plambeck10 | 18.07.2014 13:18 | Logdatei von AdwCleaner. Code:
# AdwCleaner v3.216 - Bericht erstellt am 18/07/2014 um 13:18:50
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Nicklas-Pc - NICKLASPC
# Gestartet von : C:\Users\Nicklas-Pc\Desktop\adwcleaner_3.216.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : rqpbhevlkc64
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dkinklhnkmkhkhofcnapakaoehijaoih
***** [ Browser ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Nicklas-Pc\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]
[ Datei : C:\Users\Nicklas-Pc\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.Ztje0Gae2L.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumor[...]
Zeile gelöscht : user_pref("extensions.nBbhVDHgJZ.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumor[...]
Zeile gelöscht : user_pref("extensions.sJk5IPg8sTC.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumo[...]
-\\ Google Chrome v32.0.1700.76
[ Datei : C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.sweet-page.com/web/?type=dspp&ts=1403614692&from=cor&uid=ST1000DM003-9YN162_S1D0KXFHXXXXS1D0KXFH&q={searchTerms}
Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3317742&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP79E9A268-5DD2-4A20-8866-98041DA58AD1&q={searchTerms}&SSPV=
Gelöscht [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&affID=116295&tt=111212_old_5012_8&babsrc=SP_ss&mntrId=204c3cc000000000000094dbc9e14d04
*************************
AdwCleaner[R0].txt - [27796 octets] - [16/07/2014 17:59:51]
AdwCleaner[R1].txt - [1165 octets] - [16/07/2014 18:06:50]
AdwCleaner[R2].txt - [2938 octets] - [18/07/2014 13:18:06]
AdwCleaner[S0].txt - [27142 octets] - [16/07/2014 18:00:43]
AdwCleaner[S1].txt - [1807 octets] - [16/07/2014 18:07:35]
AdwCleaner[S2].txt - [2863 octets] - [18/07/2014 13:18:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2923 octets] ########## Mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 18.07.2014
Scan Time: 13:27:35
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.07.18.04
Rootkit Database: v2014.07.17.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Nicklas-Pc
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 322851
Time Elapsed: 12 min, 11 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 2
PUP.Optional.CouponDownloader.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\APPDATALOW\SOFTWARE\Coupon Downloader, , [f705c4dcef8ce254849c2fa356ac06fa],
Malware.Trace, HKU\S-1-5-21-958759603-357473-4181541277-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\VB AND VBA PROGRAM SETTINGS\SrvID, , [c438ebb5c0bb5fd7134ef36fa2618c74],
Registry Values: 2
Hijacker.Application, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ASSOCIATIONS|bak_application, hxxp://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s, , [9d5fbde3ee8d9a9c49f7a4ca857e3ec2]
Hijacker.Application, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ASSOCIATIONS|bak_Application, hxxp://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s, , [ed0f703053281d1970d074fa40c37888]
Registry Data: 2
Hijacker.Application, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ASSOCIATIONS|Application, hxxp://www.helpmeopen.com/?n=app&ext=%s, Good: (hxxp://shell.windows.com/fileassoc/Bad: (hxxp://www.helpmeopen.com/?n=app&ext=%s),,[03f9e4bc2c4f5adc9cc5a3019b69ac54]x/xml/redir.asp?Ext=%s), %5
Hijacker.Application, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ASSOCIATIONS|Application, hxxp://www.helpmeopen.com/?n=app&ext=%s, Good: (hxxp://shell.windows.com/fileassoc/Bad: (hxxp://www.helpmeopen.com/?n=app&ext=%s),,[eb11f8a8661551e593cef1b3966e31cf]x/xml/redir.asp?Ext=%s), %5
Folders: 0
(No malicious items detected)
Files: 13
PUP.Optional.CouponDownloader.A, C:\temp\t_ff.exe, , [31cb732d2259f93d0c4d251eb34d857b],
PUP.Optional.CouponDownloader.A, C:\temp\t_ie.exe, , [f408514f7b0088aecf8a1d26c23eaa56],
Trojan.KillAV, C:\Users\Nicklas-Pc\Downloads\extlotrbftme2101trn6.zip, , [906cddc385f6b18569682258917348b8],
PUP.Optional.InstallMonetizer, C:\Users\Nicklas-Pc\Downloads\TGFtYXMrTWl0K0glQzMlQkN0ZW4rdnMuK1RvbXRyYXgrLStEZXIrS2xhbmcrRGVyK1ZlcmdlYnVuZyslMjhUaXRhbmljK01peCUyOS5tcDMuZXhl, , [0eee28782f4c270f91050228e71d23dd],
PUP.HackTool.HotKeysHook, C:\Users\Nicklas-Pc\Downloads\CrashdayTrainer1.zip, , [0def168a5c1fb87ee55381ccc242e51b],
Backdoor.Bot, C:\Users\Nicklas-Pc\Downloads\crashday_plus_4_trainer.zip, , [94689010bdbea690c0c5d69412ee58a8],
Trojan.Genome, C:\Users\Nicklas-Pc\Downloads\lotrwkingtrn11m-ch.zip, , [20dc4858f784e5515b0fe8a26c98fb05],
PUP.Optional.InstallCore, C:\Users\Nicklas-Pc\Downloads\Plex-Media-Server-v0.9.502-en-US.exe, , [b54798088fec93a3f922ebadad57fa06],
PUP.Optional.Superfish.A, C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [cb31a5fb1863a09679ce8b4520e20df3],
PUP.Optional.Superfish.A, C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [9963831db0cbca6c55f2ebe520e215eb],
Stolen.Data, C:\Users\Nicklas-Pc\AppData\Roaming\windows, , [d329f4ac4e2df93d47d7158ab94a9d63],
PUP.Optional.Conduit.A, C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "search_url": "hxxp://search.conduit.com/Results.aspx?ctid=CT3317742&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP79E9A268-5DD2-4A20-8866-98041DA58AD1&q={searchTerms}&SSPV=",), ,[1ddf782822597cbaf0270dca3aca38c8]
PUP.Optional.CrossRider.A, C:\Users\Nicklas-Pc\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\prefs.js, Good: (), Bad: (user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.pluginsurl", "hxxp://js.clientdataservice.com/plugin/apps/33036/plugins/094/ff/plugins.json");), ,[a755bee2f28983b367bd3b9b956fb947]
Physical Sectors: 0
(No malicious items detected)
(end) Hier die Zoek: Code:
Zoek.exe v5.0.0.0 Updated 16-07-2014
Tool run by Nicklas-Pc on 18.07.2014 at 13:48:23,80.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Nicklas-Pc\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
18.07.2014 13:50:54 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-958759603-357473-4181541277-1002\Software\Microsoft\Internet Explorer\SearchScopes\{FAD5A6E1-D037-46BA-924E-348B205ACE56} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js:
Added to C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\prefs.js:
Added to C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\NICKLA~1\AppData\Roaming\Thunderbird\Profiles\kyqjqqo7.default\prefs.js:
Added to C:\Users\NICKLA~1\AppData\Roaming\Thunderbird\Profiles\kyqjqqo7.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\0
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1402_.backup
ProfilePath: C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default
user.js not found
---- Lines a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036 removed from prefs.js ----
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e0497
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e0497
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.active", true);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.addressbar", "NA");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.addressbarenhanced", "");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.asyncdb.was_copied", "true");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.asyncdb_dbWasSet", true);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.asyncinternaldb.was_copied", "true");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.backgroundver", 2);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.certdomaininstaller", "");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.changeprevious", false);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.cookie._GPL_aoi.value", "%221396694871%22");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.cookie._GPL_parent_zoneid.expiration", "Fri Feb
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.cookie._GPL_parent_zoneid.value", "%22513018%22"
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.cookie.InstallationTime.value", "1386527904");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.cookie.jw_token.expiration", "Fri Feb 01 2030 00
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.cookie.jw_token.value", "%226ad81147-ab74-f3a4-8
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.description", "Turn YouTube videos to High Defin
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.domain", "");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.enablesearch", false);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.homepage", "");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.iframe", false);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.InstallationThankYouPage", false);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.InstallationTime", 1386527904);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.monetization_plugin_bundledUrls.value
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_appVer.value", "197");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.lastDailyReport", "1402842082827");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.lastUpdate", "1402842070823");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.manifesturl", "");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.name", "Plus-HD-2.2");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.newtab", "");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.opensearch", "");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.pluginsversion", 187);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.publisher", "Plus HD");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.searchstatus", 0);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.setnewtab", false);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.thankyou", "");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.updateinterval", 360);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.ver", 197);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.apps", "33036");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.bic", "14020e7aa5dff94de409cbd9ea225658");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.cid", 33036);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.FilesValidatorDueTime", "1402842152428");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.firstrun", false);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.hadappinstalled", true);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.installationdate", 1386527904);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.modetype", "production");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.reportInstall", true);
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.statsDailyCounter", 7);
---- Lines extensions.Ztje0Gae2L removed from prefs.js ----
user_pref("extensions.Ztje0Gae2L.epoch", "1405686945");
user_pref("extensions.Ztje0Gae2L.url", "hxxp://foreveryshare.ru/sync2/?q=hfZ9oek5AGhEAen0rihTB6lKDzt4okmxtNtVh7n0rjnErjrFrjrGqHkFtMFHhd9Fqda6rjCFrTr8q
---- Lines extensions.nBbhVDHgJZ removed from prefs.js ----
user_pref("extensions.nBbhVDHgJZ.epoch", "1405686945");
user_pref("extensions.nBbhVDHgJZ.url", "hxxp://toolkitsetusa.info/sync2/?q=hfZ9ofqZB75MCyVUojwMg708BNmGWj8wmihGheDUojw9rdwGqdw4qjrEqShIC7n0rjnEqHw6rjs
---- Lines extensions.sJk5IPg8sTC removed from prefs.js ----
user_pref("extensions.sJk5IPg8sTC.epoch", "1405686945");
user_pref("extensions.sJk5IPg8sTC.url", "hxxp://discountgetdirect.ru/sync2/?q=hfZ9ofq7CGhEAen0rihTB6lKDzt4okmxtNtVh7n0rjnErjs9rjU8rHw5tMFHhd9Fqda6rjCF
---- FireFox user.js and prefs.js backups ----
prefs__1402_.backup
ProfilePath: C:\Users\NICKLA~1\AppData\Roaming\Thunderbird\Profiles\kyqjqqo7.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1402_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~3\jhokmamofjfcppikpghpfbfapdoiojnf deleted
C:\PROGRA~3\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\{4EB28202-312C-477C-7191-3CBB115F4C7B} deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{4EB28202-312C-477C-7191-3CBB115F4C7B} deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{8ACAB8EC-C10C-ED1C-A65E-A833FFF6F2AA} deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{FD11D27D-BD64-AAD3-9A89-BFA294DF7A04} deleted
C:\PROGRA~3\504c2cf8db11ac3b deleted
C:\PROGRA~3\HteMlCheeckeir deleted
C:\PROGRA~3\savinshop deleted
C:\PROGRA~3\saiVeron deleted
C:\found.001 deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Nicklas-Pc\AppData\Local\cache deleted
C:\Users\Nicklas-Pc\Searches deleted
C:\Users\Nicklas-Pc\AppData\LocalLow\SIEN SA deleted
C:\Windows\Syswow64\InstallUtil.InstallLog deleted
C:\Windows\SysWow64\AI_RecycleBin deleted
C:\Windows\SysWow64\searchplugins deleted
C:\Windows\SysWow64\Extensions deleted
C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\jetpack deleted
C:\Users\Nicklas-Pc\AppData\Roaming\vbc.exe deleted
C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\extensions\779_u@yeiioo.com deleted
C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\extensions\hom09zc@youyeu.co.uk deleted
C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\extensions\tmx0ooa@r-yoea.com deleted
"C:\Windows\Installer\4103c.msi" deleted
"C:\Users\Nicklas-Pc\AppData\Roaming\buttrc" deleted
"C:\PROGRA~3\kkjkegmiadncipafbpennkgonpccihjm\kkjkegmiadncipafbpennkgonpccihjm.crx" deleted
"C:\PROGRA~3\kkjkegmiadncipafbpennkgonpccihjm\update.xml" deleted
"C:\PROGRA~3\kkjkegmiadncipafbpennkgonpccihjm" deleted
"C:\found.000" deleted
==== Firefox Extensions ======================
ProfilePath: C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\0
- Online HD TV - %ProfilePath%\extensions\onlinehdtv@onlinehd.tv.xpi
ProfilePath: C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default
- Exif Viewer - %ProfilePath%\extensions\exif_viewer@mozilla.doslash.org.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Nicklas-Pc\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash
FF0D6F82A0EC13952E83B9439100E45D - C:\Users\Nicklas-Pc\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
E09A55AB513C4D5145F1C318ED024747 - C:\Users\Nicklas-Pc\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll - AmazonMP3DownloaderPlugin
8F0B95B3AC17DAE9E138E7BBE2429B6C - C:\Users\Nicklas-Pc\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
FFF2362F6B4A46D4BC1D147E79A7547B - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll - Nexon Game Controller
4BF5DC55B3E48D974E50C7BB82BEFDF3 - C:\Windows\SysWOW64\npdeployJava1.dll - Java Deployment Toolkit 7.0.50.5
8FE7BA502945BE735D09D5703BD76FDA - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll - Shockwave for Director / Shockwave for Director
4676A8E1EE37E71486717ECD1E61C17B - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Deleted Firefox Extensions ======================
C:\Users\NICKLA~1\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\onlinehdtv@onlinehd.tv.xpi deleted
==== Chrome Look ======================
HteMlCheeckeir - Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkjkegmiadncipafbpennkgonpccihjm
Chrome Apps & Extensions Developer Tool - Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc
==== Chrome Fix ======================
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toppornsearch.com_0.localstorage deleted successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toppornsearch.com_0.localstorage-journal deleted successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkjkegmiadncipafbpennkgonpccihjm deleted successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kkjkegmiadncipafbpennkgonpccihjm_0.localstorage deleted successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kkjkegmiadncipafbpennkgonpccihjm_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="hxxp://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{845271D1-B5CD-473C-B8DA-620DC8E4FAD7} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDNE_deDE504"
==== Reset Google Chrome ======================
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyEnable"=dword:00000000
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F60730A4A66673047777F5728467D401 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401 deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Nicklas-Pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Nicklas-Pc\AppData\Local\Mozilla\Firefox\Profiles\jv4m07bm.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=2274 folders=747 335735806 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Nicklas-Pc\AppData\Local\Temp will be emptied at reboot
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\NICKLA~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 18.07.2014 at 14:09:55,20 ====================== Und Frst!´
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 01
Ran by Nicklas-Pc (administrator) on NICKLASPC on 18-07-2014 14:14:20
Running from C:\Users\Nicklas-Pc\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Users\Nicklas-Pc\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
() C:\Users\Nicklas-Pc\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(Dropbox, Inc.) C:\Users\Nicklas-Pc\AppData\Roaming\Dropbox\bin\Dropbox.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12452968 2012-03-13] (Realtek Semiconductor)
HKLM\...\Run: [MedionReminder] => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [430080 2012-05-10] (CyberLink)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [111080 2012-04-14] (CyberLink)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2011-03-30] (CyberLink Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630912 2012-05-05] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [12288 2012-04-20] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [LogitechQuickCamRibbon] => C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] ()
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-06-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\RunOnce: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey [430080 2012-05-10] (CyberLink)
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1753280 2014-07-16] (Valve Corporation)
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [Facebook Update] => C:\Users\Nicklas-Pc\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-06-29] (Facebook Inc.)
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [InbitIMC] => C:\Program Files (x86)\24im\24im Messenger\IMC.EXE [3423744 2013-07-03] (24im LLC)
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21446272 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [Dxtory Update Checker 2.0] => C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software)
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Nicklas-Pc\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [Amazon Cloud Player] => C:\Users\Nicklas-Pc\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3168576 2014-03-07] ()
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe [4777984 2013-12-14] (ManyCam LLC)
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\MountPoints2: {44fe824a-f6b1-11e1-9226-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-958759603-357473-4181541277-1002\...\MountPoints2: {533b6c92-c9e1-11e2-9999-d43d7e19a298} - F:\LGAutoRun.exe
Startup: C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Nicklas-Pc\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Nicklas-Pc\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.0 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.0 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.5.0 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.0 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Nicklas-Pc\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Nicklas-Pc\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Nicklas-Pc\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Exif Viewer - C:\Users\Nicklas-Pc\AppData\Roaming\Mozilla\Firefox\Profiles\jv4m07bm.default\Extensions\exif_viewer@mozilla.doslash.org.xpi [2013-05-18]
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-24]
CHR Extension: (Google Drive) - C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-30]
CHR Extension: (YouTube) - C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-24]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-06-24]
CHR Extension: (Google-Suche) - C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-24]
CHR Extension: (Google Wallet) - C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2014-07-10]
CHR Extension: (Google Mail) - C:\Users\Nicklas-Pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-24]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [70952 2011-04-14] (CyberLink)
R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [312616 2011-04-14] (CyberLink)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 iPod Service; "C:\Program Files\iPod\bin\iPodService.exe" [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 Bulk; C:\Windows\System32\Drivers\HDJBulk.sys [154112 2009-10-02] (© Guillemot R&D, 2009. All rights reserved.) [File not signed]
S3 HDJMidi; C:\Windows\System32\DRIVERS\HDJMidi.sys [144896 2009-10-02] (© Guillemot R&D, 2009. All rights reserved.) [File not signed]
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
S3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [60288 2010-09-15] (Generic USB smartcard reader)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-18 14:14 - 2014-07-18 14:14 - 00018463 _____ () C:\Users\Nicklas-Pc\Desktop\FRST.txt
2014-07-18 14:14 - 2014-07-18 14:14 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\FRST-OlderVersion
2014-07-18 14:07 - 2014-07-18 13:48 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-18 13:50 - 2014-07-18 14:09 - 00025142 _____ () C:\zoek-results.log
2014-07-18 13:48 - 2014-07-18 14:04 - 00000000 ____D () C:\zoek_backup
2014-07-18 13:41 - 2014-07-18 13:41 - 00004489 _____ () C:\Users\Nicklas-Pc\Desktop\mbam.txt
2014-07-18 13:24 - 2014-07-18 14:09 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-18 13:24 - 2014-07-18 13:24 - 00001098 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-18 13:24 - 2014-07-18 13:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-18 13:24 - 2014-07-18 13:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-18 13:24 - 2014-07-18 13:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-18 13:24 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-18 13:24 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-18 13:24 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-18 13:16 - 2014-07-18 13:16 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nicklas-Pc\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-18 13:16 - 2014-07-18 13:16 - 01287168 _____ () C:\Users\Nicklas-Pc\Downloads\zoek.exe
2014-07-18 13:16 - 2014-07-18 13:16 - 01287168 _____ () C:\Users\Nicklas-Pc\Desktop\zoek.exe
2014-07-18 13:15 - 2014-07-18 13:16 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nicklas-Pc\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-18 13:15 - 2014-07-18 13:15 - 01354223 _____ () C:\Users\Nicklas-Pc\Downloads\adwcleaner_3.216.exe
2014-07-18 13:15 - 2014-07-18 13:15 - 01354223 _____ () C:\Users\Nicklas-Pc\Desktop\adwcleaner_3.216.exe
2014-07-17 15:53 - 2014-07-17 15:53 - 02086912 _____ (Farbar) C:\Users\Nicklas-Pc\Downloads\FRST64 (1).exe
2014-07-16 18:02 - 2014-07-18 14:08 - 00006202 _____ () C:\Windows\PFRO.log
2014-07-16 18:00 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-16 17:59 - 2014-07-18 13:18 - 00000000 ____D () C:\AdwCleaner
2014-07-16 17:59 - 2014-07-16 17:59 - 01348263 _____ () C:\Users\Nicklas-Pc\Downloads\adwcleaner_3.215 (1).exe
2014-07-16 16:44 - 2014-07-18 14:08 - 00000728 _____ () C:\Windows\setupact.log
2014-07-16 16:44 - 2014-07-16 16:44 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-15 17:29 - 2014-07-15 17:29 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-07-15 17:29 - 2014-07-15 17:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-07-15 17:28 - 2014-07-15 17:34 - 00000000 ____D () C:\Users\Nicklas-Pc\Documents\GTA San Andreas User Files
2014-07-15 17:27 - 2014-07-15 17:29 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\FSX
2014-07-15 17:27 - 2014-07-15 16:59 - 11990847 _____ () C:\Users\Nicklas-Pc\Desktop\sa-mp-0.3z-R1-install.exe
2014-07-15 17:26 - 2014-07-15 17:26 - 701897648 _____ () C:\Users\Nicklas-Pc\Desktop\FSX.rar
2014-07-15 17:26 - 2014-07-15 16:59 - 00383517 _____ () C:\Users\Nicklas-Pc\Desktop\Deutsche Sprache GTA SA.zip
2014-07-15 16:59 - 2014-07-15 16:59 - 00383517 _____ () C:\Users\Nicklas-Pc\Downloads\Deutsche Sprache GTA SA.zip
2014-07-15 16:58 - 2014-07-15 17:26 - 701897648 _____ () C:\Users\Nicklas-Pc\Downloads\FSX.rar
2014-07-15 16:58 - 2014-07-15 16:59 - 11990847 _____ () C:\Users\Nicklas-Pc\Downloads\sa-mp-0.3z-R1-install.exe
2014-07-13 18:42 - 2014-07-13 18:42 - 00029035 _____ () C:\Users\Nicklas-Pc\Downloads\5cddde_4e9f570747c17.zip
2014-07-13 17:43 - 2014-07-13 17:54 - 00000000 ____D () C:\Users\Nicklas-Pc\Documents\HdR Die Rückkehr des Königs tm-Daten
2014-07-13 17:43 - 2014-07-13 17:43 - 00002196 _____ () C:\Users\Public\Desktop\HdR Die Rückkehr des Königs tm.lnk
2014-07-13 17:26 - 2014-07-13 17:26 - 00000277 _____ () C:\debugInstaller.txt
2014-07-13 15:41 - 2014-07-13 15:41 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\CrashdayTrainer1
2014-07-13 15:40 - 2004-09-11 19:24 - 00000444 _____ () C:\Users\Nicklas-Pc\Desktop\RL2k6.nfo
2014-07-13 15:37 - 2014-07-13 15:37 - 00136162 _____ () C:\Users\Nicklas-Pc\Downloads\crashtrainer.zip
2014-07-13 15:36 - 2014-07-13 15:36 - 00068515 _____ () C:\Users\Nicklas-Pc\Downloads\bnscd01.zip
2014-07-13 14:48 - 2014-07-13 14:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
2014-07-13 14:46 - 2014-07-13 14:46 - 00000000 ____D () C:\Program Files (x86)\Atari
2014-07-11 22:58 - 2014-07-11 23:01 - 08486489 _____ () C:\Users\Nicklas-Pc\Downloads\Maps.rar
2014-07-11 14:09 - 2014-07-11 14:10 - 00056321 _____ () C:\Users\Nicklas-Pc\Downloads\Addition.txt
2014-07-11 14:08 - 2014-07-11 14:08 - 00380416 _____ () C:\Users\Nicklas-Pc\Downloads\Gmer-19357.exe
2014-07-11 14:07 - 2014-07-18 14:14 - 02086912 _____ (Farbar) C:\Users\Nicklas-Pc\Desktop\FRST64.exe
2014-07-11 14:07 - 2014-07-18 14:14 - 00000000 ____D () C:\FRST
2014-07-11 14:07 - 2014-07-17 15:55 - 00064323 _____ () C:\Users\Nicklas-Pc\Downloads\FRST.txt
2014-07-11 14:06 - 2014-07-11 14:06 - 00000482 _____ () C:\Users\Nicklas-Pc\Downloads\defogger_disable.log
2014-07-11 14:06 - 2014-07-11 14:06 - 00000000 _____ () C:\Users\Nicklas-Pc\defogger_reenable
2014-07-11 14:05 - 2014-07-11 14:05 - 00050477 _____ () C:\Users\Nicklas-Pc\Downloads\Defogger.exe
2014-07-11 14:00 - 2014-07-11 14:00 - 00000000 ____D () C:\Users\Nicklas-Pc\Documents\24im
2014-07-10 19:54 - 2014-07-10 19:54 - 00002295 _____ () C:\Users\Nicklas-Pc\Desktop\Chrome App Launcher.lnk
2014-07-10 19:54 - 2014-07-10 19:54 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-09 21:03 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 21:03 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 21:03 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 21:03 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 21:03 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 21:03 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 21:03 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 21:03 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 21:03 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 21:03 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 21:03 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 21:03 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 21:03 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 21:03 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 21:03 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 21:03 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 21:03 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 21:03 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 21:03 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 21:03 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 21:03 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 21:03 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 21:03 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 21:03 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 21:03 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 21:03 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 21:03 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 21:03 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 21:03 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 21:03 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 21:03 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 21:03 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 21:03 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 21:03 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 21:03 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 21:03 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 21:03 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 21:03 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 21:03 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 21:03 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 21:03 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 21:03 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 21:03 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 21:03 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 21:03 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 21:03 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 21:03 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 21:03 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 21:03 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 21:03 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 21:03 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 21:03 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 21:03 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 21:03 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 21:03 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 21:03 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 21:03 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 21:03 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 21:03 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 21:03 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 21:03 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 21:03 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 21:03 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 21:03 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 21:03 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 21:03 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 21:03 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 21:03 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 21:03 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 21:03 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 21:03 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 21:03 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 21:03 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 21:03 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 21:03 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 21:03 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 21:02 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 21:02 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 21:02 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-07 18:27 - 2014-07-07 18:27 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\tower wars (one team) by dgd from pestcontrol's tower wars v 15b
2014-07-07 18:26 - 2014-07-07 18:26 - 00034591 _____ () C:\Users\Nicklas-Pc\Downloads\tower wars (one team) by dgd from pestcontrol's tower wars v 15b.zip
2014-07-07 18:26 - 2014-07-07 18:26 - 00034591 _____ () C:\Users\Nicklas-Pc\Desktop\tower wars (one team) by dgd from pestcontrol's tower wars v 15b.zip
2014-07-07 17:13 - 2014-07-07 17:13 - 26687471 _____ () C:\Users\Nicklas-Pc\Downloads\lotrbfme2-65542-german.exe
2014-07-05 22:35 - 2014-07-16 17:15 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
2014-07-05 22:10 - 2014-07-05 22:10 - 00000000 ____D () C:\blabla
2014-07-03 15:52 - 2014-07-03 15:52 - 00114352 _____ (GameRanger Technologies) C:\Users\Nicklas-Pc\Downloads\GameRangerSetup.exe
2014-07-03 15:52 - 2014-07-03 15:52 - 00001080 _____ () C:\Users\Nicklas-Pc\Desktop\GameRanger.lnk
2014-07-03 15:52 - 2014-07-03 15:52 - 00001066 _____ () C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2014-07-03 15:52 - 2014-07-03 15:52 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\GameRanger
2014-07-02 19:21 - 2014-07-02 19:21 - 00025928 _____ () C:\Users\Nicklas-Pc\Desktop\Ohne Titel.veg
2014-07-01 16:41 - 2014-07-02 18:35 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\youtube neu
2014-07-01 13:48 - 2014-07-01 13:48 - 00003146 _____ () C:\Windows\System32\Tasks\{2B815112-0996-4F93-A541-5636453BE02B}
2014-07-01 13:45 - 2014-07-01 13:45 - 00041673 _____ () C:\Users\Nicklas-Pc\Downloads\The Battle for Middle-Earth II - Witch King Trainer.zip
2014-07-01 13:42 - 2014-07-01 13:43 - 22169322 _____ () C:\Users\Nicklas-Pc\Downloads\grouch.zip
2014-07-01 13:17 - 2014-07-03 16:01 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien
2014-07-01 13:16 - 2014-07-01 13:16 - 00250281 _____ () C:\Users\Nicklas-Pc\Downloads\gghz-lotrwk_trn_20071002.zip
2014-07-01 13:16 - 2014-07-01 13:16 - 00010915 _____ () C:\Users\Nicklas-Pc\Downloads\hdr_sum2_dadhk_trn2.zip
2014-07-01 13:16 - 2014-07-01 13:16 - 00002257 _____ () C:\Users\Public\Desktop\Aufstieg des Hexenkönigs™.lnk
2014-06-30 14:24 - 2014-06-30 14:24 - 00500936 _____ () C:\Users\Nicklas-Pc\Downloads\finalbig040b.zip
2014-06-30 14:24 - 2005-02-20 19:13 - 00046884 _____ () C:\Users\Nicklas-Pc\Desktop\finalbig.ini
2014-06-30 14:13 - 2014-06-30 14:13 - 00324209 _____ () C:\Users\Nicklas-Pc\Downloads\DerHerrderRingeDieSchlachtumMittelerde2_Trainer.zip
2014-06-30 13:44 - 2014-06-30 13:44 - 09052432 _____ (Cheat Engine ) C:\Users\Nicklas-Pc\Downloads\CheatEngine64.exe
2014-06-28 19:42 - 2014-06-28 19:42 - 00042455 _____ () C:\Users\Nicklas-Pc\Downloads\lotr2cetrn.zip
2014-06-28 19:38 - 2014-06-28 19:38 - 00154717 _____ () C:\Users\Nicklas-Pc\Downloads\lord_of_the_rings_battle_for_middle_earth_2_v1_0_plus_1_trainer.zip
2014-06-28 19:33 - 2014-06-28 19:33 - 00008272 _____ () C:\Users\Nicklas-Pc\Downloads\FtlEs BFME2 Plus 3 Trn.zip
2014-06-28 19:33 - 2014-06-28 19:33 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\FtlEs BFME2 Plus 3 Trn
2014-06-28 19:29 - 2014-06-28 19:29 - 00004698 _____ () C:\Users\Nicklas-Pc\Downloads\der_herr_der_ringe_die_schlacht_um_mittelerde2 (1).zip
2014-06-28 15:39 - 2014-07-05 22:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2014-06-28 15:33 - 2014-07-05 21:50 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-28 15:21 - 2014-07-16 17:29 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Meine Die Schlacht um Mittelerde-Dateien
2014-06-28 15:21 - 2014-06-28 15:21 - 00002228 _____ () C:\Users\Public\Desktop\Die Schlacht um Mittelerde(tm).lnk
2014-06-27 22:28 - 2014-06-27 23:31 - 70332733 _____ () C:\Users\Nicklas-Pc\Downloads\DJFlyBeat MashUp&Tool Pack @10.000 Likes.rar
2014-06-27 12:29 - 2014-06-27 12:29 - 01360651 _____ () C:\Users\Nicklas-Pc\Downloads\team.rar
2014-06-26 16:58 - 2014-06-26 16:58 - 00264246 _____ () C:\Users\Nicklas-Pc\Desktop\untitled.flp
2014-06-24 16:21 - 2014-06-24 16:21 - 00005696 _____ () C:\Users\Nicklas-Pc\Desktop\10465938_678604708876966_1747226055_n.mp4.sfk
2014-06-24 16:19 - 2014-06-24 16:19 - 00377263 _____ () C:\Users\Nicklas-Pc\Desktop\10465938_678604708876966_1747226055_n.mp4
2014-06-24 15:20 - 2014-06-24 15:20 - 00003168 _____ () C:\Windows\System32\Tasks\{7652924A-FAB2-4A98-82EA-449B49FAFB3E}
2014-06-24 14:55 - 2014-07-18 13:41 - 00000000 ____D () C:\temp
2014-06-24 14:55 - 2014-06-24 14:55 - 52385872 _____ (Microsoft Corporation) C:\Users\Nicklas-Pc\Downloads\Plex-Media-Server-v0.9.502-en-US [1].exe
2014-06-23 12:10 - 2014-06-23 12:10 - 12397610 _____ () C:\Users\Nicklas-Pc\Downloads\FelixCartal-ReadyForLove.zip
2014-06-21 19:48 - 2014-06-21 19:48 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Sony Creative Software Inc
2014-06-21 18:32 - 2014-06-21 19:45 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\You
2014-06-21 13:14 - 2014-06-21 13:14 - 00003860 _____ () C:\Users\Nicklas-Pc\Downloads\Updated_No_ReadyTime_GRO_mpgh.net.zip
2014-06-21 13:13 - 2014-06-21 13:13 - 00114694 _____ () C:\Users\Nicklas-Pc\Downloads\RemoteDLLInjector.zip
2014-06-19 14:14 - 2014-06-19 14:14 - 00002074 _____ () C:\Users\Public\Desktop\XIII.lnk
2014-06-19 14:14 - 2014-06-19 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2014-06-18 18:48 - 2014-06-18 19:29 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\XIII
2014-06-18 18:36 - 2014-06-18 19:13 - 380891440 _____ () C:\Users\Nicklas-Pc\Downloads\XII_dloadgame.com.part4.rar
2014-06-18 18:36 - 2014-06-18 18:46 - 524288000 _____ () C:\Users\Nicklas-Pc\Downloads\XII_dloadgame.com.part3.rar
2014-06-18 18:36 - 2014-06-18 18:46 - 524288000 _____ () C:\Users\Nicklas-Pc\Downloads\XII_dloadgame.com.part2.rar
2014-06-18 18:35 - 2014-06-18 19:06 - 524288000 _____ () C:\Users\Nicklas-Pc\Downloads\XII_dloadgame.com.part1.rar
==================== One Month Modified Files and Folders =======
2014-07-18 14:14 - 2014-07-18 14:14 - 00018463 _____ () C:\Users\Nicklas-Pc\Desktop\FRST.txt
2014-07-18 14:14 - 2014-07-18 14:14 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\FRST-OlderVersion
2014-07-18 14:14 - 2014-07-11 14:07 - 02086912 _____ (Farbar) C:\Users\Nicklas-Pc\Desktop\FRST64.exe
2014-07-18 14:14 - 2014-07-11 14:07 - 00000000 ____D () C:\FRST
2014-07-18 14:11 - 2012-10-04 21:05 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-18 14:11 - 2012-10-04 18:49 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Skype
2014-07-18 14:10 - 2014-05-03 14:24 - 00000000 ___RD () C:\Users\Nicklas-Pc\Dropbox
2014-07-18 14:10 - 2014-05-03 14:23 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\DropboxMaster
2014-07-18 14:10 - 2014-05-03 14:22 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Dropbox
2014-07-18 14:09 - 2014-07-18 13:50 - 00025142 _____ () C:\zoek-results.log
2014-07-18 14:09 - 2014-07-18 13:24 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-18 14:09 - 2012-10-04 15:28 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-18 14:08 - 2014-07-16 18:02 - 00006202 _____ () C:\Windows\PFRO.log
2014-07-18 14:08 - 2014-07-16 16:44 - 00000728 _____ () C:\Windows\setupact.log
2014-07-18 14:08 - 2012-10-05 21:12 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
2014-07-18 14:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-18 14:07 - 2012-10-04 15:26 - 01185543 _____ () C:\Windows\WindowsUpdate.log
2014-07-18 14:06 - 2008-01-01 09:31 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-18 14:04 - 2014-07-18 13:48 - 00000000 ____D () C:\zoek_backup
2014-07-18 14:03 - 2012-10-04 15:29 - 00000000 ____D () C:\Users\Nicklas-Pc
2014-07-18 13:57 - 2012-10-04 15:28 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-18 13:52 - 2009-07-14 06:45 - 00016944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-18 13:52 - 2009-07-14 06:45 - 00016944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-18 13:48 - 2014-07-18 14:07 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-18 13:43 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-18 13:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PLA
2014-07-18 13:41 - 2014-07-18 13:41 - 00004489 _____ () C:\Users\Nicklas-Pc\Desktop\mbam.txt
2014-07-18 13:41 - 2014-06-24 14:55 - 00000000 ____D () C:\temp
2014-07-18 13:24 - 2014-07-18 13:24 - 00001098 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-18 13:24 - 2014-07-18 13:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-18 13:24 - 2014-07-18 13:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-18 13:24 - 2014-07-18 13:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-18 13:18 - 2014-07-16 17:59 - 00000000 ____D () C:\AdwCleaner
2014-07-18 13:16 - 2014-07-18 13:16 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nicklas-Pc\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-18 13:16 - 2014-07-18 13:16 - 01287168 _____ () C:\Users\Nicklas-Pc\Downloads\zoek.exe
2014-07-18 13:16 - 2014-07-18 13:16 - 01287168 _____ () C:\Users\Nicklas-Pc\Desktop\zoek.exe
2014-07-18 13:16 - 2014-07-18 13:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nicklas-Pc\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-18 13:15 - 2014-07-18 13:15 - 01354223 _____ () C:\Users\Nicklas-Pc\Downloads\adwcleaner_3.216.exe
2014-07-18 13:15 - 2014-07-18 13:15 - 01354223 _____ () C:\Users\Nicklas-Pc\Desktop\adwcleaner_3.216.exe
2014-07-18 13:15 - 2014-04-22 20:09 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Alles über Musik
2014-07-18 13:15 - 2013-05-24 15:17 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\FL Studio
2014-07-17 18:13 - 2013-06-29 15:08 - 00000948 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-958759603-357473-4181541277-1002UA.job
2014-07-17 15:55 - 2014-07-11 14:07 - 00064323 _____ () C:\Users\Nicklas-Pc\Downloads\FRST.txt
2014-07-17 15:53 - 2014-07-17 15:53 - 02086912 _____ (Farbar) C:\Users\Nicklas-Pc\Downloads\FRST64 (1).exe
2014-07-17 15:13 - 2013-06-29 15:08 - 00000926 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-958759603-357473-4181541277-1002Core.job
2014-07-17 14:56 - 2014-04-22 20:09 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Youtube Video
2014-07-17 14:56 - 2013-02-27 19:28 - 02368000 ___SH () C:\Users\Nicklas-Pc\Desktop\Thumbs.db
2014-07-16 17:59 - 2014-07-16 17:59 - 01348263 _____ () C:\Users\Nicklas-Pc\Downloads\adwcleaner_3.215 (1).exe
2014-07-16 17:29 - 2014-06-28 15:21 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Meine Die Schlacht um Mittelerde-Dateien
2014-07-16 17:15 - 2014-07-05 22:35 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
2014-07-16 17:15 - 2012-10-07 15:34 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Local\CrashDumps
2014-07-16 16:48 - 2012-10-08 18:23 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\TS3Client
2014-07-16 16:44 - 2014-07-16 16:44 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-16 16:34 - 2014-06-02 15:14 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Remixe
2014-07-16 16:17 - 2013-07-01 17:23 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Winamp
2014-07-16 16:15 - 2011-07-18 22:54 - 00000000 ____D () C:\Windows\Panther
2014-07-16 14:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-15 17:34 - 2014-07-15 17:28 - 00000000 ____D () C:\Users\Nicklas-Pc\Documents\GTA San Andreas User Files
2014-07-15 17:29 - 2014-07-15 17:29 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-07-15 17:29 - 2014-07-15 17:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-07-15 17:29 - 2014-07-15 17:27 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\FSX
2014-07-15 17:28 - 2013-01-20 08:35 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-15 17:26 - 2014-07-15 17:26 - 701897648 _____ () C:\Users\Nicklas-Pc\Desktop\FSX.rar
2014-07-15 17:26 - 2014-07-15 16:58 - 701897648 _____ () C:\Users\Nicklas-Pc\Downloads\FSX.rar
2014-07-15 16:59 - 2014-07-15 17:27 - 11990847 _____ () C:\Users\Nicklas-Pc\Desktop\sa-mp-0.3z-R1-install.exe
2014-07-15 16:59 - 2014-07-15 17:26 - 00383517 _____ () C:\Users\Nicklas-Pc\Desktop\Deutsche Sprache GTA SA.zip
2014-07-15 16:59 - 2014-07-15 16:59 - 00383517 _____ () C:\Users\Nicklas-Pc\Downloads\Deutsche Sprache GTA SA.zip
2014-07-15 16:59 - 2014-07-15 16:58 - 11990847 _____ () C:\Users\Nicklas-Pc\Downloads\sa-mp-0.3z-R1-install.exe
2014-07-13 19:23 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-07-13 19:23 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-13 19:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-07-13 18:42 - 2014-07-13 18:42 - 00029035 _____ () C:\Users\Nicklas-Pc\Downloads\5cddde_4e9f570747c17.zip
2014-07-13 17:54 - 2014-07-13 17:43 - 00000000 ____D () C:\Users\Nicklas-Pc\Documents\HdR Die Rückkehr des Königs tm-Daten
2014-07-13 17:43 - 2014-07-13 17:43 - 00002196 _____ () C:\Users\Public\Desktop\HdR Die Rückkehr des Königs tm.lnk
2014-07-13 17:43 - 2013-03-30 12:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2014-07-13 17:26 - 2014-07-13 17:26 - 00000277 _____ () C:\debugInstaller.txt
2014-07-13 17:26 - 2013-03-30 12:40 - 00000000 ____D () C:\Program Files (x86)\EA GAMES
2014-07-13 15:41 - 2014-07-13 15:41 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\CrashdayTrainer1
2014-07-13 15:37 - 2014-07-13 15:37 - 00136162 _____ () C:\Users\Nicklas-Pc\Downloads\crashtrainer.zip
2014-07-13 15:36 - 2014-07-13 15:36 - 00068515 _____ () C:\Users\Nicklas-Pc\Downloads\bnscd01.zip
2014-07-13 14:48 - 2014-07-13 14:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
2014-07-13 14:46 - 2014-07-13 14:46 - 00000000 ____D () C:\Program Files (x86)\Atari
2014-07-13 14:46 - 2011-07-18 23:23 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-12 23:34 - 2013-10-10 21:56 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Audacity
2014-07-12 23:17 - 2014-05-27 16:40 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\.purple
2014-07-12 18:57 - 2011-05-16 16:04 - 01630120 _____ () C:\Windows\system32\perfh007.dat
2014-07-12 18:57 - 2011-05-16 16:04 - 00438724 _____ () C:\Windows\system32\perfc007.dat
2014-07-12 18:57 - 2009-07-14 07:13 - 00006264 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-12 17:41 - 2013-11-06 17:41 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\edcast
2014-07-12 12:16 - 2014-04-05 15:44 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Spiele
2014-07-12 12:15 - 2013-05-12 16:47 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\ClubCooee
2014-07-12 12:15 - 2013-05-12 16:47 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Local\ClubCooee
2014-07-11 23:01 - 2014-07-11 22:58 - 08486489 _____ () C:\Users\Nicklas-Pc\Downloads\Maps.rar
2014-07-11 14:10 - 2014-07-11 14:09 - 00056321 _____ () C:\Users\Nicklas-Pc\Downloads\Addition.txt
2014-07-11 14:08 - 2014-07-11 14:08 - 00380416 _____ () C:\Users\Nicklas-Pc\Downloads\Gmer-19357.exe
2014-07-11 14:06 - 2014-07-11 14:06 - 00000482 _____ () C:\Users\Nicklas-Pc\Downloads\defogger_disable.log
2014-07-11 14:06 - 2014-07-11 14:06 - 00000000 _____ () C:\Users\Nicklas-Pc\defogger_reenable
2014-07-11 14:05 - 2014-07-11 14:05 - 00050477 _____ () C:\Users\Nicklas-Pc\Downloads\Defogger.exe
2014-07-11 14:00 - 2014-07-11 14:00 - 00000000 ____D () C:\Users\Nicklas-Pc\Documents\24im
2014-07-10 19:54 - 2014-07-10 19:54 - 00002295 _____ () C:\Users\Nicklas-Pc\Desktop\Chrome App Launcher.lnk
2014-07-10 19:54 - 2014-07-10 19:54 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-10 14:18 - 2013-05-06 14:10 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-07-10 14:12 - 2009-07-14 06:45 - 00437248 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 14:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-10 14:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-09 23:00 - 2013-07-25 20:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 22:58 - 2012-11-08 09:55 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-09 22:58 - 2011-07-18 22:31 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 17:06 - 2011-12-01 23:26 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 17:06 - 2008-01-01 09:31 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 17:06 - 2008-01-01 09:31 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-07 18:27 - 2014-07-07 18:27 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\tower wars (one team) by dgd from pestcontrol's tower wars v 15b
2014-07-07 18:26 - 2014-07-07 18:26 - 00034591 _____ () C:\Users\Nicklas-Pc\Downloads\tower wars (one team) by dgd from pestcontrol's tower wars v 15b.zip
2014-07-07 18:26 - 2014-07-07 18:26 - 00034591 _____ () C:\Users\Nicklas-Pc\Desktop\tower wars (one team) by dgd from pestcontrol's tower wars v 15b.zip
2014-07-07 17:13 - 2014-07-07 17:13 - 26687471 _____ () C:\Users\Nicklas-Pc\Downloads\lotrbfme2-65542-german.exe
2014-07-05 22:24 - 2014-06-28 15:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2014-07-05 22:10 - 2014-07-05 22:10 - 00000000 ____D () C:\blabla
2014-07-05 21:50 - 2014-06-28 15:33 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-07-03 16:01 - 2014-07-01 13:17 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien
2014-07-03 15:52 - 2014-07-03 15:52 - 00114352 _____ (GameRanger Technologies) C:\Users\Nicklas-Pc\Downloads\GameRangerSetup.exe
2014-07-03 15:52 - 2014-07-03 15:52 - 00001080 _____ () C:\Users\Nicklas-Pc\Desktop\GameRanger.lnk
2014-07-03 15:52 - 2014-07-03 15:52 - 00001066 _____ () C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2014-07-03 15:52 - 2014-07-03 15:52 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\GameRanger
2014-07-02 19:21 - 2014-07-02 19:21 - 00025928 _____ () C:\Users\Nicklas-Pc\Desktop\Ohne Titel.veg
2014-07-02 18:35 - 2014-07-01 16:41 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\youtube neu
2014-07-01 13:48 - 2014-07-01 13:48 - 00003146 _____ () C:\Windows\System32\Tasks\{2B815112-0996-4F93-A541-5636453BE02B}
2014-07-01 13:45 - 2014-07-01 13:45 - 00041673 _____ () C:\Users\Nicklas-Pc\Downloads\The Battle for Middle-Earth II - Witch King Trainer.zip
2014-07-01 13:45 - 2013-11-02 12:48 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Musik
2014-07-01 13:43 - 2014-07-01 13:42 - 22169322 _____ () C:\Users\Nicklas-Pc\Downloads\grouch.zip
2014-07-01 13:16 - 2014-07-01 13:16 - 00250281 _____ () C:\Users\Nicklas-Pc\Downloads\gghz-lotrwk_trn_20071002.zip
2014-07-01 13:16 - 2014-07-01 13:16 - 00010915 _____ () C:\Users\Nicklas-Pc\Downloads\hdr_sum2_dadhk_trn2.zip
2014-07-01 13:16 - 2014-07-01 13:16 - 00002257 _____ () C:\Users\Public\Desktop\Aufstieg des Hexenkönigs™.lnk
2014-06-30 14:24 - 2014-06-30 14:24 - 00500936 _____ () C:\Users\Nicklas-Pc\Downloads\finalbig040b.zip
2014-06-30 14:13 - 2014-06-30 14:13 - 00324209 _____ () C:\Users\Nicklas-Pc\Downloads\DerHerrderRingeDieSchlachtumMittelerde2_Trainer.zip
2014-06-30 13:44 - 2014-06-30 13:44 - 09052432 _____ (Cheat Engine ) C:\Users\Nicklas-Pc\Downloads\CheatEngine64.exe
2014-06-28 19:42 - 2014-06-28 19:42 - 00042455 _____ () C:\Users\Nicklas-Pc\Downloads\lotr2cetrn.zip
2014-06-28 19:38 - 2014-06-28 19:38 - 00154717 _____ () C:\Users\Nicklas-Pc\Downloads\lord_of_the_rings_battle_for_middle_earth_2_v1_0_plus_1_trainer.zip
2014-06-28 19:38 - 2013-05-24 15:15 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Lustige sachen
2014-06-28 19:33 - 2014-06-28 19:33 - 00008272 _____ () C:\Users\Nicklas-Pc\Downloads\FtlEs BFME2 Plus 3 Trn.zip
2014-06-28 19:33 - 2014-06-28 19:33 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\FtlEs BFME2 Plus 3 Trn
2014-06-28 19:29 - 2014-06-28 19:29 - 00004698 _____ () C:\Users\Nicklas-Pc\Downloads\der_herr_der_ringe_die_schlacht_um_mittelerde2 (1).zip
2014-06-28 15:21 - 2014-06-28 15:21 - 00002228 _____ () C:\Users\Public\Desktop\Die Schlacht um Mittelerde(tm).lnk
2014-06-27 23:31 - 2014-06-27 22:28 - 70332733 _____ () C:\Users\Nicklas-Pc\Downloads\DJFlyBeat MashUp&Tool Pack @10.000 Likes.rar
2014-06-27 19:09 - 2013-05-22 14:05 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Bilder
2014-06-27 13:42 - 2014-05-31 17:53 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Neue Lieder
2014-06-27 12:29 - 2014-06-27 12:29 - 01360651 _____ () C:\Users\Nicklas-Pc\Downloads\team.rar
2014-06-26 16:58 - 2014-06-26 16:58 - 00264246 _____ () C:\Users\Nicklas-Pc\Desktop\untitled.flp
2014-06-24 16:21 - 2014-06-24 16:21 - 00005696 _____ () C:\Users\Nicklas-Pc\Desktop\10465938_678604708876966_1747226055_n.mp4.sfk
2014-06-24 16:19 - 2014-06-24 16:19 - 00377263 _____ () C:\Users\Nicklas-Pc\Desktop\10465938_678604708876966_1747226055_n.mp4
2014-06-24 15:26 - 2012-10-21 04:46 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-06-24 15:25 - 2013-10-11 11:24 - 00000000 ____D () C:\Program Files (x86)\butt
2014-06-24 15:25 - 2012-11-20 18:50 - 00000000 ____D () C:\Fraps
2014-06-24 15:22 - 2014-05-11 14:53 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2014-06-24 15:20 - 2014-06-24 15:20 - 00003168 _____ () C:\Windows\System32\Tasks\{7652924A-FAB2-4A98-82EA-449B49FAFB3E}
2014-06-24 15:19 - 2013-09-20 20:14 - 00000000 ____D () C:\Program Files (x86)\theHunter
2014-06-24 14:55 - 2014-06-24 14:55 - 52385872 _____ (Microsoft Corporation) C:\Users\Nicklas-Pc\Downloads\Plex-Media-Server-v0.9.502-en-US [1].exe
2014-06-24 13:10 - 2013-04-03 15:17 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-23 12:10 - 2014-06-23 12:10 - 12397610 _____ () C:\Users\Nicklas-Pc\Downloads\FelixCartal-ReadyForLove.zip
2014-06-21 19:48 - 2014-06-21 19:48 - 00000000 ____D () C:\Users\Nicklas-Pc\AppData\Roaming\Sony Creative Software Inc
2014-06-21 19:45 - 2014-06-21 18:32 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\You
2014-06-21 13:29 - 2014-05-30 13:39 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\Hands Up (Show)
2014-06-21 13:14 - 2014-06-21 13:14 - 00003860 _____ () C:\Users\Nicklas-Pc\Downloads\Updated_No_ReadyTime_GRO_mpgh.net.zip
2014-06-21 13:13 - 2014-06-21 13:13 - 00114694 _____ () C:\Users\Nicklas-Pc\Downloads\RemoteDLLInjector.zip
2014-06-20 22:14 - 2014-07-09 21:03 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-20 21:39 - 2014-07-09 21:03 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-06-19 14:14 - 2014-06-19 14:14 - 00002074 _____ () C:\Users\Public\Desktop\XIII.lnk
2014-06-19 14:14 - 2014-06-19 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2014-06-19 03:39 - 2014-07-09 21:03 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-19 03:06 - 2014-07-09 21:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-19 03:06 - 2014-07-09 21:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-19 02:48 - 2014-07-09 21:03 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-19 02:42 - 2014-07-09 21:03 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-19 02:42 - 2014-07-09 21:03 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-19 02:41 - 2014-07-09 21:03 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-19 02:41 - 2014-07-09 21:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-19 02:32 - 2014-07-09 21:03 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-19 02:31 - 2014-07-09 21:03 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-19 02:26 - 2014-07-09 21:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-19 02:24 - 2014-07-09 21:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-19 02:24 - 2014-07-09 21:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-19 02:23 - 2014-07-09 21:03 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-19 02:16 - 2014-07-09 21:03 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-19 02:14 - 2014-07-09 21:03 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-19 02:09 - 2014-07-09 21:03 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-19 01:59 - 2014-07-09 21:03 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-19 01:56 - 2014-07-09 21:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-19 01:53 - 2014-07-09 21:03 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-19 01:51 - 2014-07-09 21:03 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-19 01:50 - 2014-07-09 21:03 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-19 01:48 - 2014-07-09 21:03 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-19 01:39 - 2014-07-09 21:03 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-19 01:38 - 2014-07-09 21:03 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-19 01:37 - 2014-07-09 21:03 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-19 01:36 - 2014-07-09 21:03 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-19 01:35 - 2014-07-09 21:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-06-19 01:33 - 2014-07-09 21:03 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-19 01:32 - 2014-07-09 21:03 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-19 01:28 - 2014-07-09 21:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-19 01:28 - 2014-07-09 21:03 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-19 01:27 - 2014-07-09 21:03 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-19 01:27 - 2014-07-09 21:03 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-19 01:25 - 2014-07-09 21:03 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-19 01:23 - 2014-07-09 21:03 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-19 01:22 - 2014-07-09 21:03 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-19 01:12 - 2014-07-09 21:03 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-19 01:06 - 2014-07-09 21:03 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-19 01:01 - 2014-07-09 21:03 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-19 00:59 - 2014-07-09 21:03 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-19 00:58 - 2014-07-09 21:03 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-19 00:58 - 2014-07-09 21:03 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-19 00:52 - 2014-07-09 21:03 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-19 00:51 - 2014-07-09 21:03 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-19 00:49 - 2014-07-09 21:03 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-19 00:46 - 2014-07-09 21:03 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-19 00:45 - 2014-07-09 21:03 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-19 00:35 - 2014-07-09 21:03 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-19 00:34 - 2014-07-09 21:03 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-19 00:15 - 2014-07-09 21:03 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-19 00:13 - 2014-07-09 21:03 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-19 00:09 - 2014-07-09 21:03 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-19 00:07 - 2014-07-09 21:03 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-18 19:29 - 2014-06-18 18:48 - 00000000 ____D () C:\Users\Nicklas-Pc\Desktop\XIII
2014-06-18 19:13 - 2014-06-18 18:36 - 380891440 _____ () C:\Users\Nicklas-Pc\Downloads\XII_dloadgame.com.part4.rar
2014-06-18 19:06 - 2014-06-18 18:35 - 524288000 _____ () C:\Users\Nicklas-Pc\Downloads\XII_dloadgame.com.part1.rar
2014-06-18 18:46 - 2014-06-18 18:36 - 524288000 _____ () C:\Users\Nicklas-Pc\Downloads\XII_dloadgame.com.part3.rar
2014-06-18 18:46 - 2014-06-18 18:36 - 524288000 _____ () C:\Users\Nicklas-Pc\Downloads\XII_dloadgame.com.part2.rar
2014-06-18 04:18 - 2014-07-09 21:03 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-06-18 03:51 - 2014-07-09 21:03 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-06-18 03:10 - 2014-07-09 21:03 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
Some content of TEMP:
====================
C:\Users\Nicklas-Pc\AppData\Local\Temp\avgnt.exe
C:\Users\Nicklas-Pc\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpehpgj_.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-08 17:15
==================== End Of Log ============================ --- --- ---
--- --- ---
Er hat keine Additions
.Txt durch geführt. Anscheind ist der Plagegeist aber weg :) <333 |