OTL logfile created on: 14.12.2011 14:25:57 - Run 1 |
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\xxxx\Desktop |
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation |
Internet Explorer (Version = 8.0.7601.17514) |
Locale: 00000407 |
|
4,00 Gb Total Physical Memory |
10,83 Gb Paging File |
Paging file location(s): h:\pagefile.sys 7000 7000 [binary data] |
|
%SystemDrive% = C: |
Drive C: |
Drive E: |
Drive F: |
Drive G: |
Drive H: |
Drive K: |
|
Computer Name: PC-HOME |
Boot Mode: Normal |
Company Name Whitelist: On |
|
========== Processes (SafeList) ========== |
|
PRC - [2011.12.14 14:24:47 |
PRC - [2011.11.29 14:00:56 |
PRC - [2011.10.15 09:53:00 |
PRC - [2011.10.15 00:54:40 |
PRC - [2011.08.31 16:00:48 |
PRC - [2011.07.02 16:53:25 |
PRC - [2011.06.06 11:55:28 |
PRC - [2011.03.28 15:15:04 |
PRC - [2011.03.28 15:14:56 |
PRC - [2010.05.04 11:07:22 |
|
|
========== Modules (No Company Name) ========== |
|
|
========== Win32 Services (SafeList) ========== |
|
SRV - [2011.11.29 14:00:56 |
SRV - [2011.10.15 09:53:00 |
SRV - [2011.10.15 00:54:40 |
SRV - [2011.08.31 16:00:48 |
SRV - [2011.08.23 07:43:40 |
SRV - [2011.07.02 16:53:25 |
SRV - [2011.07.01 10:46:40 |
SRV - [2011.06.06 11:55:28 |
SRV - [2011.03.28 15:15:04 |
SRV - [2010.05.04 11:07:22 |
SRV - [2010.03.18 13:16:28 |
SRV - [2009.06.10 22:23:09 |
|
|
========== Driver Services (SafeList) ========== |
|
DRV:64bit: - [2011.10.25 14:16:29 |
DRV:64bit: - [2011.08.31 16:00:50 |
DRV:64bit: - [2011.07.06 16:33:56 |
DRV:64bit: - [2011.07.02 16:53:25 |
DRV:64bit: - [2011.07.02 16:53:25 |
DRV:64bit: - [2011.04.26 10:21:06 |
DRV:64bit: - [2011.02.18 06:40:06 |
DRV:64bit: - [2011.02.18 05:47:42 |
DRV:64bit: - [2011.02.18 05:47:42 |
DRV:64bit: - [2010.11.20 14:33:35 |
DRV:64bit: - [2010.11.20 14:32:47 |
DRV:64bit: - [2010.11.20 14:32:46 |
DRV:64bit: - [2010.11.20 12:07:05 |
DRV:64bit: - [2009.07.14 02:52:20 |
DRV:64bit: - [2009.07.14 02:48:04 |
DRV:64bit: - [2009.07.14 02:45:55 |
DRV:64bit: - [2009.07.14 01:09:50 |
DRV:64bit: - [2009.06.10 21:35:42 |
DRV:64bit: - [2009.06.10 21:35:36 |
DRV:64bit: - [2009.06.10 21:34:33 |
DRV:64bit: - [2009.06.10 21:34:28 |
DRV:64bit: - [2009.06.10 21:34:23 |
DRV:64bit: - [2009.06.10 21:31:59 |
DRV - [2009.07.14 02:19:10 |
|
|
========== Standard Registry (SafeList) ========== |
|
|
========== Internet Explorer ========== |
|
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm |
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 |
|
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,DefaultNetworkProfile = 476158464 |
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.facemoods.com/?a=ddrnw |
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp |
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de |
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CB 60 8C B0 69 0A CC 01 [binary data] |
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 |
|
========== FireFox ========== |
|
|
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) |
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () |
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) |
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) |
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB) |
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) |
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) |
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) |
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) |
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) |
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) |
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) |
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) |
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) |
|
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.09 20:35:40 |
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins |
|
[2011.10.19 17:53:11 |
[2011.12.07 16:18:51 |
[2011.10.23 11:07:29 |
[2011.09.07 14:03:22 |
[2011.10.23 11:07:29 |
() (No name found) -- C:\USERS\BIGBABA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NRZ89SMY.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI |
() (No name found) -- C:\USERS\BIGBABA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NRZ89SMY.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI |
[2011.11.09 20:35:40 |
[2011.09.29 02:24:37 |
[2011.09.29 02:16:42 |
[2011.09.29 02:24:37 |
[2011.09.07 14:01:13 |
[2011.09.29 02:24:37 |
[2011.09.29 02:24:37 |
[2011.09.29 02:24:37 |
|
O1 HOSTS File: ([2009.06.10 22:00:26 |
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) |
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll File not found |
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll File not found |
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) |
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) |
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) |
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found |
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 |
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 |
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 |
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 |
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found |
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found |
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) |
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) |
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation) |
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) |
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) |
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Windows\SysWOW64\PrxerNsp.dll (Initex Software) |
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\PrxerDrv.dll (Initex Software) |
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\PrxerDrv.dll (Initex Software) |
O1364bit: - gopher Prefix: missing |
O13 - gopher Prefix: missing |
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) |
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) |
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) |
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 |
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{51AF8F05-0945-42A9-B671-70242DE0E3E1}: DhcpNameServer = 192.168.2.1 |
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF5C77E4-85F6-44A2-A91B-4623E06ED25D}: DhcpNameServer = 193.125.152.3 195.24.72.6 89.16.173.11 87.118.104.203 |
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF5C77E4-85F6-44A2-A91B-4623E06ED25D}: NameServer = 213.73.91.35,8.8.4.4 |
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ED120F95-5020-4229-BA4B-04B0DBB0BF49}: DhcpNameServer = 192.168.42.129 |
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found |
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found |
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) |
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) |
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) |
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) |
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) |
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found |
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) |
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) |
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found |
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. |
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. |
O32 - HKLM CDRom: AutoRun - 1 |
O32 - AutoRun File - [2011.09.09 20:35:07 |
O32 - AutoRun File - [2011.10.07 23:43:22 |
O33 - MountPoints2\{e3c935dc-a7c6-11e0-af81-00241dd6f30e}\Shell - "" = AutoRun |
O33 - MountPoints2\{e3c935dc-a7c6-11e0-af81-00241dd6f30e}\Shell\AutoRun\command - "" = I:\SETUP.EXE |
O33 - MountPoints2\{e3c935dc-a7c6-11e0-af81-00241dd6f30e}\Shell\configure\command - "" = I:\SETUP.EXE |
O33 - MountPoints2\{e3c935dc-a7c6-11e0-af81-00241dd6f30e}\Shell\install\command - "" = I:\SETUP.EXE |
O34 - HKLM BootExecute: (autocheck autochk *) |
O35:64bit: - HKLM\..comfile [open] -- "%1" %* |
O35:64bit: - HKLM\..exefile [open] -- "%1" %* |
O35 - HKLM\..comfile [open] -- "%1" %* |
O35 - HKLM\..exefile [open] -- "%1" %* |
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* |
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* |
O37 - HKLM\...com [@ = comfile] -- "%1" %* |
O37 - HKLM\...exe [@ = exefile] -- "%1" %* |
|
========== Files/Folders - Created Within 30 Days ========== |
|
[2011.12.14 14:24:36 |
[2011.12.02 14:46:06 |
[2011.12.02 14:46:06 |
[2011.12.02 14:46:05 |
[2011.12.02 14:46:05 |
[2011.11.29 19:51:15 |
[2011.11.29 16:01:11 |
[2011.11.29 15:59:10 |
[2011.11.29 15:59:10 |
[2011.11.29 14:08:18 |
[2011.11.29 14:08:01 |
[2011.11.28 19:38:26 |
[2011.11.28 19:35:17 |
[2011.11.28 17:25:45 |
[2011.11.28 17:25:39 |
[2011.11.28 16:18:55 |
[2011.11.28 16:18:39 |
[2011.11.28 16:18:28 |
[2011.11.28 16:18:17 |
[2011.11.28 16:18:17 |
[2011.11.28 16:18:17 |
[2011.11.28 16:17:38 |
[2011.11.18 19:42:40 |
[2011.11.18 19:36:54 |
[2011.11.18 19:35:47 |
[2011.11.18 19:13:19 |
[2011.11.17 15:43:04 |
[2011.11.17 15:43:04 |
[2011.11.17 15:43:04 |
[2011.11.17 15:42:49 |
[2011.11.17 15:42:44 |
[2011.11.17 12:11:03 |
[2011.11.14 16:22:06 |
[2011.11.14 16:22:06 |
[2011.11.14 16:21:50 |
[2011.11.14 16:21:08 |
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] |
|
========== Files - Modified Within 30 Days ========== |
|
[2011.12.14 14:24:47 |
[2011.12.14 14:22:45 |
[2011.12.14 13:37:10 |
[2011.12.14 13:35:49 |
[2011.12.14 13:35:49 |
[2011.12.14 13:32:34 |
[2011.12.14 13:32:34 |
[2011.12.14 13:32:34 |
[2011.12.14 13:32:34 |
[2011.12.14 13:32:34 |
[2011.12.14 13:28:16 |
[2011.12.14 13:28:04 |
[2011.12.14 13:27:56 |
[2011.12.13 22:30:50 |
[2011.12.09 16:05:34 |
[2011.12.06 12:31:15 |
[2011.12.05 19:28:53 |
[2011.12.05 19:28:53 |
[2011.12.05 18:52:01 |
[2011.11.29 19:51:15 |
[2011.11.29 14:01:24 |
[2011.11.29 14:00:56 |
[2011.11.28 16:40:34 |
[2011.11.18 19:36:19 |
[2011.11.18 19:12:52 |
[2011.11.17 17:27:41 |
[2011.11.17 15:43:04 |
[2011.11.14 16:21:50 |
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] |
|
========== Files Created - No Company Name ========== |
|
[2011.12.14 14:22:45 |
[2011.12.02 14:46:07 |
[2011.11.29 19:51:15 |
[2011.11.29 14:08:22 |
[2011.11.28 17:25:45 |
[2011.11.28 17:25:02 |
[2011.11.28 17:25:02 |
[2011.11.28 17:25:00 |
[2011.11.28 16:18:28 |
[2011.11.23 17:37:03 |
[2011.11.18 19:36:19 |
[2011.11.18 19:12:52 |
[2011.11.17 17:27:41 |
[2011.11.17 17:27:41 |
[2011.11.17 15:43:04 |
[2011.11.14 16:21:50 |
[2011.11.12 14:41:22 |
[2011.10.15 00:54:52 |
[2011.05.12 14:47:12 |
[2011.04.09 17:55:28 |
[2009.07.14 06:38:36 |
[2009.07.14 03:35:51 |
[2009.07.14 03:34:42 |
[2009.07.14 01:10:29 |
[2009.07.14 00:42:10 |
[2009.07.13 22:03:59 |
[2009.06.10 22:26:10 |
|
========== LOP Check ========== |
|
[2011.12.13 22:27:26 |
[2011.07.06 16:34:56 |
[2011.10.06 14:53:32 |
[2011.11.28 16:48:48 |
[2011.11.17 15:49:19 |
[2011.10.25 17:43:34 |
[2011.06.20 16:02:58 |
[2011.10.05 09:00:28 |
|
========== Purity Check ========== |
|
|
< End of report > |