![]() |
http://websearch.oversearch.info Hallo, seit ner Zeit spinnt mein Rechner... Die Internetseiten sind langsamer geworden... Sogar die Ordner gehen langsam auf... Habe mir sagen lassen, dass ich ein Virus im Rechner habe, der sich in diverse Ordner versteckt und man es nicht beliebig deinstallieren, bzw. löschen kann ! Hab versucht, dass Problem selber zu lösen, jedoch ohne Erfolg... Kenne mich nicht soooo gut mit Pc aus ! Würde mich sehr freuen, wenn ihr mir hilft, diesen Virus aus meinem Rechner zu kicken MEINE PROBLEME lauten: 1) hxxp://websearch.oversearch.info 2) Ads not by this site Bedanke mir im Voraus für Eure Hilfe FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01 --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-09-2013 01 |
:hallo: Ich bin smeenk und ich werde versuchen dir zu helfen :) Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
|
Zoek.exe Version 4.0.0.4 Updated 27-September-2013 Tool run by Keremino on 01.10.2013 at 15:39:19,34. Microsoft Windows 7 Enterprise 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Veli\AppData\Local\Temp\Temp1_zoek.zip\zoek.exe [Script inserted] ==== System Restore Info ====================== 01.10.2013 15:42:48 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3610243647-955691083-3180197658-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully HKEY_USERS\S-1-5-21-3610243647-955691083-3180197658-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} deleted successfully HKEY_USERS\S-1-5-21-3610243647-955691083-3180197658-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} deleted successfully HKEY_USERS\S-1-5-21-3610243647-955691083-3180197658-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-3610243647-955691083-3180197658-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} deleted successfully HKEY_USERS\S-1-5-21-3610243647-955691083-3180197658-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_CLASSES_ROOT\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully ==== Installed Programs ====================== 7-Zip 9.20 Acer Crystal Eye Webcam AdblockIE Adobe Flash Player 11 Plugin Adobe Reader XI (11.0.04) - Deutsch CCleaner Creative Audio-Systemsteuerung Debut Video Capture Software Free YouTube Download version 3.2.3.610 Free YouTube to MP3 Converter version 3.12.3.610 Gamesurround Muse Pocket HyperCam 2 Jasc Animation Shop 3 Java 7 Update 40 Java Auto Updater Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox 23.0.1 (x86 de) Nuvoton CIR Device Driver NVIDIA Drivers Opera 12.15 Pavtube Video Converter version 3.5.1.2185 PhotoScape RICOH R5U8xx Media Driver ver.3.62.02 Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2) SkypeT 6.6 SplitCam SWFText swMSM Synaptics Pointing Device Driver TeamViewer 8 Ulead GIF Animator 5 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) USB Multi-Channel Audio Device VideoPad Video Editor WinRAR 4.20 (32-Bit) YTD Video Downloader 4.0 ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SystemStoreService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemStoreService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SystemStoreService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SystemStoreService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WsysSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\WsysSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WsysSvc deleted successfully ==== FireFox Fix ====================== Deleted from C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\djh0uqno.default\prefs.js: user_pref("browser.search.defaultenginename", "Web Search"); user_pref("browser.search.defaultengine", "Web Search"); user_pref("browser.search.order.1", "Web Search"); user_pref("browser.search.useDBForOrder", false); Added to C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\djh0uqno.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.de"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); Deleted from C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\prefs.js: user_pref("browser.startup.homepage", "https://www.google.de/"); user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://websearch.oversearch.info/?pid=298&r=2013/09/26&hid=14353993468478840820&lg=EN&cc=DE&unqvl=36"); user_pref("browser.search.defaulturl", "hxxp://websearch.oversearch.info/?pid=298&r=2013/09/26&hid=14353993468478840820&lg=EN&cc=DE&unqvl=36&l=1&q="); user_pref("browser.search.defaultengine", "Web Search"); user_pref("browser.search.defaultenginename", "WebSearch"); user_pref("browser.search.defaultenginename,S", "WebSearch"); user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "WebSearch"); user_pref("browser.search.selectedEngine", "WebSearch"); user_pref("browser.search.selectedEngine,S", "WebSearch"); user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "WebSearch"); user_pref("browser.search.order.1", "WebSearch"); user_pref("browser.search.order.1,S", "WebSearch"); user_pref("keyword.URL", "hxxp://websearch.oversearch.info/?pid=298&r=2013/09/26&hid=14353993468478840820&lg=EN&cc=DE&unqvl=36&l=1&q="); user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://websearch.oversearch.info/?pid=298&r=2013/09/26&hid=14353993468478840820&lg=EN&cc=DE&unqvl=36&l=1&q="); user_pref("browser.search.useDBForOrder", false); Added to C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\prefs.js: Deleted from C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\prefs.js: user_pref("browser.search.defaultengine", "Web Search"); user_pref("browser.search.defaultenginename", "Web Search"); user_pref("browser.search.order.1", "Web Search"); user_pref("browser.search.useDBForOrder", false); Added to C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\prefs.js: ==== Deleting Files \ Folders ====================== "C:\Program Files\WBC Engine" not found "C:\Program Files\YourFileDownloader" not found "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\searchplugins\Ask.xml" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\searchplugins\babylon.xml" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\searchplugins\Web Search.xml" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\searchplugins\WebSearch.xml" deleted "C:\Program Files\mozilla firefox\searchplugins\Ask.xml" deleted "C:\Program Files\mozilla firefox\searchplugins\delta-homes.xml" deleted "C:\Program Files\mozilla firefox\searchplugins\qvo6.xml" deleted "C:\Program Files\mozilla firefox\searchplugins\Web Search.xml" deleted "C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml" deleted "C:\Windows\System32\Tasks\Desk 365 RunAsStdUser" deleted "C:\Windows\System32\Tasks\EPUpdater" deleted "C:\Windows\System32\Tasks\4581" deleted "C:\Windows\System32\Tasks\Software Updater" deleted "C:\Windows\System32\Tasks\YourFile DownloaderUpdate" deleted "C:\Windows\System32\Tasks\Dealply" deleted "C:\Windows\System32\Tasks\Software Updater Ui" deleted "C:\Windows\System32\Tasks\0" deleted "C:\Windows\Tasks\Dealply.job" deleted "C:\Users\Veli\Downloads\jogangandotnetCrackVideopadVideoEditor.rar.exe" deleted "C:\Users\Veli\Downloads\etypesetup.exe" deleted "C:\Users\Veli\AppData\Local\DownloadGuide" deleted "C:\Program Files\CoolPic - Fun Social Pictures" deleted "C:\Users\Veli\AppData\Roaming\Dealply" deleted "C:\ProgramData\DSearchLink" deleted "C:\ProgramData\Browser Manager" deleted "C:\Users\Veli\Documents\Optimizer Pro" deleted "C:\ProgramData\SearchNewTab" deleted "C:\Program Files\WebSearch" deleted "C:\ProgramData\SummerSoft" deleted "C:\Program Files\Optimizer Pro" deleted "C:\ProgramData\DownnlOad kuEeper" deleted "C:\Program Files\Ss.Helper" deleted "C:\ProgramData\InstallMate" deleted "C:\Users\Veli\AppData\Roaming\eType" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2013-09-25 11:24:28 1B2CE85F36F5BB6DEC7AE685978DB825 32328 ----a-w- C:\Windows\Launcher.exe ====== C:\Users\Veli\AppData\Local\Temp ==== 2013-09-30 03:58:48 09869C37B1CAE90A6275D4DE0E91D099 45868112 ----a-w- C:\Users\Veli\AppData\Local\Temp\SHSetup.exe ====== Java Cache ===== 2013-09-08 19:55:05 5FD0F92A70CF369EC5B687D9C56531BC 17530 ----a-w- C:\Users\Veli\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\2ea66e94-506a0138 ====== C:\Windows\system32 ===== 2013-09-30 19:08:47 4CAC856E64F96C6949B0931964F9EE42 692616 ----a-w- C:\Windows\System32\FlashPlayerApp.exe 2013-09-30 19:08:46 184021B2B95F3BE1B8FD7EA4F8F23C38 71048 ----a-w- C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-09-23 00:55:12 ACA17F8E1F9E8891DE15E2527D8D74D0 264616 ----a-w- C:\Windows\System32\javaws.exe 2013-09-23 00:54:58 EC94122E6DCB6E731D8513A89AC9CF12 175016 ----a-w- C:\Windows\System32\javaw.exe 2013-09-23 00:54:58 EC2A0F271C0FD4AD57B137845577F539 175016 ----a-w- C:\Windows\System32\java.exe 2013-09-23 00:54:58 65F0FBCDBBA20FC4B0DADCA922150A99 94632 ----a-w- C:\Windows\System32\WindowsAccessBridge.dll ====== C:\Windows\system32\drivers ===== 2013-09-25 10:54:13 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_Kernel_nnfwdk_01009.Wdf 2013-09-12 00:48:47 DDCE686D76C2B4DB435A3AF5BD0E691D 133056 ----a-w- C:\Windows\System32\drivers\ataport.sys 2013-09-06 20:03:00 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf ====== C:\Windows\Tasks ====== 2013-09-30 19:08:48 5B12B28D98BF11F73A1C467764AAF0D4 884 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-30 19:08:48 35FF0B400A83D1EE852F416D9A56632E 3822 ----a-w- C:\Windows\system32\Tasks\Adobe Flash Player Updater 2013-09-20 03:33:36 8CFC135F4BDE75CF76B6A2925910A8C0 3414 ----a-w- C:\Windows\system32\Tasks\{4CFD8C3F-62D5-42F7-B501-E5C559EE202A} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2013-09-30 19:20:24 -------- d-----w- C:\Program Files\GridinSoft Trojan Killer 2013-09-25 11:26:33 -------- d-----w- C:\Program Files\SoftwareUpdater 2013-09-25 11:26:31 -------- d-----w- C:\Program Files\Freetec 2013-09-23 00:55:27 -------- d-----w- C:\Program Files\Common Files\Java 2013-09-23 00:54:40 -------- d-----w- C:\Program Files\Java ======= C: ===== 2013-09-20 02:50:26 68DA3EA204996EC4B63A9568B5D99C25 206312 --sh--r- C:\XELDZ ====== C:\Users\Veli\AppData\Roaming ====== 2013-09-30 15:51:36 -------- d-----w- C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite 2013-09-26 07:23:22 -------- d-----w- C:\Users\Veli\AppData\Roaming\SkypEmoticons 2013-09-25 11:27:25 -------- d-----w- C:\Users\Veli\AppData\Local\Freetec 2013-09-25 11:23:42 -------- d-----w- C:\Users\Veli\AppData\Locallow\SimplyTech 2013-09-23 23:01:12 -------- d-----w- C:\Users\Veli\AppData\Roaming\vlc 2013-09-18 19:37:49 -------- d-----w- C:\Users\Veli\AppData\Locallow\DataMngr 2013-09-18 19:37:45 -------- d-----w- C:\Users\Veli\AppData\Local\Programs ====== C:\Users\Veli ====== 2013-09-30 20:04:16 E8DD5929CDAA01730F7C536D044F1389 1086873 ----a-w- C:\Users\Veli\Downloads\FRST.exe 2013-09-30 19:16:13 50A05EDC87893F62268E374C19BFBEB3 52176608 ----a-w- C:\Users\Veli\Downloads\gtk-2.1.8.9-setup.exe 2013-09-30 15:50:53 229261A60DBFD58471D114CC4E0456A0 4373560 ----a-w- C:\Users\Veli\Downloads\vppsetup.exe 2013-09-30 03:58:37 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Veli\Downloads\SpyHunter-Installer.exe 2013-09-28 06:27:57 1342ED24D3293559E0CACC0788A2B996 2681224 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(5).exe 2013-09-25 16:30:55 9A9B114CBD554C4A1BF9E2FCAB08B460 729736 ----a-w- C:\Users\Veli\Downloads\youtube-dlm_1.0_de-DE(1).exe 2013-09-25 16:14:44 FAC0845F41DC78C51B12AC090379B344 1238384 ----a-w- C:\Users\Veli\Downloads\CoolPic_mg_207566.exe 2013-09-25 11:22:57 86BA054C43FA55D6CA581EFA6772DA1C 729736 ----a-w- C:\Users\Veli\Downloads\youtube-dlm_1.0_de-DE.exe 2013-09-25 10:47:04 A509EB9A2388D2A329B9847E8D66FC2C 2743968 ----a-w- C:\Users\Veli\Downloads\netsight_setup_6.0.0.60_MP_Production_mid51049298465_p.exe 2013-09-24 22:50:48 FEAFF13AD04D5D945EF13587E92C3336 3362400 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(4).exe 2013-09-24 22:46:29 1342ED24D3293559E0CACC0788A2B996 2681224 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(3).exe 2013-09-23 16:30:55 1A31EC98651A9176A3669459F2EDFB78 9216 ----a-w- C:\Users\Veli\Downloads\plugin-container.exe 2013-09-23 16:28:23 B22198403FFEAF57BE49FF5A08DA1EF4 23003252 ----a-w- C:\Users\Veli\Downloads\vlc-2.0.8-win32(1).exe 2013-09-23 00:56:15 -------- d-----w- C:\ProgramData\Oracle 2013-09-23 00:54:58 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2013-09-23 00:52:28 2755BAEDEB84972D1621B9166CE29B0B 913832 ----a-w- C:\Users\Veli\Downloads\jxpiinstall(1).exe 2013-09-23 00:50:20 A4022823CFBF2C1A97BD01CCF7FE976C 7912440 ----a-w- C:\Users\Veli\Downloads\Shockwave_Installer_Slim(2).exe 2013-09-20 17:33:19 -------- d-----w- C:\Users\Veli\Videos 2013-09-18 19:38:31 -------- d-----w- C:\Users\Veli\Local Settings 2013-09-11 20:44:41 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite 2013-09-03 03:48:43 74E7F684F2198114E4AE1F6524A1653C 98304 ----a-w- C:\Users\Veli\fbchathistory.dat ====== C: exe-files == 2013-09-30 20:04:46 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2L213I0D\FRST[1].exe 2013-09-30 20:04:16 E8DD5929CDAA01730F7C536D044F1389 1086873 ----a-w- C:\Users\Veli\Downloads\FRST.exe 2013-09-30 19:16:13 50A05EDC87893F62268E374C19BFBEB3 52176608 ----a-w- C:\Users\Veli\Downloads\gtk-2.1.8.9-setup.exe 2013-09-30 19:08:47 4CAC856E64F96C6949B0931964F9EE42 692616 ----a-w- C:\Windows\System32\FlashPlayerApp.exe 2013-09-30 15:51:36 229261A60DBFD58471D114CC4E0456A0 4373560 ----a-w- C:\Program Files\NCH Software\VideoPad\videopadsetup_v3.14.exe 2013-09-30 15:50:53 229261A60DBFD58471D114CC4E0456A0 4373560 ----a-w- C:\Users\Veli\Downloads\vppsetup.exe 2013-09-30 10:34:32 6B110E925294547A7D288F26DA19D199 179687 ----a-w- C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla18.exe 2013-09-30 03:58:48 09869C37B1CAE90A6275D4DE0E91D099 45868112 ----a-w- C:\Users\Veli\AppData\Local\Temp\SHSetup.exe 2013-09-30 03:58:37 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Veli\Downloads\SpyHunter-Installer.exe 2013-09-28 06:27:57 1342ED24D3293559E0CACC0788A2B996 2681224 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(5).exe 2013-09-26 07:27:28 01E1B94A8C0011F206DF0C997EA287F4 165 ----a-w- C:\$Recycle.Bin\S-1-5-21-3610243647-955691083-3180197658-1000\$RSN6AFQ\Crack VideoPad Video Editor.exe 2013-09-26 07:23:47 A8E982D615D2FFD066F591B6E4EABBE0 5842336 ----a-w- C:\Users\Veli\AppData\Roaming\SkypEmoticons\SE.exe 2013-09-25 16:30:55 9A9B114CBD554C4A1BF9E2FCAB08B460 729736 ----a-w- C:\Users\Veli\Downloads\youtube-dlm_1.0_de-DE(1).exe 2013-09-25 16:14:44 FAC0845F41DC78C51B12AC090379B344 1238384 ----a-w- C:\Users\Veli\Downloads\CoolPic_mg_207566.exe 2013-09-25 11:27:22 4D52CFCFF7AA93ED16461705B5131235 74752 ----a-w- C:\Program Files\SoftwareUpdater\Maintenance.exe 2013-09-25 11:27:09 87E0F79093A22946A9D1ED1DF2F284C9 902144 ----a-w- C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe 2013-09-25 11:26:54 9D40AC2003DCA9F045181241C2BF47A2 296448 ----a-w- C:\Program Files\SoftwareUpdater\SystemStore.exe 2013-09-25 11:26:37 5CF463EA5AD05F5DE0BB5BBA6AA2092C 6656 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3}\chrome\bin\cmdproxy.exe 2013-09-25 11:24:28 1B2CE85F36F5BB6DEC7AE685978DB825 32328 ----a-w- C:\Windows\Launcher.exe 2013-09-25 11:22:57 86BA054C43FA55D6CA581EFA6772DA1C 729736 ----a-w- C:\Users\Veli\Downloads\youtube-dlm_1.0_de-DE.exe 2013-09-25 10:47:04 A509EB9A2388D2A329B9847E8D66FC2C 2743968 ----a-w- C:\Users\Veli\Downloads\netsight_setup_6.0.0.60_MP_Production_mid51049298465_p.exe 2013-09-24 22:50:48 FEAFF13AD04D5D945EF13587E92C3336 3362400 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(4).exe 2013-09-24 22:46:29 1342ED24D3293559E0CACC0788A2B996 2681224 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(3).exe === C: other files == 2013-10-01 04:30:30 642DB546B8E5380410C4B110C222E13F 79139 ----a-w- C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MHPKEMNJ\de_DE[1].zip 2013-10-01 04:30:07 A842B48277A2D8645A37B9F596838D2A 1230 ----a-w- C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4XDS773D\flXHR[1].vbs 2013-09-29 21:02:39 51555013F2F820E6A20E991E754752D8 123385 ----a-w- C:\Users\Veli\AppData\Local\Temp\tmp-ifv.xpi 2013-09-25 11:26:35 F28E6D902D5782720F216207ECFBC07F 18753 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi 2013-09-25 11:26:35 ED10614EC981DB30789CC7EC4B229AB9 13955 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\admin@proxy-listen.de.xpi 2013-09-25 11:26:35 E23928ED13449168CB9F26BBE67BC95F 353425 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\smarterwiki@wikiatic.com.xpi 2013-09-25 11:26:35 C9F1A4E3D10AC900B022F8F45152A3E1 194311 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\jid0-c1av474BVPIHcGJfBp3GkhlhAa4@jetpack.xpi 2013-09-25 11:26:35 BD76955067E069A01B9A0392DEA4D10B 178395 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi 2013-09-25 11:26:35 B60381F680B593366B51DE45829C179F 31123 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{2A1D5949-B519-4924-BF62-8522FE0D5274}.xpi 2013-09-25 11:26:35 AC13FB2840845FE8B03E0EC579B8EA90 723773 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\stefanvandamme@stefanvd.net.xpi 2013-09-25 11:26:35 97AA187E8476935D2933E462E7A14D06 166436 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi 2013-09-25 11:26:35 967246D501D0F4379C673099996CF121 16117 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{e9876d64-8bac-4287-bdc4-0f0c56804b4f}.xpi 2013-09-25 11:26:35 73E5FCA06973ADD85D7CA071F89853A0 76810 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\screwads@airtint.com.xpi 2013-09-25 11:26:35 4ACEE5217E47CBA244D165C0414AA7CB 409220 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\jid0-w1UVmoLd6VGudaIERuRJCPQx1dQ@jetpack.xpi 2013-09-25 11:26:35 4155DB098E14F2A8CB7BAC0FD10D9FB0 210138 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi 2013-09-25 11:26:35 3D7728D85556F98F4F967AD9F288D8F6 18509 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi 2013-09-25 11:26:35 1D062796A5FF05D60F20A97677EDD437 824302 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi 2013-09-25 11:26:35 0FD6A9943787EE1A75FD810FE2DCD58C 14810 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\YouTubeAutoReplay@arikv.com.xpi 2013-09-25 11:26:35 0B240AC326EF16591C39AE84B2958659 171002 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\jid0-irAmugmQgdURBSCIFZAcjR8ZQMg@jetpack.xpi 2013-09-25 10:37:16 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Veli\AppData\LocalLow\Microsoft\Silverlight\OutOfBrowser\index\cdn-a.sponsorpay.com ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "SearchProtect"="\SearchProtect\bin\cltmng.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-3610243647-955691083-3180197658-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "SearchProtect"="\SearchProtect\bin\cltmng.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PLFSetI"="C:\Windows\PLFSetI.exe" "NvCplDaemon"="RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /minimized /regrun" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [30.09.2013 21:08] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\djh0uqno.default - Undetermined - %ProfilePath%\extensions\tilt@mozilla.com - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default - ColorfulTabs - %ProfilePath%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} - Complete YouTube Saver - %ProfilePath%\extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3} - PlugIn-Checker - %ProfilePath%\extensions\jid0-c1av474BVPIHcGJfBp3GkhlhAa4@jetpack.xpi - Youtube To MP3 PRO converter - %ProfilePath%\extensions\jid0-irAmugmQgdURBSCIFZAcjR8ZQMg@jetpack.xpi - FireTube - %ProfilePath%\extensions\jid0-w1UVmoLd6VGudaIERuRJCPQx1dQ@jetpack.xpi - YouTube ALL HTML5 - %ProfilePath%\extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi - Undetermined - %ProfilePath%\extensions\screwads@airtint.com.xpi - FastestFox - %ProfilePath%\extensions\smarterwiki@wikiatic.com.xpi - Turn Off the Lights - %ProfilePath%\extensions\stefanvandamme@stefanvd.net.xpi - YouTube Auto Replay - %ProfilePath%\extensions\YouTubeAutoReplay@arikv.com.xpi - PDFescape Extension - %ProfilePath%\extensions\{2A1D5949-B519-4924-BF62-8522FE0D5274}.xpi - Black Youtube - %ProfilePath%\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi - Fasterfox - %ProfilePath%\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi - QuickJava - %ProfilePath%\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi - Black Google Theme - %ProfilePath%\extensions\{e9876d64-8bac-4287-bdc4-0f0c56804b4f}.xpi - JavaScript Debugger - %ProfilePath%\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049 - ColorfulTabs - C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} - Complete YouTube Saver - C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3} - Undetermined - C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} - Undetermined - C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} - ColorfulTabs - %ProfilePath%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} - Flashblock - %ProfilePath%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} - Facebook Photo Zoom - %ProfilePath%\extensions\{7c6cdf7c-8ea8-4be7-ae5a-0b3effe14d66} - Complete YouTube Saver - %ProfilePath%\extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3} - Proxy-Listen.de - Proxyswitcher - %ProfilePath%\extensions\admin@proxy-listen.de.xpi - PlugIn-Checker - %ProfilePath%\extensions\jid0-c1av474BVPIHcGJfBp3GkhlhAa4@jetpack.xpi - Youtube To MP3 PRO converter - %ProfilePath%\extensions\jid0-irAmugmQgdURBSCIFZAcjR8ZQMg@jetpack.xpi - FireTube - %ProfilePath%\extensions\jid0-w1UVmoLd6VGudaIERuRJCPQx1dQ@jetpack.xpi - YouTube ALL HTML5 - %ProfilePath%\extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi - Undetermined - %ProfilePath%\extensions\screwads@airtint.com.xpi - FastestFox - %ProfilePath%\extensions\smarterwiki@wikiatic.com.xpi - Turn Off the Lights - %ProfilePath%\extensions\stefanvandamme@stefanvd.net.xpi - YouTube Auto Replay - %ProfilePath%\extensions\YouTubeAutoReplay@arikv.com.xpi - PDFescape Extension - %ProfilePath%\extensions\{2A1D5949-B519-4924-BF62-8522FE0D5274}.xpi - Black Youtube - %ProfilePath%\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi - Fasterfox - %ProfilePath%\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi - QuickJava - %ProfilePath%\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi - Black Google Theme - %ProfilePath%\extensions\{e9876d64-8bac-4287-bdc4-0f0c56804b4f}.xpi - JavaScript Debugger - %ProfilePath%\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi AppDir: C:\Program Files\Mozilla Firefox - Undetermined - %AppDir%\extensions\ffxtlbr@babylon.com ==== Firefox Plugins ====================== Profilepath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default E5AF72B7353FF8D431A7C463A4229524 - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll - Shockwave Flash CA0E1DFBE480CF0BE13A0883BEB378B6 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U40 AF661355EBAB898EB92D5454AEF93CE0 - C:\Windows\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.400.43 148727EBD947CBC168C42A227D56DAB0 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat F045DF7AF127DC4BCC53421850114E15 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll - Silverlight Plug-In CD6D547D33C9D2935FC6F206DC4E2711 - C:\Users\Veli\AppData\Roaming\Mozilla\plugins\npspeakychat.dll - SpeakyChat 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System 7D28153B7D586330678AD522B71D89CB - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrlui.dll - Microsoft® Silverlight Profilepath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049 E5AF72B7353FF8D431A7C463A4229524 - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll - Shockwave Flash CA0E1DFBE480CF0BE13A0883BEB378B6 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U40 AF661355EBAB898EB92D5454AEF93CE0 - C:\Windows\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.400.43 148727EBD947CBC168C42A227D56DAB0 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat F045DF7AF127DC4BCC53421850114E15 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll - Silverlight Plug-In CD6D547D33C9D2935FC6F206DC4E2711 - C:\Users\Veli\AppData\Roaming\Mozilla\plugins\npspeakychat.dll - SpeakyChat 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System 7D28153B7D586330678AD522B71D89CB - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrlui.dll - Microsoft® Silverlight ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions hggpkhijoeadmdfmlbdepfbngmhaldci - C:\Program Files\DealPly\DealPly.crx[] mmiopbgcekanlhpjkonogoljpfmhpkhf - C:\Program Files\LyricsPal\125.crx[] oejkcgajlodefenbbjdnaiahmbnnoole - C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx[] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.com/" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Search Bar"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Start Page"="hxxp://websearch.oversearch.info/?pid=298&r=2013/09/26&hid=14353993468478840820&lg=EN&cc=DE&unqvl=36" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Search Bar"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=b1f47b7c-7ba3-4451-b915-8f16a5a434e7&searchtype=ds&q={searchTerms}&installDate=10/08/2013" "(Default)"="hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=b1f47b7c-7ba3-4451-b915-8f16a5a434e7&searchtype=ds&q={searchTerms}&installDate=10/08/2013" "(Default)"="hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Search Bar"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Search Bar"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "SearchAssistant"="hxxp://feed.snap.do/?publisher=ShoppingHelper&dpid=ShoppingHelper&co=DE&userid=b1f47b7c-7ba3-4451-b915-8f16a5a434e7&searchtype=ds&q={searchTerms}&installDate=10/08/2013" "Start Page"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60" "Search Bar"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=66920&st=chrome&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60&q=" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{006ee092-9658-4fd6-bd8e-a21a348e59f5}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.de" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR" ==== EOF on 01.10.2013 at 15:48:34,49 ====================== Hi Smeenk, nachdem ich das mit dem "Zoek" gemacht habe, sind "websearch.oversearch.info" & "Ads not by this site" verschwunden :daumenhoc habe vielen vielen Dank :party: ps: wars das, oder geht es weiter : ) |
Sieht schon besser aus :singsing:
Downloade Dir bitte ![]()
|
Zoek.exe Version 4.0.0.4 Updated 27-September-2013 Tool run by Keremino on 01.10.2013 at 19:58:15,41. Microsoft Windows 7 Enterprise 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Veli\AppData\Local\Temp\Temp1_zoek(1).zip\zoek.com [Quick Scan] [Auto Clean] ==== Older Logs ====================== C:\zoek-results2013-10-01-134834.log 41608 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\djh0uqno.default ---- Lines delta removed from prefs.js ---- ---- Lines delta modified from prefs.js ---- ---- Lines delta removed from user.js ---- ---- Lines certified-toolbar removed from prefs.js ---- user_pref("wtb6787.homepage", "hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60"); user_pref("wtb6787.newtab", "hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.4&ts=1380060000000.000008&tguid=66920-6787-1380108222358-7460702C987F8958BEEB078049EC5A60"); ---- Lines certified-toolbar modified from prefs.js ---- ---- Lines certified-toolbar removed from user.js ---- ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 1); ---- Lines browser.startup.page modified from prefs.js ---- ---- Lines browser.startup.page removed from user.js ---- ---- FireFox user.js and prefs.js backups ---- user__1543_.backup user__2004_.backup prefs__1543_.backup prefs__2004_.backup ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default ---- Lines delta removed from prefs.js ---- user_pref("extensions.delta.admin", false); user_pref("extensions.delta.aflt", "babsst"); user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); user_pref("extensions.delta.autoRvrt", "false"); user_pref("extensions.delta.dfltLng", "de"); user_pref("extensions.delta.excTlbr", false); user_pref("extensions.delta.ffxUnstlRst", true); user_pref("extensions.delta.id", "f8784e71000000000000001de0866c33"); user_pref("extensions.delta.instlDay", "15973"); user_pref("extensions.delta.instlRef", "sst"); user_pref("extensions.delta.newTab", false); user_pref("extensions.delta.prdct", "delta"); user_pref("extensions.delta.prtnrId", "delta"); user_pref("extensions.delta.rvrt", "false"); user_pref("extensions.delta.smplGrp", "none"); user_pref("extensions.delta.tlbrId", "base"); user_pref("extensions.delta.tlbrSrchUrl", ""); user_pref("extensions.delta.vrsn", "1.8.24.6"); user_pref("extensions.delta.vrsnTs", "1.8.24.613:44:48"); user_pref("extensions.delta.vrsni", "1.8.24.6"); user_pref("extensions.delta_i.babExt", ""); user_pref("extensions.delta_i.babTrack", "affID=124776&tt=250913_nocpn&tsp=5016"); user_pref("extensions.delta_i.srcExt", "ss"); ---- Lines delta modified from prefs.js ---- ---- Lines delta removed from user.js ---- user_pref("extensions.delta.tlbrSrchUrl", ""); user_pref("extensions.delta.id", "f8784e71000000000000001de0866c33"); user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); user_pref("extensions.delta.instlDay", "15973"); user_pref("extensions.delta.vrsn", "1.8.24.6"); user_pref("extensions.delta.vrsni", "1.8.24.6"); user_pref("extensions.delta.vrsnTs", "1.8.24.613:44:48"); user_pref("extensions.delta.prtnrId", "delta"); user_pref("extensions.delta.prdct", "delta"); user_pref("extensions.delta.aflt", "babsst"); user_pref("extensions.delta.smplGrp", "none"); user_pref("extensions.delta.tlbrId", "base"); user_pref("extensions.delta.instlRef", "sst"); user_pref("extensions.delta.dfltLng", "de"); user_pref("extensions.delta.excTlbr", false); user_pref("extensions.delta.ffxUnstlRst", true); user_pref("extensions.delta.admin", false); user_pref("extensions.delta_i.babTrack", "affID=124776&tt=250913_nocpn&tsp=5016"); user_pref("extensions.delta_i.babExt", ""); user_pref("extensions.delta_i.srcExt", "ss"); user_pref("extensions.delta.autoRvrt", "false"); user_pref("extensions.delta.rvrt", "false"); user_pref("extensions.delta.newTab", false); ---- Lines certified-toolbar removed from prefs.js ---- ---- Lines certified-toolbar modified from prefs.js ---- ---- Lines certified-toolbar removed from user.js ---- ---- Lines browser.startup.page removed from prefs.js ---- ---- Lines browser.startup.page modified from prefs.js ---- ---- Lines browser.startup.page removed from user.js ---- ---- FireFox user.js and prefs.js backups ---- user__1543_.backup user__2004_.backup prefs__1543_.backup prefs__2004_.backup ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049 ---- Lines delta removed from prefs.js ---- ---- Lines delta modified from prefs.js ---- ---- Lines delta removed from user.js ---- user_pref("extensions.delta.tlbrSrchUrl", ""); user_pref("extensions.delta.id", "f8784e71000000000000001de0866c33"); user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); user_pref("extensions.delta.instlDay", "15968"); user_pref("extensions.delta.vrsn", "1.8.24.6"); user_pref("extensions.delta.vrsni", "1.8.24.6"); user_pref("extensions.delta.vrsnTs", "1.8.24.64:42:03"); user_pref("extensions.delta.prtnrId", "delta"); user_pref("extensions.delta.prdct", "delta"); user_pref("extensions.delta.aflt", "babsst"); user_pref("extensions.delta.smplGrp", "none"); user_pref("extensions.delta.tlbrId", "base"); user_pref("extensions.delta.instlRef", "sst"); user_pref("extensions.delta.dfltLng", "de"); user_pref("extensions.delta.excTlbr", false); user_pref("extensions.delta.ffxUnstlRst", true); user_pref("extensions.delta.admin", false); user_pref("extensions.delta_i.babTrack", "affID=124784&tt=160913_m1&tsp=5011"); user_pref("extensions.delta_i.babExt", ""); user_pref("extensions.delta_i.srcExt", "ss"); user_pref("extensions.delta.autoRvrt", "false"); user_pref("extensions.delta.rvrt", "false"); user_pref("extensions.delta.newTab", false); ---- Lines certified-toolbar removed from prefs.js ---- ---- Lines certified-toolbar modified from prefs.js ---- ---- Lines certified-toolbar removed from user.js ---- ---- Lines browser.startup.page removed from prefs.js ---- ---- Lines browser.startup.page modified from prefs.js ---- ---- Lines browser.startup.page removed from user.js ---- ---- FireFox user.js and prefs.js backups ---- user__1543_.backup user__2004_.backup prefs__1543_.backup prefs__2004_.backup ==== Deleting Files \ Folders ====================== "C:\Users\Veli\AppData\LocalLow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com" deleted "C:\END" deleted "C:\Windows\Launcher.exe" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\djh0uqno.default\searchplugins\Web Search.xml" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\djh0uqno.default\foxydeal.sqlite" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\foxydeal.sqlite" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\Invalidprefs.js" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\searchplugins\babylon.xml" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\searchplugins\Ask.xml" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\searchplugins\Web Search.xml" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\foxydeal.sqlite" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\Invalidprefs.js" deleted "C:\Users\Veli\AppData\Roaming\Yandex\ui" deleted "C:\Users\Veli\AppData\Roaming\Pamela" deleted "C:\Users\Veli\AppData\Roaming\Yandex" deleted "C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com" deleted "C:\Program Files\SoftwareUpdater" deleted "C:\Program Files\WinZipper" deleted "C:\Program Files\Common Files\DVDVideoSoft\bin" deleted "C:\Program Files\LyricsPal" deleted "C:\Program Files\Desk 365" deleted "C:\SearchProtect" deleted "C:\Users\Veli\AppData\Roaming\WinZipper" deleted "C:\Users\Veli\AppData\Roaming\Desk 365" deleted "C:\Users\Veli\AppData\Roaming\eIntaller" deleted "C:\Users\Veli\AppData\Roaming\DVDVideoSoftIEHelpers" deleted "C:\Users\Veli\AppData\Roaming\BabSolution" deleted "C:\Users\Veli\AppData\Roaming\Babylon" deleted "C:\Users\Veli\AppData\Roaming\YourFileDownloader" deleted "C:\Users\Veli\AppData\Roaming\OpenCandy" deleted "C:\ProgramData\APN" deleted "C:\ProgramData\eSafe" deleted "C:\ProgramData\Tarma Installer" deleted "C:\ProgramData\Babylon" deleted "C:\ProgramData\YTD Video Downloader" deleted "C:\Users\Veli\AppData\Local\adawarebp" deleted "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader" deleted "C:\Users\Veli\AppData\LocalLow\Delta" deleted "C:\Users\Veli\AppData\LocalLow\DataMngr" deleted "C:\Users\Veli\AppData\LocalLow\SimplyTech" deleted "C:\Users\Veli\AppData\LocalLow\Conduit" deleted "C:\Windows\System32\searchplugins" deleted "C:\Windows\System32\Extensions" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\jetpack" deleted "C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\jetpack" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Veli\AppData\Local\Temp ==== 2013-09-30 03:58:48 09869C37B1CAE90A6275D4DE0E91D099 45868112 ----a-w- C:\Users\Veli\AppData\Local\Temp\SHSetup.exe ====== Java Cache ===== 2013-09-08 19:55:05 5FD0F92A70CF369EC5B687D9C56531BC 17530 ----a-w- C:\Users\Veli\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\2ea66e94-506a0138 ====== C:\Windows\system32 ===== 2013-09-30 19:08:47 4CAC856E64F96C6949B0931964F9EE42 692616 ----a-w- C:\Windows\System32\FlashPlayerApp.exe 2013-09-30 19:08:46 184021B2B95F3BE1B8FD7EA4F8F23C38 71048 ----a-w- C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-09-23 00:55:12 ACA17F8E1F9E8891DE15E2527D8D74D0 264616 ----a-w- C:\Windows\System32\javaws.exe 2013-09-23 00:54:58 EC94122E6DCB6E731D8513A89AC9CF12 175016 ----a-w- C:\Windows\System32\javaw.exe 2013-09-23 00:54:58 EC2A0F271C0FD4AD57B137845577F539 175016 ----a-w- C:\Windows\System32\java.exe 2013-09-23 00:54:58 65F0FBCDBBA20FC4B0DADCA922150A99 94632 ----a-w- C:\Windows\System32\WindowsAccessBridge.dll ====== C:\Windows\system32\drivers ===== 2013-09-25 10:54:13 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_Kernel_nnfwdk_01009.Wdf 2013-09-12 00:48:47 DDCE686D76C2B4DB435A3AF5BD0E691D 133056 ----a-w- C:\Windows\System32\drivers\ataport.sys 2013-09-06 20:03:00 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf ====== C:\Windows\Tasks ====== 2013-09-30 19:08:48 35FF0B400A83D1EE852F416D9A56632E 3822 ----a-w- C:\Windows\system32\Tasks\Adobe Flash Player Updater 2013-09-30 19:08:48 1F2ECBAC56D1E67D86A8132181D2518A 884 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-20 03:33:36 8CFC135F4BDE75CF76B6A2925910A8C0 3414 ----a-w- C:\Windows\system32\Tasks\{4CFD8C3F-62D5-42F7-B501-E5C559EE202A} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2013-09-30 19:20:24 -------- d-----w- C:\Program Files\GridinSoft Trojan Killer 2013-09-25 11:26:31 -------- d-----w- C:\Program Files\Freetec 2013-09-23 00:55:27 -------- d-----w- C:\Program Files\Common Files\Java 2013-09-23 00:54:40 -------- d-----w- C:\Program Files\Java ======= C: ===== 2013-09-20 02:50:26 68DA3EA204996EC4B63A9568B5D99C25 206312 --sh--r- C:\XELDZ ====== C:\Users\Veli\AppData\Roaming ====== 2013-09-30 15:51:36 -------- d-----w- C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite 2013-09-26 07:23:22 -------- d-----w- C:\Users\Veli\AppData\Roaming\SkypEmoticons 2013-09-25 11:27:25 -------- d-----w- C:\Users\Veli\AppData\Local\Freetec 2013-09-23 23:01:12 -------- d-----w- C:\Users\Veli\AppData\Roaming\vlc 2013-09-18 19:37:45 -------- d-----w- C:\Users\Veli\AppData\Local\Programs ====== C:\Users\Veli ====== 2013-10-01 17:57:04 5611140E8CC5927D371C27EA1F9E71A6 1045226 ----a-w- C:\Users\Veli\Downloads\adwcleaner.exe 2013-09-30 20:04:16 E8DD5929CDAA01730F7C536D044F1389 1086873 ----a-w- C:\Users\Veli\Downloads\FRST.exe 2013-09-30 19:16:13 50A05EDC87893F62268E374C19BFBEB3 52176608 ----a-w- C:\Users\Veli\Downloads\gtk-2.1.8.9-setup.exe 2013-09-30 15:50:53 229261A60DBFD58471D114CC4E0456A0 4373560 ----a-w- C:\Users\Veli\Downloads\vppsetup.exe 2013-09-30 03:58:37 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Veli\Downloads\SpyHunter-Installer.exe 2013-09-28 06:27:57 1342ED24D3293559E0CACC0788A2B996 2681224 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(5).exe 2013-09-25 16:30:55 9A9B114CBD554C4A1BF9E2FCAB08B460 729736 ----a-w- C:\Users\Veli\Downloads\youtube-dlm_1.0_de-DE(1).exe 2013-09-25 16:14:44 FAC0845F41DC78C51B12AC090379B344 1238384 ----a-w- C:\Users\Veli\Downloads\CoolPic_mg_207566.exe 2013-09-25 11:22:57 86BA054C43FA55D6CA581EFA6772DA1C 729736 ----a-w- C:\Users\Veli\Downloads\youtube-dlm_1.0_de-DE.exe 2013-09-25 10:47:04 A509EB9A2388D2A329B9847E8D66FC2C 2743968 ----a-w- C:\Users\Veli\Downloads\netsight_setup_6.0.0.60_MP_Production_mid51049298465_p.exe 2013-09-24 22:50:48 FEAFF13AD04D5D945EF13587E92C3336 3362400 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(4).exe 2013-09-24 22:46:29 1342ED24D3293559E0CACC0788A2B996 2681224 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(3).exe 2013-09-23 16:30:55 1A31EC98651A9176A3669459F2EDFB78 9216 ----a-w- C:\Users\Veli\Downloads\plugin-container.exe 2013-09-23 16:28:23 B22198403FFEAF57BE49FF5A08DA1EF4 23003252 ----a-w- C:\Users\Veli\Downloads\vlc-2.0.8-win32(1).exe 2013-09-23 00:56:15 -------- d-----w- C:\ProgramData\Oracle 2013-09-23 00:54:58 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2013-09-23 00:52:28 2755BAEDEB84972D1621B9166CE29B0B 913832 ----a-w- C:\Users\Veli\Downloads\jxpiinstall(1).exe 2013-09-23 00:50:20 A4022823CFBF2C1A97BD01CCF7FE976C 7912440 ----a-w- C:\Users\Veli\Downloads\Shockwave_Installer_Slim(2).exe 2013-09-20 17:33:19 -------- d-----w- C:\Users\Veli\Videos 2013-09-18 19:38:31 -------- d-----w- C:\Users\Veli\Local Settings 2013-09-11 20:44:41 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite 2013-09-03 03:48:43 74E7F684F2198114E4AE1F6524A1653C 98304 ----a-w- C:\Users\Veli\fbchathistory.dat ====== C: exe-files == 2013-10-01 17:57:04 5611140E8CC5927D371C27EA1F9E71A6 1045226 ----a-w- C:\Users\Veli\Downloads\adwcleaner.exe 2013-09-30 20:04:46 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2L213I0D\FRST[1].exe 2013-09-30 20:04:16 E8DD5929CDAA01730F7C536D044F1389 1086873 ----a-w- C:\Users\Veli\Downloads\FRST.exe 2013-09-30 19:16:13 50A05EDC87893F62268E374C19BFBEB3 52176608 ----a-w- C:\Users\Veli\Downloads\gtk-2.1.8.9-setup.exe 2013-09-30 19:08:47 4CAC856E64F96C6949B0931964F9EE42 692616 ----a-w- C:\Windows\System32\FlashPlayerApp.exe 2013-09-30 15:51:36 229261A60DBFD58471D114CC4E0456A0 4373560 ----a-w- C:\Program Files\NCH Software\VideoPad\videopadsetup_v3.14.exe 2013-09-30 15:50:53 229261A60DBFD58471D114CC4E0456A0 4373560 ----a-w- C:\Users\Veli\Downloads\vppsetup.exe 2013-09-30 10:34:32 6B110E925294547A7D288F26DA19D199 179687 ----a-w- C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla18.exe 2013-09-30 03:58:48 09869C37B1CAE90A6275D4DE0E91D099 45868112 ----a-w- C:\Users\Veli\AppData\Local\Temp\SHSetup.exe 2013-09-30 03:58:37 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Veli\Downloads\SpyHunter-Installer.exe 2013-09-28 06:27:57 1342ED24D3293559E0CACC0788A2B996 2681224 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(5).exe 2013-09-26 07:27:28 01E1B94A8C0011F206DF0C997EA287F4 165 ----a-w- C:\$Recycle.Bin\S-1-5-21-3610243647-955691083-3180197658-1000\$RSN6AFQ\Crack VideoPad Video Editor.exe 2013-09-26 07:23:47 A8E982D615D2FFD066F591B6E4EABBE0 5842336 ----a-w- C:\Users\Veli\AppData\Roaming\SkypEmoticons\SE.exe 2013-09-25 16:30:55 9A9B114CBD554C4A1BF9E2FCAB08B460 729736 ----a-w- C:\Users\Veli\Downloads\youtube-dlm_1.0_de-DE(1).exe 2013-09-25 16:14:44 FAC0845F41DC78C51B12AC090379B344 1238384 ----a-w- C:\Users\Veli\Downloads\CoolPic_mg_207566.exe 2013-09-25 11:26:37 5CF463EA5AD05F5DE0BB5BBA6AA2092C 6656 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3}\chrome\bin\cmdproxy.exe 2013-09-25 11:22:57 86BA054C43FA55D6CA581EFA6772DA1C 729736 ----a-w- C:\Users\Veli\Downloads\youtube-dlm_1.0_de-DE.exe 2013-09-25 10:47:04 A509EB9A2388D2A329B9847E8D66FC2C 2743968 ----a-w- C:\Users\Veli\Downloads\netsight_setup_6.0.0.60_MP_Production_mid51049298465_p.exe 2013-09-24 22:50:48 FEAFF13AD04D5D945EF13587E92C3336 3362400 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(4).exe 2013-09-24 22:46:29 1342ED24D3293559E0CACC0788A2B996 2681224 ----a-w- C:\Users\Veli\Downloads\speakychatinstall(3).exe === C: other files == 2013-10-01 04:30:30 642DB546B8E5380410C4B110C222E13F 79139 ----a-w- C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MHPKEMNJ\de_DE[1].zip 2013-10-01 04:30:07 A842B48277A2D8645A37B9F596838D2A 1230 ----a-w- C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4XDS773D\flXHR[1].vbs 2013-09-29 21:02:39 51555013F2F820E6A20E991E754752D8 123385 ----a-w- C:\Users\Veli\AppData\Local\Temp\tmp-ifv.xpi 2013-09-25 11:26:35 F28E6D902D5782720F216207ECFBC07F 18753 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi 2013-09-25 11:26:35 ED10614EC981DB30789CC7EC4B229AB9 13955 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\admin@proxy-listen.de.xpi 2013-09-25 11:26:35 E23928ED13449168CB9F26BBE67BC95F 353425 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\smarterwiki@wikiatic.com.xpi 2013-09-25 11:26:35 C9F1A4E3D10AC900B022F8F45152A3E1 194311 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\jid0-c1av474BVPIHcGJfBp3GkhlhAa4@jetpack.xpi 2013-09-25 11:26:35 BD76955067E069A01B9A0392DEA4D10B 178395 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi 2013-09-25 11:26:35 B60381F680B593366B51DE45829C179F 31123 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{2A1D5949-B519-4924-BF62-8522FE0D5274}.xpi 2013-09-25 11:26:35 AC13FB2840845FE8B03E0EC579B8EA90 723773 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\stefanvandamme@stefanvd.net.xpi 2013-09-25 11:26:35 97AA187E8476935D2933E462E7A14D06 166436 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi 2013-09-25 11:26:35 967246D501D0F4379C673099996CF121 16117 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{e9876d64-8bac-4287-bdc4-0f0c56804b4f}.xpi 2013-09-25 11:26:35 73E5FCA06973ADD85D7CA071F89853A0 76810 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\screwads@airtint.com.xpi 2013-09-25 11:26:35 4ACEE5217E47CBA244D165C0414AA7CB 409220 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\jid0-w1UVmoLd6VGudaIERuRJCPQx1dQ@jetpack.xpi 2013-09-25 11:26:35 4155DB098E14F2A8CB7BAC0FD10D9FB0 210138 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi 2013-09-25 11:26:35 3D7728D85556F98F4F967AD9F288D8F6 18509 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi 2013-09-25 11:26:35 1D062796A5FF05D60F20A97677EDD437 824302 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi 2013-09-25 11:26:35 0FD6A9943787EE1A75FD810FE2DCD58C 14810 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\YouTubeAutoReplay@arikv.com.xpi 2013-09-25 11:26:35 0B240AC326EF16591C39AE84B2958659 171002 ----a-w- C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049\extensions\jid0-irAmugmQgdURBSCIFZAcjR8ZQMg@jetpack.xpi 2013-09-25 10:37:16 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Veli\AppData\LocalLow\Microsoft\Silverlight\OutOfBrowser\index\cdn-a.sponsorpay.com ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "SearchProtect"="\SearchProtect\bin\cltmng.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-3610243647-955691083-3180197658-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "SearchProtect"="\SearchProtect\bin\cltmng.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PLFSetI"="C:\Windows\PLFSetI.exe" "NvCplDaemon"="RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /minimized /regrun" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [30.09.2013 21:08] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\djh0uqno.default - Undetermined - %ProfilePath%\extensions\tilt@mozilla.com - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default - ColorfulTabs - %ProfilePath%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} - Complete YouTube Saver - %ProfilePath%\extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3} - PlugIn-Checker - %ProfilePath%\extensions\jid0-c1av474BVPIHcGJfBp3GkhlhAa4@jetpack.xpi - Youtube To MP3 PRO converter - %ProfilePath%\extensions\jid0-irAmugmQgdURBSCIFZAcjR8ZQMg@jetpack.xpi - FireTube - %ProfilePath%\extensions\jid0-w1UVmoLd6VGudaIERuRJCPQx1dQ@jetpack.xpi - YouTube ALL HTML5 - %ProfilePath%\extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi - Undetermined - %ProfilePath%\extensions\screwads@airtint.com.xpi - FastestFox - %ProfilePath%\extensions\smarterwiki@wikiatic.com.xpi - Turn Off the Lights - %ProfilePath%\extensions\stefanvandamme@stefanvd.net.xpi - YouTube Auto Replay - %ProfilePath%\extensions\YouTubeAutoReplay@arikv.com.xpi - PDFescape Extension - %ProfilePath%\extensions\{2A1D5949-B519-4924-BF62-8522FE0D5274}.xpi - Black Youtube - %ProfilePath%\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi - Fasterfox - %ProfilePath%\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi - QuickJava - %ProfilePath%\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi - Black Google Theme - %ProfilePath%\extensions\{e9876d64-8bac-4287-bdc4-0f0c56804b4f}.xpi - JavaScript Debugger - %ProfilePath%\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi ProfilePath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049 - ColorfulTabs - C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} - Complete YouTube Saver - C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3} - Undetermined - C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} - Undetermined - C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default\extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} - ColorfulTabs - %ProfilePath%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} - Flashblock - %ProfilePath%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} - Facebook Photo Zoom - %ProfilePath%\extensions\{7c6cdf7c-8ea8-4be7-ae5a-0b3effe14d66} - Complete YouTube Saver - %ProfilePath%\extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3} - Proxy-Listen.de - Proxyswitcher - %ProfilePath%\extensions\admin@proxy-listen.de.xpi - PlugIn-Checker - %ProfilePath%\extensions\jid0-c1av474BVPIHcGJfBp3GkhlhAa4@jetpack.xpi - Youtube To MP3 PRO converter - %ProfilePath%\extensions\jid0-irAmugmQgdURBSCIFZAcjR8ZQMg@jetpack.xpi - FireTube - %ProfilePath%\extensions\jid0-w1UVmoLd6VGudaIERuRJCPQx1dQ@jetpack.xpi - YouTube ALL HTML5 - %ProfilePath%\extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi - Undetermined - %ProfilePath%\extensions\screwads@airtint.com.xpi - FastestFox - %ProfilePath%\extensions\smarterwiki@wikiatic.com.xpi - Turn Off the Lights - %ProfilePath%\extensions\stefanvandamme@stefanvd.net.xpi - YouTube Auto Replay - %ProfilePath%\extensions\YouTubeAutoReplay@arikv.com.xpi - PDFescape Extension - %ProfilePath%\extensions\{2A1D5949-B519-4924-BF62-8522FE0D5274}.xpi - Black Youtube - %ProfilePath%\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi - Fasterfox - %ProfilePath%\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi - QuickJava - %ProfilePath%\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi - Black Google Theme - %ProfilePath%\extensions\{e9876d64-8bac-4287-bdc4-0f0c56804b4f}.xpi - JavaScript Debugger - %ProfilePath%\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\qpbe3oiy.default E5AF72B7353FF8D431A7C463A4229524 - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll - Shockwave Flash CA0E1DFBE480CF0BE13A0883BEB378B6 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U40 AF661355EBAB898EB92D5454AEF93CE0 - C:\Windows\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.400.43 148727EBD947CBC168C42A227D56DAB0 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat 9B4D431459A9B935FB117F4EDDA236E8 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat F045DF7AF127DC4BCC53421850114E15 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll - Silverlight Plug-In CD6D547D33C9D2935FC6F206DC4E2711 - C:\Users\Veli\AppData\Roaming\Mozilla\plugins\npspeakychat.dll - SpeakyChat 7D28153B7D586330678AD522B71D89CB - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrlui.dll - Microsoft® Silverlight 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System Profilepath: C:\Users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_787049 E5AF72B7353FF8D431A7C463A4229524 - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll - Shockwave Flash CA0E1DFBE480CF0BE13A0883BEB378B6 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U40 AF661355EBAB898EB92D5454AEF93CE0 - C:\Windows\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.400.43 148727EBD947CBC168C42A227D56DAB0 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat F045DF7AF127DC4BCC53421850114E15 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll - Silverlight Plug-In CD6D547D33C9D2935FC6F206DC4E2711 - C:\Users\Veli\AppData\Roaming\Mozilla\plugins\npspeakychat.dll - SpeakyChat 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System 7D28153B7D586330678AD522B71D89CB - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrlui.dll - Microsoft® Silverlight ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions hggpkhijoeadmdfmlbdepfbngmhaldci - C:\Program Files\DealPly\DealPly.crx[] mmiopbgcekanlhpjkonogoljpfmhpkhf - C:\Program Files\LyricsPal\125.crx[] oejkcgajlodefenbbjdnaiahmbnnoole - C:\Program Files\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx[] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.de" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.de" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== shortcuts on Users Desktops ====================== C:\Users\Veli\Desktop\Debut Video Capture Software.lnk - C:\Program Files\NCH Software\Debut\debut.exe C:\Users\Veli\Desktop\Samata Dj Efektor Professional.lnk - C:\Samata Dj Efektor v4.6\Samata Dj Efektor v4.6.exe C:\Users\Veli\Desktop\Privat\7-Zip File Manager.lnk - C:\Program Files\7-Zip\7zFM.exe C:\Users\Veli\Desktop\Privat\Adobe Reader XI.lnk - C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Users\Veli\Desktop\Privat\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\Desktop\Privat\Audio_Realtek_(ALC889)_v.6.0.1.5901_Win7x86x64.lnk - C:\Users\Veli\Desktop\Privat\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\Desktop\Privat\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\Desktop\Privat\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\Doxillion\doxillion.exe C:\Users\Veli\Desktop\Privat\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Privat\Gamesurround Muse Pocket.lnk - C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\Musecpl.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\Desktop\Privat\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe QVO6 C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (2).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (3).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (4).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung.lnk - C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe QVO6 C:\Users\Veli\Desktop\Privat\o.tel.o.lnk - C:\Program Files\o.tel.o\o.tel.o.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\Desktop\Privat\Pavtube Video Converter.lnk - C:\Program Files\Pavtube\Video Converter\Video Converter.exe C:\Users\Veli\Desktop\Privat\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\Desktop\Privat\RichMood Editor for Skype.lnk - C:\Program Files\Pamela RichMood Editor\MoodEditor.exe C:\Users\Veli\Desktop\Privat\Sandboxed Web Browser.lnk - C:\Program Files\Sandboxie\Start.exe default_browser C:\Users\Veli\Desktop\Privat\Skype...lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\Desktop\Privat\SplitCam.lnk - C:\Program Files\SplitCam\SplitCam.exe C:\Users\Veli\Desktop\Privat\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\Desktop\Privat\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\Desktop\Privat\Tube-8 Downloader.lnk - C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe C:\Users\Veli\Desktop\Privat\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\Desktop\Privat\VLC media player.lnk - C:\Program Files\VideoLAN\VLC\vlc.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube Download.lnk - C:\Program Files\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Videos\Desktop.lnk - C:\Users\Veli\Desktop C:\Users\Veli\Desktop\Debut Video Capture Software.lnk - C:\Program Files\NCH Software\Debut\debut.exe C:\Users\Veli\Desktop\Samata Dj Efektor Professional.lnk - C:\Samata Dj Efektor v4.6\Samata Dj Efektor v4.6.exe C:\Users\Veli\Desktop\Privat\7-Zip File Manager.lnk - C:\Program Files\7-Zip\7zFM.exe C:\Users\Veli\Desktop\Privat\Adobe Reader XI.lnk - C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Users\Veli\Desktop\Privat\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\Desktop\Privat\Audio_Realtek_(ALC889)_v.6.0.1.5901_Win7x86x64.lnk - C:\Users\Veli\Desktop\Privat\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\Desktop\Privat\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\Desktop\Privat\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\Doxillion\doxillion.exe C:\Users\Veli\Desktop\Privat\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Privat\Gamesurround Muse Pocket.lnk - C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\Musecpl.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\Desktop\Privat\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe QVO6 C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (2).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (3).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (4).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung.lnk - C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe QVO6 C:\Users\Veli\Desktop\Privat\o.tel.o.lnk - C:\Program Files\o.tel.o\o.tel.o.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\Desktop\Privat\Pavtube Video Converter.lnk - C:\Program Files\Pavtube\Video Converter\Video Converter.exe C:\Users\Veli\Desktop\Privat\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\Desktop\Privat\RichMood Editor for Skype.lnk - C:\Program Files\Pamela RichMood Editor\MoodEditor.exe C:\Users\Veli\Desktop\Privat\Sandboxed Web Browser.lnk - C:\Program Files\Sandboxie\Start.exe default_browser C:\Users\Veli\Desktop\Privat\Skype...lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\Desktop\Privat\SplitCam.lnk - C:\Program Files\SplitCam\SplitCam.exe C:\Users\Veli\Desktop\Privat\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\Desktop\Privat\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\Desktop\Privat\Tube-8 Downloader.lnk - C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe C:\Users\Veli\Desktop\Privat\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\Desktop\Privat\VLC media player.lnk - C:\Program Files\VideoLAN\VLC\vlc.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube Download.lnk - C:\Program Files\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Videos\Desktop.lnk - C:\Users\Veli\Desktop C:\Users\Veli\Desktop\Debut Video Capture Software.lnk - C:\Program Files\NCH Software\Debut\debut.exe C:\Users\Veli\Desktop\Samata Dj Efektor Professional.lnk - C:\Samata Dj Efektor v4.6\Samata Dj Efektor v4.6.exe C:\Users\Veli\Desktop\Privat\7-Zip File Manager.lnk - C:\Program Files\7-Zip\7zFM.exe C:\Users\Veli\Desktop\Privat\Adobe Reader XI.lnk - C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Users\Veli\Desktop\Privat\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\Desktop\Privat\Audio_Realtek_(ALC889)_v.6.0.1.5901_Win7x86x64.lnk - C:\Users\Veli\Desktop\Privat\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\Desktop\Privat\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\Desktop\Privat\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\Doxillion\doxillion.exe C:\Users\Veli\Desktop\Privat\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Privat\Gamesurround Muse Pocket.lnk - C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\Musecpl.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\Desktop\Privat\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe QVO6 C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (2).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (3).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (4).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung.lnk - C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe QVO6 C:\Users\Veli\Desktop\Privat\o.tel.o.lnk - C:\Program Files\o.tel.o\o.tel.o.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\Desktop\Privat\Pavtube Video Converter.lnk - C:\Program Files\Pavtube\Video Converter\Video Converter.exe C:\Users\Veli\Desktop\Privat\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\Desktop\Privat\RichMood Editor for Skype.lnk - C:\Program Files\Pamela RichMood Editor\MoodEditor.exe C:\Users\Veli\Desktop\Privat\Sandboxed Web Browser.lnk - C:\Program Files\Sandboxie\Start.exe default_browser C:\Users\Veli\Desktop\Privat\Skype...lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\Desktop\Privat\SplitCam.lnk - C:\Program Files\SplitCam\SplitCam.exe C:\Users\Veli\Desktop\Privat\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\Desktop\Privat\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\Desktop\Privat\Tube-8 Downloader.lnk - C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe C:\Users\Veli\Desktop\Privat\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\Desktop\Privat\VLC media player.lnk - C:\Program Files\VideoLAN\VLC\vlc.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube Download.lnk - C:\Program Files\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Videos\Desktop.lnk - C:\Users\Veli\Desktop C:\Users\Veli\Desktop\Debut Video Capture Software.lnk - C:\Program Files\NCH Software\Debut\debut.exe C:\Users\Veli\Desktop\Samata Dj Efektor Professional.lnk - C:\Samata Dj Efektor v4.6\Samata Dj Efektor v4.6.exe C:\Users\Veli\Desktop\Privat\7-Zip File Manager.lnk - C:\Program Files\7-Zip\7zFM.exe C:\Users\Veli\Desktop\Privat\Adobe Reader XI.lnk - C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Users\Veli\Desktop\Privat\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\Desktop\Privat\Audio_Realtek_(ALC889)_v.6.0.1.5901_Win7x86x64.lnk - C:\Users\Veli\Desktop\Privat\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\Desktop\Privat\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\Desktop\Privat\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\Doxillion\doxillion.exe C:\Users\Veli\Desktop\Privat\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Privat\Gamesurround Muse Pocket.lnk - C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\Musecpl.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\Desktop\Privat\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe QVO6 C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (2).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (3).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (4).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung.lnk - C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe QVO6 C:\Users\Veli\Desktop\Privat\o.tel.o.lnk - C:\Program Files\o.tel.o\o.tel.o.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\Desktop\Privat\Pavtube Video Converter.lnk - C:\Program Files\Pavtube\Video Converter\Video Converter.exe C:\Users\Veli\Desktop\Privat\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\Desktop\Privat\RichMood Editor for Skype.lnk - C:\Program Files\Pamela RichMood Editor\MoodEditor.exe C:\Users\Veli\Desktop\Privat\Sandboxed Web Browser.lnk - C:\Program Files\Sandboxie\Start.exe default_browser C:\Users\Veli\Desktop\Privat\Skype...lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\Desktop\Privat\SplitCam.lnk - C:\Program Files\SplitCam\SplitCam.exe C:\Users\Veli\Desktop\Privat\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\Desktop\Privat\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\Desktop\Privat\Tube-8 Downloader.lnk - C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe C:\Users\Veli\Desktop\Privat\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\Desktop\Privat\VLC media player.lnk - C:\Program Files\VideoLAN\VLC\vlc.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube Download.lnk - C:\Program Files\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Videos\Desktop.lnk - C:\Users\Veli\Desktop C:\Users\Veli\Desktop\Debut Video Capture Software.lnk - C:\Program Files\NCH Software\Debut\debut.exe C:\Users\Veli\Desktop\Samata Dj Efektor Professional.lnk - C:\Samata Dj Efektor v4.6\Samata Dj Efektor v4.6.exe C:\Users\Veli\Desktop\Privat\7-Zip File Manager.lnk - C:\Program Files\7-Zip\7zFM.exe C:\Users\Veli\Desktop\Privat\Adobe Reader XI.lnk - C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Users\Veli\Desktop\Privat\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\Desktop\Privat\Audio_Realtek_(ALC889)_v.6.0.1.5901_Win7x86x64.lnk - C:\Users\Veli\Desktop\Privat\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\Desktop\Privat\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\Desktop\Privat\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\Doxillion\doxillion.exe C:\Users\Veli\Desktop\Privat\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Privat\Gamesurround Muse Pocket.lnk - C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\Musecpl.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\Desktop\Privat\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe QVO6 C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (2).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (3).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (4).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung.lnk - C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe QVO6 C:\Users\Veli\Desktop\Privat\o.tel.o.lnk - C:\Program Files\o.tel.o\o.tel.o.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\Desktop\Privat\Pavtube Video Converter.lnk - C:\Program Files\Pavtube\Video Converter\Video Converter.exe C:\Users\Veli\Desktop\Privat\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\Desktop\Privat\RichMood Editor for Skype.lnk - C:\Program Files\Pamela RichMood Editor\MoodEditor.exe C:\Users\Veli\Desktop\Privat\Sandboxed Web Browser.lnk - C:\Program Files\Sandboxie\Start.exe default_browser C:\Users\Veli\Desktop\Privat\Skype...lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\Desktop\Privat\SplitCam.lnk - C:\Program Files\SplitCam\SplitCam.exe C:\Users\Veli\Desktop\Privat\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\Desktop\Privat\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\Desktop\Privat\Tube-8 Downloader.lnk - C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe C:\Users\Veli\Desktop\Privat\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\Desktop\Privat\VLC media player.lnk - C:\Program Files\VideoLAN\VLC\vlc.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube Download.lnk - C:\Program Files\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Videos\Desktop.lnk - C:\Users\Veli\Desktop C:\Users\Veli\Desktop\Debut Video Capture Software.lnk - C:\Program Files\NCH Software\Debut\debut.exe C:\Users\Veli\Desktop\Samata Dj Efektor Professional.lnk - C:\Samata Dj Efektor v4.6\Samata Dj Efektor v4.6.exe C:\Users\Veli\Desktop\Privat\7-Zip File Manager.lnk - C:\Program Files\7-Zip\7zFM.exe C:\Users\Veli\Desktop\Privat\Adobe Reader XI.lnk - C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Users\Veli\Desktop\Privat\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\Desktop\Privat\Audio_Realtek_(ALC889)_v.6.0.1.5901_Win7x86x64.lnk - C:\Users\Veli\Desktop\Privat\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\Desktop\Privat\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\Desktop\Privat\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\Doxillion\doxillion.exe C:\Users\Veli\Desktop\Privat\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Privat\Gamesurround Muse Pocket.lnk - C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\Musecpl.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\Desktop\Privat\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe QVO6 C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (2).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (3).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung (4).lnk - C:\Users\Veli\Desktop\Privat\Kerem - Verknüpfung.lnk - C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe QVO6 C:\Users\Veli\Desktop\Privat\o.tel.o.lnk - C:\Program Files\o.tel.o\o.tel.o.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\Desktop\Privat\Pavtube Video Converter.lnk - C:\Program Files\Pavtube\Video Converter\Video Converter.exe C:\Users\Veli\Desktop\Privat\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\Desktop\Privat\RichMood Editor for Skype.lnk - C:\Program Files\Pamela RichMood Editor\MoodEditor.exe C:\Users\Veli\Desktop\Privat\Sandboxed Web Browser.lnk - C:\Program Files\Sandboxie\Start.exe default_browser C:\Users\Veli\Desktop\Privat\Skype...lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\Desktop\Privat\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\Desktop\Privat\SplitCam.lnk - C:\Program Files\SplitCam\SplitCam.exe C:\Users\Veli\Desktop\Privat\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\Desktop\Privat\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\Desktop\Privat\Tube-8 Downloader.lnk - C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe C:\Users\Veli\Desktop\Privat\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\Desktop\Privat\VLC media player.lnk - C:\Program Files\VideoLAN\VLC\vlc.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube Download.lnk - C:\Program Files\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe C:\Users\Veli\Desktop\Privat\YouTube Cekim\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\Desktop\Videos\Desktop.lnk - C:\Users\Veli\Desktop ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe ==== shortcuts in Users Start Menu ====================== C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Accounting Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressAccounts C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Classic FTP Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ClassicFTP C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Doxillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Burn CD, DVD or Blu-Ray.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressBurn C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Dictate Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Express C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Rip CD Ripper.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Rip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Zip File Compression.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressZip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Graphics File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Pixillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Invoicing Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressInvoice C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\MixPad MultiTrack Mixer.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind MixPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Prism Video File Format Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Prism C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\RecordPad Sound Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind RecordPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\SoundTap Streaming Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind SoundTap C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Switch Sound File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Switch C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Capture Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Debut C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\WavePad Sound Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind WavePad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Accounting Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressAccounts C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Classic FTP Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ClassicFTP C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Doxillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Burn CD, DVD or Blu-Ray.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressBurn C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Dictate Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Express C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Rip CD Ripper.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Rip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Zip File Compression.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressZip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Graphics File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Pixillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Invoicing Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressInvoice C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\MixPad MultiTrack Mixer.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind MixPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Prism Video File Format Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Prism C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\RecordPad Sound Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind RecordPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\SoundTap Streaming Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind SoundTap C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Switch Sound File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Switch C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Capture Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Debut C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\WavePad Sound Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind WavePad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Accounting Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressAccounts C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Classic FTP Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ClassicFTP C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Doxillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Burn CD, DVD or Blu-Ray.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressBurn C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Dictate Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Express C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Rip CD Ripper.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Rip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Zip File Compression.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressZip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Graphics File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Pixillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Invoicing Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressInvoice C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\MixPad MultiTrack Mixer.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind MixPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Prism Video File Format Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Prism C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\RecordPad Sound Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind RecordPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\SoundTap Streaming Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind SoundTap C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Switch Sound File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Switch C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Capture Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Debut C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\WavePad Sound Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind WavePad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Accounting Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressAccounts C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Classic FTP Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ClassicFTP C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Doxillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Burn CD, DVD or Blu-Ray.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressBurn C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Dictate Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Express C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Rip CD Ripper.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Rip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Zip File Compression.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressZip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Graphics File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Pixillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Invoicing Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressInvoice C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\MixPad MultiTrack Mixer.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind MixPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Prism Video File Format Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Prism C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\RecordPad Sound Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind RecordPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\SoundTap Streaming Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind SoundTap C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Switch Sound File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Switch C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Capture Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Debut C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\WavePad Sound Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind WavePad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Accounting Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressAccounts C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Classic FTP Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ClassicFTP C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Doxillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Burn CD, DVD or Blu-Ray.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressBurn C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Dictate Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Express C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Rip CD Ripper.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Rip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Zip File Compression.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressZip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Graphics File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Pixillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Invoicing Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressInvoice C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\MixPad MultiTrack Mixer.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind MixPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Prism Video File Format Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Prism C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\RecordPad Sound Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind RecordPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\SoundTap Streaming Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind SoundTap C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Switch Sound File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Switch C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Capture Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Debut C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\WavePad Sound Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind WavePad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Accounting Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressAccounts C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Classic FTP Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ClassicFTP C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Doxillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Burn CD, DVD or Blu-Ray.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressBurn C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Dictate Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Express C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Rip CD Ripper.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Rip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Zip File Compression.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressZip C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Graphics File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Pixillion C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Invoicing Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressInvoice C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\MixPad MultiTrack Mixer.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind MixPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Prism Video File Format Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Prism C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\RecordPad Sound Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind RecordPad C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\SoundTap Streaming Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind SoundTap C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Switch Sound File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Switch C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Capture Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Debut C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\WavePad Sound Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind WavePad ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1031-7B44-AB0000000001}\SC_Reader.ico C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files\Java\jre7\bin\javacpl.exe -tab about C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files\Java\jre7\bin\javacpl.exe -tab update C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files\Java\jre7\bin\javacpl.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Accounting Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressAccounts C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Classic FTP Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ClassicFTP C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Doxillion Document Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Doxillion C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Burn CD, DVD or Blu-Ray.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressBurn C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Dictate Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Express C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Rip CD Ripper.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Rip C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Zip File Compression.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressZip C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Graphics File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Pixillion C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Invoicing Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind ExpressInvoice C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\MixPad MultiTrack Mixer.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind MixPad C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Prism Video File Format Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Prism C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\RecordPad Sound Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind RecordPad C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\SoundTap Streaming Recorder.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind SoundTap C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Switch Sound File Converter.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Switch C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Capture Software.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind Debut C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\WavePad Sound Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe -extfind WavePad ==== shortcuts in Quick Launch ====================== C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe QVO6 C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Animation Shop 3.lnk - C:\Windows\Installer\{174D5678-D941-433C-BD23-58A5C7B0D36D}\Anim3TryAndBuy.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Creative Sound Card.lnk - C:\Program Files\Creative\AudioCS\CTAudCS.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Free YouTube to MP3 Converter.lnk - C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HyperCam 2.lnk - C:\Program Files\HyperCam 2\HyCam2.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PhotoScape.lnk - C:\Program Files\PhotoScape\PhotoScape.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Sound Recorder.lnk - C:\Windows\system32\SoundRecorder.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SWFText.lnk - C:\Program Files\SWFText\SWFText.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamViewer 8.lnk - C:\Program Files\TeamViewer\Version8\TeamViewer.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ulead GIF Animator 5.lnk - C:\Program Files\Ulead Systems\Ulead GIF Animator 5\ga_main.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VideoPad Video Editor.lnk - C:\Program Files\NCH Software\VideoPad\videopad.exe ==== shortcuts After Repair ====================== C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\Desktop\Privat\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\Desktop\Privat\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Veli\Desktop\Privat\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Veli\Desktop\Privat\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera.lnk - C:\Program Files\Opera\opera.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Veli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk - C:\Program Files\Opera\opera.exe ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\hggpkhijoeadmdfmlbdepfbngmhaldci deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\mmiopbgcekanlhpjkonogoljpfmhpkhf deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole deleted successfully ==== Empty IE Cache ====================== C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D64B3QVL will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Veli\AppData\Local\Mozilla\Firefox\Profiles\qpbe3oiy.default\Cache emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Veli\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D64B3QVL" not found ==== EOF on 01.10.2013 at 20:10:54,51 ====================== |
AdwCleaner Logfile: Code: # AdwCleaner v3.006 - Bericht erstellt am 01/10/2013 um 20:13:53 |
Da waren wirklich viele Funde :) Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
|
Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.02.07 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16686 Keremino :: KEREM [Administrator] 02.10.2013 18:07:51 mbam-log-2013-10-02 (18-07-51).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 187399 Laufzeit: 9 Minute(n), 23 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 2 HKCR\AppID\{33CB14BC-58BB-4B3A-9877-7946A3F41BAE} (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3444c3c5-6c56-4a16-a453-832b05bf6ea4} (PUP.Optional.MoviesToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 4 HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{FEFE89E5-A43F-4f4b-8211-B11D91D02135} (PUP.Optional.CoolPic) -> Daten: -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{FEFE89E5-A43F-4f4b-8211-B11D91D02135} (PUP.Optional.CoolPic) -> Daten: C:\Program Files\CoolPic - Fun Social Pictures\Firefox -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{14DD0E04-D4F6-45d2-A958-F361FBD4F64F} (PUP.Optional.WBCEngine) -> Daten: -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{14DD0E04-D4F6-45d2-A958-F361FBD4F64F} (PUP.Optional.WBCEngine) -> Daten: C:\Program Files\WBC Engine\Firefox -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Veli\Downloads\PhotoScape_V3.6.5.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Results of screen317's Security Check version 0.99.73 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 40 Java version out of Date! Adobe Flash Player 11.8.800.168 Adobe Reader XI Mozilla Firefox (24.0) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbam.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Meiner Meinung nach sieht alles wieder ganz OK aus :daumenhoc Tools deinstallieren Die Reihenfolge ist hier entscheidend.
Abschließend noch Tipps zu folgenden Themen:
![]() Systemupdates Man kann es gar nicht oft genug erwähnen, wie wichtig es ist, sein System aktuell zu halten. Dein Auto bringst du ja auch regelmässig zur Inspektion in die Werkstatt. Stelle also bitte sicher, dass die Systemupdates aktiviert sind:
![]() Softwareupdates Ebenso wichtig wie die Systemprogramme ist auch die Software, die du täglich nutzt. Die folgende Liste gibt dir einen kleinen Überblick mit Links zu den Updates, welche Programme dringend aktuell gehalten werden müssen (falls du sie überhaupt installiert hast und nutzt), weil durch deren Sicherheitslücken oft Malware auf die Computer gelangen kann:
![]() Sicherheitssoftware Würde dich jemand nackt auf dem Motorrad auf der Autobahn überholen würdest du auch den Kopf schütteln. Dein Computer braucht auch einen Schutz vor den täglichen kleinen Angriffen durch Schädlinge. Neben hervorragenden kommerziellen Anti-Viren-Lösungen gibt es auch durchaus gute Schutzprogramme, die kostenfrei mit reduziertem Funktionsumfang erhältlich sind. Aber vorsicht, hier gilt nicht "je mehr desto besser". Was du brauchst ist genau einen Virenscanner mit Hintergrundwächter. Nicht mehr und nicht weniger. Es gibt hier viele Produkte auf dem Markt, die einem gute Dienste leisten. Ich persönlich empfehle dir Avast Free Antivirus. Es bietet relativ guten Schutz, bei wenig nerviger Werbung und installiert dir ein Browserplugin, das dich vor gefährlichen Webseiten warnt.
![]() Sicheres Surfen Zunächst muss man sagen, dass es üblicherweise immer der menschliche Faktor ist, der es Malware ermöglicht auf einen Computer zu gelangen. Kaufst du Leuten, die an deiner Haustür klingeln, auch sofort ohne nachzudenken irgendwelches Zeug ab? Gewöhne dir daher zunächst einige Verhaltensregeln beim Surfen im Internet an:
Aber selbst bei der peinlichen Einhaltung dieser Regeln kann es dennoch zu einer sogenannten Drive-By-Infektion kommen, bei der ein Schädling aus dem Schutzmechanismus des Webbrowsers ausbricht. Um die Sicherheit noch weiter zu erhöhen gibt es spezielle Schutzsoftware, die deinen Browser noch weiter absichert.
Zuletzt denke bitte über die Benutzung eines alternativen Browsers nach. Programme, die nicht so oft verwendet werden, sind auch nicht so sehr im Focus der "bösen Jungs". D.h. du bist mit einem exotischen Browser eher auf der sicheren Seite. Grundsätzlich bist du erst einmal deutlich sicherer, wenn du nicht den Internet Explorer benutzt.
Damit wünsche ich dir noch viel Spaß beim Surfen im Internet :daumenhoc ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Grüße Smeenk |
Smeenk, habe vielen vielen Dank :daumenhoc Alles läuft wirder wie früher :dankeschoen: Selbstverständlich werde ich das Trojaner-Board unterstützen :applaus: Denn ohne Smeenk, hätte ich das ganze hier nicht geschafft :daumenhoc Benutze zwar keine Paypal, werde aber, mit einer Banküberweisung für die Unterstützung, teilnehmen. Alles Gute und Liebe wünscht dir Kerem aus Düsseldorf :party: NOCHMALS DANKE FÜR ALLES SMEENK |
Alle Zeitangaben in WEZ +1. Es ist jetzt 12:55 Uhr. |
Copyright ©2000-2025, Trojaner-Board