11:06 - 00000000 ____D C:\Users\Charlie\Desktop\FH AACHEN MASTER
2013-12-10 08:57 - 2011-08-27 13:28 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000UA
2013-12-10 08:57 - 2011-08-27 13:28 - 00003706 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000Core
2013-12-10 08:56 - 2013-12-10 08:54 - 00000000 ____D C:\Users\Charlie\AppData\Local\{66ED8E0A-8D23-4A1A-8ED7-5EF04F98519A}
2013-12-09 19:44 - 2012-11-18 19:32 - 00000000 ____D C:\Users\Charlie\Desktop\Bachelorarbeit
2013-12-09 10:47 - 2013-12-09 10:47 - 00000000 ____D C:\Users\Charlie\AppData\Local\{E1561607-14F8-404D-956F-2982AD0A7D96}
2013-12-09 10:43 - 2013-12-09 10:43 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-12-09 10:43 - 2013-12-09 10:43 - 00000000 ____D C:\Program Files\iTunes
2013-12-09 10:43 - 2013-12-09 10:43 - 00000000 ____D C:\Program Files\iPod
Files to move or delete:
====================
C:\ProgramData\UninstallFrilo.Exe
Some content of TEMP:
====================
C:\Users\Charlie\AppData\Local\Temp\CGVPNPatch_4719.exe
C:\Users\Charlie\AppData\Local\Temp\eydb2udr.dll
C:\Users\Charlie\AppData\Local\Temp\gk2sbqqe.dll
C:\Users\Charlie\AppData\Local\Temp\JavaRa.exe
C:\Users\Charlie\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Charlie\AppData\Local\Temp\jre-7u45-windows-i586.exe
C:\Users\Charlie\AppData\Local\Temp\MouseKeyboardCenterx64_1031.exe
C:\Users\Charlie\AppData\Local\Temp\MsgPlusUninstall.exe
C:\Users\Charlie\AppData\Local\Temp\ogsvm7gd.dll
C:\Users\Charlie\AppData\Local\Temp\rmup.exe
C:\Users\Charlie\AppData\Local\Temp\Setup-Foto-Mosaik-Edda.exe
C:\Users\Charlie\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Charlie\AppData\Local\Temp\twbu0-f5.dll
C:\Users\Charlie\AppData\Local\Temp\wusetup.exE
C:\Users\Charlie\AppData\Local\Temp\{35A6AE81-4359-4101-A44B-EAEAECE9B832}-25.0.1364.97_24.0.1312.57_chrome_updater.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-24 14:19
==================== End Of Log ============================ --- --- ---
--- --- --- Addition Log: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-01-2014 01
Ran by Charlie at 2014-01-08 20:28:55
Running from C:\Users\Charlie\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
Adobe AIR (x32 Version: 3.8.0.1430 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.8.0.1430 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (x32 Version: 11.6.8.638 - Adobe Systems, Inc.)
Alps Pointing-device for VAIO (Version: - ALPS ELECTRIC CO., LTD.)
Apple Application Support (x32 Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.)
ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.1.142 - ArcSoft)
ArcSoft WebCam Companion 4 (x32 Version: 4.0.21.444 - ArcSoft)
ASUS Xonar U3 Audio (Version: - )
Atheros WiFi Driver Installation (x32 Version: 3.0 - Atheros)
AutoCAD 2012 - Deutsch (Version: 18.2.51.0 - Autodesk)
AutoCAD 2012 - Deutsch (Version: 18.2.51.0 - Autodesk) Hidden
AutoCAD 2012 Language Pack - Deutsch (Version: 18.2.51.0 - Autodesk) Hidden
Autodesk Content Service (x32 Version: 2.0.90 - Autodesk)
Autodesk Inventor Fusion 2012 (Version: 1.0.0.79 - Autodesk, Inc.)
Autodesk Inventor Fusion 2012 (Version: 1.0.0.79 - Autodesk, Inc.) Hidden
Autodesk Inventor Fusion 2012 Language Pack (Version: 1.0.0.79 - Autodesk, Inc.) Hidden
Autodesk Inventor Fusion plug-in for AutoCAD 2012 (Version: 0.0.1.138 - Autodesk)
Autodesk Inventor Fusion Plugin for AutoCAD 2012 (Version: 0.0.1.138 - Autodesk) Hidden
Autodesk Inventor Fusion Plugin Language Pack for AutoCAD 2012 (Version: 0.0.1.138 - Autodesk) Hidden
Autodesk Material Library 2012 (x32 Version: 2.5.0.8 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2012 (x32 Version: 2.5.0.8 - Autodesk)
avast! Free Antivirus (x32 Version: 9.0.2008 - Avast Software)
Bluetooth Win7 Suite (64) (Version: 7.3.0.95 - Atheros Communications)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Browser Enhancer (x32 Version: - Goingo)
Browser faster (x32 Version: - Surfnet)
Canon MG5100 series Benutzerregistrierung (x32 Version: - )
Canon MG5100 series MP Drivers (Version: - )
Canon MP490 series MP Drivers (Version: - )
CCleaner (Version: 3.12 - Piriform)
Conexant HD Audio (Version: 8.54.0.53 - Conexant)
CyberGhost 5 (Version: - CyberGhost S.R.L.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (x32 Version: 4.40.2.0131 - DT Soft Ltd)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (Version: - Microsoft)
Defraggler (Version: 2.08 - Piriform)
DivX-Setup (x32 Version: 2.6.1.9 - DivX, LLC)
Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.)
eDocPrinter PDF Pro 6.83(x64) MSI (Version: 6.83.6171 - ITeksoft Corporation)
eDocPrintPro v3.17.0 (Version: 3.17.0 - MAY-Computer)
Epson Easy Photo Print 2 (x32 Version: 2.1.0.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (x32 Version: 2.30.00 - SEIKO EPSON Corporation)
EPSON Scan (x32 Version: - )
Epson Stylus SX510W_TX550W Handbuch (x32 Version: - )
EPSON SX510W Series Printer Uninstall (Version: - SEIKO EPSON Corporation)
EpsonNet Setup (x32 Version: 3.1a - SEIKO EPSON CORPORATION)
ESET Online Scanner v3 (x32 Version: - )
ESS Energie Indikator (x32 Version: 2011.0 - Nemetschek Allplan GmbH)
Facebook Messenger 2.1.4814.0 (x32 Version: 2.1.4814.0 - Facebook)
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287 - Skype Limited)
FARO LS 1.1.406.58 (x32 Version: 4.6.58.2 - FARO Scanner Production)
FH-Aachen OpenVPN 2.2.0 (x32 Version: 2.2.0 - )
FILSHtray (x32 Version: 0.12 - FILSH Media GmbH)
Firebird 2.5.1.26351 (Win32) (x32 Version: 2.5.1.26351 - Firebird Project)
Foto-Mosaik-Edda Standard V6.8.12318.1 (x32 Version: - Steffen Schirmer)
FreeOCR 3.0 (Version: 3.0 - Free OCR)
FreePDF (Remove only) (x32 Version: - )
Frilo (x32 Version: - )
Frilo Installation (x32 Version: 1.0.0 - Frilo)
Frilo.System.Next (x32 Version: 2.12.11 - Friedrich + Lochner GmbH)
FriloBase (x32 Version: 1.0.0 - Friedrich + Lochner GmbH)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
General Runtime Files for Allplan 2011-1-5 (x32 Version: 1.3.0.0 - Nemetschek Allplan GmbH) Hidden
General Runtime Files for Allplan 2012-1 Release (x32 Version: 1.6.0.0 - Nemetschek Allplan GmbH) Hidden
Google Chrome (HKCU Version: 31.0.1650.63 - Google Inc.)
GPL Ghostscript (Version: 9.04 - Artifex Software Inc.)
gs_x64 (Version: 9.00 - MAY-Computer)
HitmanPro 3.7 (Version: 3.7.8.208 - SurfRight B.V.)
HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät (Version: 28.0.1315.0 - Hewlett-Packard Co.)
iFunbox (v2.0.2103.725), iFunbox DevTeam (x32 Version: v2.0.2103.725 - )
ImgBurn (x32 Version: 2.5.6.0 - LIGHTNING UK!)
InfoCAD Studienversion 13.0a (x32 Version: - InfoGraph GmbH, Kackertstrasse 10, 52072 Aachen, Germany)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (x32 Version: 10.0.0.1046 - Intel Corporation)
-isb cad- 2013 Academy (x32 Version: 26.00.0000 - GLASER -isb cad- Programmsysteme GmbH) Hidden
iTunes (Version: 11.1.3.8 - Apple Inc.)
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java SE Development Kit 7 Update 25 (64-bit) (Version: 1.7.0.250 - Oracle)
Java(TM) 6 Update 29 (x32 Version: 6.0.290 - Oracle)
Java(TM) SE Development Kit 7 Update 1 (64-bit) (Version: 1.7.0.10 - Oracle)
Java(TM) SE Development Kit 7 Update 3 (64-bit) (Version: 1.7.0.30 - Oracle)
JavaFX 2.0.3 (64-bit) (Version: 2.0.3 - Oracle Corporation)
JavaFX 2.0.3 SDK (64-bit) (Version: 2.0.3 - Oracle Corporation)
JavaFX 2.1.0 (x32 Version: 2.1.0 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
Maple 16 (Version: - Maplesoft)
Maple 16 (x32 Version: 16.0.0.0 - Maplesoft)
Media Gallery (Version: 1.5.0.17050 - Your Company Name) Hidden
MediaMonkey 3.2 (x32 Version: 3.2 - Ventis Media Inc.)
Mepla Iso (x32 Version: 1.2.2 - Mepla Software)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft IntelliPoint 8.2 (Version: 8.20.468.0 - Microsoft Corporation)
Microsoft IntelliPoint 8.2 (Version: 8.20.468.0 - Microsoft Corporation) Hidden
Microsoft Office 2010 Service Pack 1 (SP1) (Version: - Microsoft)
Microsoft Office 2010 Service Pack 1 (SP1) (Version: - Microsoft) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Report Viewer Redistributable 2008 (KB971119) (x32 Version: - Microsoft Corporation)
Microsoft Report Viewer Redistributable 2008 (KB971119) (x32 Version: 9.0.30731 - Microsoft Corporation) Hidden
Microsoft Report Viewer Redistributable 2008 SP1 (x32 Version: - Microsoft Corporation)
Microsoft Report Viewer Redistributable 2008 SP1 (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual Basic Power Packs 3.0 (x32 Version: 9.0.30214 - Microsoft)
Microsoft Visual Basic PowerPacks 10.0 (x32 Version: 10.0.20911 - Microsoft)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 24.0 (x86 en-US) (x32 Version: 24.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 24.0 - Mozilla)
MSI to redistribute MS VS2005 CRT libraries (x32 Version: 8.0.50727.42 - The Firebird Project)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation)
Nemetschek Allplan 2011 (x32 Version: 2011.0 - Nemetschek Allplan GmbH)
Nemetschek Allplan 2012 (x32 Version: 2012.0 - Nemetschek Allplan GmbH)
Nemetschek SoftLock 2006 (x32 Version: 1.26.55 - )
Nur Entfernen der CopyTrans Suite möglich (HKCU Version: 2.37 - WindSolutions)
NVIDIA 3D Vision Treiber 269.73 (Version: 269.73 - NVIDIA Corporation)
NVIDIA Grafiktreiber 269.73 (Version: 269.73 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.2.24.0 (Version: 1.2.24.0 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.265.42.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.12.0507 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.12.0507 (Version: 9.12.0507 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6973 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 269.73 (Version: 269.73 - NVIDIA Corporation) Hidden
PDF Architect (x32 Version: 1.0.52.8917 - pdfforge)
PDF Blender (x32 Version: - )
PDFCreator (x32 Version: 1.6.2 - pdfforge)
PDF-XChange Viewer (Version: 2.5.199.0 - Tracker Software Products Ltd.)
PMB (x32 Version: 5.5.02.12220 - Sony Corporation)
PMB VAIO Edition Guide (x32 Version: 1.5.00.02250 - Sony Corporation) Hidden
PMB VAIO Edition Plug-in (Version: 1.5.10.05300 - Sony Corporation) Hidden
PMB VAIO Edition Plug-in (x32 Version: 1.5.00.02250 - Sony Corporation) Hidden
PMB VAIO Edition Plug-in (x32 Version: 1.5.10.06150 - Sony Corporation) Hidden
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
PPÖúÊÖ PC°æ 1.1.0.2 (x32 Version: 1.1.0.2 - ¹ãÖÝÌúÈËÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾)
Qualcomm Atheros Direct Connect (x32 Version: 3.0 - Qualcomm Atheros) Hidden
Quick Web Access (x32 Version: 1.4.6.9 - Sony Corporation)
Quick Web Access (x32 Version: 1.4.6.9 - Sony Corporation) Hidden
QuickTime (x32 Version: 7.71.80.42 - Apple Inc.)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek PCIE Card Reader (x32 Version: 6.1.7601.92 - Realtek Semiconductor Corp.)
RedMon - Redirection Port Monitor (Version: - )
Remote Keyboard (x32 Version: 1.1.1.07060 - Sony Corporation) Hidden
Remote Play with PlayStation 3 (x32 Version: 1.1.0.15070 - Sony Corporation) Hidden
RuckZuck Student (x32 Version: 6.0.11 - MURSOFT)
Secunia PSI (2.0.0.4002) (x32 Version: - )
Skype™ 6.3 (x32 Version: 6.3.105 - Skype Technologies S.A.)
Sony Corporation (Version: 1.0.0 - Default Company Name) Hidden
SopCast 3.4.0 (x32 Version: 3.4.0 - www.sopcast.com)
SSLx64 (Version: 1.0.0 - Sony Corporation ) Hidden
SSLx86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TAP-Windows 9.9.2 (Version: 9.9.2 - )
TeamViewer 8 (x32 Version: 8.0.22298 - TeamViewer)
UltraVnc (Version: 1.0.9.6.1 - uvnc bvba)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553065) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2566458) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 64-Bit Edition (Version: - Microsoft)
USB PnP Sound Device (Version: - )
VAIO - Media Gallery (x32 Version: 1.5.1.17050 - Sony Corporation)
VAIO - PMB VAIO Edition Guide (x32 Version: 1.5.00.02250 - Sony Corporation)
VAIO - PMB VAIO Edition Plug-in (x32 Version: 1.6.10.11160 - Sony Corporation)
VAIO - Remote Play mit PlayStation®3 (x32 Version: 1.1.0.15070 - Sony Corporation)
VAIO - Remote-Tastatur (x32 Version: 1.1.0.07060 - Sony Corporation)
VAIO Care (x32 Version: 6.4.2.11150 - Sony Corporation) Hidden
VAIO Control Center (x32 Version: 4.5.0.03040 - Sony Corporation)
VAIO Data Restore Tool (x32 Version: 1.6.0.13140 - Sony Corporation)
VAIO Data Restore Tool (x32 Version: 1.6.0.13140 - Sony Corporation) Hidden
VAIO Easy Connect (x32 Version: 1.1.2.01120 - Sony Corporation)
VAIO Easy Connect (x32 Version: 1.1.2.01120 - Sony Corporation) Hidden
VAIO Event Service (x32 Version: 5.5.0.03040 - Sony Corporation)
VAIO Gate (x32 Version: 2.4.0.06210 - Sony Corporation)
VAIO Gate Default (x32 Version: 2.4.0.03240 - Sony Corporation)
VAIO Hardware Diagnostics (x32 Version: 4.2.0.14280 - Sony Corporation) Hidden
VAIO Hero Screensaver - Summer 2011 Screensaver (x32 Version: - )
VAIO Improvement (x32 Version: 1.0.0.14150 - Sony Corporation)
VAIO Improvement Validation (Version: 1.0.4.01190 - Sony Corporation)
VAIO Sample Contents (x32 Version: 1.4.2.09010 - Sony Corporation)
VAIO Smart Network (x32 Version: 3.8.1.08270 - Sony Corporation)
VAIO Update (x32 Version: 6.3.0.08010 - Sony Corporation)
VAIO-Handbuch (x32 Version: 2.0.0.02250 - Sony Corporation)
VAIO-Support für Übertragungen (x32 Version: 1.4.0.14230 - Sony Corporation)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VCCx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VESx64 (Version: 1.0.0 - Sony Corporation) Hidden
VESx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
Virtual DJ - Atomix Productions (x32 Version: - )
VIx64 (Version: 1.0.0 - Sony Corporation) Hidden
VIx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VLC media player 2.1.1 (Version: 2.1.1 - VideoLAN)
VSNx64 (Version: 1.0.0 - Sony Corporation) Hidden
VSNx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden
VWSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
webcam 7 (x32 Version: 0.9.9.22 - Moonware Studios)
WebTect (x32 Version: - Succes Stream)
Win sys filter (x32 Version: - Appdev Ltd)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Корпорація Майкрософт) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорація Майкрософт) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8 - Microsoft Corp)
Windows Mobile-Gerätecenter (Version: 6.1.6965.0 - Microsoft Corporation)
WinRAR 4.01 (32-Bit) (x32 Version: 4.01.0 - win.rar GmbH)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основи Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотоколекція Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Restore Points =========================
14-12-2013 08:36:22 Windows Update
15-12-2013 02:00:15 Windows Update
15-12-2013 15:19:37 Windows Update
16-12-2013 07:55:35 Windows Update
22-12-2013 13:59:14 Windows Update
30-12-2013 17:55:43 Windows Update
01-01-2014 15:05:21 Windows Update
04-01-2014 15:01:13 Windows Update
06-01-2014 20:14:49 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:34 - 2013-06-16 17:22 - 00000081 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {00C76439-EFC1-466F-8DEC-53D714897F33} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2013-08-01] (Sony Corporation)
Task: {0F3405DB-A7DD-4530-9A0F-DCA526AC30A0} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {1CA46AD9-19CB-4D14-AFB2-C14B74AAB7EE} - System32\Tasks\Allplan AutoUpdate 2011-1 => C:\Program Files (x86)\Nemetschek\Allplan\Prg\NemDownloadHandler.exe [2012-01-30] (Nemetschek Allplan GmbH)
Task: {210A544D-764A-4DF3-88C7-35BAA13F9161} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000Core => C:\Users\Charlie\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-27] (Google Inc.)
Task: {2BEB40A9-C3FC-4F88-93CC-13F8D427342F} - System32\Tasks\WebContent AutoUpdate 2011 => C:\Program Files (x86)\Nemetschek\Allplan\Prg\NemDownloadHandler.exe [2012-01-30] (Nemetschek Allplan GmbH)
Task: {35AAC1E7-0D37-4C4C-90E0-3658545157FF} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-11-26] (AVAST Software)
Task: {5A497CC6-D250-47A3-BA55-D6F02952D348} - System32\Tasks\WebContent AutoUpdate 2012 => C:\Program Files (x86)\Nemetschek\Allplan_1\Prg\NemDownloadHandler.exe [2012-03-21] (Nemetschek Allplan GmbH)
Task: {726F6F97-44DD-45CA-A7F6-A2F9DB43873D} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2011-08-01] (Microsoft Corporation)
Task: {74ED0844-1807-465F-8C50-B53E5C7C99BB} - System32\Tasks\Sony Corporation\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2011-06-21] (Sony Corporation)
Task: {8FC439DD-E29B-4E99-97A6-9B2094BF7F7C} - System32\Tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation => C:\Program Files\Sony\VAIO Improvement Validation\viv.exe [2011-01-20] (Sony Corporation)
Task: {9BCDAD67-FDF2-4DE8-A1D3-B8158CA9DB4F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-15] (Adobe Systems Incorporated)
Task: {9D15F457-6214-47ED-B671-9E8518EF366C} - System32\Tasks\AutoUpdate Allplan 2012 => C:\Program Files (x86)\Nemetschek\Allplan_1\Prg\NemDownloadHandler.exe [2012-03-21] (Nemetschek Allplan GmbH)
Task: {A8F4A950-7C02-46C8-9B76-20AEFF15A51B} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2011-02-15] (Sony Corporation)
Task: {B9759462-045D-4D13-A974-74012A8EAA30} - System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => C:\Program Files\Sony\VAIO Smart Network\VSNClient
Task: {BD588BF4-14ED-4F1E-881E-05E35BF02FD5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000Core => C:\Users\Charlie\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {C3D4DCFB-7C8F-4375-8FDB-34AF2E57B5DC} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C929619F-63D0-4215-9DA6-5DA5A3D8B9A1} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2013-08-01] (Sony Corporation)
Task: {D2BA3FD6-698D-44D5-9A1B-EA1D5CCAF4EC} - System32\Tasks\Sony Corporation\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2011-06-21] (Sony Corporation)
Task: {D363324A-A57A-450D-B957-77317C3F56AF} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
Task: {D6387372-4A70-4A75-AE95-F9C467546B43} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000UA => C:\Users\Charlie\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-27] (Google Inc.)
Task: {F74BF3CC-C03D-41B9-B61F-55FAE5ED7621} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000UA => C:\Users\Charlie\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Allplan AutoUpdate 2011-1.job => C:\Program Files (x86)\Nemetschek\Allplan\prg\NemDownloadHandler.exe
Task: C:\Windows\Tasks\AutoUpdate Allplan 2012.job => C:\Program Files (x86)\Nemetschek\Allplan_1\prg\NemDownloadHandler.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000Core.job => C:\Users\Charlie\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000UA.job => C:\Users\Charlie\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000Core.job => C:\Users\Charlie\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1747016203-3155398904-578371931-1000UA.job => C:\Users\Charlie\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\WebContent AutoUpdate 2011.job => C:\Program Files (x86)\Nemetschek\Allplan\prg\NemDownloadHandler.exe
Task: C:\Windows\Tasks\WebContent AutoUpdate 2012.job => C:\Program Files (x86)\Nemetschek\Allplan_1\prg\NemDownloadHandler.exe
==================== Loaded Modules (whitelisted) =============
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2011-07-01 19:57 - 2011-05-28 21:05 - 00164864 _____ () M:\Programme\WinRar\rarext64.dll
2014-01-08 13:41 - 2014-01-08 12:03 - 02153472 _____ () C:\Program Files\AVAST Software\Avast\defs\14010800\algo.dll
2013-12-31 01:09 - 2013-12-31 01:09 - 04140032 _____ () C:\ProgramData\WebTect\WebTect.dll
2013-12-31 13:18 - 2013-12-31 13:18 - 00179024 _____ () C:\ProgramData\Browser faster\BrowserfasterSvc.dll
2013-12-31 13:18 - 2013-12-31 13:18 - 04134912 _____ () C:\ProgramData\Browser faster\Browserfaster.dll
2013-12-31 01:09 - 2013-12-31 01:09 - 00179536 _____ () C:\ProgramData\WebTect\WebTectSvc.dll
2014-01-01 16:05 - 2014-01-01 16:05 - 00177488 _____ () C:\ProgramData\Browser Enhancer\BrowserEnhancerSvc.dll
2014-01-01 16:05 - 2014-01-01 16:05 - 04331520 _____ () C:\ProgramData\Browser Enhancer\BrowserEnhancer.dll
2011-09-27 06:23 - 2011-09-27 06:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-09-27 06:22 - 2011-09-27 06:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-05-10 04:41 - 2011-03-05 15:42 - 00013824 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Charlie\AppData\Roaming\Dropbox\bin\libcef.dll
2013-11-26 21:32 - 2013-11-26 21:32 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-12-05 11:53 - 2013-12-04 03:47 - 00702416 _____ () C:\Users\Charlie\AppData\Local\Google\Chrome\Application\31.0.1650.63\libglesv2.dll
2013-12-05 11:53 - 2013-12-04 03:47 - 00099792 _____ () C:\Users\Charlie\AppData\Local\Google\Chrome\Application\31.0.1650.63\libegl.dll
2013-12-05 11:53 - 2013-12-04 03:48 - 04055504 _____ () C:\Users\Charlie\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll
2013-12-05 11:53 - 2013-12-04 03:48 - 00399312 _____ () C:\Users\Charlie\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
2013-12-05 11:53 - 2013-12-04 03:47 - 01619408 _____ () C:\Users\Charlie\AppData\Local\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll
2011-05-10 04:30 - 2010-09-13 17:28 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
==================== Faulty Device Manager Devices =============
Name: Microsoft Virtual WiFi Miniport Adapter #2
Description: Microsoft-Adapter für Miniports virtueller WiFis
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/08/2014 08:23:17 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/08/2014 07:37:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/08/2014 06:03:10 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2153
Error: (01/08/2014 06:03:10 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2153
Error: (01/08/2014 06:03:10 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/08/2014 06:03:09 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 998
Error: (01/08/2014 06:03:09 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 998
Error: (01/08/2014 06:03:09 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/08/2014 03:10:07 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/08/2014 09:18:33 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1014
System errors:
=============
Error: (01/08/2014 08:23:17 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "HitmanPro 3.7 Crusader (Boot)" wurde mit folgendem dienstspezifischem Fehler beendet: %%0.
Error: (01/08/2014 08:22:29 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "CyberGhost VPN 5 Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (01/08/2014 08:22:29 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst CyberGhost VPN 5 Client Service erreicht.
Error: (01/08/2014 08:22:28 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (01/08/2014 08:21:19 PM) (Source: BTHUSB) (User: )
Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen.
Error: (01/08/2014 08:21:33 PM) (Source: BugCheck) (User: )
Description: 0x0000007e (0xffffffffc0000005, 0x0000000000000000, 0xfffff880031bd8e8, 0xfffff880031bd140)C:\Windows\MEMORY.DMP010814-40841-01
Error: (01/08/2014 08:21:12 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 08.01.2014 um 20:19:11 unerwartet heruntergefahren.
Error: (01/08/2014 07:37:15 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (01/08/2014 07:31:45 PM) (Source: BTHUSB) (User: )
Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen.
Error: (01/08/2014 03:10:31 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "CyberGhost VPN 5 Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Microsoft Office Sessions:
=========================
Error: (01/08/2014 08:23:17 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/08/2014 07:37:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/08/2014 06:03:10 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2153
Error: (01/08/2014 06:03:10 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2153
Error: (01/08/2014 06:03:10 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/08/2014 06:03:09 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 998
Error: (01/08/2014 06:03:09 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 998
Error: (01/08/2014 06:03:09 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/08/2014 03:10:07 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/08/2014 09:18:33 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1014
CodeIntegrity Errors:
===================================
Date: 2013-02-11 10:41:43.791
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-11 10:41:43.664
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-11 10:41:39.307
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-11 10:41:39.184
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-11 10:41:37.014
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-11 10:41:36.907
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-11-10 22:02:38.011
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-11-10 22:02:37.997
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 55%
Total physical RAM: 4077.86 MB
Available physical RAM: 1833.54 MB
Total Pagefile: 8153.9 MB
Available Pagefile: 5441.59 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:291.83 GB) (Free:116.92 GB) NTFS
Drive m: (Volume) (Fixed) (Total:290.73 GB) (Free:274.44 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 99DAAE85)
Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=292 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=291 GB) - (Type=OF Extended)
==================== End Of Log ============================ |