Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

SW-Booster, possibly more... Adware [Solved]

swbooster sw-booster adware

  • This topic is locked This topic is locked

#1
okiol

okiol

    Member

  • Member
  • PipPip
  • 46 posts

Hi, first of all I want to thank you a lot for the amazing support I recieved the last time I was here. I meant to say thank you, but couldn't bring my lazy [bleep] to do it. However, I was very thankful and I am sure that there are some people in my social circle who are tired of hearing about the online super hero site which solves all the problems you knew you had and a lot more you didn't know.

 

My problem:

 

WinPatrol detected new automatic startup, c:\something\ES-BOOSTER\ etc .dll, when declining it keeps asking within a minute or so.

 

Adware in web browser. SW-Booster was detected talking to google chrome before I removed it, so that's probably it. Adds that I haven't seen before and hotlinked words like "result" in texts.

 

After uninstalling SW-BOOSTER with revo uninstaller on the advanced settings, the problem was still there, so I went into the appdata folder to remove the SW-BOOSTER map that had somehow not been removed. The WinPatrol message now changed to this weird adress instead: C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL (the folder names might be in swedish)

 

There might have been more installations than just the SW-BOOSTER at the same time, I know that it tried many, but I think that I only installed this one.

 

What I have done so far:

 

Uninstalled SW-BOOSTER with revo uninstaller, removed the SW-BOOSTER map from the system files.

 

I ran AdwCleaner. Here is the report:

 

# AdwCleaner v3.023 - Report created 06/04/2014 at 11:06:50
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Home Premium  (64 bits)
# Username : Jens - JENS-DATOR
# Running from : C:\Users\Jens\Downloads\AdwCleaner (1).exe
# Option : Clean
 
***** [ Services ] *****
 
Service Deleted : HssSrv
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\hotspot shield
Folder Deleted : C:\ProgramData\YoutubeAdblocker
[/!\] Not Deleted ( Junction ) : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\Delta
Folder Deleted : C:\Program Files (x86)\hotspot shield
Folder Deleted : C:\Program Files (x86)\pc speed up
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Users\Jens\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Jens\AppData\Local\PackageAware
Folder Deleted : C:\Users\Jens\AppData\Local\torch
Folder Deleted : C:\Users\Jens\AppData\LocalLow\Delta
Folder Deleted : C:\Users\Jens\AppData\Roaming\Delta
Folder Deleted : C:\Users\Jens\AppData\Roaming\EZDownloader
Folder Deleted : C:\Users\Jens\AppData\Roaming\hotspot shield
Folder Deleted : C:\Users\postgres.Jens-Dator\AppData\Local\torch
Folder Deleted : C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\xgq5bm67.default\Extensions\[email protected]
Folder Deleted : C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\xgq5bm67.default\Extensions\staged
File Deleted : C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\xgq5bm67.default\searchplugins\Web Search.xml
File Deleted : C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
File Deleted : C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
File Deleted : C:\Windows\System32\Tasks\BrowserProtect
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\HssIE.HssIEApp
Key Deleted : HKLM\SOFTWARE\Classes\HssIE.HssIEApp.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_little-fighter-2_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_little-fighter-2_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E69D4A59-73DE-4E38-9FB3-740EC4D9060D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\fTalk
Key Deleted : HKCU\Software\hotspotshield
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\WEDLMNGR
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\Software\PIP
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\fTalk
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hotspotshield
Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v8.0.7600.16722
 
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
 
-\\ Mozilla Firefox v19.0.2 (sv-SE)
 
[ File : C:\Users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\xgq5bm67.default\prefs.js ]
 
Line Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://feed.snap.do/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=SE&userid=7690b97e-e48f-4053-8c05-91f0772bfa6c&searchtype=hp&installDate=06/04/2013");
Line Deleted : user_pref("extensions.helperbar.Country", "Sweden");
Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Deleted : user_pref("extensions.helperbar.SmartbarDisabled", false);
Line Deleted : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Line Deleted : user_pref("extensions.helperbar.UserID", "7690b97e-e48f-4053-8c05-91f0772bfa6c");
Line Deleted : user_pref("extensions.helperbar.Visibility", true);
Line Deleted : user_pref("keyword.URL", "hxxp://feed.snap.do/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=SE&userid=7690b97e-e48f-4053-8c05-91f0772bfa6c&searchtype=ds&installDate=06/04/2013&q=");
 
-\\ Google Chrome v33.0.1750.154
 
[ File : C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted : homepage
 
*************************
 
AdwCleaner[R0].txt - [14650 octets] - [06/04/2014 11:02:55]
AdwCleaner[S0].txt - [13044 octets] - [06/04/2014 11:06:50]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13105 octets] ##########
 
 
OTL-Scan: (Done after the AdwCleaner
 

OTL logfile created on: 2014-04-06 11:22:21 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Jens\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd
 
3,86 Gb Total Physical Memory | 1,18 Gb Available Physical Memory | 30,65% Memory free
7,73 Gb Paging File | 3,79 Gb Available in Paging File | 49,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 490,00 Gb Total Space | 55,22 Gb Free Space | 11,27% Space Free | Partition Type: NTFS
 
Computer Name: JENS-DATOR | User Name: Jens | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014-04-06 11:21:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jens\Downloads\OTL.exe
PRC - [2014-03-19 17:44:46 | 032,667,896 | ---- | M] (Dropbox, Inc.) -- C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2014-03-15 02:50:42 | 000,859,976 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014-03-07 13:39:00 | 000,444,760 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
PRC - [2014-03-03 10:53:02 | 001,363,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014-03-03 10:52:32 | 001,748,608 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2013-09-20 16:29:04 | 009,828,864 | ---- | M] (Apache Software Foundation) -- C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
PRC - [2013-09-20 16:29:04 | 000,103,936 | ---- | M] (Apache Software Foundation) -- C:\Program Files (x86)\OpenOffice 4\program\swriter.exe
PRC - [2013-09-20 16:29:02 | 009,837,056 | ---- | M] (Apache Software Foundation) -- C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
PRC - [2013-07-07 15:38:18 | 000,912,904 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\Viber.exe
PRC - [2013-03-12 07:32:58 | 000,506,744 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2013-03-07 01:32:44 | 004,767,304 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013-03-07 01:32:44 | 000,045,248 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013-03-05 21:41:44 | 000,418,024 | ---- | M] (BillP Studios) -- C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2010-03-02 19:52:00 | 000,140,640 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
PRC - [2010-02-25 06:59:21 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2009-12-10 03:39:04 | 000,065,536 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe
PRC - [2009-12-10 03:37:16 | 003,690,496 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
PRC - [2009-11-02 01:39:48 | 001,094,736 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009-10-01 06:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009-10-01 06:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009-09-25 01:42:32 | 000,261,888 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2009-09-25 01:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2009-09-11 07:42:46 | 000,305,448 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
PRC - [2009-09-11 07:42:30 | 000,349,480 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
PRC - [2009-08-28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009-07-14 03:14:47 | 000,254,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2009-07-04 04:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2009-06-05 05:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009-06-05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2009-02-23 17:57:12 | 000,058,648 | ---- | M] (Sierra Wireless Inc.) -- C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\WaHelper.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014-04-06 11:13:44 | 000,041,984 | ---- | M] () -- c:\users\jens\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpn2wgdc.dll
MOD - [2014-03-15 02:50:40 | 013,637,448 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll
MOD - [2014-03-15 02:50:40 | 000,394,568 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
MOD - [2014-03-15 02:50:38 | 004,061,000 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll
MOD - [2014-03-15 02:50:35 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libglesv2.dll
MOD - [2014-03-15 02:50:34 | 000,100,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libegl.dll
MOD - [2014-03-15 02:50:32 | 001,647,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll
MOD - [2014-03-15 02:50:30 | 000,051,016 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll
MOD - [2014-03-13 12:14:41 | 000,622,592 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\sqldrivers\qsqlite.dll
MOD - [2014-03-13 12:14:39 | 014,442,496 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\libViber.dll
MOD - [2014-03-13 12:14:39 | 000,835,584 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\platforms\qwindows.dll
MOD - [2014-03-13 12:14:39 | 000,729,088 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\libGLESv2.dll
MOD - [2014-03-13 12:14:39 | 000,278,528 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qtiff.dll
MOD - [2014-03-13 12:14:39 | 000,221,184 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qmng.dll
MOD - [2014-03-13 12:14:39 | 000,212,992 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qjpeg.dll
MOD - [2014-03-13 12:14:39 | 000,098,304 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\qfacebook.dll
MOD - [2014-03-13 12:14:39 | 000,049,152 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\libEGL.dll
MOD - [2014-03-13 12:14:39 | 000,024,576 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qico.dll
MOD - [2014-03-13 12:14:39 | 000,024,576 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qgif.dll
MOD - [2014-03-13 12:14:39 | 000,016,384 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qwbmp.dll
MOD - [2014-03-13 12:14:39 | 000,016,384 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qtga.dll
MOD - [2014-03-13 12:14:39 | 000,016,384 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qsvg.dll
MOD - [2014-03-13 12:14:38 | 000,032,768 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\iconengines\qsvgicon.dll
MOD - [2014-01-03 03:09:26 | 003,610,624 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013-09-20 14:50:06 | 000,988,160 | ---- | M] () -- C:\Program Files (x86)\OpenOffice 4\program\libxml2.dll
MOD - [2013-09-17 05:54:38 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\OpenOffice 4\program\libxslt.dll
MOD - [2013-08-23 21:01:44 | 025,100,288 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2013-07-07 15:38:18 | 000,912,904 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\Viber.exe
MOD - [2013-03-31 18:40:20 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ac9e3eca6c148504588e7c6d09fe83e3\System.Management.ni.dll
MOD - [2013-03-31 18:38:15 | 001,021,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\e7b4706dfe18f29486dbaf5d35e01765\System.Runtime.DurableInstancing.ni.dll
MOD - [2013-03-31 18:38:14 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ef7642a4f2724135d445e2ea36582e78\SMDiagnostics.ni.dll
MOD - [2013-03-31 18:38:13 | 002,647,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\910fe53ec2122cf3a2ad11c2b2f5cbfd\System.Runtime.Serialization.ni.dll
MOD - [2013-03-31 18:38:11 | 000,393,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\d01a925ecd339eae8ea1da8488eb2283\System.Xml.Linq.ni.dll
MOD - [2013-03-31 18:37:38 | 001,801,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll
MOD - [2013-03-30 04:50:40 | 018,002,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\14f511c47523f19ca591eb207e9e2084\PresentationFramework.ni.dll
MOD - [2013-03-30 04:50:19 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e10fd15441d278c04a03302880a3e231\PresentationCore.ni.dll
MOD - [2013-03-30 04:50:15 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\39f4c7717661667c68f9af8c4f6402b9\System.Windows.Forms.ni.dll
MOD - [2013-03-30 04:49:52 | 003,858,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\7a9ff5ce3a909d075179a2ac70d8f388\WindowsBase.ni.dll
MOD - [2013-03-30 04:49:47 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll
MOD - [2013-03-30 04:49:43 | 000,309,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\82f376255a9523982c52cf58b13268d3\PresentationFramework.Classic.ni.dll
MOD - [2013-03-30 04:44:06 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll
MOD - [2013-03-30 04:43:58 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\5de5d8c1c02e33789e3cf7e3f54c0ec9\System.Configuration.ni.dll
MOD - [2013-03-30 04:43:41 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\27dcf04ed7a3506045597c02a5a1fc31\System.Core.ni.dll
MOD - [2013-03-30 04:43:29 | 009,094,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll
MOD - [2013-03-30 04:43:19 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll
MOD - [2012-12-10 03:46:38 | 000,600,868 | ---- | M] () -- C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll
MOD - [2010-02-25 06:59:21 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe
MOD - [2009-02-03 03:33:56 | 000,460,199 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2013-03-07 01:32:44 | 000,045,248 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2009-12-10 11:15:06 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009-11-02 22:48:18 | 000,126,352 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2009-10-03 04:39:44 | 000,873,248 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2009-10-01 00:44:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2009-07-14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2009-07-04 04:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009-03-28 04:10:16 | 000,016,896 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
SRV - [2014-03-03 10:53:02 | 001,363,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014-03-03 10:52:32 | 001,748,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014-02-05 13:50:04 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013-10-23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-03-07 16:29:15 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012-09-05 17:56:44 | 000,234,776 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe -- (McComponentHostService)
SRV - [2012-08-13 03:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012-02-14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011-06-01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011-04-20 14:50:18 | 000,152,064 | ---- | M] (Avanquest Software) [Disabled | Stopped] -- C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion)
SRV - [2010-03-18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-12-10 03:39:04 | 000,065,536 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe -- (pgsql-8.3)
SRV - [2009-10-01 06:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009-10-01 06:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009-09-25 01:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2009-09-11 07:42:46 | 000,305,448 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009-08-28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009-06-05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014-01-22 09:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2013-11-15 08:37:28 | 000,033,448 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzdaendpt.sys -- (rzdaendpt)
DRV:64bit: - [2013-11-15 08:37:24 | 000,030,888 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzvkeyboard.sys -- (rzvkeyboard)
DRV:64bit: - [2013-11-15 08:37:14 | 000,149,160 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd)
DRV:64bit: - [2013-03-07 01:33:21 | 001,025,808 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013-03-07 01:33:21 | 000,377,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2013-03-07 01:33:21 | 000,178,624 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2013-03-07 01:33:21 | 000,070,992 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2013-03-07 01:33:21 | 000,068,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2013-03-07 01:33:21 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013-03-07 01:33:20 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2013-03-07 01:33:20 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2013-03-07 01:33:20 | 000,022,600 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd)
DRV:64bit: - [2013-02-22 03:43:20 | 000,046,280 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\hssdrv6.sys -- (HssDRV6)
DRV:64bit: - [2012-11-09 00:33:17 | 000,030,568 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2012-09-20 06:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012-08-24 15:43:16 | 000,384,352 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2012-07-26 03:21:28 | 000,291,680 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2012-04-19 04:50:26 | 000,028,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2012-01-31 04:46:48 | 000,036,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2011-12-23 13:32:14 | 000,047,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2011-12-23 13:32:04 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avgidsfiltera.sys -- (AVGIDSFilter)
DRV:64bit: - [2011-12-23 13:31:58 | 000,124,496 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2011-04-21 14:16:32 | 000,027,176 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
DRV:64bit: - [2011-04-21 14:16:32 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
DRV:64bit: - [2011-01-15 18:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010-12-17 00:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010-08-29 17:11:08 | 000,021,072 | ---- | M] (Mobile Stream) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\easytthr.sys -- (easytether)
DRV:64bit: - [2009-12-10 13:40:30 | 006,179,328 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009-11-11 17:44:26 | 000,034,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\point64k.sys -- (Point64)
DRV:64bit: - [2009-11-06 22:56:06 | 001,550,848 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009-11-02 22:48:02 | 000,013,784 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2009-10-26 22:39:44 | 000,151,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009-10-12 15:23:22 | 000,114,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbdev.sys -- (hwusbdev)
DRV:64bit: - [2009-10-03 09:47:38 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2009-09-18 06:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009-09-17 22:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009-09-10 15:31:56 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2009-08-29 20:15:32 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2009-08-29 20:15:26 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2009-08-13 21:20:46 | 001,209,856 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:64bit: - [2009-08-06 14:43:58 | 000,320,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
DRV:64bit: - [2009-07-23 00:06:26 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2009-07-14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009-07-14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-07-14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-07-02 13:46:58 | 000,052,264 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2009-06-25 04:23:24 | 000,205,472 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2009-06-20 04:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E)
DRV:64bit: - [2009-06-10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009-06-10 22:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009-06-05 04:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009-06-03 05:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009-06-03 05:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009-06-03 05:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009-05-06 02:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009-05-06 02:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2009-04-08 16:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2009-02-25 11:44:10 | 000,195,456 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\swumxa3.sys -- (SWUMXA3)
DRV:64bit: - [2009-02-25 11:43:12 | 000,219,136 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\swnc8ua3.sys -- (SWNC8UA3)
DRV:64bit: - [2009-01-22 22:34:55 | 000,034,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\swmsflt.sys -- (swmsflt)
DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer...68z1i5t54j1d19p
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = 
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...68z1i5t54j1d19p
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer...68z1i5t54j1d19p
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = 
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.7
FF - prefs.js..extensions.enabledAddons: %7B7690b97e-e48f-4053-8c05-91f0772bfa6c%7D:1.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.3.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.3.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@bankid.com/BankID säkerhetsprogram,version=5.1.3.2: C:\Program Files (x86)\BankID\npBispBrowser.dll (Finansiell ID-Teknik BID AB)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@se.nexus/Personal:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.0.1818576\npmathplugin.dll (Wolfram Research, Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Jens\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Jens\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jens\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jens\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012-09-10 16:33:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-22 21:35:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013-06-20 04:09:49 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\AddLyrics\FF\
 
[2012-12-03 08:30:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jens\AppData\Roaming\mozilla\Extensions
[2014-04-06 11:06:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jens\AppData\Roaming\mozilla\Firefox\Profiles\xgq5bm67.default\extensions
[2014-03-24 11:46:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
File not found (No name found) -- C:\USERS\JENS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XGQ5BM67.DEFAULT\EXTENSIONS\{7690B97E-E48F-4053-8C05-91F0772BFA6C}
File not found (No name found) -- C:\USERS\JENS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XGQ5BM67.DEFAULT\EXTENSIONS\[email protected]
[2013-05-28 15:23:38 | 000,249,136 | ---- | M] (SecMaker AB) -- C:\Program Files (x86)\mozilla firefox\plugins\npiidplg.dll
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\PepperFlash\12.0.0.70\pepflashplayer.dll
CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll
CHR - plugin: Net iD (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: NPCIG.dll (Enabled) = C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll
CHR - plugin: Wolfram Mathematica (Enabled) = C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.0.1818576\npmathplugin.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Java™ Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Nexus Personal (Enabled) = C:\Program Files (x86)\Personal\bin\np_prsnl.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Jens\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jens\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll
CHR - Extension: YoutubeAdblocker = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbemjihlimhgfipfdbaeeilcilgjnllg\1.0\
CHR - Extension: YouTube = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Sök på Google = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Speed Surfing = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkpaakpeehepibjpdmoocdaonognfiog\207\
CHR - Extension: sAfewaeb = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmcmnlopflehldikjhmfkhjlfgdmeabh\1.1\
CHR - Extension: avast! WebRep = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1483_0\
CHR - Extension: Google Wallet = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2013-02-09 22:36:12 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [Net iD] C:\Program Files\Net iD\iid.exe (SecMaker AB)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Net iD] C:\Program Files (x86)\Net iD\iid.exe (SecMaker AB)
O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
O4 - HKLM..\Run: [WatcherHelper] C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\WaHelper.exe (Sierra Wireless Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Viber] C:\Users\Jens\AppData\Local\Viber\Viber.exe ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Autostart - genväg (2).lnk = C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2014-04-01 11:06:47 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bok.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\Projekt 2014-10-09\bok.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Capture.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\RPM\Capture.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Commitment.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\RPM\Commitment.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Inspiration extras.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Hur man är en människa\Mentalt\Extras\Inspiration extras.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\länkar.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\glada saker\länkar.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Måluppnående - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående [2014-04-06 11:14:48 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Plan.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\Plan.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\random notes.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\random notes.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Saker som gör mig glad.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\Projekt 2014-10-09\kväll\Saker som gör mig glad.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Short-term planning.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Tidsplanering\Short-term planning.odt ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Skicka bild till &Bluetooth-enhet... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Skicka sida till &Bluetooth-enhet... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Skicka bild till &Bluetooth-enhet... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Skicka sida till &Bluetooth-enhet... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Jens\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Jens\Desktop\PartyPoker.lnk File not found
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.3.1)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_03)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1F47FF6-5D10-445E-9BB5-363E7C2754DE}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL) -  File not found
O20 - AppInit_DLLs: (c:\progra~2\sw-boo~1\assist~1.dll) -  File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014-04-06 11:02:51 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-04-04 15:48:02 | 000,000,000 | ---D | C] -- C:\ProgramData\GreenApp
[2014-04-04 15:46:20 | 000,000,000 | ---D | C] -- C:\ProgramData\ssafeweb
[2014-04-04 15:46:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ssafeweb
[2014-04-04 15:45:48 | 000,000,000 | ---D | C] -- C:\ProgramData\39b559e409962429
[2014-04-04 15:45:46 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Local\Comodo
[2014-04-01 11:06:42 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Roaming\DropboxMaster
[2014-03-23 01:17:28 | 000,000,000 | ---D | C] -- C:\Users\Jens\Application Data
[2014-03-23 01:16:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XMind
[2014-03-23 01:15:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XMind
[2014-03-18 15:23:38 | 000,000,000 | ---D | C] -- C:\Users\Jens\Documents\Edraw Max
[2014-03-18 15:22:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Edraw Max 7.6
[2014-03-18 15:22:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Edraw Max
[2014-03-09 14:26:25 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Local\FluxSoftware
[2014-03-07 21:28:56 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Roaming\OpenOffice
[2014-03-07 21:21:07 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
[2014-03-07 21:18:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenOffice 4
[2014-03-07 21:04:04 | 000,000,000 | ---D | C] -- C:\Users\Jens\Desktop\OpenOffice 4.0.1 (sv) Installation Files
[2011-12-12 06:20:52 | 002,149,888 | ---- | C] (Python Software Foundation) -- C:\Program Files (x86)\python26.dll
[2009-11-05 05:33:04 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
[8 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014-04-06 11:27:03 | 000,001,000 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2523931591-3497646636-795491354-1000UA.job
[2014-04-06 11:25:10 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-04-06 11:25:10 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-04-06 11:11:43 | 000,000,990 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-04-06 11:11:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014-04-06 11:11:34 | 3111,518,208 | -HS- | M] () -- C:\hiberfil.sys
[2014-04-06 10:55:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014-04-06 10:11:22 | 000,000,994 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014-04-05 21:27:01 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2523931591-3497646636-795491354-1000Core.job
[2014-04-01 11:06:47 | 000,001,054 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2014-04-01 11:06:42 | 000,000,880 | ---- | M] () -- C:\Windows\wininit.ini
[2014-03-31 12:27:45 | 001,574,104 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014-03-31 12:27:45 | 000,661,972 | ---- | M] () -- C:\Windows\SysNative\perfh01D.dat
[2014-03-31 12:27:45 | 000,652,376 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014-03-31 12:27:45 | 000,141,742 | ---- | M] () -- C:\Windows\SysNative\perfc01D.dat
[2014-03-31 12:27:45 | 000,121,308 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014-03-30 23:00:00 | 000,001,632 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\länkar.odt - genväg.lnk
[2014-03-27 18:59:45 | 000,000,066 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\mbam.context.scan
[2014-03-23 01:16:32 | 000,000,993 | ---- | M] () -- C:\Users\Jens\Desktop\XMind 2013.lnk
[2014-03-21 17:27:56 | 000,001,777 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Commitment.odt - genväg.lnk
[2014-03-18 15:38:41 | 000,020,992 | ---- | M] () -- C:\Users\Jens\Desktop\Whiteboardinköp.eddx
[2014-03-18 15:22:52 | 000,000,999 | ---- | M] () -- C:\Users\Jens\Desktop\Edraw Max.lnk
[2014-03-17 19:47:51 | 000,001,697 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\random notes.odt - genväg.lnk
[2014-03-14 19:01:26 | 000,000,218 | ---- | M] () -- C:\Users\Jens\.recently-used.xbel
[2014-03-14 19:01:21 | 000,003,297 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\DreamPie
[2014-03-09 17:22:24 | 000,002,036 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Autostart - genväg (2).lnk
[2014-03-09 16:18:07 | 000,001,197 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Capture.odt - genväg.lnk
[2014-03-08 14:37:38 | 000,408,504 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[8 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014-03-30 23:00:00 | 000,001,632 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\länkar.odt - genväg.lnk
[2014-03-27 18:59:45 | 000,000,066 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\mbam.context.scan
[2014-03-23 01:16:32 | 000,000,993 | ---- | C] () -- C:\Users\Jens\Desktop\XMind 2013.lnk
[2014-03-21 17:27:56 | 000,001,777 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Commitment.odt - genväg.lnk
[2014-03-18 15:27:43 | 000,020,992 | ---- | C] () -- C:\Users\Jens\Desktop\Whiteboardinköp.eddx
[2014-03-18 15:22:52 | 000,000,999 | ---- | C] () -- C:\Users\Jens\Desktop\Edraw Max.lnk
[2014-03-17 19:47:51 | 000,001,697 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\random notes.odt - genväg.lnk
[2014-03-14 19:01:26 | 000,000,218 | ---- | C] () -- C:\Users\Jens\.recently-used.xbel
[2014-03-09 17:22:24 | 000,002,036 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Autostart - genväg (2).lnk
[2014-03-09 16:18:07 | 000,001,197 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Capture.odt - genväg.lnk
[2013-08-21 03:51:06 | 000,005,085 | ---- | C] () -- C:\ProgramData\kmytnfun.aqy
[2013-07-05 06:58:56 | 000,005,079 | ---- | C] () -- C:\ProgramData\lrbivjdu.eai
[2013-06-19 22:19:36 | 000,005,076 | ---- | C] () -- C:\ProgramData\flwjycbm.bab
[2013-04-18 03:40:44 | 021,954,496 | ---- | C] () -- C:\Users\Jens\AppData\Local\TempFullTiltPokerEuSetup.exe
[2013-04-12 19:37:03 | 000,007,606 | ---- | C] () -- C:\Users\Jens\AppData\Local\Resmon.ResmonCfg
[2013-03-29 20:20:11 | 001,552,890 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013-03-28 15:54:40 | 000,000,880 | ---- | C] () -- C:\Windows\wininit.ini
[2013-02-06 14:05:50 | 000,723,230 | ---- | C] () -- C:\Windows\unins000.exe
[2013-02-06 14:05:50 | 000,210,747 | ---- | C] () -- C:\Windows\unins000.dat
[2012-10-12 14:47:57 | 149,692,413 | ---- | C] () -- C:\Users\Jens\Two.and.a.Half.Men.S10E03.HDTV.x264-LOL.mp4
[2012-10-12 14:45:54 | 142,770,927 | ---- | C] () -- C:\Users\Jens\The.Big.Bang.Theory.S06E03.HDTV.x264-LOL.mp4
[2012-08-26 20:45:51 | 001,887,546 | ---- | C] () -- C:\Users\Jens\Savoy___Magic_Bullets_feedthebrain.net.pdf
[2012-05-28 12:41:10 | 000,034,814 | ---- | C] () -- C:\Users\Jens\AppData\Local\dt.dat
[2012-02-22 14:33:55 | 000,000,938 | -H-- | C] () -- C:\Users\Jens\.gitk
[2012-02-22 11:31:01 | 000,000,092 | ---- | C] () -- C:\Users\Jens\.gitconfig
[2011-12-27 09:50:32 | 000,000,600 | ---- | C] () -- C:\Users\Jens\AppData\Local\PUTTY.RND
[2011-12-12 06:23:11 | 000,000,290 | ---- | C] () -- C:\Program Files (x86)\protext.ini
[2011-10-03 02:36:38 | 000,003,297 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\DreamPie
[2011-02-26 21:33:17 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010-10-09 02:06:58 | 000,000,000 | ---- | C] () -- C:\Users\Jens\AppData\Local\prvlcl.dat
[2010-09-27 19:21:10 | 000,005,077 | ---- | C] () -- C:\ProgramData\bltofzsb.qlf
 
========== ZeroAccess Check ==========
 
[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010-07-27 16:59:11 | 014,162,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010-07-27 16:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2011-12-14 18:07:46 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\.anki
[2014-02-17 16:58:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\155856
[2011-11-15 01:01:07 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\AVG
[2011-10-14 04:26:35 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\AVG2012
[2014-02-24 20:52:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\BankID
[2011-12-12 23:07:34 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\benibela
[2012-12-21 21:14:02 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Canon
[2012-11-04 23:04:55 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013-02-06 14:07:17 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\CRDeltaTB
[2014-04-06 11:20:04 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Dropbox
[2014-04-01 11:06:44 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\DropboxMaster
[2013-04-21 04:54:26 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Foxit Software
[2013-11-18 15:02:51 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\GoPanda
[2013-12-18 22:32:38 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\gtk-2.0
[2013-06-19 06:20:05 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\HEM Data
[2013-06-20 20:06:03 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\HoldemManager
[2013-06-19 19:45:08 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\iid
[2012-03-01 21:53:21 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Internet Chess Club
[2013-12-22 09:59:20 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\kombilo
[2012-12-02 19:03:31 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\LyX2.0
[2011-12-13 19:04:39 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Miranda
[2011-12-08 16:55:22 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\mplayer
[2012-01-04 03:18:23 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Notepad++
[2010-11-07 21:34:51 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Octoshape
[2014-03-07 21:28:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\OpenOffice
[2010-06-18 22:11:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\OpenOffice.org
[2011-08-06 22:53:50 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Opera
[2014-02-24 20:50:31 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Personal
[2013-06-20 07:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\PokerCoach
[2013-06-19 06:24:55 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Roaming
[2010-06-18 17:50:52 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Sierra Wireless
[2013-04-29 09:28:22 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Spotify
[2011-05-24 23:03:41 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\SynthMaker
[2013-08-28 00:58:43 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\TS3Client
[2011-05-08 21:48:51 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Unified Remote
[2014-04-04 16:08:11 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\uTorrent
[2014-04-06 11:13:53 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\ViberPC
[2011-12-08 18:17:37 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Windows Live Writer
[2013-04-08 00:02:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\WinPatrol
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 168 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:0B9176C0
 
< End of report >
 

Note: this includes report from both AdwCleaner aswell as OTL.

 

Thanks in advance!


  • 0

Advertisements


#2
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,700 posts
Hello and Welcome on board okiol :welcome:,

my Name is Machiavelli and I will assist you with your problem.
If you booted into safe mode on your computer then print my instructions!
I'm in the 'Senior Team of the forum' and will provide you with advice:

To remove Malware on a computer can be very complicated. Malware (malicious software) is able to hide and so I may not be able to find it so easily. In order to remove Malware from you Computer, you need to follow my instructions carefully. Don't be worried if you don't know what to do. just ask me! Please stay in contact with me until the problem is fixed.

Below are a few tips:
  • Removing Malware is usually very difficult.
    We need to search and analyse a lot of files. As this is done in our free time, please be patient especially if I don't answer every day!
  • Please follow these instructions
    If you don't follow the instructions your computer may crash. If you fix your PC by yourself, this can be very risky!
  • Please stay in contact with me until your problem is resolved
    As Malware may not be totally removed in one session or in one day, please stay in contact with me until the problem is resolved.
  • Please don't run any other tools without consulting with me as this can complicate finding and removing all Malware
    Don't run any tools while I'm fixing your PC. That is counter productive and again, will only complicate finding and removing all Malware!
  • Read my post completely
    If you don't do so, you may make mistakes that could result in your System crashing by your own actions!
I am currently in training and my posts will need to be reviewed by an expert, so expect a slight delay between posts. 

 

There should be an Extras.txt Log under C:\Users\Jens\Downloads - please post the content of that file, if it doesn't exist there, please do this:
  • Move the OTL.exe from C:\Users\Jens\Downloads to your Desktop.
  • Run OTL by double-clicking on it. (If you have Windows Vista / Windows 7 / Windows 8 please do a Right click on the OTL icon and select Run as Administrator).
  • Click the none Button
  • Change the following options:
    • Extra Registry > All
  • Click Run Scan to start OTL.
  • When OTL finishes scanning, Extras.txt will open
  • Copy (Ctrl+C) and Paste (Ctrl+V) the content of Extras.txt into your next post please.

  • 0

#3
okiol

okiol

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
OTL Extras logfile created on: 2014-04-06 11:22:21 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Jens\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd
 
3,86 Gb Total Physical Memory | 1,18 Gb Available Physical Memory | 30,65% Memory free
7,73 Gb Paging File | 3,79 Gb Available in Paging File | 49,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 490,00 Gb Total Space | 55,22 Gb Free Space | 11,27% Space Free | Partition Type: NTFS
 
Computer Name: JENS-DATOR | User Name: Jens | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L"
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L"
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\SwiApiMux.exe" = C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\SwiApiMux.exe:*:Enabled:SwiApiMux -- (Sierra Wireless, Inc.)
"C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\TRUUpdater.exe" = C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe:*:Enabled:TRUUpdater -- (Sierra Wireless, Inc.)
"C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMux.exe" = C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMux.exe:*:Enabled:SwiApiMux -- (Sierra Wireless, Inc.)
"C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\SwiApiMux.exe" = C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\SwiApiMux.exe:*:Enabled:SwiApiMux -- (Sierra Wireless, Inc.)
"C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\TRUUpdater.exe" = C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe:*:Enabled:TRUUpdater -- (Sierra Wireless, Inc.)
"C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMux.exe" = C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMux.exe:*:Enabled:SwiApiMux -- (Sierra Wireless, Inc.)
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05480496-623E-479E-936A-CFE781056A92}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{22F2C166-2F5A-40BC-BBF3-8EA498F06490}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{239909B2-D52D-4F81-81BC-AC7A5D395384}" = lport=445 | protocol=6 | dir=in | app=system | 
"{26758517-85FE-48B6-B42B-4F0DD77B3945}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{2ACA24D8-9702-476B-8217-E8ADE1324E58}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 | 
"{3D662938-D99A-42E6-A743-C7007168EF1C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{40DB4CD3-9AC1-4284-A0A7-DD768CAAFA9B}" = rport=445 | protocol=6 | dir=out | app=system | 
"{43D7B91D-A1F0-441E-B96C-C6C6DBBD9B60}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{444B806B-C057-43A8-ACE6-03AF9B25C7B6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{44D207C8-2A1B-4392-81C2-9D8A1B421F23}" = rport=139 | protocol=6 | dir=out | app=system | 
"{48BEC4F9-57A8-42BB-A779-700CE80E6036}" = rport=137 | protocol=17 | dir=out | app=system | 
"{5093C36D-A090-4156-96A0-59B5AC2F08C6}" = lport=139 | protocol=6 | dir=in | app=system | 
"{54F76FC0-3EFF-4BD0-A05B-632FD218FE42}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{6593A402-46EF-4C16-8726-FFB0ADA9B7EF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{70D8B7A5-54EF-4D75-B587-42A921BB5116}" = lport=137 | protocol=17 | dir=in | app=system | 
"{7CCE8193-FD18-4408-B777-A12598D9948D}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{89596483-F3AB-4533-A8DE-299F842FE627}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{AF407809-1271-43F5-885D-35BD0364C39F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{B0CF93C9-1DAB-4576-8CF5-67798A136E95}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{B7EADA62-EC33-4433-81C7-119E5E562102}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{BC0FD706-DA4F-4444-A1A1-3DEC05131A97}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{C2898D36-A661-4666-8DFD-110238358930}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
"{C476AAB4-34E6-4F72-82BF-B12FB972735E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{C779DB23-A0BE-41F3-B472-8218081646E4}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{CF04E9ED-F2AD-4C10-BBA5-5EC633B0C872}" = lport=138 | protocol=17 | dir=in | app=system | 
"{DE41648B-BD25-4983-9690-95373424F906}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{E8B0C786-1682-4AE6-B204-ADB9E2947B28}" = rport=138 | protocol=17 | dir=out | app=system | 
"{FFCE2C4E-6C86-4923-8FDD-FF09D6363EDA}" = lport=2869 | protocol=6 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00F368CD-2184-47DF-8F51-658D717B61CA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{0261561A-70DB-4055-A370-A64C2737834D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{02CDD9F6-5CE4-4DF2-9878-64D09F638E50}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{043B7EB8-6988-4AD6-8EEA-2F2F48CA41C4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{069B34A0-5EA3-45D1-AA9D-6499ABE7DC56}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | 
"{08A10B2F-AA0C-4728-8C93-0D449CDBA23C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{09657E01-ABB2-4388-9E0D-39E9D569DAF1}" = protocol=6 | dir=in | app=c:\program files\wolfram research\mathematica\8.0\mathematica.exe | 
"{0AECAFAC-7AA4-4708-9B68-57CA69951BC1}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe | 
"{0C0833AF-B3A0-48D2-9961-A3A34875CBA0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{0D02681A-3917-4C3C-AF43-73842134FE1C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{0DB6D84B-C4B3-4795-840E-326176D780E7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{0F3BD5C7-A301-413B-9585-DEAE5FF31B9F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{1198ECB5-77DC-43C3-BB2E-06999DD1E72F}" = protocol=17 | dir=in | app=c:\users\jens\appdata\roaming\utorrent\utorrent.exe | 
"{11E7CF78-0D76-4267-9A7E-93CC8D2FAC19}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe | 
"{137B36BB-64EC-4E81-8217-306C80C5215D}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe | 
"{15A1FC9A-71AA-4614-8514-0D9191D5CC79}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{15B83A26-1D75-4C6F-AB15-891271BE1387}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{18E1F2B9-E342-40C8-BDEB-6AFFCD36D646}" = protocol=17 | dir=in | app=c:\program files\wolfram research\mathematica\8.0\mathkernel.exe | 
"{1ABA5C6B-9016-45E9-8B68-4A55256B6AAC}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe | 
"{1EE79990-D7C4-47EF-839E-FA2402248625}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe | 
"{1F323731-0808-414C-9892-E397C1E7D87B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{2165F4DF-EC8B-4940-8DC1-CA847A7C7084}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | 
"{217AC924-2129-4DE0-AE92-596A6A37C60C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{220080B7-1952-4FA1-89E3-BA9916C32618}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | 
"{224AD946-9A3E-4AF5-918F-8719D87249CC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{22854264-637E-411A-A93A-39D4329264E2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{24D5E1CE-9065-4E82-A61E-BE2E69130171}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | 
"{266F5D59-38F9-490D-8D85-F7921199C498}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{26AE3C2E-6FCE-46F7-A66E-207B74EF48C8}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{279078B1-74D2-4423-9074-F1B40ECDCDD4}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | 
"{2895F317-72D1-4F93-B616-EBDFBE35F604}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{29248562-128F-4769-A7BB-F3392FAA2906}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{2A1A2EBD-71C6-4060-8E83-AC469022262C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{2D8914D0-F4C2-483D-B6BD-9B215784B6FD}" = dir=in | app=c:\users\jens\appdata\local\viber\viber.exe | 
"{2DB34EDB-F05D-4069-85FF-3BB60F44661E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{2E0D35F5-8A3D-4C7A-9ED7-299E8A980F27}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | 
"{311CFA53-12A8-4CD7-BEB7-F0AF1323FC75}" = protocol=6 | dir=in | app=c:\users\jens\appdata\roaming\dropbox\bin\dropbox.exe | 
"{312F038E-4142-4F69-9ED8-5CA9BE63283D}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe | 
"{31949168-10C5-4B76-B202-1DD198B1FE17}" = protocol=6 | dir=in | app=c:\program files\wolfram research\mathematica\8.0\math.exe | 
"{320C7F56-60A6-4197-9FB4-F585C6764727}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\playmovie\playmovie.exe | 
"{33AB0A75-E691-426E-ADBA-7BD0CB9DC3F0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{33FEF243-8C90-445C-A723-DAA9175FB63D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{369F677C-521A-48E1-B10D-E7181AA1E7CC}" = protocol=6 | dir=in | app=c:\program files\wolfram research\mathematica\8.0\mathkernel.exe | 
"{36A35C9D-3B1F-48D6-BE17-32F83051D783}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | 
"{37D61B34-FDB3-4F40-AAD2-725797A8AE52}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{38C22668-BDA2-4243-8805-4436E0E3DD9B}" = protocol=1 | dir=out | [email protected],-28544 | 
"{3A08B88D-61F1-4EA1-849E-5B36812C8BBC}" = protocol=17 | dir=in | app=c:\program files\wolfram research\mathematica\8.0\math.exe | 
"{3B973B9E-8D5C-4346-A435-7DF5F477F43E}" = protocol=17 | dir=in | app=c:\users\jens\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe | 
"{427104F6-E9DF-4519-88DF-5816CC9F2AC9}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | 
"{45EC8D3B-311C-45EF-B742-7DE08B793018}" = protocol=6 | dir=out | app=system | 
"{47B8F0F6-B9AC-42ED-A0BD-2FB4DAFCCAD1}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{48EBE09E-1DC2-464E-BDEB-BF60CA89B977}" = protocol=6 | dir=in | app=c:\program files (x86)\steam2\steam.exe | 
"{4A41B04B-2FAA-4183-915B-B192A9020DB8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{4A8F6E84-613A-498D-A952-6EC97807A4F8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{4EED5917-B5C9-49E4-B853-9F09979D8390}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{50BAA29A-6F06-4D0E-B8DF-05E561E9A54A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{53161156-D58F-4946-B872-0984AFA6C8E9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{5437B2B3-0454-4DB6-B4A0-EF7E2943CE97}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{5489CE50-72A5-4B67-8853-326D352CAED0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{570BD6CB-3D2F-4361-89D9-554AC840BC22}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{5AE22131-85C9-465F-9295-2887BDFEDED1}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe | 
"{5B4D3BF5-6A38-4D99-B0F2-DC6C41FFDC4E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{5CADB74E-56FC-42B5-9E1E-80F2B825C78E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{5E104C9C-989B-4149-BA57-9E89C1B6CB04}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe | 
"{6393ADED-C950-495F-8196-B6849E4969F5}" = protocol=58 | dir=in | [email protected],-28545 | 
"{644DCAD3-A050-48DA-8E41-6EEF3BBD8E6A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam2\steam.exe | 
"{664BE36B-68DC-4369-AE85-4BB88C293DF3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{66E8821B-F85B-4178-80AF-F3B776F87339}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{67B3D5D4-A93B-48E5-B8EF-9A9590913417}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{687EBC72-E291-4CC4-9AAA-BB620D2EE62F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{6A911289-B58E-4C7F-8995-637665616596}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{6D850B83-0610-4BD9-B692-1115ED104802}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{6E542442-75AD-4E0F-8887-6AA77BB559B3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{7104290C-00C9-42DC-AF6C-2E0E0E6FD3AC}" = protocol=17 | dir=in | app=c:\users\jens\appdata\local\google\google talk plugin\googletalkplugin.exe | 
"{71DE746C-78CB-41BA-BC31-B4D9F940A688}" = protocol=6 | dir=in | app=c:\users\jens\appdata\roaming\utorrent\utorrent.exe | 
"{75450DB8-E4DB-4224-BEF3-7CD598CE8CEC}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer_service.exe | 
"{7547687C-4451-421B-90C1-F05BACA0A480}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
"{766654DA-97B6-46B9-96BF-993CB5D9C499}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | 
"{76A5FE2D-7C31-4382-9D83-679916EEFF58}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{76D8CC24-0444-4BDE-B085-30766FC67196}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\homemedia\homemedia.exe | 
"{786B5702-5CA7-44F0-B888-D9C58D428E02}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{7B81C35A-F8F8-4FBB-B044-33D203B48C90}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{7D4728B1-5371-448C-BD33-A2DE2A1745AD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{7DEF6060-9990-4318-A328-C339A8DB2AD0}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe | 
"{7E4116A3-4061-4D95-9E85-44E5EA3471F7}" = protocol=17 | dir=in | app=c:\program files (x86)\sony ericsson\update engine\sony ericsson update engine.exe | 
"{80062283-B7BF-4655-B914-129E463E3663}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{81BC7B92-945C-43FB-9337-F88ABAD640ED}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe | 
"{82A24844-2B3C-4F1B-B3C3-C2E4FD6CF5CD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{83328338-8525-4EC6-9BAA-80642A7057EF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{840E2B78-1585-4F4C-9783-2B5D47E5901C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe | 
"{842C30C6-DB29-43C0-927C-BE072051828D}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | 
"{8494D68F-1A0D-43E5-86D2-B80BFAC84D21}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe | 
"{84AF330D-B7E9-4250-9FDB-B4364B7B92D0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{87D1EFB6-56FA-49E0-9955-82EF79BD9028}" = protocol=58 | dir=out | [email protected],-28546 | 
"{87F2015C-5614-43CD-B6CD-4F261F474F60}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{882DCCF2-674E-4140-98A6-1C7C4B2132F0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{8898F205-5E5F-4DAA-9103-8ED82093E57B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{8B7D4B73-CDBB-46E1-B5D9-CCB8B9B69060}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | 
"{90E7493B-543F-4DDE-9F27-2052DC4D6A80}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | 
"{91CD5C02-E79D-4439-AD53-994F925F0293}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{9266DA7C-B5E6-4EDF-BEB2-B9C4C08BC3FD}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | 
"{97A013AA-8189-474E-8D3C-E8941CBDEB5C}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe | 
"{987B80B3-ED39-4B7B-9AE8-B00CA175C4FB}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | 
"{A156A4AB-9B5F-465B-BEC0-21078CF79152}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{A1B5A6E9-09C0-4265-9244-F85C2BC8E9D4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{A2E04EC2-1155-421E-A63B-648DDCD54DE3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{A3DE4C4C-07FC-4D89-91CA-ADAA907614F2}" = protocol=17 | dir=in | app=c:\program files\wolfram research\mathematica\8.0\mathematica.exe | 
"{A58AD689-77DA-48A1-BC86-D7FC33DF4ED3}" = protocol=6 | dir=in | app=c:\users\jens\appdata\local\google\google talk plugin\googletalkplugin.exe | 
"{AB494D9A-3ADA-4FA6-8299-C59785238B1E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{AB887CE9-026E-4D19-9CC4-7524826A58F0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{B7EA9A15-E194-4884-9A87-5E419A9EED17}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
"{B82CE64A-AD24-44A9-B497-7457BC878118}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{B879B3BA-5CFC-4FB5-ABE3-8B740BE1946A}" = protocol=1 | dir=in | [email protected],-28543 | 
"{B8FD963F-613B-4C09-ADAD-DA03BE297408}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | 
"{BAC55FA5-4DAC-4F38-AC9F-5A036D9E4C19}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
"{C10EC1F2-B66C-4A5F-8910-1386D8BAD389}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe | 
"{C152E80D-344C-41EE-A6B3-5F7196072617}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{C16454DE-51BA-47A5-BB0E-3CFB77FCB167}" = protocol=6 | dir=in | app=c:\program files (x86)\sony ericsson\update engine\sony ericsson update engine.exe | 
"{C1F92670-C4F1-43C0-9244-EA6D1B50EF8B}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version6\teamviewer.exe | 
"{C23C5464-CD2E-4081-8478-02149EC199A9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe | 
"{C8D3BC27-578B-4E86-8C6A-62B8F85A1CE4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{CD48E4D2-21DC-4B1C-92F3-BF399FEDA924}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe | 
"{CE0572EB-CB7F-480B-81F0-F5A5C2316C69}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\playmovie\pmvservice.exe | 
"{CE153497-4D0A-427B-A618-13B189A6218E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | 
"{CF0C50FC-529B-4DF4-AEB9-D1903BFD5C3B}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | 
"{D3DCB0ED-712F-48DC-AE20-A7D18903BC2E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{D68FDA92-EE29-4FB6-B6CF-A14DEE9881E6}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{D88ABBEE-533B-40A2-8D06-47A14780DDE6}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe | 
"{D8C887A0-F54B-4E5C-A5DF-FCEF880C22F2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{D9AADB09-5860-4099-A755-A4ACCE4AF1E5}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | 
"{DD2BB182-8818-45A2-AB76-B627555237A7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe | 
"{E11B83B3-EDE8-4C60-91D7-4AA12ED3BAA6}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe | 
"{E583F244-E802-447F-B92F-DEE330B5BCB5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{E9519B11-5C23-4B94-8E6B-1109AE0F9803}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{EB456B3D-8BA5-451E-BC52-E971855069D4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{ECD6203C-A4F8-4B65-AEE4-CBE4EBF0A15C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{ECF27527-060C-42F7-82A5-09C6B5F33D32}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe | 
"{EE28484D-13EF-498B-B968-3DAC3A589AEA}" = protocol=6 | dir=in | app=c:\users\jens\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe | 
"{EF2E16A0-A407-42AE-85DD-71BF035B74CD}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe | 
"{F746F0DB-A544-40BE-A7DE-D07009BC5C3D}" = protocol=17 | dir=in | app=c:\users\jens\appdata\roaming\dropbox\bin\dropbox.exe | 
"{FC3270AA-C2BB-461B-9CA6-B6948A247BF7}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | 
"{FC7A16B6-7B8E-49B8-98BC-A5BB94698F5D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FCC7D248-EEAB-43EB-BBEF-1825C6A2A974}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"TCP Query User{016BD6CA-C401-4544-ACC7-3F21A272D981}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe | 
"TCP Query User{060ADCAB-7429-4D21-A53E-6C1FCA2D1AD6}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe | 
"TCP Query User{0D9448A8-8F46-46A0-AF40-6B34BCD60AD7}C:\users\jens\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\jens\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe | 
"TCP Query User{19491D3A-70D7-49BB-864C-DB36C830E7B4}C:\program files (x86)\b2bpoker\noiqpoker\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\b2bpoker\noiqpoker\jre\bin\javaw.exe | 
"TCP Query User{1D8D2F6A-3CE3-4F25-B493-23BB70257CAF}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe | 
"TCP Query User{2157070E-45CA-4B81-AD14-5435F35F8060}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe | 
"TCP Query User{27C3AAE4-607C-41F9-AF0A-02A3D8AE5C5C}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | 
"TCP Query User{3090F07B-8B4E-42CA-8169-F9BCF1342852}C:\users\jens\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\jens\appdata\roaming\dropbox\bin\dropbox.exe | 
"TCP Query User{3C8FAAFF-AF78-4591-A110-217B7F59A20D}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe | 
"TCP Query User{57436BDE-4D0D-4365-BEC8-142018C12BC8}C:\program files (x86)\wbaduk\oro20.exe" = protocol=6 | dir=in | app=c:\program files (x86)\wbaduk\oro20.exe | 
"TCP Query User{5FEEC675-C213-4B5B-AB9A-401E5E8E30E5}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe | 
"TCP Query User{61D8968F-C3E1-4C51-AD19-B83CCA2453AF}C:\users\jens\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\jens\appdata\roaming\spotify\spotify.exe | 
"TCP Query User{648B7D28-3972-4F50-934D-6519C333787C}C:\windows\system32\javaw.exe" = protocol=6 | dir=in | app=c:\windows\system32\javaw.exe | 
"TCP Query User{75325281-ACF5-49D4-8AF3-573B3F0470D1}C:\program files (x86)\miranda im\miranda32.exe" = protocol=6 | dir=in | app=c:\program files (x86)\miranda im\miranda32.exe | 
"TCP Query User{816D3833-C9B5-462A-85AE-3587EADE941F}C:\program files (x86)\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | 
"TCP Query User{88C8090B-536D-41B8-A951-AEEEFCE018D2}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | 
"TCP Query User{A4C30311-1AAA-49BC-B108-3065A3D40AAC}C:\windows\system32\javaw.exe" = protocol=6 | dir=in | app=c:\windows\system32\javaw.exe | 
"TCP Query User{ACDD4F8D-141E-4690-936E-C5E09DEE5089}C:\program files (x86)\b2bpoker\pokersaints\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\b2bpoker\pokersaints\jre\bin\javaw.exe | 
"TCP Query User{D1902C6D-CCE7-4ACF-8397-C58E8CD33BC5}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
"TCP Query User{D5E5473A-8C82-4F3E-BD96-19716D8E9460}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe | 
"TCP Query User{ECEB9752-6030-45ED-A91E-D4D9A756C69C}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe | 
"TCP Query User{F5A9FC9D-43FB-4775-8A89-5E9863E343F6}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe | 
"TCP Query User{F5FC2741-F92D-4046-A54E-EA762F2F77BC}C:\program files (x86)\b2bpoker\pokersaints\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\b2bpoker\pokersaints\jre\bin\javaw.exe | 
"TCP Query User{FA43C33D-9B5D-4020-9F70-3826C3E4E87D}C:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"TCP Query User{FBFEAB3A-E865-4D39-9823-B57E842576F8}C:\program files (x86)\starcraft ii\starcraft ii.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | 
"UDP Query User{0B7CBB78-FC6B-42D1-A027-30D1C752967E}C:\program files (x86)\b2bpoker\noiqpoker\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\b2bpoker\noiqpoker\jre\bin\javaw.exe | 
"UDP Query User{18A993F2-CC39-43E9-82FC-C4E678DD0206}C:\program files (x86)\b2bpoker\pokersaints\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\b2bpoker\pokersaints\jre\bin\javaw.exe | 
"UDP Query User{1B1897EF-14FE-4E2A-A771-2B9A77232993}C:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"UDP Query User{21AC1FF4-DE81-4C3E-A663-B9720224E296}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe | 
"UDP Query User{26AEAD93-E1EB-4FDD-BC1A-8E0DAF6D4391}C:\users\jens\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\jens\appdata\roaming\dropbox\bin\dropbox.exe | 
"UDP Query User{2E38B7FC-5F89-4CAD-8A05-0CD520716D59}C:\users\jens\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\jens\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe | 
"UDP Query User{38CFB99B-FD28-437E-A20B-7F65F4B2F1AC}C:\program files (x86)\starcraft ii\starcraft ii.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | 
"UDP Query User{3FF96F38-2C6F-4838-B708-DBA8A7D1437A}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | 
"UDP Query User{573B5911-0FCA-4B3B-A78C-BB7054C5ADA8}C:\program files (x86)\wbaduk\oro20.exe" = protocol=17 | dir=in | app=c:\program files (x86)\wbaduk\oro20.exe | 
"UDP Query User{5A60E5B2-C1FE-4344-8D58-CC4037698585}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe | 
"UDP Query User{694CE6F1-6CCF-4609-AB64-703D1650D25C}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe | 
"UDP Query User{6C0418AA-EBB2-4563-B683-35CA715C3922}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe | 
"UDP Query User{751E3C0B-AFE1-4EEB-9800-C9D7600A3F9E}C:\program files (x86)\miranda im\miranda32.exe" = protocol=17 | dir=in | app=c:\program files (x86)\miranda im\miranda32.exe | 
"UDP Query User{784DB64E-9594-46FB-B6C0-5BAEE6B1AFE0}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
"UDP Query User{7D7A20C6-AAF7-4114-9B23-B62D0B2B9812}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe | 
"UDP Query User{A85AAF1E-8E22-44E9-9C13-0BC45319F6FA}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe | 
"UDP Query User{AE8C0270-E44C-4D53-B617-4A757C984BFC}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe | 
"UDP Query User{C0B6A97D-BF77-40D9-B5DB-16920D811F8B}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe | 
"UDP Query User{C9F031DB-9DD0-40A3-9AD5-374FA62BB1B0}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe | 
"UDP Query User{D2020FC4-56DF-4CE0-8F2C-C4E4FEEE3012}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | 
"UDP Query User{DB4A30F1-D797-44B6-BC42-87A8383C675E}C:\users\jens\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\jens\appdata\roaming\spotify\spotify.exe | 
"UDP Query User{E1F34853-24B8-4BD9-8E23-497F7F5E8D02}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe | 
"UDP Query User{E857233C-1F5F-4BD4-90A8-33DBE9EB26CE}C:\program files (x86)\b2bpoker\pokersaints\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\b2bpoker\pokersaints\jre\bin\javaw.exe | 
"UDP Query User{F2DB6C0B-78E3-42CC-BE50-580E344B509F}C:\program files (x86)\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | 
"UDP Query User{F4B05118-CB0E-4768-8E96-8856EBB568E8}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1111706F-666A-4037-7777-203648764D10}" = JavaFX 2.0.3 (64-bit)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6100_series" = Canon MG6100 series MP Drivers
"{11F38253-8940-FFDA-D131-B14120C357E4}" = ATI Catalyst Install Manager
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{2222706F-666A-4037-7777-203648764D10}" = JavaFX 2.0.3 SDK (64-bit)
"{26A24AE4-039D-4CA4-87B4-2F86417003FF}" = Java™ 7 Update 3 (64-bit)
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}" = Intel® Turbo Boost Technology Monitor
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4BB7A109-FDB5-45E3-9DB9-ECB2EA7B80EE}" = WinPatrol
"{4BF3A357-3C4F-49EE-B16C-D45D7D7F1819}" = EasyTether
"{5EBE0F1F-45DF-4298-AC6B-E8E54EAEC834}" = Microsoft IntelliPoint 7.1
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64A3A4F4-B792-11D6-A78A-00B0D0170030}" = Java™ SE Development Kit 7 Update 3 (64-bit)
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6D8CEB72-EF89-3670-8133-966AF0CCDA86}" = Microsoft .NET Framework 4 Extended SVE Language Pack
"{6FEDAFB4-A2AE-4D6B-A505-D82B07291F40}" = AVG 2012
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-002A-041D-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Swedish) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96CC6DCC-8EBA-3F85-899B-933F599C4142}" = Microsoft .NET Framework 4 Client Profile SVE Language Pack
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A108BD40-0A8C-4385-8874-74C4B6086CC3}" = AVG 2012
"{A325B368-A9EC-40EF-A95C-9DEAD3683AE3}" = Broadcom Gigabit NetLink Controller
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BD41C9CA-7722-7C0F-8BFE-E88A81865287}" = ccc-utility64
"{BF46C84D-1AC3-4CC3-A45C-EF6257B80984}" = AVG 2012
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"3932CA781A7894D20116FDF60F878301800EA8AB" = Windows Driver Package - Broadcom Bluetooth  (09/11/2009 6.2.0.9407)
"3BA80AB4C7E9F8497C115C844953A3D4BEB84D21" = Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800)
"6B6B5E96843E55CF5CF8C7E45FB457F1FE642FF1" = Windows Driver Package - Broadcom Bluetooth  (07/30/2009 6.2.0.9405)
"AVG" = AVG 2012
"A-WIN-Extras 8.0.0 1818576_is1" = Mathematica Extras 8.0 (1818576)
"CCleaner" = CCleaner
"Emotum Mobile Broadband" = Telenor Stay Connected
"iid" = Net iD 5.7.1
"LSI Soft Modem" = LSI HDA Modem
"MatlabR2011a" = MATLAB R2011a
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile SVE Language Pack" = Microsoft .NET Framework 4 Client Profile Language Pack - SVE
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended SVE Language Pack" = Microsoft .NET Framework 4 Extended Language Pack - SVE
"M-WIN-G 8.0.0 1819003_is1" = Wolfram Mathematica 8 for Students (M-WIN-G 8.0.0 1819003)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR 4.00 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}" = Razer Synapse 2.0
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = LizardTech DjVu Control
"{127BEFB3-24B2-4B44-8E99-AD22C2A5A8ED}" = Full Tilt Poker.Eu
"{12CEE8C7-8983-4FEC-A046-3FB4AE3A691C}" = Windows Live Sync
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker
"{14D6085A-9A42-C0B5-823E-8C9619AC1026}" = Catalyst Control Center Graphics Full New
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FF19BBD-554D-733C-3BDF-B55C99349198}" = Catalyst Control Center Core Implementation
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216018F0}" = Java™ 6 Update 18
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common
"{2C1B58D5-6549-472C-86B7-17BE57186628}" = Microsoft Works
"{2D6973ED-BBF2-434E-993C-37E05087B8C8}" = BankID säkerhetsprogram
"{2DFA85ED-588F-4CE3-A175-29E52C3804A8}_is1" = Folder Size 3.0.0.0
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{346D6B7A-4AD8-5C2C-E249-34CA3CD7D34B}" = CCC Help Polish
"{34A0D249-747E-4D6C-803D-329C120C6B79}" = Catalyst Control Center - Branding
"{34b2530c-6349-4292-9dc3-60bda4aed93c}" = Python 3.2.1
"{357C0C30-051F-FE77-4709-025786123FB1}" = ccc-core-static
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{41BC23C5-157F-77A0-6662-17A5096E7946}" = Catalyst Control Center Graphics Previews Vista
"{4507185D-FAB8-B77D-4546-2CF31DA906AD}" = Catalyst Control Center Graphics Full Existing
"{46BCB691-9148-4FCB-B215-CCDF70B5D95A}" = OpenOffice 4.0.1
"{4967ADB1-27A6-635F-A217-754BD9A05E2E}" = CCC Help Czech
"{497C131E-2032-051B-B32A-C69A960FBB13}" = ssafeweb
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{54DFD48E-0E0D-5D0C-BD93-CE3DF090EC1C}" = CCC Help Japanese
"{5528C69D-4018-C4BD-7D00-67F90623EB33}" = CCC Help Italian
"{5582C24D-5597-42D2-537E-BA329164D78D}" = CCC Help Thai
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple-programstöd
"{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}" = SW-Sustainer 1.80
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{662CFD19-EA80-4EFE-A0D8-EE10EFEB3C83}" = Livestream Procaster
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources
"{6A67578E-095B-4661-88F7-0B199CEC3371}" = Windows Live Messenger
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{739126B3-1C80-4F1F-8D59-312A19633E1A}_is1" = Epub reader
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{785F975B-50FB-C523-5E58-C6EFE9E62424}" = CCC Help Portuguese
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14
"{7D62622F-78B7-91B0-5B75-4082DDFAC775}" = CCC Help Swedish
"{7DE2B39B-97F0-EC01-06D6-E25C6D4164DF}" = CCC Help German
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{842C72F9-447D-4FCF-AC7D-E313113518D0}" = Flopzilla
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D09F48-CDAB-4B4C-8806-F6C16F17935A}" = PokerStrategy.com Equilab
"{878789F8-276E-4D98-20E6-78DCBD77AD7D}" = CCC Help Turkish
"{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F2AE892-C036-C2F8-0D45-0ED891440D68}" = CCC Help French
"{90120000-0015-041D-0000-0000000FF1CE}" = Microsoft Office Access MUI (Swedish) 2007
"{90120000-0015-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-041D-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Swedish) 2007
"{90120000-0016-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0017-041D-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (Swedish) 2007
"{90120000-0017-041D-0000-0000000FF1CE}_OMUI.sv-se_{0D91BBE6-10C4-419E-887C-EB9455BF7D73}" = Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-041D-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Swedish) 2007
"{90120000-0018-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-041D-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Swedish) 2007
"{90120000-0019-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-041D-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Swedish) 2007
"{90120000-001A-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-041D-0000-0000000FF1CE}" = Microsoft Office Word MUI (Swedish) 2007
"{90120000-001B-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_OMUI.sv-se_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_OMUI.sv-se_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040B-0000-0000000FF1CE}" = Microsoft Office Proof (Finnish) 2007
"{90120000-001F-040B-0000-0000000FF1CE}_OMUI.sv-se_{C3B4672B-3FE7-4D6F-AFF3-80D290C1131E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-041D-0000-0000000FF1CE}" = Microsoft Office Proof (Swedish) 2007
"{90120000-001F-041D-0000-0000000FF1CE}_OMUI.sv-se_{4A960AFC-E28F-4233-953F-1903BE859B79}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-041D-0000-0000000FF1CE}" = Compatibility Pack för Office 2007-systemet
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-041D-1000-0000000FF1CE}_OMUI.sv-se_{18651597-9190-4C03-902A-6F8F58A91A3E}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-002C-041D-0000-0000000FF1CE}" = Microsoft Office Proofing (Swedish) 2007
"{90120000-0044-041D-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Swedish) 2007
"{90120000-0044-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-041D-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Swedish) 2007
"{90120000-006E-041D-0000-0000000FF1CE}_OMUI.sv-se_{18651597-9190-4C03-902A-6F8F58A91A3E}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-041D-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Swedish) 2007
"{90120000-00A1-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-041D-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Swedish) 2007
"{90120000-00BA-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0100-041D-0000-0000000FF1CE}" = Microsoft Office O MUI (Swedish) 2007
"{90120000-0100-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0101-041D-0000-0000000FF1CE}" = Microsoft Office X MUI (Swedish) 2007
"{90120000-0101-041D-0000-0000000FF1CE}_OMUI.sv-se_{6DB23E19-BC1C-4C62-8158-391F65D84457}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-041D-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (Swedish)
"{95D40BD8-2EA7-C51E-A218-B2F863481573}" = CCC Help Chinese Standard
"{98A7C691-304F-31DC-A21C-3675E1D68501}" = CCC Help Chinese Traditional
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AF58701-B88C-4106-BCCB-816AE6855486}" = CardRunnersEV
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A33B56D0-F273-F6C2-C335-50AE0C83C85C}" = CCC Help Finnish
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8CB3994-B273-D81E-315C-CA3A8376415E}" = Catalyst Control Center Localization All
"{A8D450FB-F8F7-4250-7CE3-A3C24CDE5722}" = CCC Help Hungarian
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AB82BA59-B05B-70DC-992B-D2D7A2AF4EE5}" = CCC Help Korean
"{AFECFED6-0A43-488F-8511-1DC6B52F31C3}_is1" = Fast Duplicate File Finder 3.7.0.1
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B823632F-3B72-4514-8861-B961CE263224}" = PostgreSQL 8.3
"{BB285C9F-C821-4770-8970-56C4AB52C87E}" = Skype Click to Call
"{BFB59706-4FEC-37A8-96CD-C7F6932AD6DD}" = CCC Help Norwegian
"{C0608AE3-FAFD-4702-A79C-67CC6A2F71B7}" = WBaduk
"{C09EECFB-8925-5E54-1580-3FAEB6A78856}" = Catalyst Control Center Graphics Light
"{C0ED2557-8BCC-71B6-253C-BDFE26A9B37D}" = CCC Help Spanish
"{C29E675E-4439-4090-9C7D-F24A00AADD04}" = GoPanda2
"{C5288856-CAB4-432A-8CF2-CFCA60A0D36E}" = Mobile Broadband
"{C8773FDB-D0DB-BE52-D536-F48F9886B57B}" = Adobe Download Assistant
"{CC62C6C8-0D7F-3F0D-9BD6-49CB16029A6A}" = CCC Help Greek
"{CC6D2A70-B152-E250-ABEA-5D7D681469F8}" = CCC Help English
"{CD11704A-4B99-4666-8681-ADA43EC3B3FD}" = Huawei Driver Installation
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.124.1120
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{D9D22492-C0B2-49F5-AD1E-BB38E81E7DB5}" = FusekiLibrary
"{DAFFBC42-ABA2-882C-68CB-593B9CF9ACF5}" = CCC Help Russian
"{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}" = Alcor Micro USB Card Reader
"{DCAB6BA7-6533-44BF-9235-E5BF33B7431C}" = Windows Live Writer
"{DFF2D0B9-1706-6AA8-85CD-A70DF44AE3F8}" = CCC Help Danish
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E121A4FE-009B-385B-BB0D-B934E2A88288}" = Google Talk Plugin
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E6AAFC37-EB31-768D-A9A5-AA8A84612615}" = CCC Help Dutch
"{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}" = Google Drive
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.01.192
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6B7BF58-36D0-A76E-53E2-F65DBD4A6A52}" = Catalyst Control Center InstallProxy
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FFE13E36-6C99-4D46-BF65-0E8239C4E022}" = Sierra Wireless Watcher
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"Anki" = Anki
"ASIO4ALL" = ASIO4ALL
"avast" = avast! Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data" = Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data
"Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data" = Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MG6100 series användarregistrering" = Canon MG6100 series användarregistrering
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Death Rally" = Death Rally for Windows
"Drago_is1" = Drago 4.21
"DreamPie" = DreamPie
"Dungeon Keeper II" = Dungeon Keeper 2
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-PhotoPrint Pro" = Canon Easy-PhotoPrint Pro
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Edraw Max_is1" = Edraw Max 7.6
"Elasto Mania" = Elasto Mania
"FL Studio 10" = FL Studio 10
"Foxit Reader_is1" = Foxit Reader
"Git_is1" = Git version 1.7.9-preview20120201
"Google Chrome" = Google Chrome
"GOWrite2_is1" = GOWrite 2 version 2.3.28
"GridVista" = Acer GridVista
"HoldemManager2" = Holdem Manager 2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Identity Card" = Identity Card
"iid" = Net iD 5.7.1 (32-bit Edition)
"IL Download Manager" = IL Download Manager
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager
"InstallShield_{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}" = Alcor Micro USB Card Reader
"Kombilo_is1" = Kombilo 0.7.4
"Little Fighter 2" = Little Fighter 2 1.9c
"LManager" = Launch Manager
"LyX205" = LyX 2.0.5
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Maxima-5.28.0-2_is1" = Maxima 5.28.0-2
"McAfee Security Scan" = McAfee Security Scan Plus
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"MiKTeX 2.9" = MiKTeX 2.9
"Miranda IM" = Miranda IM 0.9.37
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 19.0.2 (x86 sv-SE)" = Mozilla Firefox 19.0.2 (x86 sv-SE)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"Notepad++" = Notepad++
"OMUI.sv-se" = Microsoft Office Language Pack 2007 - Swedish/svenska
"Opera 12.14.1738" = Opera 12.14
"OPoker.com" = OPoker.com
"PartyPoker" = PartyPoker
"PhotoStitch" = Canon Utilities PhotoStitch
"PokerCoach_is1" = PokerCoach
"PokerStars" = PokerStars
"PokerTracker3" = PokerTracker 3 (remove only)
"PokerTracker4" = PokerTracker 4 (remove only)
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Revo Uninstaller" = Revo Uninstaller 1.94
"SmoothDraw_is1" = SmoothDraw 3.2.10
"SpeedFan" = SpeedFan (remove only)
"Spotify" = Spotify
"StarCraft II" = StarCraft II
"Svenska Spels Poker " = Svenska Spels Poker
"TeamViewer 6" = TeamViewer 6
"TexMakerX_is1" = TexMakerX 2.1
"Tygem Baduk" = TygemBaduk Remove
"Update Engine" = Sony Ericsson Update Engine
"uTorrent" = µTorrent
"WinLiveSuite" = Windows Live Essentials
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 2.1.3
"VoiceMix_is1" = VoiceMix v1
"XMind_is1" = XMind 2013 (v3.4.1)
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CGoban 3-NFA" = CGoban 3-NFA
"Dropbox" = Dropbox
"Flux" = f.lux
"FoxTab PDF Creator" = FoxTab PDF Creator
"Octoshape Streaming Services" = Octoshape Streaming Services
"Spotify" = Spotify
"uTorrent" = µTorrent
"Viber" = Viber
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 2014-03-07 15:30:03 | Computer Name = Jens-Dator | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Det gick inte att extrahera tredjepartsrotlista från autouppdaterings-CAB-filen
 Fel: Ett nödvändigt certifikat är inte inom sin giltighetstid när det verifieras
 mot den aktuella systemklockan eller tidsstämpeln i den signerade filen.  .
 
Error - 2014-03-09 13:19:28 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-13 12:25:33 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-15 08:24:53 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-15 13:17:47 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-17 12:24:18 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-17 15:32:59 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-17 15:39:38 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-17 15:47:45 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-18 12:48:15 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-19 14:05:11 | Computer Name = Jens-Dator | Source = Steam Client Service | ID = 1
Description = Error: Failed to poke open firewall
 
Error - 2014-03-30 07:32:27 | Computer Name = Jens-Dator | Source = Application Error | ID = 1000
Description = Felet uppstod i programmet med namn: Viber.exe, version 3.1.0.887,
 tidsstämpel 0x51d96f48  , felet uppstod i modulen med namn: Qt5Gui.dll, version 5.1.1.0,
 tidsstämpel 0x522099d2  Undantagskod: 0xc0000005  Felförskjutning: 0x0002ce00  Process-ID:
 0x1364  Programmets starttid: 0x01cf4c09e273ccf4  Sökväg till program: C:\Users\Jens\AppData\Local\Viber\Viber.exe
Sökväg
 till modul: C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\Qt5Gui.dll  Rapport-ID: 
f844ea47-b7fe-11e3-94d1-be646f51746b
 
[ OSession Events ]
Error - 2010-11-21 21:02:04 | Computer Name = Jens-Dator | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 2012-05-09 06:35:25 | Computer Name = Jens-Dator | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.6654.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 992
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 2012-05-09 19:09:52 | Computer Name = Jens-Dator | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
 12.0.6654.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 628
 seconds with 0 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 2014-04-06 05:14:57 | Computer Name = Jens-Dator | Source = PNRPSvc | ID = 102
Description = 
 
Error - 2014-04-06 05:14:57 | Computer Name = Jens-Dator | Source = Service Control Manager | ID = 7023
Description = Tjänsten PNRP (Peer Name Resolution Protocol) avbröts med följande
 fel:   %%-2140993535
 
Error - 2014-04-06 05:14:57 | Computer Name = Jens-Dator | Source = Service Control Manager | ID = 7001
Description = Tjänsten Peer Networking Grouping är beroende av tjänsten PNRP (Peer
 Name Resolution Protocol). Den sistnämnda kunde inte starta på grund av följande
 fel:   %%-2140993535
 
Error - 2014-04-06 05:15:06 | Computer Name = Jens-Dator | Source = PNRPSvc | ID = 102
Description = 
 
Error - 2014-04-06 05:15:06 | Computer Name = Jens-Dator | Source = PNRPSvc | ID = 102
Description = 
 
Error - 2014-04-06 05:15:06 | Computer Name = Jens-Dator | Source = Service Control Manager | ID = 7023
Description = Tjänsten PNRP (Peer Name Resolution Protocol) avbröts med följande
 fel:   %%-2140993535
 
Error - 2014-04-06 05:15:06 | Computer Name = Jens-Dator | Source = Service Control Manager | ID = 7001
Description = Tjänsten Peer Networking Grouping är beroende av tjänsten PNRP (Peer
 Name Resolution Protocol). Den sistnämnda kunde inte starta på grund av följande
 fel:   %%-2140993535
 
Error - 2014-04-06 05:15:06 | Computer Name = Jens-Dator | Source = Service Control Manager | ID = 7023
Description = Tjänsten PNRP (Peer Name Resolution Protocol) avbröts med följande
 fel:   %%-2140993535
 
Error - 2014-04-06 05:15:06 | Computer Name = Jens-Dator | Source = Service Control Manager | ID = 7001
Description = Tjänsten Peer Networking Grouping är beroende av tjänsten PNRP (Peer
 Name Resolution Protocol). Den sistnämnda kunde inte starta på grund av följande
 fel:   %%-2140993535
 
Error - 2014-04-06 05:18:10 | Computer Name = Jens-Dator | Source = Service Control Manager | ID = 7022
Description = Tjänsten Windows Update stannade under start.
 
 
< End of report >

  • 0

#4
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,700 posts
Hey,
now we are going to remove the nasty animals in your computer.

Step 1: P2P Warning

IMPORTANT I see, you have one or more P2P (Person to Person) programs installed.

1.) You have following P2P program installed: u Torrent
2.) If you download files from non-documented sources per a P2P File sharing Program, you can expect a infection of malware. That isn't good for your PC. A long time ago File-sharing with P2P programs like UTorrent was fairly safe. But at this time it isn't true any more. Of course you can use P2P programs at your own risk, but that is maybe your source of your infection. It would be nice if you read this here. So after reading the text you will recognize why you shouldn't have them.
3.) Please read this reports about the danger of P2P Programs:
  • Cyber Education
  • 500000 computers infected
  • USA
  • infoworld
4.) I would recommend that you uninstall the above. That would be nice. If you like to uninstall the P2P Program, you can do it via Start >> Control Panel >> Add or Remove Programs
5.) If you want to keep the program on your computer , don't use it while we are fixing your computer!

Step 2: Multiple AV's

I notice that you have multiple anti virus programs installed on your system. If more than one program is running real time protection, then there is a very high chance of conflicts being created. This could cause the programs to 'fight' against eachother and they may render the other useless, hence reducing your protection. It is very important to ensure that you are only running one anti virus program at the same time.

Please remove avast FreeAntivirus or AVG2012 before we continue. If you are unsure about how to do this, a list of removal tools can be found here:

http://kb.eset.com/e...tent&id=SOLN146

Step 3: FreeSpace Warning

I see you have only less than 15% free space on your PC. That is another reason for the slowness of your computer. Because of that I recommend uninstalling software which you don't use at all.

Step 4: Uninstalls
  • Click on the Start Start%20Orb.jpg button and select Control Panel
  • Click on Programs then click on Uninstall a program
  • You will now see a list of your installed software, double click on the following one by one to uninstall them:
    • ssafeweb
    • SW-Sustainer 1.80

  • Once you have done this, reboot your computer
Step 5: Chrome Homepage

Please visit this site here and change the homepage to whatever you want. I recommend changing it to Google.com.

Step 6: Chrome Extensions

Run Chrome and please enter this into the address bar: chrome:extensions
This will display a page of all installed extensions. Please remove the extensions in the list below by clicking the trash can icon beside each one.

Extensions to be removed:
  • Speed Surfing
  • sAfewaeb
Step 7: OTL Fix
  • Run OTL (If you have Windows Vista / Windows 7 / Windows 8 please do a Right click on the OTL icon and select Run as Administrator).
  • Copy (Ctrl+C) and Paste (Ctrl+V) all of the following text into the Custom Scans/Fixes box:


    :Commands
    [CREATERESTOREPOINT]
    
    :OTL
    FF - user.js - File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@se.nexus/Personal:  File not found
    FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Jens\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll File not found
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\AddLyrics\FF\
    File not found (No name found) -- C:\USERS\JENS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XGQ5BM67.DEFAULT\EXTENSIONS\{7690B97E-E48F-4053-8C05-91F0772BFA6C}
    File not found (No name found) -- C:\USERS\JENS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XGQ5BM67.DEFAULT\EXTENSIONS\[email protected]
    O3:64bit: - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O4 - HKLM..\Run: []  File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Jens\Desktop\PartyPoker.lnk File not found
    O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Jens\Desktop\PartyPoker.lnk File not found
    O13 - gopher Prefix: missing
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL) -  File not found
    O20 - AppInit_DLLs: (c:\progra~2\sw-boo~1\assist~1.dll) -  File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    [2014-04-04 15:48:02 | 000,000,000 | ---D | C] -- C:\ProgramData\GreenApp
    [2014-04-04 15:46:20 | 000,000,000 | ---D | C] -- C:\ProgramData\ssafeweb
    [2014-04-04 15:46:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ssafeweb
    [2014-04-04 15:45:48 | 000,000,000 | ---D | C] -- C:\ProgramData\39b559e409962429
    [2013-08-21 03:51:06 | 000,005,085 | ---- | C] () -- C:\ProgramData\kmytnfun.aqy
    [2013-07-05 06:58:56 | 000,005,079 | ---- | C] () -- C:\ProgramData\lrbivjdu.eai
    [2013-06-19 22:19:36 | 000,005,076 | ---- | C] () -- C:\ProgramData\flwjycbm.bab
    [2013-02-06 14:05:50 | 000,723,230 | ---- | C] () -- C:\Windows\unins000.exe
    [2013-02-06 14:05:50 | 000,210,747 | ---- | C] () -- C:\Windows\unins000.dat
    [2012-05-28 12:41:10 | 000,034,814 | ---- | C] () -- C:\Users\Jens\AppData\Local\dt.dat
    [2011-12-27 09:50:32 | 000,000,600 | ---- | C] () -- C:\Users\Jens\AppData\Local\PUTTY.RND
    [2010-09-27 19:21:10 | 000,005,077 | ---- | C] () -- C:\ProgramData\bltofzsb.qlf
    [2014-02-17 16:58:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\155856
    [2013-02-06 14:07:17 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\CRDeltaTB
    [2013-06-19 06:24:55 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Roaming
    @Alternate Data Stream - 168 bytes -> C:\ProgramData\Temp:0B4227B4
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:0B9176C0
    
    :Commands
    [EMPTYTEMP]
    
  • Click the Run Fix button.
  • After your computer has rebooted, post the Fixlog into your next reply
Step 8: Junkware Removal Tool

thisisujrt.gif  Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 9: OTL Quickscan
  • Run OTL by double-clicking on it. (If you have Windows Vista / Windows 7 / Windows 8 please do a Right click on OTL.exe and select Run as Administrator)
  • Click Quick Scan to start OTL.
  • When OTL finishes scanning, a logs, OTL.txt will open.
  • Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this log into your next post please.
Step 10: Question

How is the PC running?
  • 0

#5
okiol

okiol

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts

I have skipped 1. and 3., and done everything else line by line, including half of 4., but after that I arrived at a problem with this: SW-Sustainer 1.80

 

When I try to uninstall it there is an error message: "An error occured while starting C:\PROGRA~2\SW-BOO~1\ASSIST~1.DLL"

 

I'll await more instructions before I continue with the remaining steps.


  • 0

#6
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,700 posts

I'll await more instructions before I continue with the remaining steps.

Ignore that step for now. Please proceed with the other steps, thanks!
  • 0

#7
okiol

okiol

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts

step 7:

 

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@se.nexus/Personal\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3\ deleted successfully.
Registry value HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected] deleted successfully.
File C:\Program Files (x86)\AddLyrics\FF not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\!{2318C2B1-4965-11d4-9B18-009027A5CD4F} deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\!{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\!{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\!{2318C2B1-4965-11d4-9B18-009027A5CD4F} deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\!{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\!{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Low Rights\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Starting removal of ActiveX control {7530BFB8-7293-4D34-9923-61A11451AFC5}
C:\Windows\Downloaded Program Files\OnlineScanner.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~2\sw-boo~1\assist~1.dll deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
C:\ProgramData\GreenApp\Setup folder moved successfully.
C:\ProgramData\GreenApp folder moved successfully.
C:\ProgramData\ssafeweb folder moved successfully.
C:\Program Files (x86)\ssafeweb folder moved successfully.
C:\ProgramData\39b559e409962429 folder moved successfully.
C:\ProgramData\kmytnfun.aqy moved successfully.
C:\ProgramData\lrbivjdu.eai moved successfully.
C:\ProgramData\flwjycbm.bab moved successfully.
C:\Windows\unins000.exe moved successfully.
C:\Windows\unins000.dat moved successfully.
C:\Users\Jens\AppData\Local\dt.dat moved successfully.
C:\Users\Jens\AppData\Local\PUTTY.RND moved successfully.
C:\ProgramData\bltofzsb.qlf moved successfully.
C:\Users\Jens\AppData\Roaming\155856 folder moved successfully.
C:\Users\Jens\AppData\Roaming\CRDeltaTB folder moved successfully.
C:\Users\Jens\AppData\Roaming\Roaming\HoldemManager\config folder moved successfully.
C:\Users\Jens\AppData\Roaming\Roaming\HoldemManager folder moved successfully.
C:\Users\Jens\AppData\Roaming\Roaming folder moved successfully.
ADS C:\ProgramData\Temp:0B4227B4 deleted successfully.
ADS C:\ProgramData\Temp:0B9176C0 deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administratör
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Gäst
 
User: HomeGroupUser$
 
User: Jens
->Temp folder emptied: 3129529776 bytes
->Temporary Internet Files folder emptied: 33036604 bytes
->Java cache emptied: 1727183 bytes
->FireFox cache emptied: 5060358 bytes
->Google Chrome cache emptied: 339081506 bytes
->Opera cache emptied: 52990276 bytes
->Flash cache emptied: 80474 bytes
 
User: postgres
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: postgres.Jens-Dator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 79932294 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 108341902 bytes
RecycleBin emptied: 34264822 bytes
 
Total Files Cleaned = 3 609,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 04072014_161819
 
Files\Folders moved on Reboot...
C:\Users\Jens\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\Low\SkypeClickToCall\Logs\AutoUpdateSvc.log scheduled to be moved on reboot.
 
PendingFileRenameOperations files...
 
Registry entries deleted on Reboot...
 
 
step 8:
 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Jens on 2014-04-07 at 17:19:37,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2523931591-3497646636-795491354-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\addlyrics1050_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\addlyrics1050_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\addlyrics1050_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\addlyrics1050_RASMANCS
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\Users\Jens\appdata\locallow\datamngr"
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{001C7053-B69C-48A3-B74B-D57BF9763C24}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{00C37511-BC3D-4D90-AD66-80B5C322FDBB}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{03EC947B-496F-400A-B078-9B41109B57A0}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{040E2993-B141-4E1D-8DFB-4E7FD9DFE40F}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{04843A6F-54F5-4F09-96C5-120336153B37}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{064289E1-CF9C-4968-AE49-C427DA93AA66}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{066EB372-FFED-499A-BD8E-3F1AF2E27282}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{06A55869-9727-4841-A8B9-604BDCD06E51}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{06E995A3-1F15-43A1-89D5-52CCB533AB90}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{078C1825-EAFB-487C-86C2-E8F4B79F6DDF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{0950798E-9121-4E05-BB6E-A052B7DCC652}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{09DB0772-CC6B-47C0-B026-12AE2DC5373A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{0A313555-C502-4FA5-888D-E209433544A9}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{0B0EE2DF-49F9-4A2F-9243-91625D946EC8}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{0E3F8F09-AE81-4E86-90D9-D71D68B9AA73}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1089DF05-637E-4F0E-B40B-38644A3D511C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{10A9F084-965E-4AC8-91E8-570F7A47F8E4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1308EB9F-F469-428E-A00B-98F1FAF48535}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{141BD8B1-D730-4988-BE2A-A8F8B973E046}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{14467C2F-A8F5-4BE5-950C-69A63E4DAD17}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1611308F-8EC9-4AFC-B557-53985030BEF8}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{165342FB-2F26-4F31-8DA5-82611DB343CC}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{16889E56-A702-400F-BBD3-294D279F2AB4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1A18E438-7610-4E02-B21C-A892BF12E52D}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1A485484-9C1E-478A-A86F-FF67A9777B7F}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1B0ECA8E-101B-4031-A96C-8F40985A3ACF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1D126FB6-B623-4DA9-9A1A-D7B60835181A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1D8AD12D-B052-4787-9DE5-D8BBA4A87CF6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1F0A49AE-97BB-47F1-B5ED-0FF5BDFCE29B}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{1F4FCD75-A20B-4138-A21C-47FB258432C9}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{234FAF14-33B7-4B83-82D9-E910F4DDE5CA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2375BAD3-2DC8-47F8-B54C-8001EAE3490A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2438FD83-2C41-4343-B359-15A765D234B2}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{24E7DD03-593C-4A92-BB6C-50CF68B035EF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2564A486-5E9C-4168-A2FB-222B93E10600}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{25B2332A-DB19-4DEF-A10A-89C1C139B9D8}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{29383863-8137-44A1-AF8C-CB804C56C918}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{29A64DE7-EF14-4E73-AA59-25743E594629}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2AC187AB-2958-47D9-99BA-20D66E368965}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2AE0A9EF-3EF9-4780-A836-1756714F3BCC}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2C67140F-20C1-4BD2-A384-B9B13D1B9B38}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2C8804C0-09DC-43BC-BF8F-E7A08B92CA41}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2E05D475-2A5A-462F-85A7-09E7C36858F6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2E7D6737-0B95-4CFB-92C4-FA60C76695F2}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2EEA5E75-DC63-44A5-A09B-2FCF823ED833}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2F42A620-6325-4A90-A319-8C149BFDE05D}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{2FA1CDF4-BB29-431E-98A7-7C616C442318}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{30648FD4-590D-436B-A929-FDFF2964EFFB}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{31614D86-EDC4-42AE-8F44-469475E51825}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{31B06BA3-8C9D-48AF-AA93-7BF7DE98646F}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{31D3D072-BA38-4FDC-9C6E-60A73D7874EE}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{31F99D58-4B5E-43F7-860A-B2AB0A44639A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{32FCAD69-B7D6-4AB5-8358-912F6FC0D3A9}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{34FF0CD2-25F1-431F-B839-F96E11F3C6E2}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3520CFBA-4724-4BA6-8771-F1BF8317E3AE}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3733F23B-BE08-47B4-9F21-A04240309598}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3A1258AC-23B4-40B5-B241-160CE82A22FF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3A59F6A6-F4A9-42A2-BBAE-5B7A585532AA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3A722698-0E5D-40D1-9FA0-3E26DBD44807}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3B1CE2ED-7DB6-4AEF-9AB5-FFC35801FE4C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3B2EB553-C20F-41B1-B661-EA3C04500133}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3B6CDE61-AD8B-4F8A-B94C-8E2EB7E75626}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3BBF2E46-8E54-43E4-9790-5E0C87206EB4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3C150C29-87A4-46B8-A92D-6BAABF0685B6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3C7CC0BB-BEF6-445B-AB77-A0003A9E775A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3D269714-8F85-4A84-989A-0B22D4B096AF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{3F64CA24-A4F9-4FEB-8B1A-90F40E49EC89}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{40287DC0-A5FC-403B-89BC-71AA53482FA8}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{40718729-4AC9-4DD6-BBF0-4B7AA5534C39}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{409D1CC0-23B1-47E9-9B7E-719615E1F429}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{40A25E74-7BCF-4A2F-B5A8-E930E723F87A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{42EA4010-06E4-4401-8C1F-A738E13779CC}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{44B7538F-9FC0-46A8-A3B0-9129A8807DDD}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{45CB5BC8-B065-45DF-B02B-E68B41E5601D}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{466AC73E-B929-4C35-BB0A-C953D4567161}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{46AD759B-AA72-48D7-A6D5-8D933A54A2BD}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{4B6306A9-8381-4146-B824-B54F6CEB4CB7}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{4EC6153B-F89C-46F2-9F00-6B57EF65F601}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{4F6BC461-DFB8-4302-85EF-224FE1CE2F0B}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{5008A98B-2FB7-4610-AA80-55A6E3174331}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{5073369A-C569-4D20-B2FA-4F644D2370CF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{50F663F5-4ED8-44DA-8C89-2111716CEC2F}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{530F9872-E951-4539-A65B-A8658203C936}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{532B7037-066F-4F6A-8C89-3E5F0709C29D}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{536D9647-7BF2-419C-8C34-470BF8A041E4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{58C7C6DD-096E-4127-AAF5-915A30693C58}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{5A713FD3-3C50-4FFF-BD05-4DC0E219B792}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{5C188FD0-BCE0-4751-A48E-F320E5C1DE86}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{5C438D76-5993-46F4-B5AC-54984455CAEA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{5C656C9D-A496-4712-A734-CC6568537147}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{5F5E3100-EA93-4893-B1B1-96B23EEC74AA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{61DB6492-202E-47C5-87A9-948682DC495D}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{65ABF7FC-C68F-4A72-AC72-DCC1C5A64717}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{65BB060C-3E0C-4296-8D9C-92A74C7D11A6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{65DBD621-55AD-42BF-A19E-563E6F158B31}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{6A66B887-2C5F-42C9-8ACC-CFFA3B8E95DA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{6BC639B5-F6F1-4E2A-AEBF-78DEEE853A89}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{6CAE581B-8FB0-410A-BD75-5EBD30C8C398}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{6CE8EEAA-A60C-406D-9386-BD96EA74637C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{6E0E08D0-562D-4A81-9B13-D8697D35DEA2}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{6E6C3476-D4BF-4795-B45A-8433F5967F42}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{6EA8586C-EBD8-49D9-B7A0-B4D57CDBCD72}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{6F2C28A6-2497-4FC5-BC52-3219304BCCA3}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{70985A4A-0277-4C8D-8D8D-23AC71FB029D}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{7264CA57-BE2D-4D20-9995-D1E502879200}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{726DBD86-B97F-49AE-B956-D9DA10289979}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{726F2DC6-3E87-4391-BB87-9BAC6CE4F708}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{72FD7095-3F69-4288-90AE-BF2E9BDDECF6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{73A42278-CEC3-4869-8F3B-7D0945A405F5}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{7487101D-B91D-446F-94FA-A21E712A0073}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{76E7874C-B45A-43AA-94B5-85A4F668E1E3}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{776E25D6-F350-42BE-A42A-9E7F27D3FEB4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{777F22F9-7126-4425-8750-094C0461A732}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{77F303AB-DD9B-48A3-93AA-76D44B68B421}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{797FF0AD-B508-4A23-BE71-C747F672A66A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{7ABBCE9A-3A85-4A28-BCB2-2E6D36C69781}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{7C39DBC0-2BBE-4F45-AFD3-97CD715A8ADA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{7C8BEC88-4542-4108-AA14-BC08EA8C5CFF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{7D107635-6EB4-4F85-B03D-BE0D7EFB27CF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{7E2D5E25-070E-476D-BC5D-1BD0FC083546}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{80F6F828-73B6-4402-8FFD-F7D7CCB4D748}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{80FBB1FD-1AD5-499F-9658-CD4B153B148B}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{8256FBBD-0A26-495E-8BB6-E8F408A47F31}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{831EAF65-094F-40E7-AC30-EE8BE4EF21CA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{8512B081-453F-4C73-9C9A-61F0B5C89AF3}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{8575CD77-B611-4CEB-A479-51B870660142}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{862AE1A2-69D6-412A-844E-55D404A0F74E}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{875CED51-D10B-4F63-B429-A2005C8D095F}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{87622773-ADE9-4C01-8F84-A71E267DF37E}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{87E9EB1C-4CC0-4CDE-92AC-F01C9278B811}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{88B6779A-80BD-4F4A-B6AC-2E43CBD2C7F3}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{8A8EBA6C-519B-43CC-8132-4D99B2614446}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{8E811594-B058-401F-80FF-C9A0665B7FFA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{8EDD722C-B49E-404B-AB4B-531E86FAD6D1}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{8F1E2D3F-18B7-4B96-8874-BA5BC8C5DF11}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{912BF16C-38E8-4F0E-A37E-D3BC53166BD6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{91E19168-CADE-4004-A97F-4F904BCFD77B}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{949364D9-21EC-4945-BB4C-8859BF16ECAF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{9589DD1F-9F5E-4EFF-8EF0-6A9EE8F30572}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{95F22D6B-CCC6-4A36-A644-90F72EAC62D5}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{984CC6FF-9CE8-4D97-A4B4-3189C4901D6C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{98FF9FBF-B2DA-4E4A-BC1D-0779EFE490B6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{994CEB59-531A-43E0-8429-FD341D122FB1}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{996BD726-CC90-4FC7-813F-1B757A609127}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{A267F4AE-C18F-4F70-B1FA-AAFA073CC91D}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{A46E97E1-B2B7-426B-85F0-5F350F4E7F20}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{A61B3592-BFB9-4253-855B-B4C27277E742}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{A74B8C38-6749-4CBA-9F0B-7224156C0662}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{A8F09B7F-3F35-4FA9-9B3D-83751399C3DC}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{AB03599F-448D-4944-846B-77F6B453E2A5}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{AC56CDF0-5739-4735-AC44-B3C67A8F6E76}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{AF7BC0A4-A600-4A11-8566-D1439B273F99}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B0D4B03B-3D08-4FE8-8D59-AE846E4D3D32}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B0DFA14D-E31A-4E7D-AAEF-F16B51D2CCAD}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B0EF50D7-7BA0-4CCE-8605-0794B28BDF4A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B1A50CFA-C91A-4A31-B801-27A47632FBB4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B363F4FC-88DF-4F7A-A0A8-1FD3CA9458B0}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B41C40D2-BF81-4772-B041-33F7A0D3025C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B4318A6F-F7AA-46D9-9AB5-D6FE70772531}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B4964D84-DD7F-4080-BA4D-008D86E0AEC2}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B5853F43-3F40-4E59-86A7-F9277E8B6AE4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B5C0EA80-13F6-4499-8257-F5BFDB0D9F2B}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B97BB50F-B1B9-4431-9F43-FAB929384A6B}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{B989BB5F-2406-4C6E-8395-4B22B2B20A0A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BA09D085-FBEC-4391-BF62-D33BF07F163F}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BA89A2BF-26A1-4528-917E-ECF3D1A2876E}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BBADF8D4-E8CA-4BB0-BE7D-D1084D752732}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BBDE659A-C318-4B29-86CE-15D242DF9105}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BC7090D9-D208-482E-A5EA-8B053794F934}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BE96865C-5279-4B44-A30F-00843897FA94}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BEA23BE7-382F-43EB-AC1D-B26EFB83216C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BFD030A4-57D7-42EB-A476-E16828F93F0C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{BFFC9200-CB90-4485-8B0A-2AE071C20EC6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C0467A15-A42A-4623-966E-E8322A8CF42B}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C123ACF6-BBC0-4575-BCBE-22DA5E4C1A31}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C284E505-ED52-479B-B9AB-47C85C34B181}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C3DBB60A-BBBC-41F1-B179-B321C1F01804}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C3DCEEAB-ADB6-4631-8624-74CA84D0D6D4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C40F95BB-8D49-45E9-8ABD-7BC9B4268B30}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C541A426-F14E-4431-A2B5-96A6E9507360}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C606E52D-C811-4D8F-A1A7-038801420BD9}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C6DE1C78-5DCA-47DE-B21F-BD144576638F}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C808D4BF-5672-49A3-B27E-05E90BDCCD7A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{C9B5A8B5-60FD-424B-80B3-934E813DC758}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{CA276CFF-0037-43E5-AFAD-623DF7F00DF4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{CA5E423E-890F-48F5-989A-9E9972AEB938}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{CC4EFAAE-E4F2-48B8-86BB-620F6BFB88DF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{CD4C6D90-80EC-43A6-B648-7E3502EFE350}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{CE0F4D99-E5A8-4163-BA06-338C0921A651}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{CF315773-F1E8-4D31-A45D-5923F8722654}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{CF8DBA0C-C008-4AE9-8483-297A154567A8}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D2950FDB-8381-4413-ADA9-AC793DD77D46}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D3174755-59F1-4022-8216-2C92E6642F6A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D32B605B-194E-44FD-839C-5FD9AEE48FDE}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D48E02C2-8083-48A0-BCD1-56A4583C2B9B}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D497707D-0F12-49A4-8837-35A1945B35D8}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D5B2E889-FA51-49AB-9C6D-F37E5A779E93}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D6F53AC5-4E65-41CD-A9F4-A2E2010787CB}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D94C15DF-90B8-4500-9B52-FFED14ADC039}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D9957060-192A-47F5-B898-DD00BE7A0660}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{D9F9156E-EEBE-4703-9E53-114D4D516917}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DA689350-5FA9-474E-A0A5-B736787BB07E}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DAD66546-8171-40C1-84B2-FF52E1D37741}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DBB0C7B3-7583-4D72-B506-46033A4D4EA6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DBE6275B-FFE5-406C-B5FD-D305C849476D}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DC06D374-243E-4ACA-AC11-AC186AEE93BA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DD088EB2-2998-4234-8643-B2D38DA18644}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DD7EDD14-981C-403B-8D91-E0A01904D2A8}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DED22B12-FAC7-402C-B727-CA397DBD75B0}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DF99B8E3-E09B-488C-BC14-897A095C94EA}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{DFAB57DF-A476-43B3-B1BD-21FE4D2A8814}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{E0CD8D6E-5170-401C-9FC4-3D398A7BC243}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{E2AB5379-D906-4692-8AA5-CA074D4DDA2E}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{E36186C8-5495-4FD3-90B8-17E98ECF7079}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{E3D6FED7-97CF-4B6B-BAEF-D0A28A096189}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{E80329A0-30EF-4B98-9734-946FAC2F872A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{EBFF8440-A47D-465F-B2E8-EB6D3602E0CC}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{EE03BE36-FD4D-4006-9464-6E509CA1E6B2}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{EFE52430-F73B-46ED-9819-2C26A5D2C2FB}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F1CC5AB3-8BF0-4AF4-BD71-1652DA018BFB}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F209A88D-37B7-4B9C-B3D1-859D66608D12}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F405AFBE-B99A-4B55-A9B3-E519A0E90314}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F4D9622F-8AE0-4DF3-A7F0-0E0A2F787235}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F4FDD3EF-EB36-48A8-BD4A-9E6C37549424}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F5ABE7B4-29C2-415E-BA2F-C2442EE728E6}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F647966F-4385-45C9-85CF-005EA629A728}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F6A234D2-DA53-4014-A70D-F2EC9E026D90}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F6A83DA4-38BD-41C7-9B57-A4478B445F5C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F7004308-129F-4065-8D50-4B8C4F67783C}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F7489C43-1D88-4A6C-BFF4-DD5460E3883E}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F81D48CA-C5B2-4450-8C2E-E89730E0F779}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F89EE5B5-F7FD-4833-A9EB-3D7C0B1DE4F4}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{F8A0E300-33F8-4CBE-881C-17EADC99F4A2}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{FA3853D1-8356-4189-9F99-D0DC5EF1A7EF}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{FA6510FE-BAD7-4D2A-87A1-C47D6BBD817A}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{FAFB988E-FA26-4C52-8A9E-B1E61C442471}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{FBEE82D4-A202-47D4-8A8E-7508EEC80B58}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{FBF79336-E6A9-4E51-9623-5D40E17E3004}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{FCAB9A28-6B30-4ECF-A257-65AEC73DC596}
Successfully deleted: [Empty Folder] C:\Users\Jens\appdata\local\{FE610C80-290C-43E6-96A5-54D4C88FAC4F}
 
 
 
~~~ Chrome
 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\kdlfddggdloaadnphbhejknhaggjaeld
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2014-04-07 at 17:28:15,66
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
step 9:
 

OTL logfile created on: 2014-04-07 17:30:17 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Jens\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd
 
3,86 Gb Total Physical Memory | 1,14 Gb Available Physical Memory | 29,40% Memory free
7,73 Gb Paging File | 3,64 Gb Available in Paging File | 47,17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 490,00 Gb Total Space | 58,02 Gb Free Space | 11,84% Space Free | Partition Type: NTFS
 
Computer Name: JENS-DATOR | User Name: Jens | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014-04-07 17:15:55 | 001,016,261 | ---- | M] (Thisisu) -- C:\Users\Jens\Downloads\JRT.exe
PRC - [2014-04-06 11:21:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jens\Downloads\OTL.exe
PRC - [2014-03-19 17:44:46 | 032,667,896 | ---- | M] (Dropbox, Inc.) -- C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2014-03-15 02:50:42 | 000,859,976 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014-03-07 13:39:00 | 000,444,760 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
PRC - [2014-03-03 10:53:02 | 001,363,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014-03-03 10:52:32 | 001,748,608 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2013-09-20 16:29:04 | 009,828,864 | ---- | M] (Apache Software Foundation) -- C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
PRC - [2013-09-20 16:29:04 | 000,103,936 | ---- | M] (Apache Software Foundation) -- C:\Program Files (x86)\OpenOffice 4\program\swriter.exe
PRC - [2013-09-20 16:29:02 | 009,837,056 | ---- | M] (Apache Software Foundation) -- C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
PRC - [2013-07-07 15:38:18 | 000,912,904 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\Viber.exe
PRC - [2013-03-12 07:32:58 | 000,506,744 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2013-03-07 01:32:44 | 004,767,304 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013-03-07 01:32:44 | 000,045,248 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013-03-05 21:41:44 | 000,418,024 | ---- | M] (BillP Studios) -- C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2010-03-02 19:52:00 | 000,140,640 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
PRC - [2010-02-25 06:59:21 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2009-12-10 03:39:04 | 000,065,536 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe
PRC - [2009-12-10 03:37:16 | 003,690,496 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
PRC - [2009-11-02 01:39:48 | 001,094,736 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009-10-01 06:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009-10-01 06:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009-09-25 01:42:32 | 000,261,888 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2009-09-25 01:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2009-09-11 07:42:46 | 000,305,448 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
PRC - [2009-09-11 07:42:30 | 000,349,480 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
PRC - [2009-08-28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009-07-14 03:14:15 | 000,301,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
PRC - [2009-06-05 05:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009-06-05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2009-02-23 17:57:12 | 000,058,648 | ---- | M] (Sierra Wireless Inc.) -- C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\WaHelper.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014-04-07 16:55:54 | 000,041,984 | ---- | M] () -- c:\users\jens\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzqejeu.dll
MOD - [2014-03-15 02:50:40 | 013,637,448 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll
MOD - [2014-03-15 02:50:40 | 000,394,568 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
MOD - [2014-03-15 02:50:38 | 004,061,000 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll
MOD - [2014-03-15 02:50:35 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libglesv2.dll
MOD - [2014-03-15 02:50:34 | 000,100,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libegl.dll
MOD - [2014-03-15 02:50:32 | 001,647,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll
MOD - [2014-03-15 02:50:30 | 000,051,016 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll
MOD - [2014-03-13 12:14:41 | 000,622,592 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\sqldrivers\qsqlite.dll
MOD - [2014-03-13 12:14:39 | 014,442,496 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\libViber.dll
MOD - [2014-03-13 12:14:39 | 000,835,584 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\platforms\qwindows.dll
MOD - [2014-03-13 12:14:39 | 000,729,088 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\libGLESv2.dll
MOD - [2014-03-13 12:14:39 | 000,278,528 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qtiff.dll
MOD - [2014-03-13 12:14:39 | 000,221,184 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qmng.dll
MOD - [2014-03-13 12:14:39 | 000,212,992 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qjpeg.dll
MOD - [2014-03-13 12:14:39 | 000,098,304 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\qfacebook.dll
MOD - [2014-03-13 12:14:39 | 000,049,152 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\libEGL.dll
MOD - [2014-03-13 12:14:39 | 000,024,576 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qico.dll
MOD - [2014-03-13 12:14:39 | 000,024,576 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qgif.dll
MOD - [2014-03-13 12:14:39 | 000,016,384 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qwbmp.dll
MOD - [2014-03-13 12:14:39 | 000,016,384 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qtga.dll
MOD - [2014-03-13 12:14:39 | 000,016,384 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\imageformats\qsvg.dll
MOD - [2014-03-13 12:14:38 | 000,032,768 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\4.1.0.1703\iconengines\qsvgicon.dll
MOD - [2014-01-03 03:09:26 | 003,610,624 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013-09-20 14:50:06 | 000,988,160 | ---- | M] () -- C:\Program Files (x86)\OpenOffice 4\program\libxml2.dll
MOD - [2013-09-17 05:54:38 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\OpenOffice 4\program\libxslt.dll
MOD - [2013-08-23 21:01:44 | 025,100,288 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2013-07-07 15:38:18 | 000,912,904 | ---- | M] () -- C:\Users\Jens\AppData\Local\Viber\Viber.exe
MOD - [2013-03-31 18:40:20 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ac9e3eca6c148504588e7c6d09fe83e3\System.Management.ni.dll
MOD - [2013-03-31 18:38:33 | 000,096,768 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\a1b65a602c75409c0c1ce7fa1f2a0983\UIAutomationProvider.ni.dll
MOD - [2013-03-31 18:38:15 | 001,021,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\e7b4706dfe18f29486dbaf5d35e01765\System.Runtime.DurableInstancing.ni.dll
MOD - [2013-03-31 18:38:14 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ef7642a4f2724135d445e2ea36582e78\SMDiagnostics.ni.dll
MOD - [2013-03-31 18:38:13 | 002,647,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\910fe53ec2122cf3a2ad11c2b2f5cbfd\System.Runtime.Serialization.ni.dll
MOD - [2013-03-31 18:38:11 | 000,393,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\d01a925ecd339eae8ea1da8488eb2283\System.Xml.Linq.ni.dll
MOD - [2013-03-31 18:37:38 | 001,801,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll
MOD - [2013-03-31 18:37:28 | 000,044,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\e290208a6d4ea4451ac118f1e0c3b488\Accessibility.ni.dll
MOD - [2013-03-30 04:50:40 | 018,002,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\14f511c47523f19ca591eb207e9e2084\PresentationFramework.ni.dll
MOD - [2013-03-30 04:50:19 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e10fd15441d278c04a03302880a3e231\PresentationCore.ni.dll
MOD - [2013-03-30 04:50:15 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\39f4c7717661667c68f9af8c4f6402b9\System.Windows.Forms.ni.dll
MOD - [2013-03-30 04:49:52 | 003,858,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\7a9ff5ce3a909d075179a2ac70d8f388\WindowsBase.ni.dll
MOD - [2013-03-30 04:49:47 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll
MOD - [2013-03-30 04:49:43 | 000,309,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\82f376255a9523982c52cf58b13268d3\PresentationFramework.Classic.ni.dll
MOD - [2013-03-30 04:44:06 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll
MOD - [2013-03-30 04:43:58 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\5de5d8c1c02e33789e3cf7e3f54c0ec9\System.Configuration.ni.dll
MOD - [2013-03-30 04:43:41 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\27dcf04ed7a3506045597c02a5a1fc31\System.Core.ni.dll
MOD - [2013-03-30 04:43:29 | 009,094,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll
MOD - [2013-03-30 04:43:19 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll
MOD - [2012-12-10 03:46:38 | 000,600,868 | ---- | M] () -- C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll
MOD - [2010-02-25 06:59:21 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe
MOD - [2009-02-03 03:33:56 | 000,460,199 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2013-03-07 01:32:44 | 000,045,248 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2009-12-10 11:15:06 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009-11-02 22:48:18 | 000,126,352 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2009-10-03 04:39:44 | 000,873,248 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2009-10-01 00:44:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2009-07-14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2009-07-04 04:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Stopped] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009-03-28 04:10:16 | 000,016,896 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
SRV - [2014-03-03 10:53:02 | 001,363,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014-03-03 10:52:32 | 001,748,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014-02-05 13:50:04 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013-10-23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-03-07 16:29:15 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012-09-05 17:56:44 | 000,234,776 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe -- (McComponentHostService)
SRV - [2012-08-13 03:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012-02-14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011-06-01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011-04-20 14:50:18 | 000,152,064 | ---- | M] (Avanquest Software) [Disabled | Stopped] -- C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion)
SRV - [2010-03-18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-12-10 03:39:04 | 000,065,536 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe -- (pgsql-8.3)
SRV - [2009-10-01 06:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009-10-01 06:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009-09-25 01:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2009-09-11 07:42:46 | 000,305,448 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009-08-28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009-06-05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014-01-22 09:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2013-11-15 08:37:28 | 000,033,448 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzdaendpt.sys -- (rzdaendpt)
DRV:64bit: - [2013-11-15 08:37:24 | 000,030,888 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzvkeyboard.sys -- (rzvkeyboard)
DRV:64bit: - [2013-11-15 08:37:14 | 000,149,160 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd)
DRV:64bit: - [2013-03-07 01:33:21 | 001,025,808 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013-03-07 01:33:21 | 000,377,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2013-03-07 01:33:21 | 000,178,624 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2013-03-07 01:33:21 | 000,070,992 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2013-03-07 01:33:21 | 000,068,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2013-03-07 01:33:21 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013-03-07 01:33:20 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2013-03-07 01:33:20 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2013-03-07 01:33:20 | 000,022,600 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd)
DRV:64bit: - [2013-02-22 03:43:20 | 000,046,280 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\hssdrv6.sys -- (HssDRV6)
DRV:64bit: - [2012-11-09 00:33:17 | 000,030,568 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2012-09-20 06:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2011-04-21 14:16:32 | 000,027,176 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
DRV:64bit: - [2011-04-21 14:16:32 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
DRV:64bit: - [2011-01-15 18:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010-12-17 00:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010-08-29 17:11:08 | 000,021,072 | ---- | M] (Mobile Stream) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\easytthr.sys -- (easytether)
DRV:64bit: - [2009-12-10 13:40:30 | 006,179,328 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009-11-11 17:44:26 | 000,034,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\point64k.sys -- (Point64)
DRV:64bit: - [2009-11-06 22:56:06 | 001,550,848 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009-11-02 22:48:02 | 000,013,784 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2009-10-26 22:39:44 | 000,151,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009-10-12 15:23:22 | 000,114,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbdev.sys -- (hwusbdev)
DRV:64bit: - [2009-10-03 09:47:38 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2009-09-18 06:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009-09-17 22:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009-09-10 15:31:56 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2009-08-29 20:15:32 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2009-08-29 20:15:26 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2009-08-13 21:20:46 | 001,209,856 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:64bit: - [2009-08-06 14:43:58 | 000,320,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
DRV:64bit: - [2009-07-23 00:06:26 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2009-07-14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009-07-14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-07-14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-07-02 13:46:58 | 000,052,264 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2009-06-25 04:23:24 | 000,205,472 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2009-06-20 04:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E)
DRV:64bit: - [2009-06-10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009-06-10 22:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009-06-05 04:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009-06-03 05:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009-06-03 05:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009-06-03 05:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009-05-06 02:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009-05-06 02:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2009-04-08 16:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2009-02-25 11:44:10 | 000,195,456 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\swumxa3.sys -- (SWUMXA3)
DRV:64bit: - [2009-02-25 11:43:12 | 000,219,136 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\swnc8ua3.sys -- (SWNC8UA3)
DRV:64bit: - [2009-01-22 22:34:55 | 000,034,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\swmsflt.sys -- (swmsflt)
DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer...68z1i5t54j1d19p
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = 
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...68z1i5t54j1d19p
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer...68z1i5t54j1d19p
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = 
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.7
FF - prefs.js..extensions.enabledAddons: %7B7690b97e-e48f-4053-8c05-91f0772bfa6c%7D:1.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.3.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.3.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@bankid.com/BankID säkerhetsprogram,version=5.1.3.2: C:\Program Files (x86)\BankID\npBispBrowser.dll (Finansiell ID-Teknik BID AB)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.0.1818576\npmathplugin.dll (Wolfram Research, Inc.)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Jens\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jens\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jens\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012-09-10 16:33:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-22 21:35:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013-06-20 04:09:49 | 000,000,000 | ---D | M]
 
[2012-12-03 08:30:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jens\AppData\Roaming\mozilla\Extensions
[2014-04-07 11:17:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jens\AppData\Roaming\mozilla\Firefox\Profiles\xgq5bm67.default\extensions
[2014-04-07 11:17:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jens\AppData\Roaming\mozilla\Firefox\Profiles\xgq5bm67.default\extensions\staged
[2014-03-24 11:46:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
File not found (No name found) -- C:\USERS\JENS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XGQ5BM67.DEFAULT\EXTENSIONS\{7690B97E-E48F-4053-8C05-91F0772BFA6C}
File not found (No name found) -- C:\USERS\JENS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XGQ5BM67.DEFAULT\EXTENSIONS\[email protected]
[2013-05-28 15:23:38 | 000,249,136 | ---- | M] (SecMaker AB) -- C:\Program Files (x86)\mozilla firefox\plugins\npiidplg.dll
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\PepperFlash\12.0.0.70\pepflashplayer.dll
CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll
CHR - plugin: Net iD (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: NPCIG.dll (Enabled) = C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll
CHR - plugin: Wolfram Mathematica (Enabled) = C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.0.1818576\npmathplugin.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Java™ Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Nexus Personal (Enabled) = C:\Program Files (x86)\Personal\bin\np_prsnl.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Jens\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Jens\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jens\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll
CHR - Extension: YoutubeAdblocker = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbemjihlimhgfipfdbaeeilcilgjnllg\1.0\
CHR - Extension: YouTube = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Sök på Google = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: NextCoup = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcfijijikmncbeebokpkckgkpgnpfkao\1.0\
CHR - Extension: avast! WebRep = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1483_0\
CHR - Extension: Google Wallet = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Jens\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2013-02-09 22:36:12 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [Net iD] C:\Program Files\Net iD\iid.exe (SecMaker AB)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Net iD] C:\Program Files (x86)\Net iD\iid.exe (SecMaker AB)
O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
O4 - HKLM..\Run: [WatcherHelper] C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\WaHelper.exe (Sierra Wireless Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Viber] C:\Users\Jens\AppData\Local\Viber\Viber.exe ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Autostart - genväg (2).lnk = C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2014-04-07 11:47:33 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bok.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\Projekt 2014-10-09\bok.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Capture.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\RPM\Capture.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Jens\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Inspiration extras.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Hur man är en människa\Mentalt\Extras\Inspiration extras.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\länkar.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\glada saker\länkar.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Måluppnående - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående [2014-04-07 16:58:46 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Plan.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\Plan.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\random notes.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\random notes.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Results.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\RPM\Results.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Saker som gör mig glad.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Måluppnående\Projekt 2014-10-09\kväll\Saker som gör mig glad.odt ()
O4 - Startup: C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Short-term planning.odt - genväg.lnk = C:\Users\Jens\Dropbox\personlig utveckling\Tidsplanering\Short-term planning.odt ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O8:64bit: - Extra context menu item: Skicka bild till &Bluetooth-enhet... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Skicka sida till &Bluetooth-enhet... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Skicka bild till &Bluetooth-enhet... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Skicka sida till &Bluetooth-enhet... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.3.1)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_03)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1F47FF6-5D10-445E-9BB5-363E7C2754DE}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014-04-07 17:18:08 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014-04-07 16:18:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2014-04-07 11:17:26 | 000,000,000 | ---D | C] -- C:\ProgramData\NextCoup
[2014-04-07 11:17:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NextCoup
[2014-04-07 11:17:25 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Local\Torch
[2014-04-07 11:12:24 | 000,000,000 | ---D | C] -- C:\Users\Jens\Desktop\auto
[2014-04-06 11:02:51 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-04-04 15:45:46 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Local\Comodo
[2014-04-01 11:06:42 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Roaming\DropboxMaster
[2014-03-23 01:17:28 | 000,000,000 | ---D | C] -- C:\Users\Jens\Application Data
[2014-03-23 01:16:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XMind
[2014-03-23 01:15:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XMind
[2014-03-18 15:23:38 | 000,000,000 | ---D | C] -- C:\Users\Jens\Documents\Edraw Max
[2014-03-18 15:22:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Edraw Max 7.6
[2014-03-18 15:22:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Edraw Max
[2014-03-09 14:26:25 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Local\FluxSoftware
[2011-12-12 06:20:52 | 002,149,888 | ---- | C] (Python Software Foundation) -- C:\Program Files (x86)\python26.dll
[2009-11-05 05:33:04 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
[8 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014-04-07 17:27:00 | 000,001,000 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2523931591-3497646636-795491354-1000UA.job
[2014-04-07 17:11:00 | 000,000,994 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014-04-07 17:08:10 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-04-07 17:08:10 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-04-07 16:55:14 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014-04-07 16:53:05 | 000,000,990 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-04-07 16:52:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014-04-07 16:52:43 | 3111,518,208 | -HS- | M] () -- C:\hiberfil.sys
[2014-04-07 11:17:09 | 001,612,104 | ---- | M] () -- C:\Windows\SysWow64\setup.exe
[2014-04-07 11:02:48 | 000,000,856 | ---- | M] () -- C:\Users\Jens\Desktop\µTorrent.lnk
[2014-04-07 11:00:05 | 000,001,744 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Results.odt - genväg.lnk
[2014-04-06 21:27:01 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2523931591-3497646636-795491354-1000Core.job
[2014-04-01 11:06:47 | 000,001,054 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2014-04-01 11:06:42 | 000,000,880 | ---- | M] () -- C:\Windows\wininit.ini
[2014-03-31 12:27:45 | 001,574,104 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014-03-31 12:27:45 | 000,661,972 | ---- | M] () -- C:\Windows\SysNative\perfh01D.dat
[2014-03-31 12:27:45 | 000,652,376 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014-03-31 12:27:45 | 000,141,742 | ---- | M] () -- C:\Windows\SysNative\perfc01D.dat
[2014-03-31 12:27:45 | 000,121,308 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014-03-30 23:00:00 | 000,001,632 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\länkar.odt - genväg.lnk
[2014-03-27 18:59:45 | 000,000,066 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\mbam.context.scan
[2014-03-23 01:16:32 | 000,000,993 | ---- | M] () -- C:\Users\Jens\Desktop\XMind 2013.lnk
[2014-03-18 15:38:41 | 000,020,992 | ---- | M] () -- C:\Users\Jens\Desktop\Whiteboardinköp.eddx
[2014-03-18 15:22:52 | 000,000,999 | ---- | M] () -- C:\Users\Jens\Desktop\Edraw Max.lnk
[2014-03-17 19:47:51 | 000,001,697 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\random notes.odt - genväg.lnk
[2014-03-14 19:01:26 | 000,000,218 | ---- | M] () -- C:\Users\Jens\.recently-used.xbel
[2014-03-14 19:01:21 | 000,003,297 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\DreamPie
[2014-03-09 17:22:24 | 000,002,036 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Autostart - genväg (2).lnk
[2014-03-09 16:18:07 | 000,001,197 | ---- | M] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Capture.odt - genväg.lnk
[8 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014-04-07 11:17:09 | 001,612,104 | ---- | C] () -- C:\Windows\SysWow64\setup.exe
[2014-04-07 11:02:48 | 000,000,856 | ---- | C] () -- C:\Users\Jens\Desktop\µTorrent.lnk
[2014-04-07 11:00:05 | 000,001,744 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Results.odt - genväg.lnk
[2014-03-30 23:00:00 | 000,001,632 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\länkar.odt - genväg.lnk
[2014-03-27 18:59:45 | 000,000,066 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\mbam.context.scan
[2014-03-23 01:16:32 | 000,000,993 | ---- | C] () -- C:\Users\Jens\Desktop\XMind 2013.lnk
[2014-03-18 15:27:43 | 000,020,992 | ---- | C] () -- C:\Users\Jens\Desktop\Whiteboardinköp.eddx
[2014-03-18 15:22:52 | 000,000,999 | ---- | C] () -- C:\Users\Jens\Desktop\Edraw Max.lnk
[2014-03-17 19:47:51 | 000,001,697 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\random notes.odt - genväg.lnk
[2014-03-14 19:01:26 | 000,000,218 | ---- | C] () -- C:\Users\Jens\.recently-used.xbel
[2014-03-09 17:22:24 | 000,002,036 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Autostart - genväg (2).lnk
[2014-03-09 16:18:07 | 000,001,197 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Capture.odt - genväg.lnk
[2013-04-18 03:40:44 | 021,954,496 | ---- | C] () -- C:\Users\Jens\AppData\Local\TempFullTiltPokerEuSetup.exe
[2013-04-12 19:37:03 | 000,007,606 | ---- | C] () -- C:\Users\Jens\AppData\Local\Resmon.ResmonCfg
[2013-03-29 20:20:11 | 001,552,890 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013-03-28 15:54:40 | 000,000,880 | ---- | C] () -- C:\Windows\wininit.ini
[2012-10-12 14:47:57 | 149,692,413 | ---- | C] () -- C:\Users\Jens\Two.and.a.Half.Men.S10E03.HDTV.x264-LOL.mp4
[2012-10-12 14:45:54 | 142,770,927 | ---- | C] () -- C:\Users\Jens\The.Big.Bang.Theory.S06E03.HDTV.x264-LOL.mp4
[2012-08-26 20:45:51 | 001,887,546 | ---- | C] () -- C:\Users\Jens\Savoy___Magic_Bullets_feedthebrain.net.pdf
[2012-02-22 14:33:55 | 000,000,938 | -H-- | C] () -- C:\Users\Jens\.gitk
[2012-02-22 11:31:01 | 000,000,092 | ---- | C] () -- C:\Users\Jens\.gitconfig
[2011-12-12 06:23:11 | 000,000,290 | ---- | C] () -- C:\Program Files (x86)\protext.ini
[2011-10-03 02:36:38 | 000,003,297 | ---- | C] () -- C:\Users\Jens\AppData\Roaming\DreamPie
[2011-02-26 21:33:17 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010-10-09 02:06:58 | 000,000,000 | ---- | C] () -- C:\Users\Jens\AppData\Local\prvlcl.dat
 
========== ZeroAccess Check ==========
 
[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010-07-27 16:59:11 | 014,162,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010-07-27 16:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2011-12-14 18:07:46 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\.anki
[2011-11-15 01:01:07 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\AVG
[2014-02-24 20:52:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\BankID
[2011-12-12 23:07:34 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\benibela
[2012-12-21 21:14:02 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Canon
[2012-11-04 23:04:55 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2014-04-07 17:08:06 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Dropbox
[2014-04-01 11:06:44 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\DropboxMaster
[2013-04-21 04:54:26 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Foxit Software
[2013-11-18 15:02:51 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\GoPanda
[2013-12-18 22:32:38 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\gtk-2.0
[2013-06-19 06:20:05 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\HEM Data
[2013-06-20 20:06:03 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\HoldemManager
[2013-06-19 19:45:08 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\iid
[2012-03-01 21:53:21 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Internet Chess Club
[2013-12-22 09:59:20 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\kombilo
[2012-12-02 19:03:31 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\LyX2.0
[2011-12-13 19:04:39 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Miranda
[2011-12-08 16:55:22 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\mplayer
[2012-01-04 03:18:23 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Notepad++
[2010-11-07 21:34:51 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Octoshape
[2014-03-07 21:28:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\OpenOffice
[2010-06-18 22:11:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\OpenOffice.org
[2011-08-06 22:53:50 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Opera
[2014-02-24 20:50:31 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Personal
[2013-06-20 07:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\PokerCoach
[2010-06-18 17:50:52 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Sierra Wireless
[2013-04-29 09:28:22 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Spotify
[2011-05-24 23:03:41 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\SynthMaker
[2013-08-28 00:58:43 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\TS3Client
[2011-05-08 21:48:51 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Unified Remote
[2014-04-07 13:40:09 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\uTorrent
[2014-04-07 16:56:45 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\ViberPC
[2011-12-08 18:17:37 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\Windows Live Writer
[2013-04-08 00:02:56 | 000,000,000 | ---D | M] -- C:\Users\Jens\AppData\Roaming\WinPatrol
 
========== Purity Check ==========
 
 
 
< End of report >
 

 

The adware seems to be gone.


  • 0

#8
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,700 posts
Hey!

The adware seems to be gone.

Sounds good. :)

Are you able to uninstall SW-Sustainer 1.80 now?
  • 0

#9
okiol

okiol

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts

No, I'm not exactly sure what the problem is, but it looks like maybe I removed them in the wrong order?

 

"An error ocurred with the start of
C:\PROGRA~\ SW-BOO~1\ASSIST~1.DLL
We were unable to find the given module."

 

I'm translating from Swedish, so might not be 100% accurate.


  • 0

#10
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,700 posts
Hey,

Step 1: Chrome Extensions

Run Chrome and please enter this into the address bar: chrome:extensions
This will display a page of all installed extensions. Please remove the extensions in the list below by clicking the trash can icon beside each one.

Extensions to be removed:
  • NextCoup
Step 2: OTL Fix
  • Run OTL (If you have Windows Vista / Windows 7 / Windows 8 please do a Right click on the OTL icon and select Run as Administrator).
  • Copy (Ctrl+C) and Paste (Ctrl+V) all of the following text into the Custom Scans/Fixes box:


    :Commands
    [CREATERESTOREPOINT]
    
    :OTL
    File not found (No name found) -- C:\USERS\JENS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XGQ5BM67.DEFAULT\EXTENSIONS\{7690B97E-E48F-4053-8C05-91F0772BFA6C}
    File not found (No name found) -- C:\USERS\JENS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XGQ5BM67.DEFAULT\EXTENSIONS\[email protected]
    [2014-04-07 11:17:26 | 000,000,000 | ---D | C] -- C:\ProgramData\NextCoup
    [2014-04-07 11:17:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NextCoup
    [2014-04-07 11:17:25 | 000,000,000 | ---D | C] -- C:\Users\Jens\AppData\Local\Torch
    
    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}"=-
    
    
    :Commands
    [EMPTYTEMP]
    
  • Click the Run Fix button.
  • After your computer has rebooted, run OTL and click Quick Scan.
  • Copy and paste the contents of the log that it produces into your next post.
Step 3: SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :folderfind
    *SW-Sustainer*
    
    :filefind
    *SW-Sustainer*
    
    :regfind
    SW-Sustainer
    
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
  • 0

Advertisements


#11
okiol

okiol

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
step 2:
 
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
C:\ProgramData\NextCoup folder moved successfully.
C:\Program Files (x86)\NextCoup folder moved successfully.
C:\Users\Jens\AppData\Local\Torch\User Data\Default\Extensions\gcfijijikmncbeebokpkckgkpgnpfkao\1.0 folder moved successfully.
C:\Users\Jens\AppData\Local\Torch\User Data\Default\Extensions\gcfijijikmncbeebokpkckgkpgnpfkao folder moved successfully.
C:\Users\Jens\AppData\Local\Torch\User Data\Default\Extensions folder moved successfully.
C:\Users\Jens\AppData\Local\Torch\User Data\Default folder moved successfully.
C:\Users\Jens\AppData\Local\Torch\User Data folder moved successfully.
C:\Users\Jens\AppData\Local\Torch folder moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}\ not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administratör
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Gäst
 
User: HomeGroupUser$
 
User: Jens
->Temp folder emptied: 515846348 bytes
->Temporary Internet Files folder emptied: 365866 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 140573226 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: postgres
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: postgres.Jens-Dator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9440 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 11876584 bytes
 
Total Files Cleaned = 638,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 04072014_201121
 
Files\Folders moved on Reboot...
C:\Users\Jens\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\Jens\AppData\Local\Temp\~PI1C00.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PI1F3.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PI204.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PI2665.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PI8631.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PI8642.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PIAC6F.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PIC90.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PIC91.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PICEF.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PICF0.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PIEE4.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PIF24.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PIFFEE.tmp not found!
File\Folder C:\Users\Jens\AppData\Local\Temp\~PIFFEF.tmp not found!
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\Low\SkypeClickToCall\Logs\AutoUpdateSvc.log scheduled to be moved on reboot.
 
PendingFileRenameOperations files...
 
Registry entries deleted on Reboot...
 
step 3:
 
SystemLook 30.07.11 by jpshortstuff
Log created at 20:23 on 07/04/2014 by Jens
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.
 
========== folderfind ==========
 
Searching for "*SW-Sustainer*"
No folders found.
 
========== filefind ==========
 
Searching for "*SW-Sustainer*"
No files found.
 
========== regfind ==========
 
Searching for "SW-Sustainer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}]
"DisplayName"="SW-Sustainer 1.80"
 
-= EOF =-

  • 0

#12
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,700 posts
Hey,
looks good so far! ;)

Step 1: OTL Fix
  • Run OTL (If you have Windows Vista / Windows 7 / Windows 8 please do a Right click on the OTL icon and select Run as Administrator).
  • Copy (Ctrl+C) and Paste (Ctrl+V) all of the following text into the Custom Scans/Fixes box:


    :Commands
    [CREATERESTOREPOINT]
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}]
    
    :Commands
    [EMPTYTEMP]
    
  • Click the Run Fix button.
  • After your computer has rebooted, run OTL and click Quick Scan.
  • Copy and paste the contents of the log that it produces into your next post.
Step 2: MBAM

Please download Malwarebytes Anti-Malware to your desktop
Install the progamme and select update
Once it has updated select Settings > Detection and Protection
Tick Scan for rootkits

MBAMsettings.JPG

Go back to the Dashboard and select Scan Now

MBAMScan.JPG

If threats are detected, click the Apply Actions button, MBAM will ask for a reboot.

MBAMReboot.JPG

MBAMLog.JPG

On completion of the scan (or after the reboot) select View Detailed Log
Select Export > Select text file and save to the desktop
Attach/Post that log

Step 3: ESET

Please disable your AntiVirus before doing these steps!
  • If you have Win Vista / Win 7 / Win 8 please start IE as Administrator!
  • This will only work for Internet Explorer or FireFox
  • Please download ESET Online Scanner from here
How to do this?
  • Visit this website here
  • You will see a screen like this:

    e922iil8.png
    • Click Run ESET Online Scanner

      4e3svhbd.png
    • A Window will open (see above) - please click on the link
    • A window will pop up - please download the file to your Desktop
    • When the download has finished please run the program (for Win Vista/ Win7 / Win 8 User please run it as Administrator)

      p35jbmyy.png
    • Tick the box next to YES, I accept the Terms of Use then click on: Start
    • You may see a panel towards the top of the screen telling you the website wants to install an addon... click and allow it to install. If your firewall asks whether you want to allow installation, say yes.

      p3b9meru.png
    • Make sure that the option Remove found threats is NOT checked.
    • Make sure that the option Scan archives is checked.
    • Now click on Advanced Settings and select the following:
      • Scan for potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth Technology
    • Then click on Start
    • virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
    • When completed the Online Scan will begin automatically. The scan may take several hours.
    • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
    • After the scan is finished please click on Finish
  • Use notepad to open the logfile located at C:\Program Files (x86)\ESET\ESET Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic.
  • I want you to uninstall following programs (XP: Start > Control Panel > Add/Remove Programs | Vista / Win7 / Win8: Start > Control Panel > uninstall a program):
    • ESET Online Scanner
Step 4: SecurityCheck

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

  • 0

#13
okiol

okiol

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts

alright, this was a longer one ^^

 

step 1:

 

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}\ not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administratör
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Gäst
 
User: HomeGroupUser$
 
User: Jens
->Temp folder emptied: 322605 bytes
->Temporary Internet Files folder emptied: 174789 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 19950678 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: postgres
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: postgres.Jens-Dator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9356 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36140186 bytes
RecycleBin emptied: 183454491 bytes
 
Total Files Cleaned = 229,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 04082014_094804
 
Files\Folders moved on Reboot...
C:\Users\Jens\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\Low\SkypeClickToCall\Logs\AutoUpdateSvc.log scheduled to be moved on reboot.
 
PendingFileRenameOperations files...
 
Registry entries deleted on Reboot...
 
 
step 2:
 
uhm.... I uninstalled it before I copied the log file... it seems completely gone, only took whole day to run that script... fml...
 
step 3:
 

 Results of screen317's Security Check version 0.99.81  
 Windows 7  x64 (UAC is enabled)  
``````````````Antivirus/Firewall Check:`````````````` 
avast! Internet Security           
AVG Anti-Virus Free Edition 2012   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 AVG PC Tuneup 2011  
 Java™ 6 Update 18  
 Java 7 Update 25  
 Java version out of Date! 
 Adobe Flash Player 12.0.0.77  
 Mozilla Firefox 19.0.2 Firefox out of Date!  
 Google Chrome 33.0.1750.146  
 Google Chrome 33.0.1750.154  
````````Process Check: objlist.exe by Laurent````````  
 WinPatrol winpatrol.exe 
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 system32 AvastSvc.exe -?-   
 AVAST Software Avast AvastUI.exe  
 BillP Studios WinPatrol WinPatrol.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log`````````````````````` 
 

  • 0

#14
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,700 posts

uhm.... I uninstalled it before I copied the log file... it seems completely gone, only took whole day to run that script... fml...

Did it found anything?
  • 0

#15
okiol

okiol

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts

don't know, it was at it for hours, then I came back and the computer was off so I figured it had finished.


  • 0






Similar Topics


Also tagged with one or more of these keywords: swbooster, sw-booster, adware

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP